Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Trouble with enabling TLS on Postfix
Search
Sponsored
·
SiteGround - Reliable hosting with speed, security, and support you can count on.
→
hirofumihida
February 03, 2017
Technology
1
3.2k
Trouble with enabling TLS on Postfix
hirofumihida
February 03, 2017
Tweet
Share
More Decks by hirofumihida
See All by hirofumihida
how-to-start-ansible-with-vmware
hirofumihida
0
920
Other Decks in Technology
See All in Technology
データの整合性を保ちたいだけなんだ
shoheimitani
8
3.1k
usermode linux without MMU - fosdem2026 kernel devroom
thehajime
0
240
Frontier Agents (Kiro autonomous agent / AWS Security Agent / AWS DevOps Agent) の紹介
msysh
3
180
GitHub Issue Templates + Coding Agentで簡単みんなでIaC/Easy IaC for Everyone with GitHub Issue Templates + Coding Agent
aeonpeople
1
240
Bill One急成長の舞台裏 開発組織が直面した失敗と教訓
sansantech
PRO
2
380
登壇駆動学習のすすめ — CfPのネタの見つけ方と書くときに意識していること
bicstone
3
120
10Xにおける品質保証活動の全体像と改善 #no_more_wait_for_test
nihonbuson
PRO
2
310
StrandsとNeptuneを使ってナレッジグラフを構築する
yakumo
1
120
Introduction to Bill One Development Engineer
sansan33
PRO
0
360
名刺メーカーDevグループ 紹介資料
sansan33
PRO
0
1k
SREチームをどう作り、どう育てるか ― Findy横断SREのマネジメント
rvirus0817
0
300
Webhook best practices for rock solid and resilient deployments
glaforge
1
290
Featured
See All Featured
Refactoring Trust on Your Teams (GOTO; Chicago 2020)
rmw
35
3.4k
HU Berlin: Industrial-Strength Natural Language Processing with spaCy and Prodigy
inesmontani
PRO
0
220
Leveraging Curiosity to Care for An Aging Population
cassininazir
1
160
Large-scale JavaScript Application Architecture
addyosmani
515
110k
Introduction to Domain-Driven Design and Collaborative software design
baasie
1
590
Tips & Tricks on How to Get Your First Job In Tech
honzajavorek
0
440
New Earth Scene 8
popppiees
1
1.5k
Darren the Foodie - Storyboard
khoart
PRO
2
2.4k
How STYLIGHT went responsive
nonsquared
100
6k
How to make the Groovebox
asonas
2
1.9k
Bootstrapping a Software Product
garrettdimon
PRO
307
120k
Paper Plane (Part 1)
katiecoart
PRO
0
4.3k
Transcript
POSTFIX ͷ TLS ԽͰࠔͬͨ ͱ͋Δ Πϯϑϥ ͕ 2017-02-03 21Caffe @
intra_security#2 LT
TEXT ࣗݾհ ▸ ໊લ: Hirofumi Hida ▸ ΠϯϑϥΤϯδχΞ(UnixΛओʹ) ▸ SI
ͷݱʹ์Γࠐ·ΕͨΓ (ࠓͷ) ▸ Ops ͬͨΓ(ͲͪΒ͔ͱ͍͏ͱ͍·͕͖ͬͪ͜) ▸ Twitter: @gekko_qv ▸ Qiita: http://qiita.com/hirofumihida
TEXT ·͓͖͑ ▸ Postfix ͱ ▸ MTA mail transfer agent
▸ smtpd αʔόʔͰϝʔϧΛड͚औͬͯ ▸ smtp ΫϥΠΞϯτͰྡͷ MTA ʹϝʔϧΛసૹ ▸ TLS ͱ ▸ ௨৴ͷ҉߸Խ Transport Layer Security ▸ ࠓճ ྡͷMTA͘͠ϝʔϥʔ ͔Β smtpd αʔόʔ ·ͰͱɺsmtpΫϥΠ Ξϯτ ͔Β ྡͷsmtpdαʔόʔ ͕ؒ TLS (҉߸)Խର
TEXT ࠔͬͨ͜ͱ 1/4 ▸ ͕ࣗ postfix ϝʔϧηΩϡϦςΟ Α͘Βͳ͍ ▸
ͳΜͰͦΜͳਓؒΛϝΠϯͰΞαΠϯʁ ▸ શʹձ͔ࣾΒແৼΓ͞Εͨײ…Ͱ ▸ Ғ͍ਓʮࣄલௐࠪ(?)ऴΘͬͯΔ͔Βେৎʯ w w w w w w w w w w w w w w w ▸ ࢲʮྑ͔ͬͨɻָͳࣄʹͳΓͦ͏ͩͳɻɻʯ ▸ ࢲʮͰɺݱঢ়ͷ֬ೝΛͯ͠ΈΑ͏͔ɻʯ
TEXT ࠔͬͨ͜ͱ 2/4 ▸ OpenSSL ͕ݹ͗͢Δʂ ▸ Heart Bleed Ͳ͜ΖͰͳ͍
▸ TLS1.2 ͢ΒΕͳ͍ʂ ▸ ͕͢͞ʹ͜Εόʔδϣϯ্͛ͯΒ͑ͨɻ
TEXT ࠔͬͨ͜ͱ 3/4 ▸ ͬͨͱݴΘΕͨࣄલௐࠪ ▸ ࣮ػΑΓݹ͍όʔδϣϯͷຊޠυΩϡϝϯτ͔֬͠ೝ͠ ͯͳ͔ͬͨɻɻ ▸ ݁ہઃఆύϥϝʔλʔݟ͠ɻɻ
▸ ݕূΓ͠ɻɻ ▸ ͦͷ͓͋ΓͰɻɻ
TEXT ࠔͬͨ͜ͱ 4/4 ▸ ΤΠδϯάظ͕ؒͳ͍ɻɻ ▸ TLS Ωϟογϡ DB ͕ංେԽ͢Δ͕݅͋;
ɻɻ ▸ ͷͪʹ RFC5077 ͷଘࡏΛΔ࣌͢Ͱʹ͠ ▸ TLS1.2 ಉ࢜ͳΒ૿͑ͳ͍͕ɺSSLv3 ͱ௨৴͢Δͱ૿͑ ΔͬΆ͍ʁ
TEXT RFC5077 ͱʁ ▸ Transport Layer Security (TLS) Session Resumption
without Server-Side State ▸ https://tools.ietf.org/html/rfc5077 ▸ ৄ͘͠ https://techblog.yahoo.co.jp/infrastructure/ssl-session- resumption/
TEXT ڭ܇ ▸ૉਓ͚ͩͰηΩϡϦςΟҊ݅ʹؔΘΒͳ͍ํ͕ྑ͍ ▸Postfix ؚΊɺιϑτΣΞग़དྷΔ͚ͩ࠷৽൛Λ͓͏ ▸Postfix ݹͯ͘ RFC5077 ରԠͷ 2.11
Ҏ߱Λ͓͏ ▸࣮ػͱಉҰόʔδϣϯͷΦϦδφϧυΩϡϝϯτ(Ұ࣍ ใ)Λ֬ೝ͠Α͏ ▸ͦΕ͕ӳޠ൛͔͠ͳͯ͘
TEXT ͓ΘΓ ▸ ͝੩ௌ͋Γ͕ͱ͏͍͟͝·ͨ͠ :)