Yonke into obufuna ukuyazi malunga nomnikezeli we-Intanethi ophakathi, kodwa woyika ukubuza

Molo emva kwemini, Luluntu!

Igama lam ndingu Yanislav Basyuk. Ndingumququzeleli wombutho woluntu "Medium".

Kule nqaku ndizamile ukuqokelela ulwazi olubanzi malunga nokuba yintoni le isebenza kwintsimi yeRussian Federation. umboneleli we-intanethi owandisiweyo.

Ndiza kuthi:

    Yonke into obufuna ukuyazi malunga nomnikezeli we-Intanethi ophakathi, kodwa woyika ukubuza   Yintoni iMedium?
    Yonke into obufuna ukuyazi malunga nomnikezeli we-Intanethi ophakathi, kodwa woyika ukubuza   Yintoni i-Yggdrasil kwaye kutheni i-Medium iyisebenzisa njengeyona ndlela yokuthutha
    Yonke into obufuna ukuyazi malunga nomnikezeli we-Intanethi ophakathi, kodwa woyika ukubuza   Uyiqwalasela njani ngokufanelekileyo imeko-bume yokusebenzisa izixhobo zothungelwano oluPhakathi

Yonke into obufuna ukuyazi malunga nomnikezeli we-Intanethi ophakathi, kodwa woyika ukubuza

Yintoni iMedium?

phakathi (eng. phakathi - "umthetheleli", isilogeni sokuqala - Musa ukukubuza imfihlo yakho. Yibuyisele; kwakhona ngesiNgesi igama medium kuthetha "ophakathi") - umnikezeli we-Intanethi waseRussia onikezela ngeenkonzo zokufikelela kwinethiwekhi Yggdrasil simahla kungafunwanga ntlawulo.

Nini, phi kwaye kutheni iMedium yadalwa?

Ekuqaleni, le projekthi yaqanjwa njenge umnatha womnatha в Isithili sasedolophini saseKolomna.

“Ephakathi” yasekwa ngo-Epreli ka-2019 njengenxalenye yokuyilwa kwendawo yonxibelelwano ezimeleyo ngokubonelela abasebenzisi bokugqibela ukufikelela kwimithombo yothungelwano yeYggdrasil ngokusetyenziswa kobuchwephesha bokuhambisa idatha engenazingcingo ye-Wi-Fi.

Ndingalufumana phi uluhlu olupheleleyo lwazo zonke iindawo zenethiwekhi?Ungayifumana kwi iindawo zokugcina kwiGitHub.

Yonke into obufuna ukuyazi malunga nomnikezeli we-Intanethi ophakathi, kodwa woyika ukubuza

Yintoni iYggdrasil kwaye kutheni iMedium iyisebenzisa njengeyona ndlela yothutho?

Yggdrasil kukuzicwangcisa umnatha womnatha, enekhono lokudibanisa ii-routers zombini kwimodi yokwaleka (phezulu kwi-Intanethi) kwaye ngokuthe ngqo komnye nomnye ngoqhagamshelwano olungenazintambo okanye olungenazintambo.

I-Yggdrasil kukuqhubekeka kweprojekthi CjDNS. Owona mahluko mkhulu phakathi kweYggdrasil kunye neCjDNS kusetyenziso lweprotocol STP (iprotocol yomthi enwebekayo).

Yonke into obufuna ukuyazi malunga nomnikezeli we-Intanethi ophakathi, kodwa woyika ukubuza

Ngokungagqibekanga, zonke iirouter ezikwinethiwekhi ziyasetyenziswa uguqulelo oluntsonkothileyo ekupheleni ukuya ekupheleni ukudlulisa idatha phakathi kwabanye abathathi-nxaxheba.

Ukukhethwa kwenethiwekhi yeYggdrasil njengothutho oluphambili ngenxa yesidingo sokwandisa isantya soxhulumaniso (kude kube ngu-Agasti 2019, i-Medium isetyenzisiwe. I2P).

Utshintsho oluya kwi-Yggdrasil lukwanike abathathi-nxaxheba beprojekthi ithuba lokuqalisa ukusasaza inethiwekhi yeMesh ene-Full-Mesh topology. Umbutho wothungelwano olunjalo lolona nyango lusebenzayo lokuvalelwa.

Yonke into obufuna ukuyazi malunga nomnikezeli we-Intanethi ophakathi, kodwa woyika ukubuza

I-Yggdrasil isebenzisa uguqulelo oluntsonkothileyo ekupheleni ukuya-ekupheleni ngokungagqibekanga. Kutheni iinkonzo zenethiwekhi eziPhakathi zisebenzisa i-HTTPS?

Akukho sidingo sokusebenzisa i-HTTPS ukuqhagamshela kwiinkonzo zewebhu kuthungelwano lweYggdrasil ukuba uqhagamshela kubo ngomzila wothungelwano weYggdrasil osebenza ekuhlaleni.

Ngokwenene: Uthutho lweYggdrasil lukwinqanaba umthetho olandelwayo ikuvumela ukuba usebenzise ngokukhuselekileyo izixhobo ngaphakathi kwenethiwekhi yeYggdrasil - ukukwazi ukuqhuba Ukuhlaselwa kwe-MITM ngaphandle ngokupheleleyo.

Imeko iyatshintsha kakhulu ukuba ufikelela kwimithombo ye-intranet ye-Yggdarsil kungekhona ngokuthe ngqo, kodwa ngokusebenzisa i-node ephakathi - indawo yokufikelela kwinethiwekhi ePhakathi, elawulwa ngumqhubi wayo.

Kule meko, ngubani onokubeka esichengeni idatha oyithumelayo:

  1. Umsebenzisi wendawo yokufikelela. Kucacile ukuba umqhubi wangoku wendawo yokufikelela kwinethiwekhi ePhakathi unokuphulaphula i-traffic engafihlwanga edlula kwizixhobo zayo.
  2. umhlaseli (indoda phakathi). Eliphakathi linengxaki efana ne Ingxaki yenethiwekhi yeTor, kuphela ngokunxulumene neendawo zokungena kunye neziphakathi.

Oku kubonakala ngathiYonke into obufuna ukuyazi malunga nomnikezeli we-Intanethi ophakathi, kodwa woyika ukubuza

Isisombululo: ukufikelela kwiinkonzo zewebhu ngaphakathi kwenethiwekhi yeYggdrasil, sebenzisa iprotocol yeHTTPS (inqanaba lesi-7 Iimodeli ze-OSI). Ingxaki kukuba akwenzeki ukukhupha isatifikethi sokhuseleko lokwenyani kwiinkonzo zenethiwekhi yeYggdrasil ngeendlela eziqhelekileyo ezinje Masibhale.

Ke ngoko, saseka iziko lethu lezatifiketi - "Medium Root CA". Uninzi lweenkonzo zothungelwano oluPhakathi zisayinwe sisatifikethi sokhuseleko esiyingcambu salo gunyaziwe wesatifikethi.

Yonke into obufuna ukuyazi malunga nomnikezeli we-Intanethi ophakathi, kodwa woyika ukubuza

Ithuba lokunciphisa isatifikethi sengcambu yegunya lesatifikethi, ngokuqinisekileyo, sithathelwe ingqalelo - kodwa apha isatifikethi siyimfuneko ngakumbi ukuqinisekisa ukunyaniseka kokudluliselwa kwedatha kunye nokuphelisa ukuhlaselwa kwe-MITM.

Iinkonzo zothungelwano oluphakathi ezisuka kubasebenzisi abohlukeneyo zinezatifikethi zokhuseleko ezohlukeneyo, ngendlela enye okanye enye esayinwe ngugunyaziwe woqinisekiso lweengcambu. Nangona kunjalo, abasebenzisi be-Root CA abakwazi kuvala i-traffic efihliweyo kwiinkonzo abatyikitye kuzo izatifikethi zokhuseleko (bona "Yintoni i-CSR?").

Abo baxhalabele ngokukhethekileyo ukhuseleko lwabo banokusebenzisa iindlela ezinjalo njengokhuseleko olongezelelweyo, njenge PGP и efanayo.

Okwangoku, isiseko sesiseko soluntu sothungelwano oluPhakathi lunamandla okukhangela ubume besatifikethi sisebenzisa iprotocol I-OCSP okanye ngokusebenzisa I-CRL.

Ngaba iMedium inenkqubo yayo yegama lesizinda?

Ekuqaleni, inethiwekhi ePhakathi yayingenalo iseva yegama lesizinda esisembindini esinokuvumela abathathi-nxaxheba bothungelwano ukuba bafikelele kwezona zixhobo zityelelwa rhoqo ngendlela elula neqhelekileyo (ngokuchaseneyo nokusebenzisa idilesi ye-IPv6 yomncedisi othile).

Thina kwiMedium sagqiba ekubeni siphefumle ubomi kule ngcamango-kwaye, sijonge phambili kancinci, siphumelele!

Yonke into obufuna ukuyazi malunga nomnikezeli we-Intanethi ophakathi, kodwa woyika ukubuza

Ubhaliso lwegama lesizinda lwenzeka ngokuzenzekelayo - kufuneka uchaze idilesi ye-IPv6 yomncedisi apho inkonzo isebenza khona. Irobhothi iya kukhangela ukuba le dilesi yeyomntu ozama ukubhalisa igama lesizinda.

Ukuba uphumelele, igama lesizinda liya kongezwa kwi-database yegama lesizinda kwiiyure ze-24. Ukuba umncedisi uyeka ukuphendula kwi-robot kwaye ayifumaneki ngaphezu kweeyure ze-72, igama lesizinda liya kukhutshwa.

Akunakwenzeka ukubhalisa igama lesizinda kwi::1Yonke into obufuna ukuyazi malunga nomnikezeli we-Intanethi ophakathi, kodwa woyika ukubuza

Ikopi yoluhlu olupheleleyo lwamagama e-domain abhalisiweyo iyafumaneka iindawo zokugcina kwiGitHub. Oku kusivumela ukuba siqinisekise ubuninzi obucacileyo malunga nemeko yangoku yamagama esizinda kunye nokuphelisa ukubhloka kwabo ngokusekelwe kwimeko enokwenzeka yokuvela kwe-ambivalent ngenxa yesenzo somntu. Kuthekani ukuba umqhubi we-DNS akayithandi into?.

Yonke into obufuna ukuyazi malunga nomnikezeli we-Intanethi ophakathi, kodwa woyika ukubuza

Kuthekani ngokukhupha izatifikethi ze-SSL kwiinkonzo zewebhu?

Ukudalwa kwe-domain ye-domain ye-server kwakungenxa yesidingo sokuthumela isiseko esingundoqo soluntu - ukwenzela ukuba kukhutshwe isatifikethi, kufuneka sibe nebala le-CN (igama eliqhelekileyo), eliligama lesizinda apho isatifikethi sikhutshwe khona.

Inkqubo yokukhupha izatifikethi ezisayinwe ngugunyaziwe wesatifikethi yenzeke ngokuzenzekelayo - i-robot ihlola ukuchaneka kunye nokunyaniseka kwedatha efakwe ngumsebenzisi. Ukuba kuphumelele, i-imeyile ithunyelwa kumsebenzisi wokugqibela equka nesatifikethi esisayiniweyo.

NantsiYonke into obufuna ukuyazi malunga nomnikezeli we-Intanethi ophakathi, kodwa woyika ukubuza

Yonke into obufuna ukuyazi malunga nomnikezeli we-Intanethi ophakathi, kodwa woyika ukubuza

Uyiqwalasela njani ngokufanelekileyo imeko-bume yokusebenzisa izixhobo zothungelwano oluPhakathi?

Iimpawu zenkqubo yokumisela indawo yokusebenza zixhomekeke kwindlela yokusebenza oyisebenzisayo.

Khetha ngobulumko (umfanekiso ucofa):

Yonke into obufuna ukuyazi malunga nomnikezeli we-Intanethi ophakathi, kodwa woyika ukubuzaYonke into obufuna ukuyazi malunga nomnikezeli we-Intanethi ophakathi, kodwa woyika ukubuza

I-Intanethi yasimahla eRussia iqala ngawe

Unokunikezela ngalo lonke uncedo olunokwenzeka ekusekeni i-Intanethi yasimahla eRashiya namhlanje. Siqulunqe uluhlu olubanzi lwendlela onokunceda ngayo inethiwekhi:

    Yonke into obufuna ukuyazi malunga nomnikezeli we-Intanethi ophakathi, kodwa woyika ukubuza   Xelela abahlobo bakho kunye noogxa bakho malunga nenethiwekhi ePhakathi
    Yonke into obufuna ukuyazi malunga nomnikezeli we-Intanethi ophakathi, kodwa woyika ukubuza   Yabelana ireferensi kweli nqaku kwiintanethi zentlalo okanye kwiblogi yomntu
    Yonke into obufuna ukuyazi malunga nomnikezeli we-Intanethi ophakathi, kodwa woyika ukubuza   Thatha inxaxheba kwiingxoxo zemiba yobugcisa yothungelwano oluPhakathi kwiGitHub
    Yonke into obufuna ukuyazi malunga nomnikezeli we-Intanethi ophakathi, kodwa woyika ukubuza   Yenza inkonzo yakho yewebhu kwinethiwekhi yeYggdrasil kwaye uyongeze kuyo Inethiwekhi yeDNS "Phakathi"
    Yonke into obufuna ukuyazi malunga nomnikezeli we-Intanethi ophakathi, kodwa woyika ukubuza   Phakamisa eyakho indawo yokufikelela kwinethiwekhi ePhakathi

Funda kwakhona:

Sthandwa, sibulala i-Intanethi
Umnikezeli weNkonzo ye-Intanethi onikezelweyo "oPhakathi" - kwiinyanga ezintathu kamva
"Phakathi" ngumnikezeli wokuqala we-Intanethi onikezelweyo eRashiya

SikwiTelegram: @medium_isp

Ngabasebenzisi ababhalisiweyo kuphela abanokuthatha inxaxheba kuphando. Ngena, ndiyacela.

Olunye ukuvota: kubalulekile kuthi ukuba sazi uluvo lwabo bangenayo iakhawunti epheleleyo kuHabré

Bali-138 abasebenzisi abavotileyo. Abasebenzisi abasi-65 abakhange.

umthombo: www.habr.com

Yongeza izimvo