22
1 SSLの暗号アルゴリズム移行について 2014.2

Sha 2 Migration

Embed Size (px)

DESCRIPTION

sha2

Citation preview

  • 1SSL

    2014.2

  • 2

    SSL(

    )

    (

    )

    ID()

    (CACertificationAuthoritySymantec

  • 3SSL

    SSL

  • SSL

    SSL SSL(CA)

    4

    SSL https://

    SSL

    SSL

    SSL

    ()

    ()

  • SSL

    5

    RSA, ECC, DSA

    RC4, DES/3DES, AES

    SHA-1, SHA-2 (SHA-256)

    SSL

  • SSL

    SSL

    1()

    ()

    6

    SHA1 05673990ABD9FCF205CECBD07F8DD57F22A6859B

    SHA2 FBEB25E663FB9808255A8E87079129C020FC7320D5B18FA32C742778286D5569

    SHA1 6D13285B76B102564E9E5167CBB4EEF8A35C93CA

    SHA2 31334AEA370EE4D2AC7579E64AE40824A08DAEE42C92F3BBDB6555085957EDDC

    SSL

  • 7

    https://www.example.com/index.html

    SSL

    SSL

    SSL

  • 8

    RSA1024

    SHA-1

    80bit

    2010

    RSA2048

    SHA-2 (SHA-224)

    112bit

    2011

    SHA-2(SHA-256)

    RSA3072ECC256

    128bit

    2031

    MD2,MD4,MD5

    RSA512....

    ()

    2013

    :SSL()

    !!

    2010RSA1024

    NIST ()

    SSL

  • RSA1024SHA-1

    RSA2048SHA-2

    SHA2

    9

    SSL

    ECC384

  • 10

    SSL

  • 11

    SHA2 (NIST):SHA12013 PCIDSS:NIST (SHA12013 ) (NISC) :SHA12019 (CA/BForumBaselineRequirement) :2016(Microsoft)

    * WindowsOSSSL

    SHA2SHA1

    SHA1 SHA1

    SSL 20151231 20161231

    * http://technet.microsoft.com/ja-jp/security/advisory/2880823http://social.technet.microsoft.com/wiki/contents/articles/1760.windows-root-certificate-program-technical-requirements-version-2-0.aspx

    SSL

  • SHA1

    12

    SHA1

    SSL

  • SHA2SHA2SHA1

    SHA2SSL

    SHA12015SHA12016

    /

    SSLRSA

    (SHA1)RSA

    (SHA2)ECC

    (SHA2) PKIforSSL (SSL) * (SSL) *

    New!New! New!New!*IDID EV

    13

    SSL

  • 14

    SHA2 SHA1

    SHA2 SHA2(

    20161231)

    SHA12017SHA2

    API

    SHA2

    SHA2(20161231)

    SHA12017SHA2

    SHA2 SHA2

    SHA1

    SHA13SHA2

    SSL

  • ECC

    ECC(SHA2)SSLWebCPU467

    15

    ECC()

    SSL

  • 16

  • exe

    17

    * SSLSHA11(SHA12015)

    SHA1 SHA1

    20151231 20151231

    OK

    * http://technet.microsoft.com/ja-jp/security/advisory/2880823http://social.technet.microsoft.com/wiki/contents/articles/1760.windows-root-certificate-program-technical-requirements-version-2-0.aspx

  • 18

    SHA2 SHA1

    SHA2 SHA2(

    20151231)

    SHA12016SHA2

    SHA2 SHA2

    SHA1

    SHA12SHA2

  • 19

    ID

    ID

  • ID

    ID

    20

    * SHA12015SHA12016

    SHA1 SHA1

    ID 20151231 20161231

    ID

    * http://technet.microsoft.com/ja-jp/security/advisory/2880823http://social.technet.microsoft.com/wiki/contents/articles/1760.windows-root-certificate-program-technical-requirements-version-2-0.aspx

  • ID

    21

    SHA2 SHA1

    SHA2 SHA2 (2016

    1231)

    SHA12016SHA2

    ASP

    SHA2 SHA2

    SHA1

    ID

    SHA13SHA2

  • 22