ื›ื™ืฆื“ ืœื”ื’ื“ื™ืจ ื›ืจืื•ื™ SNI ื‘-Zimbra OSE?

ื‘ืชื—ื™ืœืช ื”ืžืื” ื”-21, ืžืฉืื‘ ื›ืžื• ื›ืชื•ื‘ื•ืช IPv4 ื ืžืฆื ืขืœ ืกืฃ ืžื™ืฆื•ื™. ืขื•ื“ ื‘-2011, IANA ื”ืงืฆืชื” ืืช ื—ืžืฉืช ื”-/8 ื‘ืœื•ืงื™ื ื”ืื—ืจื•ื ื™ื ืฉื ื•ืชืจื• ืžืžืจื—ื‘ ื”ื›ืชื•ื‘ื•ืช ืฉืœื” ืœืจืฉืžื™ ืื™ื ื˜ืจื ื˜ ืื–ื•ืจื™ื™ื, ื•ื›ื‘ืจ ื‘-2017 ืื–ืœื• ื”ื›ืชื•ื‘ื•ืช. ื”ืชืฉื•ื‘ื” ืœืžื—ืกื•ืจ ื”ืงื˜ืกื˜ืจื•ืคืœื™ ื‘ื›ืชื•ื‘ื•ืช IPv4 ื”ื™ื™ืชื” ืœื ืจืง ื”ื•ืคืขืช ืคืจื•ื˜ื•ืงื•ืœ IPv6, ืืœื ื’ื ื˜ื›ื ื•ืœื•ื’ื™ื™ืช SNI, ืฉืืคืฉืจื” ืœืืจื— ืžืกืคืจ ืขืฆื•ื ืฉืœ ืืชืจื™ื ืขืœ ื›ืชื•ื‘ืช IPv4 ืื—ืช. ื”ืžื”ื•ืช ืฉืœ SNI ื”ื™ื ืฉื”ืจื—ื‘ื” ื–ื• ืžืืคืฉืจืช ืœืœืงื•ื—ื•ืช, ื‘ืžื”ืœืš ืชื”ืœื™ืš ืœื—ื™ืฆืช ื”ื™ื“, ืœื•ืžืจ ืœืฉืจืช ืืช ืฉื ื”ืืชืจ ืืœื™ื• ื”ื•ื ืจื•ืฆื” ืœื”ืชื—ื‘ืจ. ื–ื” ืžืืคืฉืจ ืœืฉืจืช ืœืื—ืกืŸ ืื™ืฉื•ืจื™ื ืžืจื•ื‘ื™ื, ืžื” ืฉืื•ืžืจ ืฉืžืกืคืจ ื“ื•ืžื™ื™ื ื™ื ื™ื›ื•ืœื™ื ืœืคืขื•ืœ ืขืœ ื›ืชื•ื‘ืช IP ืื—ืช. ื˜ื›ื ื•ืœื•ื’ื™ื™ืช SNI ื”ืคื›ื” ืœืคื•ืคื•ืœืจื™ืช ื‘ืžื™ื•ื—ื“ ื‘ืงืจื‘ ืกืคืงื™ SaaS ืœืขืกืงื™ื, ืฉื™ืฉ ืœื”ื ื”ื–ื“ืžื ื•ืช ืœืืจื— ืžืกืคืจ ื›ืžืขื˜ ื‘ืœืชื™ ืžื•ื’ื‘ืœ ืฉืœ ื“ื•ืžื™ื™ื ื™ื ืœืœื ืงืฉืจ ืœืžืกืคืจ ื›ืชื•ื‘ื•ืช ื”-IPv4 ื”ื ื“ืจืฉื•ืช ืœื›ืš. ื‘ื•ืื• ืœื’ืœื•ืช ื›ื™ืฆื“ ื ื™ืชืŸ ืœื™ื™ืฉื ืชืžื™ื›ืช SNI ื‘ืžื”ื“ื•ืจืช ืงื•ื“ ืคืชื•ื— ืฉืœ Zimbra Collaboration Suite.

ื›ื™ืฆื“ ืœื”ื’ื“ื™ืจ ื›ืจืื•ื™ SNI ื‘-Zimbra OSE?

SNI ืขื•ื‘ื“ ื‘ื›ืœ ื”ื’ืจืกืื•ืช ื”ืขื“ื›ื ื™ื•ืช ื•ื”ื ืชืžื›ื•ืช ืฉืœ Zimbra OSE. ืื ื™ืฉ ืœืš Zimbra Open-Source ืฉืคื•ืขืœ ืขืœ ืชืฉืชื™ืช ืžืจื•ื‘ืช ืฉืจืชื™ื, ืชืฆื˜ืจืš ืœื‘ืฆืข ืืช ื›ืœ ื”ืฉืœื‘ื™ื ืฉืœื”ืœืŸ ื‘ืฆื•ืžืช ืขื ืฉืจืช Zimbra Proxy ืžื•ืชืงืŸ. ื‘ื ื•ืกืฃ, ืชื–ื“ืงืง ืœื–ื•ื’ื•ืช ืื™ืฉื•ืจ+ืžืคืชื— ืชื•ืืžื™ื, ื›ืžื• ื’ื ืฉืจืฉืจื•ืช ืื™ืฉื•ืจื™ื ืžื”ื™ืžื ื•ืช ืžื”-CA ืฉืœืš ืขื‘ื•ืจ ื›ืœ ืื—ื“ ืžื”ื“ื•ืžื™ื™ื ื™ื ืฉื‘ืจืฆื•ื ืš ืœืืจื— ื‘ื›ืชื•ื‘ืช ื”-IPv4 ืฉืœืš. ืฉื™ืžื• ืœื‘ ืฉื”ื’ื•ืจื ืœืจื•ื‘ ื”ืžื•ื—ืœื˜ ืฉืœ ื”ืฉื’ื™ืื•ืช ื‘ืขืช ื”ื’ื“ืจืช SNI ื‘-Zimbra OSE ื”ื•ื ื‘ื“ื™ื•ืง ืงื‘ืฆื™ื ืฉื’ื•ื™ื™ื ืขื ืื™ืฉื•ืจื™ื. ืœื›ืŸ, ืื ื• ืžืžืœื™ืฆื™ื ืœืš ืœื‘ื“ื•ืง ื”ื™ื˜ื‘ ื”ื›ืœ ืœืคื ื™ ื”ืชืงื ืชื ื™ืฉื™ืจื•ืช.

ืงื•ื“ื ื›ืœ, ื›ื“ื™ ืฉ-SNI ื™ืขื‘ื•ื“ ื›ืจื’ื™ืœ, ืืชื” ืฆืจื™ืš ืœื”ื–ื™ืŸ ืืช ื”ืคืงื•ื“ื” zmprov mcf zimbraReverseProxySNIEEnabled TRUE ื‘ืฆื•ืžืช ื”-Proxy ืฉืœ Zimbra, ื•ืœืื—ืจ ืžื›ืŸ ื”ืคืขืœ ืžื—ื“ืฉ ืืช ืฉื™ืจื•ืช ื”-Proxy ื‘ืืžืฆืขื•ืช ื”ืคืงื•ื“ื” ื”ืคืขืœื” ืžื—ื“ืฉ ืฉืœ zmproxyctl.

ื ืชื—ื™ืœ ื‘ื™ืฆื™ืจืช ืฉื ื“ื•ืžื™ื™ืŸ. ืœื“ื•ื’ืžื”, ื ื™ืงื— ืืช ื”ื“ื•ืžื™ื™ืŸ company.ru ื•ืœืื—ืจ ืฉื”ื“ื•ืžื™ื™ืŸ ื›ื‘ืจ ื ื•ืฆืจ, ื ื—ืœื™ื˜ ืขืœ ืฉื ื”ืžืืจื— ื”ื•ื™ืจื˜ื•ืืœื™ ืฉืœ Zimbra ื•ื›ืชื•ื‘ืช ื”-IP ื”ื•ื™ืจื˜ื•ืืœื™ืช. ืฉื™ืžื• ืœื‘ ืฉืฉื ื”ืžืืจื— ื”ื•ื™ืจื˜ื•ืืœื™ ืฉืœ Zimbra ื—ื™ื™ื‘ ืœื”ืชืื™ื ืœืฉื ืฉืขืœ ื”ืžืฉืชืžืฉ ืœื”ื–ื™ืŸ ื‘ื“ืคื“ืคืŸ ื›ื“ื™ ืœื’ืฉืช ืœื“ื•ืžื™ื™ืŸ, ื•ื›ืŸ ืœื”ืชืื™ื ืœืฉื ื”ืžืฆื•ื™ืŸ ื‘ืชืขื•ื“ื”. ืœื“ื•ื’ืžื”, ื‘ื•ืื• ื ื™ืงื— ืืช Zimbra ื›ืฉื ื”ืžืืจื— ื”ื•ื™ืจื˜ื•ืืœื™ mail.company.ru, ื•ื›ื›ืชื•ื‘ืช IPv4 ื•ื™ืจื˜ื•ืืœื™ืช ืื ื• ืžืฉืชืžืฉื™ื ื‘ื›ืชื•ื‘ืช 1.2.3.4.

ืœืื—ืจ ืžื›ืŸ, ืคืฉื•ื˜ ื”ื–ืŸ ืืช ื”ืคืงื•ื“ื” zmprov md company.ru zimbraVirtualHostName mail.company.ru zimbraVirtualIPAddress 1.2.3.4ืœืื’ื“ ืืช ื”ืžืืจื— ื”ื•ื™ืจื˜ื•ืืœื™ ืฉืœ Zimbra ืœื›ืชื•ื‘ืช IP ื•ื™ืจื˜ื•ืืœื™ืช. ืฉื™ืžื• ืœื‘ ืฉืื ื”ืฉืจืช ืžืžื•ืงื ืžืื—ื•ืจื™ NAT โ€‹โ€‹ืื• ื—ื•ืžืช ืืฉ, ืขืœื™ื›ื ืœื•ื•ื“ื ืฉื›ืœ ื”ื‘ืงืฉื•ืช ืœื“ื•ืžื™ื™ืŸ ื™ืขื‘ืจื• ืœื›ืชื•ื‘ืช ื”-IP ื”ื—ื™ืฆื•ื ื™ืช ื”ืžืฉื•ื™ื›ืช ืืœื™ื•, ื•ืœื ืœื›ืชื•ื‘ืช ืฉืœื• ื‘ืจืฉืช ื”ืžืงื•ืžื™ืช.

ืœืื—ืจ ืฉื”ื›ืœ ื ืขืฉื”, ื›ืœ ืฉื ื•ืชืจ ื”ื•ื ืœื‘ื“ื•ืง ื•ืœื”ื›ื™ืŸ ืืช ืื™ืฉื•ืจื™ ื”ื“ื•ืžื™ื™ืŸ ืœื”ืชืงื ื”, ื•ืœืื—ืจ ืžื›ืŸ ืœื”ืชืงื™ืŸ ืื•ืชื.

ืื ื”ื ืคืงืช ืชืขื•ื“ืช ื“ื•ืžื™ื™ืŸ ื”ื•ืฉืœืžื” ื›ื”ืœื›ื”, ืืžื•ืจื™ื ืœื”ื™ื•ืช ืœืš ืฉืœื•ืฉื” ืงื‘ืฆื™ื ืขื ืชืขื•ื“ื•ืช: ืฉื ื™ื™ื ืžื”ื ื”ื ืฉืจืฉืจื•ืช ืฉืœ ืชืขื•ื“ื•ืช ืžืจืฉื•ืช ื”ืื™ืฉื•ืจื™ื ืฉืœืš, ื•ืื—ื“ ื”ื•ื ืชืขื•ื“ื” ื™ืฉื™ืจื” ืœื“ื•ืžื™ื™ืŸ. ื‘ื ื•ืกืฃ, ืขืœื™ืš ืœื”ื—ื–ื™ืง ื‘ืงื•ื‘ืฅ ืขื ื”ืžืคืชื— ื‘ื• ื”ืฉืชืžืฉืช ืœืงื‘ืœืช ื”ืชืขื•ื“ื”. ืฆื•ืจ ืชื™ืงื™ื” ื ืคืจื“ืช /tmp/company.ru ื•ื”ืฆื‘ ืฉื ืืช ื›ืœ ื”ืงื‘ืฆื™ื ื”ื–ืžื™ื ื™ื ืขื ืžืคืชื—ื•ืช ื•ืชืขื•ื“ื•ืช. ื”ืชื•ืฆืื” ื”ืกื•ืคื™ืช ืฆืจื™ื›ื” ืœื”ื™ื•ืช ืžืฉื”ื• ื›ื–ื”:

ls /tmp/company.ru
company.ru.key
 company.ru.crt
 company.ru.root.crt
 company.ru.intermediate.crt

ืœืื—ืจ ืžื›ืŸ, ื ืฉืœื‘ ืืช ืฉืจืฉืจืื•ืช ื”ืื™ืฉื•ืจื™ื ืœืงื•ื‘ืฅ ืื—ื“ ื‘ืืžืฆืขื•ืช ื”ืคืงื•ื“ื” cat company.ru.root.crt company.ru.intermediate.crt >> company.ru_ca.crt ื•ืœื•ื•ื“ื ืฉื”ื›ืœ ืžืกื•ื“ืจ ืขื ื”ืชืขื•ื“ื•ืช ื‘ืืžืฆืขื•ืช ื”ืคืงื•ื“ื” /opt/zimbra/bin/zmcertmgr verifycrt comm /tmp/company.ru/company.ru.key /tmp/company.ru/company.ru.crt /tmp/company.ru/company.ru_ca.crt. ืœืื—ืจ ืฉืื™ืžื•ืช ื”ืื™ืฉื•ืจื™ื ื•ื”ืžืคืชื— ื”ืฆืœื™ื—, ืชื•ื›ืœ ืœื”ืชื—ื™ืœ ืœื”ืชืงื™ืŸ ืื•ืชื.

ืขืœ ืžื ืช ืœื”ืชื—ื™ืœ ื‘ื”ืชืงื ื”, ื ืฉืœื‘ ืชื—ื™ืœื” ืืช ืชืขื•ื“ืช ื”ื“ื•ืžื™ื™ืŸ ื•ืจืฉืชื•ืช ืžื”ื™ืžื ื•ืช ืžืจืฉื•ื™ื•ืช ื”ืื™ืฉื•ืจื™ื ืœืงื•ื‘ืฅ ืื—ื“. ื ื™ืชืŸ ืœืขืฉื•ืช ื–ืืช ื’ื ื‘ืืžืฆืขื•ืช ืคืงื•ื“ื” ืื—ืช ื›ืžื• cat company.ru.crt company.ru_ca.crt >> company.ru.bundle. ืœืื—ืจ ืžื›ืŸ, ืขืœื™ืš ืœื”ืคืขื™ืœ ืืช ื”ืคืงื•ื“ื” ื›ื“ื™ ืœื›ืชื•ื‘ ืืช ื›ืœ ื”ืื™ืฉื•ืจื™ื ื•ื”ืžืคืชื— ืœ-LDAP: /opt/zimbra/libexec/zmdomaincertmgr savecrt company.ru company.ru.bundle company.ru.keyื•ืœืื—ืจ ืžื›ืŸ ื”ืชืงืŸ ืืช ื”ืื™ืฉื•ืจื™ื ื‘ืืžืฆืขื•ืช ื”ืคืงื•ื“ื” /opt/zimbra/libexec/zmdomaincertmgr deploycrts. ืœืื—ืจ ื”ื”ืชืงื ื”, ื”ืื™ืฉื•ืจื™ื ื•ื”ืžืคืชื— ืœื“ื•ืžื™ื™ืŸ company.ru ื™ืื•ื—ืกื ื• ื‘ืชื™ืงื™ื™ื” /opt/zimbra/conf/domaincerts/company.ru

ืขืœ ื™ื“ื™ ื—ื–ืจื” ืขืœ ืฉืœื‘ื™ื ืืœื” ื‘ืืžืฆืขื•ืช ืฉืžื•ืช ื“ื•ืžื™ื™ื ื™ื ืฉื•ื ื™ื ืืš ื‘ืื•ืชื” ื›ืชื•ื‘ืช IP, ื ื™ืชืŸ ืœืืจื— ื›ืžื” ืžืื•ืช ื“ื•ืžื™ื™ื ื™ื ื‘ื›ืชื•ื‘ืช IPv4 ืื—ืช. ื‘ืžืงืจื” ื–ื”, ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ืชืขื•ื“ื•ืช ืžืžื’ื•ื•ืŸ ืžืจื›ื–ื™ ื”ื ืคืงื” ืœืœื ื›ืœ ื‘ืขื™ื”. ืืชื” ื™ื›ื•ืœ ืœื‘ื“ื•ืง ืืช ื ื›ื•ื ื•ืช ื›ืœ ื”ืคืขื•ืœื•ืช ืฉื‘ื•ืฆืขื• ื‘ื›ืœ ื“ืคื“ืคืŸ, ื›ืืฉืจ ื›ืœ ืฉื ืžืืจื— ื•ื™ืจื˜ื•ืืœื™ ืฆืจื™ืš ืœื”ืฆื™ื’ ืชืขื•ื“ืช SSL ืžืฉืœื•. 

ืœื›ืœ ื”ืฉืืœื•ืช ื”ืงืฉื•ืจื•ืช ืœ-Zextras Suite, ื ื™ืชืŸ ืœื™ืฆื•ืจ ืงืฉืจ ืขื ื ืฆื™ื’ืช Zextras Ekaterina Triandafilidi ื‘ื“ื•ืืจ ืืœืงื˜ืจื•ื ื™ [ืžื•ื’ืŸ ื‘ื“ื•ื"ืœ]

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”