Kukho uluvo: Itekhnoloji ye-DANE yeebhrawuza ayiphumelelanga

Sithetha malunga nokuba yeyiphi iteknoloji ye-DANE yokuqinisekisa amagama esizinda usebenzisa i-DNS kwaye kutheni ingasetyenziswanga ngokubanzi kwiziphequluli.

Kukho uluvo: Itekhnoloji ye-DANE yeebhrawuza ayiphumelelanga
/unsplash/ UPaulius Dragunas

Yintoni iDANE

IziGunyaziso zeZiqinisekiso (CAs) yimibutho ethi bathembisene ngomtshato isatifikethi se-cryptographic izatifikethi ze-SSL. Bafaka utyikityo lwabo lwe-elektroniki kubo, beqinisekisa ubunyani babo. Nangona kunjalo, ngamanye amaxesha kuvela iimeko xa izatifikethi zikhutshwe ngokuphulwa. Umzekelo, kulo nyaka uphelileyo uGoogle uqalise "inkqubo yokungathembeki" kwizatifikethi zeSymantec ngenxa yokulalanisa kwabo (siligubungele eli bali ngokweenkcukacha kwibhlog yethu - maxesha ΠΈ Π΄Π²Π°).

Ukuphepha iimeko ezinjalo, kwiminyaka emininzi eyadlulayo i-IETF waqala ukuphuhlisa Itekhnoloji ye-DANE (kodwa ayisetyenziswa kakhulu kwizikhangeli- siza kuthetha malunga nokuba kutheni le nto yenzeke kamva).

I-DANE (i-DNS-based Authentication of Named Entities) yiseti yeenkcukacha ezikuvumela ukuba usebenzise i-DNSSEC (Izandiso zeNkqubo yoKhuseleko yeGama) ukulawula ukunyaniseka kwezatifikethi ze-SSL. I-DNSSEC lulwandiso lweNkqubo yeGama leDomain enciphisa uhlaselo lwe-spoofing yeedilesi. Ukusebenzisa ezi teknoloji zimbini, umphathi wewebhu okanye umxhasi unokuqhagamshelana nomnye wabaqhubi bezowuni ye-DNS kwaye aqinisekise ukunyaniseka kwesatifikethi esisetyenziswayo.

Ngokusisiseko, i-DANE isebenza njengesatifikethi esizisayinileyo (umqinisekisi wokuthembeka kwayo yi-DNSSEC) kwaye izalisekisa imisebenzi ye-CA.

ntoni lo msebenzi

Iinkcukacha ze-DANE zichazwe kwi I-RFC6698. Ngokoxwebhu, kwi Iirekhodi zemithombo ye-DNS uhlobo olutsha longezwa - iTLSA. Iqulethe ulwazi malunga nesatifikethi esigqithiselwayo, ubungakanani kunye nodidi lwedatha ekhutshelwayo, kunye nedatha ngokwayo. Umphathi wewebhu wenza ubhontsi wedijithali wesatifikethi, usisayine nge-DNSSEC, kwaye usibeke kwi-TLSA.

Umxhasi uqhagamshela kwisayithi kwi-Intanethi kwaye uthelekisa isatifikethi sayo kunye "nekopi" efunyenwe kumqhubi we-DNS. Ukuba ziyahambelana, ngoko ke isibonelelo sithathwa njengethembekile.

Iphepha le-DANE wiki libonelela ngomzekelo olandelayo wesicelo se-DNS kumzekelo.org kwizibuko le-TCP 443:

IN TLSA _443._tcp.example.org

Impendulo ibonakala ngolu hlobo:

 _443._tcp.example.com. IN TLSA (
   3 0 0 30820307308201efa003020102020... )

I-DANE inezandiso ezininzi ezisebenza ngeerekhodi ze-DNS ngaphandle kwe-TLSA. Eyokuqala yi SSHFP DNS irekhodi yokuqinisekisa izitshixo kuqhagamshelo lwe-SSH. Ichazwe kwi I-RFC4255I-RFC6594 ΠΈ I-RFC7479. Okwesibini lungeno lwe OPENPGPKEY lotshintshiselwano olungundoqo usebenzisa i PGP (I-RFC7929). Ekugqibeleni, eyesithathu yirekhodi ye-SMIMEA (umgangatho awukho ngokusesikweni kwi-RFC, kukho idrafti nje yayo) kutshintshiselwano lwesitshixo se-cryptographic nge-S/MIME.

Yintoni ingxaki nge DANE

Phakathi koMeyi, inkomfa ye-DNS-OARC yabanjwa (le yintlangano engenzi nzuzo ejongene nokhuseleko, ukuzinza kunye nophuhliso lwenkqubo yegama lesizinda). Iingcali kwenye yeepaneli kwafikelela kwisigqiboukuba iteknoloji ye-DANE kwiziphequluli ayiphumelelanga (ubuncinane ekuphunyezweni kwayo kwangoku). Ukhoyo kwinkomfa uGeoff Huston, iNzululwazi yoPhando eNkokelayo UMNTU, omnye wababhalisi be-Intanethi abahlanu, waphendula malunga ne-DANE njenge "teknoloji efileyo".

Iibhrawuza ezidumileyo azixhasi uqinisekiso lwesatifikethi kusetyenziswa i-DANE. Kwimarike kukho iiplagi ezikhethekileyo, ebonisa ukusebenza kweerekhodi ze-TLSA, kodwa kunye nenkxaso yazo ngokuthe ngcembe uyeke.

Iingxaki ngokusasazwa kwe-DANE kwizikhangeli zinxulunyaniswa nobude benkqubo yokuqinisekisa ye-DNSSEC. Inkqubo inyanzelekile ukuba yenze izibalo ze-cryptographic ukuqinisekisa ubunyani besatifikethi se-SSL kwaye idlule kwikhonkco lonke leeseva ze-DNS (ukusuka kwindawo yengcambu ukuya kwi-domain host) xa uqala ukuxhuma kwi-resource.

Kukho uluvo: Itekhnoloji ye-DANE yeebhrawuza ayiphumelelanga
/unsplash/ Kaley Dykstra

IMozilla izamile ukuphelisa le ngxaki isebenzisa indlela DNSSEC Ukwandiswa kweChayini ye-TLS. Bekufanele kuncitshiswe inani leerekhodi ze-DNS ekufuneka umxhasi ajonge phezulu ngexesha lokuqinisekisa. Nangona kunjalo, ukungaboni ngasonye kwavela phakathi kweqela lophuhliso elingenako ukusonjululwa. Ngenxa yoko, iprojekthi iye yashiywa, nangona yamkelwe yi-IETF ngoMatshi ka-2018.

Esinye isizathu sokuthandwa okuphantsi kwe-DANE kukuxhaphaka okuphantsi kwe-DNSSEC kwihlabathi- kuphela li-19% lezibonelelo ezisebenza nayo. Iingcali zivakalelwa kukuba oku akwanelanga ukukhuthaza i-DANE.

Okunokwenzeka, ishishini liya kuphuhlisa kwicala elahlukileyo. Esikhundleni sokusebenzisa i-DNS ukuqinisekisa izatifikethi ze-SSL/TLS, abadlali beemarike baya kukhuthaza i-DNS-over-TLS (DoT) kunye ne-DNS-over-HTTPS (DoH) protocol. Sayikhankanya le yokugqibela kwenye yethu izixhobo zangaphambili kuHabre. Bafihla kwaye baqinisekise izicelo zabasebenzisi kwiseva ye-DNS, ukukhusela abahlaseli kwi-spoofing data. Ekuqaleni konyaka, i-DoT yayisele isele iphunyeziwe kuGoogle kwiDNS yayo yoLuntu. Ngokuphathelele i-DANE, ukuba itekhnoloji iya kukwazi "ukubuyisela isali" kwaye isasazeke isaza kubonakala kwixesha elizayo.

Yintoni enye esinayo ukuze sifunde ngakumbi:

Kukho uluvo: Itekhnoloji ye-DANE yeebhrawuza ayiphumelelanga Indlela yokwenza ngokuzenzekelayo ulawulo lweziseko zophuhliso lwe-IT - ukuxoxa ngeendlela ezintathu
Kukho uluvo: Itekhnoloji ye-DANE yeebhrawuza ayiphumelelanga JMAP - iprotocol evulekileyo eya kuthatha indawo ye-IMAP xa utshintshisa ngee-imeyile

Kukho uluvo: Itekhnoloji ye-DANE yeebhrawuza ayiphumelelanga UGcina Njani ngeNkqubo yeSijongano seNkqubo
Kukho uluvo: Itekhnoloji ye-DANE yeebhrawuza ayiphumelelanga I-DevOps kwinkonzo yefu isebenzisa umzekelo we-1cloud.ru
Kukho uluvo: Itekhnoloji ye-DANE yeebhrawuza ayiphumelelanga I-Evolution ye-1cloud cloud architecture

Kukho uluvo: Itekhnoloji ye-DANE yeebhrawuza ayiphumelelanga Isebenza njani inkxaso ye-1cloud yobugcisa?
Kukho uluvo: Itekhnoloji ye-DANE yeebhrawuza ayiphumelelanga Iintsomi malunga nobuchwepheshe bamafu

umthombo: www.habr.com

Yongeza izimvo