ื”ื•ืฆืื” ืžืฉื™ืžื•ืฉ ืฉืœ ืื™ืฉื•ืจ ืฉื•ืจืฉ AddTrust ื’ื•ืจื ืœืงืจื™ืกื•ืช ื‘ืžืขืจื›ื•ืช OpenSSL ื•-GnuTLS

ื‘-30 ื‘ืžืื™ ืคื’ื” ืชืงื•ืคืช ื”ืชื•ืงืฃ ืฉืœ ืื™ืฉื•ืจ ื”ืฉื•ืจืฉ ืœ-20 ืฉื ื” AddTrustืืฉืจ ืžื™ื•ืฉื ืœื™ืฆื•ืจ ืชืขื•ื“ื•ืช ื—ืชื•ื ืฆื•ืœื‘ื•ืช ืฉืœ ืื—ืช ืžืจืฉื•ื™ื•ืช ื”ืื™ืฉื•ืจ ื”ื’ื“ื•ืœื•ืช ืฉืœ Sectigo (Comodo). ื—ืชื™ืžื” ืฆื•ืœื‘ืช ืืคืฉืจื” ืชืื™ืžื•ืช ืœืžื›ืฉื™ืจื™ื ืžื“ื•ืจ ืงื•ื“ื ืฉืื™ืฉื•ืจ ื”ืฉื•ืจืฉ ื”ื—ื“ืฉ ืฉืœ USERTRust ืœื ื”ื•ืกืฃ ืœืžืื’ืจ ืื™ืฉื•ืจื™ ื”ืฉื•ืจืฉ ืฉืœื”ื.

ื”ื•ืฆืื” ืžืฉื™ืžื•ืฉ ืฉืœ ืื™ืฉื•ืจ ืฉื•ืจืฉ AddTrust ื’ื•ืจื ืœืงืจื™ืกื•ืช ื‘ืžืขืจื›ื•ืช OpenSSL ื•-GnuTLS

ืชื™ืื•ืจื˜ื™ืช, ื”ืคืกืงืช ืื™ืฉื•ืจ ื”ืฉื•ืจืฉ ืฉืœ AddTrust ืืžื•ืจื” ืœื”ื•ื‘ื™ืœ ืจืง ืœื”ืคืจื” ืฉืœ ืชืื™ืžื•ืช ืขื ืžืขืจื›ื•ืช ืžื“ื•ืจ ืงื•ื“ื (ืื ื“ืจื•ืื™ื“ 2.3, Windows XP, Mac OS X 10.11, iOS 9 ื•ื›ื•'), ืžื›ื™ื•ื•ืŸ ืฉืื™ืฉื•ืจ ื”ืฉื•ืจืฉ ื”ืฉื ื™ ื”ืžืฉืžืฉ ื‘ื—ืชื™ืžื” ื”ืฆื•ืœื‘ืช ื ืฉืืจ ื“ืคื“ืคื ื™ื ื—ื•ืงื™ื™ื ื•ืžื•ื“ืจื ื™ื™ื ืœื•ืงื—ื™ื ื–ืืช ื‘ื—ืฉื‘ื•ืŸ ื‘ืขืช โ€‹โ€‹ื‘ื“ื™ืงืช ืฉืจืฉืจืช ื”ืืžื•ืŸ. ืขืœ ืชืจื’ื•ืœ ื”ื•ืคื™ืข ื‘ืขื™ื•ืช ื‘ืื™ืžื•ืช ื—ืชื™ืžื” ืฆื•ืœื‘ืช ื‘ืœืงื•ื—ื•ืช TLS ืฉืื™ื ื ื“ืคื“ืคื ื™ื, ื›ื•ืœืœ ืืœื” ื”ืžื‘ื•ืกืกื™ื ืขืœ OpenSSL 1.0.x ื•-GnuTLS. ืœื ื ื•ืฆืจ ืขื•ื“ ื—ื™ื‘ื•ืจ ืžืื•ื‘ื˜ื— ืขื ืฉื’ื™ืื” ื”ืžืฆื™ื™ื ืช ืฉื”ืื™ืฉื•ืจ ืื™ื ื• ืžืขื•ื“ื›ืŸ ืื ื”ืฉืจืช ืžืฉืชืžืฉ ื‘ืื™ืฉื•ืจ Sectigo ื”ืžืงื•ืฉืจ ื‘ืืžืฆืขื•ืช ืฉืจืฉืจืช ืืžื•ืŸ ืœืื™ืฉื•ืจ ื”ืฉื•ืจืฉ AddTrust.

ืื ืžืฉืชืžืฉื™ ื“ืคื“ืคื ื™ื ืžื•ื“ืจื ื™ื™ื ืœื ืฉืžื• ืœื‘ ืœื”ืชื™ื™ืฉื ื•ืช ืฉืœ ืชืขื•ื“ืช ื”ืฉื•ืจืฉ AddTrust ื‘ืขืช ืขื™ื‘ื•ื“ ืชืขื•ื“ื•ืช Sectigo ืขื ื—ืชื™ืžื•ืช ืฆื•ืœื‘ื•ืช, ืื– ื”ื—ืœื• ืœืฆื•ืฅ ื‘ืขื™ื•ืช ื‘ื™ื™ืฉื•ืžื™ ืฆื“ ืฉืœื™ืฉื™ ื•ืžื˜ืคืœื™ื ื‘ืฆื“ ื”ืฉืจืช, ืžื” ืฉื”ื•ื‘ื™ืœ ืœ ื”ึฒืคึธืจึธื” ืœืขื‘ื•ื“ ืชืฉืชื™ื•ืช ืจื‘ื•ืช ื”ืžืฉืชืžืฉื•ืช ื‘ืขืจื•ืฆื™ ืชืงืฉื•ืจืช ืžื•ืฆืคื ื™ื ืœืื™ื ื˜ืจืืงืฆื™ื” ื‘ื™ืŸ ืจื›ื™ื‘ื™ื.

ืœืžืฉืœ, ื”ื™ื• ื‘ืขื™ื•ืช ืขื ื’ื™ืฉื” ืœื›ืžื” ืžืื’ืจื™ ื—ื‘ื™ืœื•ืช ื‘ื“ื‘ื™ืืŸ ื•ื‘ืื•ื‘ื•ื ื˜ื• (apt ื”ื—ืœื” ืœื™ืฆื•ืจ ืฉื’ื™ืืช ืื™ืžื•ืช ืชืขื•ื“ื”), ื‘ืงืฉื•ืช ืžืกืงืจื™ืคื˜ื™ื ื‘ืืžืฆืขื•ืช ื›ืœื™ ื”ืฉื™ืจื•ืช "curl" ื•-"wget" ื”ื—ืœื• ืœื”ื™ื›ืฉืœ, ืฉื’ื™ืื•ืช ื ืฆืคื• ื‘ืขืช ื”ืฉื™ืžื•ืฉ ื‘-Git, ื”ื•ืคืจ ืคืœื˜ืคื•ืจืžืช ื”ืกื˜ืจื™ืžื™ื ื’ ืฉืœ Roku ืขื•ื‘ื“ืช, ื”ืžื˜ืคืœื™ื ื›ื‘ืจ ืœื ื ืงืจืื™ื ืคึผึทืก ะธ ื ืชื•ื ื™ื, ื”ืชื—ื™ืœ ืžืชืจื—ืฉื•ืช ืงืจื™ืกื•ืช ื‘ืืคืœื™ืงืฆื™ื•ืช Heroku, ื—ื“ืœื• ืœืงื•ื—ื•ืช OpenLDAP ืžืชื—ื‘ืจื™ื, ืžืชื’ืœื•ืช ื‘ืขื™ื•ืช ื‘ืฉืœื™ื—ืช ื“ื•ืืจ ืœืฉืจืชื™ SMTPS ื•-SMTP ืขื STARTTLS. ื‘ื ื•ืกืฃ, ื ืฆืคื•ืช ื‘ืขื™ื•ืช ื‘ืกืงืจื™ืคื˜ื™ื ืฉื•ื ื™ื ืฉืœ Ruby, PHP ื•-Python ื”ืžืฉืชืžืฉื™ื ื‘ืžื•ื“ื•ืœ ืขื ืœืงื•ื— http. ื‘ืขื™ื” ื‘ื“ืคื“ืคืŸ ืžืฉืคื™ืข Epiphany, ืฉื”ืคืกื™ืงื” ืœื˜ืขื•ืŸ ืจืฉื™ืžื•ืช ื—ืกื™ืžืช ืžื•ื“ืขื•ืช.

ืชื•ื›ื ื™ื•ืช Go ืœื ืžื•ืฉืคืขื•ืช ืžื‘ืขื™ื” ื–ื• ืžื›ื™ื•ื•ืŸ ืฉ-Go ืžืฆื™ืขื” ื™ื™ืฉื•ื ืžืฉืœื• TLS.

ื–ื” ื”ื™ื” ืืžื•ืจืฉื”ื‘ืขื™ื” ืžืฉืคื™ืขื” ืขืœ ืžื”ื“ื•ืจื•ืช ื”ืคืฆื” ื™ืฉื ื•ืช ื™ื•ืชืจ (ื›ื•ืœืœ ื“ื‘ื™ืืŸ 9, ืื•ื‘ื•ื ื˜ื• 16.04, RHEL 6/7) ืฉืžืฉืชืžืฉื™ื ื‘ืขื ืคื™ OpenSSL ื‘ืขื™ื™ืชื™ื™ื, ืื‘ืœ ื”ื‘ืขื™ื” ื‘ืื” ืœื™ื“ื™ ื‘ื™ื˜ื•ื™ ื’ื ื›ืืฉืจ ืžื ื”ืœ ื”ื—ื‘ื™ืœื•ืช ืฉืœ APT ืคื•ืขืœ ื‘ืžื”ื“ื•ืจื•ืช ื”ื ื•ื›ื—ื™ื•ืช ืฉืœ Debian 10 ื•-Ubuntu 18.04/20.04, ืžื›ื™ื•ื•ืŸ ืฉ-APT ืžืฉืชืžืฉ ื‘ืกืคืจื™ื™ืช GnuTLS. ืขื™ืงืจ ื”ื‘ืขื™ื” ื”ื•ื ืฉืกืคืจื™ื•ืช TLS/SSL ืจื‘ื•ืช ืžื ืชื—ื•ืช ืชืขื•ื“ื” ื›ืฉืจืฉืจืช ืœื™ื ื™ืืจื™ืช, ื‘ืขื•ื“ ืฉืœืคื™ RFC 4158, ืชืขื•ื“ื” ื™ื›ื•ืœื” ืœื™ื™ืฆื’ ื’ืจืฃ ืžืขื’ืœื™ ืžื‘ื•ื–ืจ ืžื›ื•ื•ืŸ ืขื ืขื•ื’ื ื™ ืืžื•ืŸ ืžืจื•ื‘ื™ื ืฉื™ืฉ ืœืงื—ืช ื‘ื—ืฉื‘ื•ืŸ. ืขืœ ื”ืคื’ื ื”ื–ื” ื‘-OpenSSL ื•-GnuTLS ื–ื” ื”ื™ื” ื™ื“ื•ืข ื‘ืžืฉืš ืฉื ื™ื ืจื‘ื•ืช. ื‘-OpenSSL ื”ื‘ืขื™ื” ืชื•ืงื ื” ื‘ืกื ื™ืฃ 1.1.1, ื•ื‘ gnuTLS ืฉื‚ึฐืจึดื™ื“ึดื™ื ืœื ืžืชื•ืงืŸ.

ื›ืคืชืจื•ืŸ ืขื•ืงืฃ, ืžื•ืžืœืฅ ืœื”ืกื™ืจ ืืช ืื™ืฉื•ืจ "AddTrust External CA Root" ืžื—ื ื•ืช ื”ืžืขืจื›ืช (ืœื“ื•ื’ืžื”, ืœื”ืกื™ืจ ืž-/etc/ca-certificates.conf ื•-/etc/ssl/certs, ื•ืœืื—ืจ ืžื›ืŸ ืœื”ืคืขื™ืœ ืืช "update-ca" -certificates -f -v"), ืœืื—ืจ ืžื›ืŸ OpenSSL ืžืชื—ื™ืœ ืœืขื‘ื“ ื‘ื“ืจืš ื›ืœืœ ืื™ืฉื•ืจื™ื ื‘ื—ืชื™ืžื” ืฆื•ืœื‘ืช ื‘ื”ืฉืชืชืคื•ืชื•. ื‘ืขืช ืฉื™ืžื•ืฉ ื‘ืžื ื”ืœ ื”ื—ื‘ื™ืœื•ืช ืฉืœ APT, ืืชื” ื™ื›ื•ืœ ืœื”ืฉื‘ื™ืช ืืช ืื™ืžื•ืช ื”ืื™ืฉื•ืจ ืขื‘ื•ืจ ื‘ืงืฉื•ืช ื‘ื•ื“ื“ื•ืช ืขืœ ืื—ืจื™ื•ืชืš ื‘ืœื‘ื“ (ืœื“ื•ื’ืžื”, "apt-get update -o Acquire::https::download.jitsi.org::Verify-Peer=false") .

ื›ื“ื™ ืœื—ืกื•ื ืืช ื”ื‘ืขื™ื” ืคื ื™ืžื” ืคื“ื•ืจื” ะธ ืจื”ืœ ืžื•ืฆืข ืœื”ื•ืกื™ืฃ ืืช ืื™ืฉื•ืจ AddTrust ืœืจืฉื™ืžื” ื”ืฉื—ื•ืจื”:

trust dump โ€”filter ยซpkcs11:id=%AD%BD%98%7A%34%B4%26%F7%FA%C4%26%54%EF%03%BD%E0%24%CB%54%1A;type=certยป \
> /etc/pki/ca-trust/source/blacklist/addtrust-external-root.p11-kit
ืชืžืฆื™ืช update-ca-trust

ืื‘ืœ ื”ืฉื™ื˜ื” ื”ื–ื• ืœื ืขื•ื‘ื“ ืขื‘ื•ืจ GnuTLS (ืœื“ื•ื’ืžื”, ืฉื’ื™ืืช ืื™ืžื•ืช ืื™ืฉื•ืจ ืžืžืฉื™ื›ื” ืœื”ื•ืคื™ืข ื‘ืขืช ื”ืคืขืœืช ื›ืœื™ ื”ืฉื™ืจื•ืช wget).

ื‘ืฆื“ ื”ืฉืจืช ืืชื” ื™ื›ื•ืœ ืฉื™ื ื•ื™ ืœืงืฆืฅ ืจื™ืฉื•ื ื”ืื™ืฉื•ืจื™ื ื‘ืฉืจืฉืจืช ื”ืืžื•ืŸ ืฉื ืฉืœื—ื” ืขืœ ื™ื“ื™ ื”ืฉืจืช ืœืœืงื•ื— (ืื ื”ืื™ืฉื•ืจ ื”ืžืฉื•ื™ืš ืœ-"AddTrust External CA Root" ื™ื•ืกืจ ืžื”ืจืฉื™ืžื”, ื”ืื™ืžื•ืช ืฉืœ ื”ืœืงื•ื— ื™ืฆืœื™ื—). ื›ื“ื™ ืœื‘ื“ื•ืง ื•ืœื™ื™ืฆืจ ืฉืจืฉืจืช ืืžื•ืŸ ื—ื“ืฉื”, ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ืฉื™ืจื•ืช whatsmychaincert.com. ื’ื ืกืงื˜ื™ื’ื• ะฟั€ะตะดะพัั‚ะฐะฒะธะปะฐ ืชืขื•ื“ืช ื‘ื™ื ื™ื™ื ื—ืœื•ืคื™ืช ื‘ื—ืชื™ืžื” ืฆื•ืœื‘ืช"ืฉื™ืจื•ืชื™ ืชืขื•ื“ืช AAA", ืืฉืจ ื™ื”ื™ื” ืชืงืฃ ืขื“ 2028 ื•ื™ืฉืžื•ืจ ืขืœ ืชืื™ืžื•ืช ืขื ื’ืจืกืื•ืช ื™ืฉื ื•ืช ื™ื•ืชืจ ืฉืœ ืžืขืจื›ืช ื”ื”ืคืขืœื”.

ืชื•ืกืคืช: ื‘ืขื™ื” ื’ื ืžื•ืคื™ืข ื‘-LibreSSL.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”