Slide 22
Slide 22 text
懸念点2: サービス間の認証の仕組み
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 4 (0x4)
Signature Algorithm: ecdsa-with-SHA384
Issuer: C=US, O=SPIFFE
...
Subject: C=US, O=SPIRE
...
X509v3 extensions:
X509v3 Key Usage: critical
Digital Signature, Key Encipherment, Key Agreement
X509v3 Extended Key Usage:
TLS Web Server Authentication, TLS Web Client Authentication
...
X509v3 Subject Alternative Name:
URI:
spiffe://example.org/workload
...
▶ X.509 SVID の例(SAN の URI にサービスを識別するための SPIFFE ID をセットする)