ืชืคื•ื’ื” ืฉืœ ืชืขื•ื“ืช ื”ืฉื•ืจืฉ ืฉืœ IdenTrust ืชื•ื‘ื™ืœ ืœืื•ื‘ื“ืŸ ื”ืืžื•ืŸ ื‘-Let's Encrypt ื‘ืžื›ืฉื™ืจื™ื ื™ืฉื ื™ื ื™ื•ืชืจ

ื‘-30 ื‘ืกืคื˜ืžื‘ืจ ื‘ืฉืขื” 17:01 ืฉืขื•ืŸ ืžื•ืกืงื‘ื”, ืชืขื•ื“ืช ื”ืฉื•ืจืฉ ืฉืœ IdenTrust (DST Root CA X3), ืืฉืจ ืฉื™ืžืฉื” ืœื—ืชื™ืžื” ืฆื•ืœื‘ืช ืขืœ ืชืขื•ื“ืช ื”ืฉื•ืจืฉ ืฉืœ ืจืฉื•ืช ื”ืื™ืฉื•ืจื™ื Let's Encrypt (ISRG Root X1), ื”ื ืฉืœื˜ืช ืขืœ ื™ื“ื™ ื”ืงื”ื™ืœื” ืžืกืคืง ืชืขื•ื“ื•ืช ื—ื™ื ื ืœื›ื•ืœื, ื™ืคื•ื’. ื—ืชื™ืžื” ืฆื•ืœื‘ืช ื”ื‘ื˜ื™ื—ื” ืฉืชืขื•ื“ื•ืช Let's Encrypt ื”ื™ื• ืžื”ื™ืžื ื•ืช ื‘ืžื’ื•ื•ืŸ ืจื—ื‘ ืฉืœ ืžื›ืฉื™ืจื™ื, ืžืขืจื›ื•ืช ื”ืคืขืœื” ื•ื“ืคื“ืคื ื™ื ื‘ืขื•ื“ ืฉืื™ืฉื•ืจ ื”ืฉื•ืจืฉ ืฉืœ Let's Encrypt ืžืฉืœื• ื”ื™ื” ืžืฉื•ืœื‘ ื‘ืžืื’ืจื™ ืื™ืฉื•ืจื™ ืฉื•ืจืฉ.

ื‘ืžืงื•ืจ ืชื•ื›ื ืŸ ื›ื™ ืœืื—ืจ ื”ื•ืฆืื” ืžืฉื™ืžื•ืฉ ืฉืœ DST Root CA X3, ืคืจื•ื™ืงื˜ Let's Encrypt ื™ืขื‘ื•ืจ ืœื”ืคืงืช ื—ืชื™ืžื•ืช ืชื•ืš ืฉื™ืžื•ืฉ ืจืง ื‘ืชืขื•ื“ืช ื”ืฉื•ืจืฉ ืฉืœื•, ืืš ืžื”ืœืš ื›ื–ื” ื™ื•ื‘ื™ืœ ืœืื•ื‘ื“ืŸ ืชืื™ืžื•ืช ืœืžืกืคืจ ืจื‘ ืฉืœ ืžืขืจื›ื•ืช ื™ืฉื ื•ืช ื™ื•ืชืจ ืฉืœื ืขืฉื• ื–ืืช. ื”ื•ืกืฃ ืืช ืื™ืฉื•ืจ ื”ืฉื•ืจืฉ Let's Encrypt ืœืžืื’ืจื™ื ืฉืœื”ื. ื‘ืคืจื˜, ืœื›-30% ืžืžื›ืฉื™ืจื™ ื”ืื ื“ืจื•ืื™ื“ ื”ื ืžืฆืื™ื ื‘ืฉื™ืžื•ืฉ ืื™ืŸ ื ืชื•ื ื™ื ืขืœ ืชืขื•ื“ืช ื”ืฉื•ืจืฉ Let's Encrypt, ืฉืชืžื™ื›ื” ื‘ื” ื”ื•ืคื™ืขื” ืจืง ื”ื—ืœ ืžืคืœื˜ืคื•ืจืžืช ืื ื“ืจื•ืื™ื“ 7.1.1, ืฉืคื•ืจืกืžื” ื‘ืกื•ืฃ 2016.

Let's Encrypt ืœื ืชื›ื ื ื” ืœื”ืชืงืฉืจ ื‘ื”ืกื›ื ื—ื“ืฉ ื‘ื—ืชื™ืžื” ืฆื•ืœื‘ืช, ืฉื›ืŸ ื”ื“ื‘ืจ ืžื˜ื™ืœ ืื—ืจื™ื•ืช ื ื•ืกืคืช ืขืœ ื”ืฆื“ื“ื™ื ืœื”ืกื›ื, ืฉื•ืœืœ ืžื”ื ืขืฆืžืื•ืช ื•ืงื•ืฉืจ ืืช ื™ื“ื™ื”ื ื‘ื›ืœ ื”ื ื•ื’ืข ืœืขืžื™ื“ื” ื‘ื›ืœ ื”ื ื”ืœื™ื ื•ื”ื›ืœืœื™ื ืฉืœ ืจืฉื•ืช ืื™ืฉื•ืจื™ื ืื—ืจืช. ืืš ืขืงื‘ ื‘ืขื™ื•ืช ืคื•ื˜ื ืฆื™ืืœื™ื•ืช ื‘ืžืกืคืจ ืจื‘ ืฉืœ ืžื›ืฉื™ืจื™ ืื ื“ืจื•ืื™ื“, ื”ืชื•ื›ื ื™ืช ืฉื•ืงื ื”. ื ื—ืชื ื”ืกื›ื ื—ื“ืฉ ืขื ืจืฉื•ืช ื”ืื™ืฉื•ืจื™ื ืฉืœ IdenTrust, ื‘ืžืกื’ืจืชื• ื ื•ืฆืจื” ืชืขื•ื“ืช ื‘ื™ื ื™ื™ื ื—ืœื•ืคื™ืช ื‘ื—ืชื™ืžื” ืฆื•ืœื‘ืช Let's Encrypt. ื”ื—ืชื™ืžื” ื”ืฆื•ืœื‘ืช ืชื”ื™ื” ืชืงืคื” ืœืฉืœื•ืฉ ืฉื ื™ื ื•ืชืฉืžื•ืจ ืขืœ ืชืžื™ื›ื” ื‘ืžื›ืฉื™ืจื™ ืื ื“ืจื•ืื™ื“ ื”ื—ืœ ืžื’ืจืกื” 2.3.6.

ืขื ื–ืืช, ืชืขื•ื“ืช ื”ื‘ื™ื ื™ื™ื ื”ื—ื“ืฉื” ืื™ื ื” ืžื›ืกื” ืžืขืจื›ื•ืช ืจื‘ื•ืช ืื—ืจื•ืช ืžื“ื•ืจ ืงื•ื“ื. ืœื“ื•ื’ืžื”, ื›ืืฉืจ ืื™ืฉื•ืจ ื”-DST Root CA X3 ื™ื•ืฆื ืžืฉื™ืžื•ืฉ ื‘-30 ื‘ืกืคื˜ืžื‘ืจ, ืื™ืฉื•ืจื™ Let's Encrypt ืœื ื™ืชืงื‘ืœื• ืขื•ื“ ื‘ืงื•ืฉื—ื” ื•ื‘ืžืขืจื›ื•ืช ื”ืคืขืœื” ืฉืื™ื ืŸ ื ืชืžื›ื•ืช ื”ื“ื•ืจืฉื•ืช ื”ื•ืกืคืช ืื™ืฉื•ืจ ISRG Root X1 ื‘ืื•ืคืŸ ื™ื“ื ื™ ืœืžืื’ืจ ืื™ืฉื•ืจื™ ื”ืฉื•ืจืฉ ื›ื“ื™ ืœื”ื‘ื˜ื™ื— ืืžื•ืŸ ื‘ืชืขื•ื“ื•ืช Let's Encrypt. . ื”ื‘ืขื™ื•ืช ื™ืชื‘ื˜ืื• ื‘:

  • OpenSSL ืขื“ ืกื ื™ืฃ 1.0.2 ื›ื•ืœืœ (ื”ืชื—ื–ื•ืงื” ืฉืœ ืกื ื™ืฃ 1.0.2 ื”ื•ืคืกืงื” ื‘ื“ืฆืžื‘ืจ 2019);
  • NSS < 3.26;
  • Java 8 < 8u141, Java 7 < 7u151;
  • Windows < XP SP3;
  • macOS < 10.12.1;
  • iOS < 10 (ืื™ื™ืคื•ืŸ < 5);
  • ืื ื“ืจื•ืื™ื“ < 2.3.6;
  • Mozilla Firefox < 50;
  • ืื•ื‘ื•ื ื˜ื• < 16.04;
  • ื“ื‘ื™ืืŸ < 8.

ื‘ืžืงืจื” ืฉืœ OpenSSL 1.0.2, ื”ื‘ืขื™ื” ื ื’ืจืžืช ืขืœ ื™ื“ื™ ื‘ืื’ ืฉืžื•ื ืข ืขื™ื‘ื•ื“ ืชืขื•ื“ื•ืช ื‘ื—ืชื™ืžื” ืฆื•ืœื‘ืช ืื ืคื’ ืชื•ืงืฃ ืื—ื“ ืžืชืขื•ื“ื•ืช ื”ืฉื•ืจืฉ ื”ืžืฉืžืฉื•ืช ืœื—ืชื™ืžื”, ื’ื ืื ื ื•ืชืจื• ืฉืจืฉืจื•ืช ืืžื•ืŸ ืชืงืคื•ืช ืื—ืจื•ืช. ื”ื‘ืขื™ื” ืฆืฆื” ืœืจืืฉื•ื ื” ื‘ืฉื ื” ืฉืขื‘ืจื” ืœืื—ืจ ืฉืชืขื•ื“ืช AddTrust ื”ืžืฉืžืฉืช ืœื”ื—ืชืžืช ืื™ืฉื•ืจื™ื ืžืจืฉื•ืช ื”ืื™ืฉื•ืจื™ื ืฉืœ Sectigo (Comodo) ื”ืชื™ื™ืฉื ื”. ืขื™ืงืจ ื”ื‘ืขื™ื” ื”ื•ื ืฉ-OpenSSL ื ื™ืชื— ืืช ื”ืชืขื•ื“ื” ื›ืฉืจืฉืจืช ืœื™ื ื™ืืจื™ืช, ื‘ืขื•ื“ ืฉืœืคื™ RFC 4158, ืชืขื•ื“ื” ื™ื›ื•ืœื” ืœื™ื™ืฆื’ ื’ืจืฃ ืžืขื’ืœื™ ืžื‘ื•ื–ืจ ืžื›ื•ื•ืŸ ืขื ืขื•ื’ื ื™ ืืžื•ืŸ ืžืจื•ื‘ื™ื ืฉื™ืฉ ืœืงื—ืช ื‘ื—ืฉื‘ื•ืŸ.

ืœืžืฉืชืžืฉื™ื ื‘ื”ืคืฆื•ืช ื™ืฉื ื•ืช ื™ื•ืชืจ ื”ืžื‘ื•ืกืกื•ืช ืขืœ OpenSSL 1.0.2 ืžื•ืฆืขื•ืช ืฉืœื•ืฉ ื“ืจื›ื™ื ืœืขืงื™ืคืช ื”ื‘ืขื™ื”:

  • ื”ืกืจ ื™ื“ื ื™ืช ืืช ืื™ืฉื•ืจ ื”ืฉื•ืจืฉ ืฉืœ IdenTrust DST Root CA X3 ื•ื”ืชืงืŸ ืืช ืื™ืฉื•ืจ ื”ืฉื•ืจืฉ ืฉืœ ISRG Root X1 ื”ืขืฆืžืื™ (ืœื ื—ืชื•ื ืฆื•ืœื‘).
  • ื‘ืขืช ื”ืคืขืœืช ื”ืคืงื•ื“ื•ืช openssl verify ื•-s_client, ืืชื” ื™ื›ื•ืœ ืœืฆื™ื™ืŸ ืืช ื”ืืคืฉืจื•ืช "-trusted_first".
  • ื”ืฉืชืžืฉ ื‘ืฉืจืช ื‘ืื™ืฉื•ืจ ื”ืžืื•ืฉืจ ืขืœ ื™ื“ื™ ืื™ืฉื•ืจ ืฉื•ืจืฉ ื ืคืจื“ SRG Root X1, ืฉืื™ืŸ ืœื• ื—ืชื™ืžื” ืฆื•ืœื‘ืช. ืฉื™ื˜ื” ื–ื• ืชื•ื‘ื™ืœ ืœืื•ื‘ื“ืŸ ืชืื™ืžื•ืช ืขื ืœืงื•ื—ื•ืช ืื ื“ืจื•ืื™ื“ ื™ืฉื ื™ื ื™ื•ืชืจ.

ื‘ื ื•ืกืฃ, ืื ื• ื™ื›ื•ืœื™ื ืœืฆื™ื™ืŸ ืฉืคืจื•ื™ืงื˜ Let's Encrypt ื”ืชื’ื‘ืจ ืขืœ ืื‘ืŸ ื”ื“ืจืš ืฉืœ ืฉื ื™ ืžื™ืœื™ืืจื“ ืชืขื•ื“ื•ืช ืฉื ื•ืฆืจื•. ืื‘ืŸ ื”ื“ืจืš ืฉืœ ืžื™ืœื™ืืจื“ ื”ื•ืฉื’ื” ื‘ืคื‘ืจื•ืืจ ืืฉืชืงื“. 2.2-2.4 ืžื™ืœื™ื•ืŸ ืชืขื•ื“ื•ืช ื—ื“ืฉื•ืช ื ื•ืฆืจื•ืช ืžื“ื™ ื™ื•ื. ืžืกืคืจ ื”ืชืขื•ื“ื•ืช ื”ืคืขื™ืœื•ืช ื”ื•ื 192 ืžื™ืœื™ื•ืŸ (ืชืขื•ื“ื” ืชืงืคื” ืœืฉืœื•ืฉื” ื—ื•ื“ืฉื™ื) ื•ืžื›ืกื” ื›-260 ืžื™ืœื™ื•ืŸ ื“ื•ืžื™ื™ื ื™ื (195 ืžื™ืœื™ื•ืŸ ื“ื•ืžื™ื™ื ื™ื ื›ื•ืกื• ืœืคื ื™ ืฉื ื”, 150 ืžื™ืœื™ื•ืŸ ืœืคื ื™ ืฉื ืชื™ื™ื, 60 ืžื™ืœื™ื•ืŸ ืœืคื ื™ ืฉืœื•ืฉ ืฉื ื™ื). ืœืคื™ ื ืชื•ื ื™ื ืกื˜ื˜ื™ืกื˜ื™ื™ื ืžืฉื™ืจื•ืช Firefox Telemetry, ื”ื ืชื— ื”ืขื•ืœืžื™ ืฉืœ ื‘ืงืฉื•ืช ื”ื“ืคื™ื ื‘ืืžืฆืขื•ืช HTTPS ื”ื•ื 82% (ืœืคื ื™ ืฉื ื” - 81%, ืœืคื ื™ ืฉื ืชื™ื™ื - 77%, ืœืคื ื™ ืฉืœื•ืฉ ืฉื ื™ื - 69%, ืœืคื ื™ ืืจื‘ืข ืฉื ื™ื - 58%).

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”