Digest iyi ikufuna kuwonjezera chidwi cha Community pa nkhani yachinsinsi, yomwe, potengera zochitika zaposachedwa imakhala yofunika kwambiri kuposa kale.
Pa ndandanda:
Okonda ochokera mdera la "Medium" omwe ali ndi intaneti akupanga makina awo osakira
Medium yakhazikitsa bungwe latsopano la certification, Medium Global Root CA. Ndani adzakhudzidwa ndi kusinthaku?
Zikalata zachitetezo panyumba iliyonse - momwe mungapangire ntchito zanu pa intaneti ya Yggdrasil ndikutulutsa satifiketi yovomerezeka ya SSL yake
Ndikumbutseni - "Medium" ndi chiyani?
sing'anga (Eng. sing'anga - "mkhalapakati", mawu oyamba - Osafunsa zachinsinsi chanu. Bweretsaninso; komanso mu Chingerezi mawu sing'anga amatanthauza "wapakatikati") - wopereka intaneti waku Russia yemwe amapereka chithandizo chamaneti Yggdrasil kwaulere.
Okonda ochokera mdera la "Medium" omwe ali ndi intaneti akupanga makina awo osakira
Poyamba pa intaneti Yggdrasil, amene Decentralized Internet service provider Medium amagwiritsa ntchito monga zoyendera, analibe DNS yake seva kapena zomangira kiyi pagulu - Komabe, kufunika kutulutsa ziphaso chitetezo kwa ntchito Medium network anathetsa mavuto awiriwa.
Chifukwa chiyani mukufunikira PKI ngati Yggdrasil kunja kwa bokosilo imakupatsani mwayi wosunga ma traffic pakati pa anzanu?Palibe chifukwa chogwiritsa ntchito HTTPS kuti mulumikizane ndi mautumiki apaintaneti pa Yggdrasil netiweki ngati mulumikizane nawo kudzera pa rauta ya Yggdrasil netiweki yomwe ikuyenda kwanuko.
Zowonadi: mayendedwe a Yggdrasil ali panjira ndondomeko limakupatsani mwayi wogwiritsa ntchito zopezeka mkati mwa netiweki ya Yggdrasil - kuthekera kochita Kuukira kwa MITM osaphatikizidwa kwathunthu.
Zinthu zimasintha kwambiri ngati mutapeza zida za intranet za Yggdarsil osati mwachindunji, koma kudzera pa node yapakatikati - malo ofikira pa intaneti, omwe amayendetsedwa ndi wogwiritsa ntchito.
Apa, ndani angasokoneze zomwe mumatumiza:
Wothandizira malo ofikira. Ndizodziwikiratu kuti wogwiritsa ntchito pano pa Medium network access point amatha kuyang'ana magalimoto osadziwika omwe amadutsa zida zake.
wolowerera (munthu mkatikati). Wapakati ali ndi vuto lofanana ndi Tor network vuto, pokhapokha pokhudzana ndi zolowetsa ndi zapakati.
Izi ndi momwe zimawonekera
chisankho: kuti mupeze mawebusayiti mkati mwa netiweki ya Yggdrasil, gwiritsani ntchito protocol ya HTTPS (level 7 Zithunzi za OSI). Vuto ndiloti sizingatheke kutulutsa chiphaso chenicheni chachitetezo cha ma network a Yggdrasil kudzera mu njira wamba monga Tiyeni Tilembetse.
Chifukwa chake, tidakhazikitsa malo athu a certification - "Medium Global Root CA". Ntchito zambiri mu netiweki ya Medium zimasainidwa ndi chiphaso chachitetezo chaulamuliro wapakatikati wa Medium Domain Validation Secure Server CA.
Kuthekera kwa kuphwanya chiphaso chaulamuliro wa certification kunali, ndithudi, kuganiziridwa - koma apa satifiketi ndiyofunika kwambiri kutsimikizira kukhulupirika kwa kufalitsa deta ndikuchotsa kuthekera kwa kuukira kwa MITM.
Ntchito zama netiweki zapakatikati kuchokera kwa ogwira ntchito osiyanasiyana zimakhala ndi ziphaso zotetezedwa, mwanjira imodzi kapena zina zosainidwa ndi oyang'anira certification. Komabe, ogwiritsira ntchito Root CA sangathe kumvetsera za magalimoto obisika kuchokera kuzinthu zomwe asayina ziphaso zachitetezo (onani "CSR ndi chiyani?").
Wogwiritsa ntchito @NXShock adayamba kupanga makina osakira mawebusayiti omwe ali pa netiweki ya Yggdrasil. Chofunikira ndichakuti kutsimikiza kwa ma adilesi a IPv6 akamasaka kumachitika potumiza pempho ku seva ya DNS yomwe ili mkati mwa netiweki yapakatikati.
TLD yayikulu ndi .ygg. Mayina ambiri amakhala ndi TLD iyi, kupatulapo ziwiri: .isp ΠΈ .gg.
Injini yofufuzira ikupangidwa, koma kugwiritsa ntchito kwake kuli kotheka kale lero - ingoyenderani tsambalo search.medium.isp.
Medium yakhazikitsa bungwe latsopano la certification, Medium Global Root CA. Ndani adzakhudzidwa ndi kusinthaku?
Dzulo, kuyesa kwapagulu kwa magwiridwe antchito a Medium Root CA certification center kunamalizidwa. Pamapeto pa kuyezetsa, zolakwika pakugwiritsa ntchito ntchito zamagulu akuluakulu aboma zidakonzedwa ndipo chikalata chatsopano chaulamuliro wa certification "Medium Global Root CA" chidapangidwa.
Ma nuances onse ndi mawonekedwe a PKI adaganiziridwa - tsopano satifiketi yatsopano ya CA "Medium Global Root CA" idzaperekedwa patatha zaka khumi (pambuyo pa tsiku lotha ntchito). Tsopano ziphaso zachitetezo zimaperekedwa ndi akuluakulu apakatikati - mwachitsanzo, "Medium Domain Validation Secure Server CA".
Popeza mautumiki ena amagwiritsa ntchito HSTS, musanagwiritse ntchito zida za Medium network, muyenera kuchotsa deta kuchokera kuzinthu zapakatikati za intranet. Mungathe kuchita izi mu Mbiri ya msakatuli wanu.
Muyenera kutulutsanso satifiketi ya ntchito yanu patsamba pki.medium.isp (ntchitoyi imapezeka pa Medium network yokha).
Zikalata zachitetezo panyumba iliyonse - momwe mungapangire ntchito zanu pa intaneti ya Yggdrasil ndikutulutsa satifiketi yovomerezeka ya SSL yake
Chifukwa cha kukula kwa chiwerengero cha mautumiki a intranet pa intaneti ya Medium, kufunikira kopereka ziphaso zatsopano zachitetezo ndikukonzekera mautumiki awo kuti athandizire SSL kwawonjezeka.
Popeza Habr ndi chida chaukadaulo, muzogaya zatsopano zilizonse chimodzi mwazinthu zomwe zikuwonetsedwa zimawulula ukadaulo wa Medium network network. Mwachitsanzo, pansipa pali malangizo athunthu operekera satifiketi ya SSL pa ntchito yanu.
Zitsanzo ziwonetsa dzina la domain domain.ygg, zomwe ziyenera kusinthidwa ndi dzina lachidziwitso la utumiki wanu.
Khwelero 1. Pangani makiyi achinsinsi ndi magawo a Diffie-Hellman