Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
コピペでQualys SSL Server Test A+ ゲットだぜ!
Search
atpons
September 25, 2016
Programming
180
0
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
コピペでQualys SSL Server Test A+ ゲットだぜ!
設定の見直し
atpons
September 25, 2016
More Decks by atpons
See All by atpons
食べログのサーキットブレーカー導入を振り返って
atpons
1
170
TLSから見るSREの未来
atpons
3
780
Securing Credentials for Package Manager and Bundler
atpons
0
240
AWS Organizations で実現する、 マルチ AWS アカウントのルートユーザー管理からの脱却
atpons
1
710
Other Decks in Programming
See All in Programming
気づいたらRubyで100作品 ー クリエイティブコーディングが生活の一部になるまで / 100 Ruby Sketches Later: How Creative Coding Became Part of My Life
chobishiba
3
550
Dataformのリポジトリを立ち上げるときにまずやること / dataform-day0-2026
snhryt
0
110
TAKTでAI駆動開発の品質を設計する
j5ik2o
6
990
AIエージェントと協働するCLI開発 — BunとOpenClawで学んだこと
yoshikouki
1
240
The NotImplementedError Problem in Ruby
koic
1
610
AIエージェントの隔離技術の徹底比較
kawayu
0
460
AI駆動開発勉強会 広島支部 第一回勉強会 AI駆動開発概要とワークショップ
hayatoshimiu
0
450
不変条件と整合性境界—ビジネスが決める設計判断と実現パターン / Invariants and Consistency Boundaries
nrslib
13
3.5k
生成AI時代にこそ効くGo | Why Go Works in the Age of Generative AI
mom0tomo
8
3.1k
net-httpのHTTP/2対応について
naruse
0
450
Why Laravel apps break—Mastering the fundamentals to keep them maintainable
kentaroutakeda
1
340
AIチームを指揮するOSS「TAKT」活用術 / How to Use “TAKT,” an OSS Tool for Orchestrating AI Teams
nrslib
6
840
Featured
See All Featured
Visual Storytelling: How to be a Superhuman Communicator
reverentgeek
2
550
Optimizing for Happiness
mojombo
378
71k
The untapped power of vector embeddings
frankvandijk
2
1.7k
How Fast Is Fast Enough? [PerfNow 2025]
tammyeverts
3
600
Building a Scalable Design System with Sketch
lauravandoore
463
34k
Prompt Engineering for Job Search
mfonobong
0
330
The agentic SEO stack - context over prompts
schlessera
0
790
A better future with KSS
kneath
240
18k
Jamie Indigo - Trashchat’s Guide to Black Boxes: Technical SEO Tactics for LLMs
techseoconnect
PRO
0
160
The Power of CSS Pseudo Elements
geoffreycrofte
82
6.3k
Practical Tips for Bootstrapping Information Extraction Pipelines
honnibal
25
1.9k
The AI Revolution Will Not Be Monopolized: How open-source beats economies of scale, even for LLMs
inesmontani
PRO
3
3.5k
Transcript
ίϐϖͰQualys SSL Server Test A+ ήοτͩͥʂ atpons @ IGGG Meetup
2016 Summer
ࣗݾհ
atpons / ϙϯਣ
https://atpons.com/ ϗεςΟϯά࣌ͷݟ
Έͳ͞Μ SSL ͯ͠·͔͢ʁ
Έͳ͞Μ TLS ͯ͠·͔͢ʁ
None
҆શͳଓ
ੲͷৗࣝ
ূ໌ॻߴ͍
ࠓͷৗࣝ
None
ແྉͷূ໌ॻ
ςετڥ
- Ubuntu 16.04.1 LTS - Apache/2.4.18 (Ubuntu) - $ sudo
letsencrypt —-apache ࡁ ˎˎˎˎˎˎˎˎˎˎ on DigitalOcean
ͳɺͳΜͩͬͯʁ
ʮnginxʯͩͱʁ
;ɺ;͚͟Δͳ ✊
ʮApacheʯͰ ѹత
SSL/TLSͷ੬ऑੑ
Heartbleed POODLE etc…
HTTPSαʔό ઃఆͷॏཁੑ
SSL/TLS ༗ޮ͚ͩͰ ҙຯ͕ͳ͍
ݹ͍ Cipher SuiteͰ ҙຯ͕ͳ͍
Cipher Suite ʹԿΛબͿ 5-4పఈԋश4QFBLFS%FDLIUUQTTQFBLFSEFDLDPNTIJHFLJUMTDIFEJZBOYJΑΓҾ༻ ࠓ5-4ʹԿΛ͏ʁ 伴ަ 34" 'PSXBSE4FDSFDZ %)& &$%)&
σδλϧॺ໊ 34" %44 %4" &$%4" ର҉߸ %&4 3$ "&4 $IB$IB ͦͷଞ ҉߸Ϟʔυ $#$ "&"% $$. ($. 1PMZ ϝοηʔδೝূ ʢϋογϡʣ .% 4)" 4)" 4)" ɿΘͳ͍ɺԫɿҙɺɿࠓͷͱ͜Ζͬͯେৎ ҙɺ҉߸ֶతҙͱকདྷతʹීٴ͕ݟࠐ·Εͳ͍ҙؚ·Ε·͢ ͪͳΈʹɺ ྔࢠίϯϐϡʔλͰ伴ަɺσδλ ϧॺ໊શ෦Ξτʂ Cipher Suite
HTTPSαʔόςετͷ ॏཁੑ
Qualys SSL Server Test
Qualys SSL Server Test
ͱΓ͋͑ͣ͜͜Ͱ A+ औͬͯQiitaʹࡌͤ Ε͍͍ΜͰ͠ΐ
None
HTTPSαʔό ઃఆͩΔ͍ʁ
ྑ͍ײ͡ͷ configΛు͘
Mozilla SSL Configuration Generator
https://mozilla.github.io/ server-side-tls /ssl-config-generator/
σϞ
Demo • Mozilla SSL Configuration Generator • Apache / Intermediate
/ HSTS Enabled • Cipher Suite • ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE- ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA- AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM- SHA256:DHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE- RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256- SHA384:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES256-SHA384:ECDHE-ECDSA- AES256-SHA:ECDHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128- SHA:DHE-RSA-AES256-SHA256:DHE-RSA-AES256-SHA:ECDHE-ECDSA-DES-CBC3- SHA:ECDHE-RSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES128-GCM- SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128- SHA:AES256-SHA:DES-CBC3-SHA:!DSS
Qualys SSL Server Test
A+ήοτͩͥʂ
Conclusion • A+ ධՁΛಘΔͨΊʹϓϩτίϧCipher Suiteͷ ݟ͕͠ඞཁ • ࠓޙHTTP/2ߦ͘ͳΒTLS 1.2͕ཁ݅ʹͳ͍ͬͯΔ •
͋͘·ͰHTTPSαʔόͷSSL/TLSͷݕূ • Webαʔόࣗମͷ੬ऑੑɼXSSͱ͔ɼҰൠతͳη ΩϡϦςΟରࡦඞཁͰ͢ʢࠓճলུ͍ͯ͠·͢ʣ
Conclusion • Let’s Encrypt • DVূ໌ॻͳͷͰݸਓϢʔε͚ͩΑͶ • 90Ͱͷߋ৽͕ඞཁͳͷͰͦͷ࡞ۀͷࣗಈ ԽΛΕΔͱࠔΔ •
ͪΖΜcronͰࣗಈԽʙ
ࢀߟจݙ • TLSపఈԋश • https://speakerdeck.com/shigeki/tlsche-di- yan-xi