Upgrade to Pro — share decks privately, control downloads, hide ads and more …

RDSのSSL/TLS証明書の更新

 RDSのSSL/TLS証明書の更新

第28回 中国地方DB勉強会の発表内容です。

Yamamoto Kazuhisa

January 25, 2020
Tweet

More Decks by Yamamoto Kazuhisa

Other Decks in Technology

Transcript

  1. 44-઀ଓ w &$ͷ"NB[PO-JOVY͔ΒQTRMίϚϯυͰ%#ʹ઀ଓ͢Δ ͱ࣍ͷΑ͏ʹදࣔ͞Ε·͢ <CPOEHBUF!JQDVSSFOU>QTRMIPHFITUBHJOHEFBECFBGBQ OPSUIFBTUSETBNB[POBXTDPN QTRM   44-DPOOFDUJPO

    QSPUPDPM5-4W DJQIFS&$%)&34""&4($. 4)" CJUT DPNQSFTTJPOP⒎  5ZQFIFMQGPSIFMQ IPHF w 44-઀ଓ͞Ε͍ͯΔͷͰ"84ͷΞφ΢ϯε௨Γ઀ଓݩͷ ূ໌ॻ΋ߋ৽͢Δඞཁ͕͋Γ·͢ΑͶʁ
  2. "84ͷαϙʔτʹฉ͍ͯΈͨ ͓ੈ࿩ʹͳΓ·͢ɻ ΫϥΠΞϯτͷSSL/TLS ূ໌ॻߋ৽ͷඞཁੑʹ͍࣭ͭͯ໰͕͋Γ·͢ɻ DBͷ઀ଓݩΫϥΠΞϯτ͸EC2(AmazonLinux)ͰRDS͸PostgreSQLΛར༻͍ͯ͠·͢ɻ ࣍ͷΑ͏ʹpsql ίϚϯυͰDBʹ઀ଓ͢ΔͱʮSSL connectionʯͱදࣔ͞ΕΔͨΊɺݱࡏ͸SSL઀ଓ͍ͯ͠Δ͸ͣͰ͢ɻ --------------------------------------------------------------------------- [bondgate@ip-10-2-0-13

    ~]$ psql hoge -h staging.deadbeaf.ap-northeast-1.rds.amazonaws.com psql (9.5.15) SSL connection (protocol: TLSv1.2, cipher: ECDHE-RSA-AES256-GCM-SHA384, bits: 256, compression: off) Type "help" for help. hoge=> --------------------------------------------------------------------------- https://docs.aws.amazon.com/ja_jp/AmazonRDS/latest/UserGuide/UsingWithRDS.SSL-certificate-rotation.html ͪ͜ΒͷΞφ΢ϯε௨Γɺ2020೥2݄5೔·ͰʹRDSͷূ໌ॻΛrds-ca-2015͔Βrds-ca-2019ʹมߋ͢Δඞཁ͕͋Δ͜ͱ͸ཧղͰ͖·ͨ͠ɻ ݕূ༻RDSͰূ໌ॻΛrds-ca-2019ʹมߋͨ͠ͱ͜Ζɺrds-ca-2015ͷ࣌ͱಉ͡Α͏ʹΫϥΠΞϯτ͔Β઀ଓ͢Δ͜ͱ͕Ͱ͖·ͨ͠ɻ ࢿྉΛಡΉͱΫϥΠΞϯτͷSSL/TLS ূ໌ॻ΋ߋ৽͢Δඞཁ͕͋Δͱॻ͔Ε͍ͯΔͷͰ͕͢ɺ͜Ε͸ෆཁͳͷͰ͠ΐ͏͔ʁ ͦΕͱ΋ɺݱࡏͷEC2ʹrds-ca-2019ʹରԠ͢Δূ໌ॻ͕͢ͰʹΠϯετʔϧ͞Ε͍ͯΔͱ͍͏͜ͱͰ͠ΐ͏͔ʁ RDS্ͷSSL/TLSূ໌ॻͱΫϥΠΞϯτͷূ໌ॻͷؔ܎͕͏·͘ཧղͰ͖͍ͯͳ͍ͷͰ͕͢ɺ͝આ໌͍͚ͨͩΕ͹޾͍Ͱ͢ɻ ΑΖ͓͘͠Ͷ͕͍͠·͢ɻ DB Πϯελϯε:
  3. ͙͢ʹฦࣄ͕ฦ͖ͬͯͨ w ཁ໿͢Δͱ w QTRMίϚϯυʹ͓͚Δ44-5-4઀ଓ࣌ͷಈ࡞ʹ͍ͭͯ͸ TTMNPEFͱ͍͏ઃఆʹΑΓܾ·Δ w ݱࡏͷ઀ଓ͸TTMNPEF͸ઃఆ͞Ε͓ͯΒͣɺσϑΥϧτͷ TTMNPEFQSFGFSͱͯ͠ಈ࡞͍ͯ͠Δɻ w

    TTMNPEFQSFGFS͸ɺΫϥΠΞϯτ͸σʔλϕʔεαʔόଆ ͕44-5-4઀ଓʹରԠ͍ͯ͠Δ৔߹ʹ͸σʔλͷ҉߸Խ͸ ߦ͏΋ͷͷɺαʔόূ໌ॻͷݕূ͸ߦΘͳ͍ಈ࡞ͱͳΔɻ
  4. .*5.๷ࢭͱ͸ʁ w தؒऀ߈ܸ w σʔλ͕ΫϥΠΞϯτɾαʔόؒͰ౉͞Ε͍ͯΔ࣌ ʹɺୈࡾऀ͕ͦͷσʔλΛมߋͰ͖Ε͹ɺαʔόΛ૷ ͏͜ͱ͕Ͱ͖ɺैͬͯͨͱ͑҉߸Խ͞Ε͍ͯͯ΋σʔ λΛཧղ͠มߋ͢Δ͜ͱ͕Ͱ͖·͢ɻୈࡾऀ͸ͦ͜Ͱɺ͜ͷ߈ܸ Λݕग़ෆՄೳʹ͢Δ઀ଓ৘ใͱσʔλΛݩͷαʔόʹૹΔ͜ͱ͕Ͱ͖·͢ɻ͜ΕΛߦ͏ ڞ௨ͨ͠ഔհ͸%/4ϙΠζχϯάͱΞυϨε৐ͬऔΓΛؚΈɺͦΕʹैͬͯΫϥΠΞϯ

    τ͸ҙਤͨ͠αʔόͰ͸ͳ͘ҟͳͬͨαʔόʹ༠ಋ͞Ε·͢ɻಉ࣌ʹɺ͜ͷ͜ͱΛ੒͠ ਱͛Δ͍͔ͭ͘ͷҟͳͬͨ߈ܸ΋ଘࡏ͠·͢ɻ44-͸ΫϥΠΞϯτʹର͠αʔόΛೝূ ͢Δ͜ͱͰɺ͜ͷ๷ࢭʹূ໌ॻݕূΛ࢖༻͠·͢ɻ https://www.postgresql.jp/document/9.5/html/libpq-ssl.html