ื‘ื™ื˜ื•ืœ ื‘ื›ืžื•ืช ื’ื“ื•ืœื” ืฉืœ ืื™ืฉื•ืจื™ Let's Encrypt

Let's Encrypt ื”ื™ื ืจืฉื•ืช ืื™ืฉื•ืจื™ื ืœืœื ืžื˜ืจื•ืช ืจื•ื•ื— ื”ื ืฉืœื˜ืช ืขืœ ื™ื“ื™ ืงื”ื™ืœื” ื”ืžืกืคืงืช ืื™ืฉื•ืจื™ื ื‘ื—ื™ื ื ืœื›ื•ืœื. ื”ื–ื”ื™ืจ ืขืœ ื”ื‘ื™ื˜ื•ืœ ื”ืงืจื•ื‘ ืฉืœ ืชืขื•ื“ื•ืช TLS/SSL ืจื‘ื•ืช ืฉื”ื•ื ืคืงื• ื‘ืขื‘ืจ. ืžืชื•ืš 116 ืžื™ืœื™ื•ืŸ ืื™ืฉื•ืจื™ Let's Encrypt ื”ืชืงืคื™ื ื›ื™ื•ื, ืงืฆืช ื™ื•ืชืจ ืž-3 ืžื™ืœื™ื•ืŸ (2.6%) ื™ื‘ื•ื˜ืœื•, ืžืชื•ื›ื ื›ืžื™ืœื™ื•ืŸ ื›ืคื•ืœื™ื ื”ืงืฉื•ืจื™ื ืœืื•ืชื• ืชื—ื•ื (ื”ืฉื’ื™ืื” ืคื’ืขื” ื‘ืขื™ืงืจ ื‘ืชืขื•ื“ื•ืช ืฉืžืชืขื“ื›ื ื•ืช ื‘ืชื“ื™ืจื•ืช ื’ื‘ื•ื”ื”, ื›ืœื•ืžืจ ืœืžื” ื™ืฉ ื›ืœ ื›ืš ื”ืจื‘ื” ื›ืคื™ืœื•ื™ื•ืช). ื”ืจื™ืงื•ืœ ืžืชื•ื›ื ืŸ ืœ-1 ื‘ืžืจืฅ (ื”ืฉืขื” ื”ืžื“ื•ื™ืงืช ื˜ืจื ื ืงื‘ืขื”, ืืš ื”ืจื™ืงื•ืœ ื™ืชืจื—ืฉ ืจืง ื‘ืฉืขื” 4:3 MSK).

ื”ืฆื•ืจืš ื‘ืจื™ืงื•ืœ ื ื•ื‘ืข ืžื”ื’ื™ืœื•ื™ ื‘-29 ื‘ืคื‘ืจื•ืืจ ื‘ื˜ืขื•ืช. ื”ื‘ืขื™ื” ืžื•ืคื™ืขื” ืžืื– 25 ื‘ื™ื•ืœื™ 2019 ื•ืžืฉืคื™ืขื” ืขืœ ื”ืžืขืจื›ืช ืœื‘ื“ื™ืงืช ืจืฉื•ืžื•ืช CAA ื‘-DNS. ืฉื™ื CAA (RFC-6844,ืื™ืฉื•ืจ ืจืฉื•ืช ืื™ืฉื•ืจื™ื) ืžืืคืฉืจ ืœื‘ืขืœ ื”ื“ื•ืžื™ื™ืŸ ืœื”ื’ื“ื™ืจ ื‘ืžืคื•ืจืฉ ืจืฉื•ืช ืื™ืฉื•ืจื™ื ื‘ืืžืฆืขื•ืชื” ื ื™ืชืŸ ืœื”ืคื™ืง ืื™ืฉื•ืจื™ื ืขื‘ื•ืจ ืชื—ื•ื ืžื•ื’ื“ืจ. ืื CA ืื™ื ื• ืจืฉื•ื ื‘ืจืฉื•ืžื•ืช ื”-CAA, ืขืœื™ื• ืœื—ืกื•ื ืืช ื”ื ืคืงืช ื”ืื™ืฉื•ืจื™ื ืขื‘ื•ืจ ื“ื•ืžื™ื™ืŸ ื ืชื•ืŸ ื•ืœื™ื™ื“ืข ืืช ื‘ืขืœ ื”ื“ื•ืžื™ื™ืŸ ืขืœ ื ื™ืกื™ื•ื ื•ืช ืคืฉืจื”. ื‘ืจื•ื‘ ื”ืžืงืจื™ื, ื”ืื™ืฉื•ืจ ืžืชื‘ืงืฉ ืžื™ื“ ืœืื—ืจ ืžืขื‘ืจ ื‘ื“ื™ืงืช CAA, ืืš ืชื•ืฆืืช ื”ื‘ื“ื™ืงื” ื ื—ืฉื‘ืช ืœืชืงืคื” ืœืžืฉืš 30 ื™ื•ื ื ื•ืกืคื™ื. ื”ื›ืœืœื™ื ืžื—ื™ื™ื‘ื™ื ื’ื ืœื‘ืฆืข ืื™ืžื•ืช ื—ื•ื–ืจ ืœื ื™ืื•ื—ืจ ืž-8 ืฉืขื•ืช ืœืคื ื™ ื”ื ืคืงืช ืชืขื•ื“ื” ื—ื“ืฉื” (ื›ืœื•ืžืจ, ืื ื—ืœืคื• 8 ืฉืขื•ืช ืžื”ื‘ื“ื™ืงื” ื”ืื—ืจื•ื ื” ื‘ืขืช ื‘ืงืฉืช ืชืขื•ื“ื” ื—ื“ืฉื”, ื ื“ืจืฉ ืื™ืžื•ืช ื—ื•ื–ืจ).

ื”ืฉื’ื™ืื” ืžืชืจื—ืฉืช ืื ื‘ืงืฉืช ื”ืื™ืฉื•ืจ ืžื›ืกื” ืžืกืคืจ ืฉืžื•ืช ื“ื•ืžื™ื™ืŸ ื‘ื•-ื–ืžื ื™ืช, ืฉื›ืœ ืื—ื“ ืžื”ื ื“ื•ืจืฉ ื‘ื“ื™ืงืช ืจืฉื•ืžื•ืช CAA. ืžื”ื•ืช ื”ืฉื’ื™ืื” ื”ื™ื ืฉื‘ื–ืžืŸ ื”ื‘ื“ื™ืงื” ืžื—ื“ืฉ, ื‘ืžืงื•ื ืื™ืžื•ืช ื›ืœ ื”ื“ื•ืžื™ื™ื ื™ื, ื ื‘ื“ืง ืžื—ื“ืฉ ืจืง ื“ื•ืžื™ื™ืŸ ืื—ื“ ืžื”ืจืฉื™ืžื” (ืื ืœื‘ืงืฉื” ื”ื™ื• N ื“ื•ืžื™ื™ื ื™ื, ื‘ืžืงื•ื N ื‘ื“ื™ืงื•ืช ืฉื•ื ื•ืช, ื“ื•ืžื™ื™ืŸ ืื—ื“ ื ื‘ื“ืง N ืคึผึดื™). ืœื’ื‘ื™ ืฉืืจ ื”ืชื—ื•ืžื™ื, ืœื ื‘ื•ืฆืขื” ื‘ื“ื™ืงื” ืฉื ื™ื™ื” ื•ื”ื ืชื•ื ื™ื ืžื”ื‘ื“ื™ืงื” ื”ืจืืฉื•ื ื” ืฉื™ืžืฉื• ื‘ืขืช ืงื‘ืœืช ื”ื”ื—ืœื˜ื” (ื›ืœื•ืžืจ, ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘ื ืชื•ื ื™ื ืฉื”ื™ื• ื‘ื ื™ ืขื“ 30 ื™ื•ื). ื›ืชื•ืฆืื” ืžื›ืš, ืชื•ืš 30 ื™ื•ื ืœืื—ืจ ื”ืื™ืžื•ืช ื”ืจืืฉื•ืŸ, Let's Encrypt ืชื•ื›ืœ ืœื”ื ืคื™ืง ืื™ืฉื•ืจ ื’ื ืื ื”ืขืจืš ืฉืœ ืจืฉื•ืžืช ื”-CAA ืฉื•ื ื” ื•-Let's Encrypt ื”ื•ืกืจ ืžืจืฉื™ืžืช ื”-CAs ื”ืžืงื•ื‘ืœื™ื.

ื”ืžืฉืชืžืฉื™ื ื”ืžื•ืฉืคืขื™ื ืžืงื‘ืœื™ื ื”ื•ื“ืขื” ื‘ื“ื•ื"ืœ ืื ืคืจื˜ื™ ื”ืงืฉืจ ืžื•ืœืื• ื‘ืขืช ืงื‘ืœืช ื”ืื™ืฉื•ืจ. ืืชื” ื™ื›ื•ืœ ืœื‘ื“ื•ืง ืืช ื”ืื™ืฉื•ืจื™ื ืฉืœืš ืขืœ ื™ื“ื™ ื”ื•ืจื“ื” ัะฟะธัะพะบ ืžืกืคืจื™ื ืกื™ื“ื•ืจื™ื™ื ืฉืœ ืชืขื•ื“ื•ืช ืฉื‘ื•ื˜ืœื• ืื• ืฉื™ืžื•ืฉ ืฉื™ืจื•ืช ืžืงื•ื•ืŸ (ืžืžื•ืงื ื‘ื›ืชื•ื‘ืช ื”-IP, ื—ึธืกื•ึผื ื‘ืคื“ืจืฆื™ื” ื”ืจื•ืกื™ืช ืžืืช Roskomnadzor). ืืชื” ื™ื›ื•ืœ ืœื‘ืจืจ ืืช ื”ืžืกืคืจ ื”ืกื™ื“ื•ืจื™ ืฉืœ ื”ืื™ืฉื•ืจ ืขื‘ื•ืจ ืชื—ื•ื ื”ืขื ื™ื™ืŸ ื‘ืืžืฆืขื•ืช ื”ืคืงื•ื“ื”:

openssl s_client -connect example.com:443 -showcerts /dev/null\
| openssl x509 -ื˜ืงืกื˜ -noout | grep -A 1 ืžืกืคืจ ืกื™ื“ื•ืจื™\ | tr -d :

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”