Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Trouble with enabling TLS on Postfix
Search
Sponsored
·
Ship Features Fearlessly
Turn features on and off without deploys. Used by thousands of Ruby developers.
→
hirofumihida
February 03, 2017
Technology
3.2k
1
Share
Trouble with enabling TLS on Postfix
hirofumihida
February 03, 2017
More Decks by hirofumihida
See All by hirofumihida
how-to-start-ansible-with-vmware
hirofumihida
0
920
Other Decks in Technology
See All in Technology
Cursor Subagentsはいいぞ
yug1224
2
130
バックオフィスPJのPjMをコーポレートITが担うとうまくいく3つの理由
yueda256
1
160
OCI技術資料 : ロード・バランサ 概要 - FLB・NLB共通
ocise
4
27k
OPENLOGI Company Profile
hr01
0
83k
昔話で振り返るAWSの歩み ~S3誕生から20年、クラウドはどう進化したのか~
nrinetcom
PRO
0
140
【Oracle Cloud ウェビナー】データ主権はクラウドで守れるのか?NTTデータ様のOracle Alloyで実現するソブリン対応クラウドの最適解
oracle4engineer
PRO
3
130
出版記念イベントin大阪「書籍紹介&私がよく使うMCPサーバー3選と社内で安全に活用する方法」
kintotechdev
0
140
第26回FA設備技術勉強会 - Claude/Claude_codeでデータ分析 -
happysamurai294
0
350
AIエージェント時代に必要な オペレーションマネージャーのロールとは
kentarofujii
0
290
QA組織のAI戦略とAIテスト設計システムAITASの実践
sansantech
PRO
1
310
Physical AI on AWS リファレンスアーキテクチャ / Physical AI on AWS Reference Architecture
aws_shota
1
310
【関西電力KOI×VOLTMIND 生成AIハッカソン】空間AIブレイン ~⼤阪おばちゃんフィジカルAIに続く道~
tanakaseiya
0
110
Featured
See All Featured
Navigating Weather and Climate Data
rabernat
0
160
Breaking role norms: Why Content Design is so much more than writing copy - Taylor Woolridge
uxyall
0
240
4 Signs Your Business is Dying
shpigford
187
22k
30 Presentation Tips
portentint
PRO
1
270
Building Applications with DynamoDB
mza
96
7k
Primal Persuasion: How to Engage the Brain for Learning That Lasts
tmiket
0
310
How STYLIGHT went responsive
nonsquared
100
6k
Evolving SEO for Evolving Search Engines
ryanjones
0
170
Ecommerce SEO: The Keys for Success Now & Beyond - #SERPConf2024
aleyda
1
1.9k
Navigating the Design Leadership Dip - Product Design Week Design Leaders+ Conference 2024
apolaine
0
260
Leadership Guide Workshop - DevTernity 2021
reverentgeek
1
260
Building Adaptive Systems
keathley
44
3k
Transcript
POSTFIX ͷ TLS ԽͰࠔͬͨ ͱ͋Δ Πϯϑϥ ͕ 2017-02-03 21Caffe @
intra_security#2 LT
TEXT ࣗݾհ ▸ ໊લ: Hirofumi Hida ▸ ΠϯϑϥΤϯδχΞ(UnixΛओʹ) ▸ SI
ͷݱʹ์Γࠐ·ΕͨΓ (ࠓͷ) ▸ Ops ͬͨΓ(ͲͪΒ͔ͱ͍͏ͱ͍·͕͖ͬͪ͜) ▸ Twitter: @gekko_qv ▸ Qiita: http://qiita.com/hirofumihida
TEXT ·͓͖͑ ▸ Postfix ͱ ▸ MTA mail transfer agent
▸ smtpd αʔόʔͰϝʔϧΛड͚औͬͯ ▸ smtp ΫϥΠΞϯτͰྡͷ MTA ʹϝʔϧΛసૹ ▸ TLS ͱ ▸ ௨৴ͷ҉߸Խ Transport Layer Security ▸ ࠓճ ྡͷMTA͘͠ϝʔϥʔ ͔Β smtpd αʔόʔ ·ͰͱɺsmtpΫϥΠ Ξϯτ ͔Β ྡͷsmtpdαʔόʔ ͕ؒ TLS (҉߸)Խର
TEXT ࠔͬͨ͜ͱ 1/4 ▸ ͕ࣗ postfix ϝʔϧηΩϡϦςΟ Α͘Βͳ͍ ▸
ͳΜͰͦΜͳਓؒΛϝΠϯͰΞαΠϯʁ ▸ શʹձ͔ࣾΒແৼΓ͞Εͨײ…Ͱ ▸ Ғ͍ਓʮࣄલௐࠪ(?)ऴΘͬͯΔ͔Βେৎʯ w w w w w w w w w w w w w w w ▸ ࢲʮྑ͔ͬͨɻָͳࣄʹͳΓͦ͏ͩͳɻɻʯ ▸ ࢲʮͰɺݱঢ়ͷ֬ೝΛͯ͠ΈΑ͏͔ɻʯ
TEXT ࠔͬͨ͜ͱ 2/4 ▸ OpenSSL ͕ݹ͗͢Δʂ ▸ Heart Bleed Ͳ͜ΖͰͳ͍
▸ TLS1.2 ͢ΒΕͳ͍ʂ ▸ ͕͢͞ʹ͜Εόʔδϣϯ্͛ͯΒ͑ͨɻ
TEXT ࠔͬͨ͜ͱ 3/4 ▸ ͬͨͱݴΘΕͨࣄલௐࠪ ▸ ࣮ػΑΓݹ͍όʔδϣϯͷຊޠυΩϡϝϯτ͔֬͠ೝ͠ ͯͳ͔ͬͨɻɻ ▸ ݁ہઃఆύϥϝʔλʔݟ͠ɻɻ
▸ ݕূΓ͠ɻɻ ▸ ͦͷ͓͋ΓͰɻɻ
TEXT ࠔͬͨ͜ͱ 4/4 ▸ ΤΠδϯάظ͕ؒͳ͍ɻɻ ▸ TLS Ωϟογϡ DB ͕ංେԽ͢Δ͕݅͋;
ɻɻ ▸ ͷͪʹ RFC5077 ͷଘࡏΛΔ࣌͢Ͱʹ͠ ▸ TLS1.2 ಉ࢜ͳΒ૿͑ͳ͍͕ɺSSLv3 ͱ௨৴͢Δͱ૿͑ ΔͬΆ͍ʁ
TEXT RFC5077 ͱʁ ▸ Transport Layer Security (TLS) Session Resumption
without Server-Side State ▸ https://tools.ietf.org/html/rfc5077 ▸ ৄ͘͠ https://techblog.yahoo.co.jp/infrastructure/ssl-session- resumption/
TEXT ڭ܇ ▸ૉਓ͚ͩͰηΩϡϦςΟҊ݅ʹؔΘΒͳ͍ํ͕ྑ͍ ▸Postfix ؚΊɺιϑτΣΞग़དྷΔ͚ͩ࠷৽൛Λ͓͏ ▸Postfix ݹͯ͘ RFC5077 ରԠͷ 2.11
Ҏ߱Λ͓͏ ▸࣮ػͱಉҰόʔδϣϯͷΦϦδφϧυΩϡϝϯτ(Ұ࣍ ใ)Λ֬ೝ͠Α͏ ▸ͦΕ͕ӳޠ൛͔͠ͳͯ͘
TEXT ͓ΘΓ ▸ ͝੩ௌ͋Γ͕ͱ͏͍͟͝·ͨ͠ :)