ã¯ããã«
TLS(SSL)éä¿¡ã§ã®ã¯ã©ã€ã¢ã³ãèªèšŒãã客æ§ãããªã¯ãšã¹ããæ¥ããèŠä»¶ã«å«ãŸããŠããããããšããããŸãããïŒ
ãããŸã§ã¯NLBã§443/tcpãçŽ éãããŠEC2ã€ã³ã¹ã¿ã³ã¹ã§èªèšŒãã以å€ã®æ¹æ³ããªãã£ãã®ã§ãããããããã¯ãã©ã¹ãã¹ãã¢ãéžæè¢ãšããŠæ€èšã§ããããã«ãªããŸããã
çºè¡šãããŠãããã°ãããã£ãŠããã®ã§ãããã©ããªäœ¿ãåæãªã®ãç¥ãã«ã¯å®éã«äœ¿ã£ãŠã¿ãã®ãäžçªïŒãšããããšã§è©ŠããŠã¿ãŸããã
ããã
- ãã©ã¹ãã¹ãã¢ãšã¯
- èšŒææžãæºåãã
- ãã¹ãç°å¢ãæºåãã
- æ¥ç¶ããŠã¿ã
- ãŸãšã
ãã©ã¹ãã¹ãã¢ãšã¯
ãã©ã¹ãã¹ãã¢ãšã¯ãã¢ããªã±ãŒã·ã§ã³ããŒããã©ã³ãµãŒ(ALB)ã§å©çšå¯èœãªèšŒææžèªèšŒã«é¢ãããªãã·ã§ã³ã§ãããšå
ãããšãæžããŠãŸãããèŠã¯TLSã¯ã©ã€ã¢ã³ãèªèšŒãããããã«ãªã¹ããŒã«ã¢ã¿ããããããªãœãŒã¹ã®ããšã§ãã
ãã©ã¹ãã¹ãã¢ãäœæããã«ããã£ãŠãæäœéãèªèšŒå±ãã³ãã«ãã¡ã€ã«ãããã°å€§äžå€«ã§ããããã§ã¯æ©éäœã£ãŠã¿ãŸãã
èšŒææžãæºåãã
åäœç¢ºèªã«ããã£ãŠã¯çœ²åããã¯ã©ã€ã¢ã³ãçšã®èšŒææžïŒïŒéµãã¢ïŒãåŸã§å¿
èŠã«ãªãã®ã§ãããã§ãŸãšããŠäœããŸããAWS Private CAã§ãããã®ã§ãããä»åã¯å®éšãªã®ã§ããŸããã«ãããããããªãããšããææãããããæè»œã«å©çšã§ããXCAãå©çšããŠäœæããŸããã
CAèšŒææžãã³ãã«ãšã¯ãã¯ã©ã€ã¢ã³ãåŽã«ã€ã³ã¹ããŒã«ããŠããèšŒææžã«çœ²åããèšŒææžããã«ãŒãèšŒææžããé çªã«åèšãããã®ã«ãªããŸãã
èšŒææžã®æ§æ
ä»åçšæããèšŒææžã®æ§æã¯äžèšã®ãšããã§ãã
| çšé | 眲åã®ç¶æ | çšæããåœ¢åŒ |
|---|---|---|
| ã«ãŒãèšŒææž | èªçœ² | X.509èšŒææž(PEM圢åŒ) |
| 眲åçšèšŒææž | ã«ãŒãèšŒææžã§çœ²å | X.509èšŒææž(PEM圢åŒ) |
| ã¯ã©ã€ã¢ã³ãèšŒææž | 眲åçšèšŒææžã§çœ²å | èšŒææžïŒéµãã¢(PKCS#12圢åŒ) |
XCAã®ããªãŒçã«ã¯ãã®ãããªæãã§ãã
CAèšŒææžãã³ãã«ã®äœæ
ã¯ã©ã€ã¢ã³ãèšŒææžãŸã§ã®ä¿¡é Œãã§ã€ã³ãã€ãªãããããã«ãŒãèšŒææžããã®ãã¹ãŠã®èšŒææžãçµåãããã¡ã€ã«ãçšæããŸãã
ä»åã®å Žåã¯ã1. ã«ãŒãèšŒææžãâã2. 眲åçšèšŒææžãâã3. ã¯ã©ã€ã¢ã³ãèšŒææžãã®é çªã§ä¿¡é Œé¢ä¿ãç¯ãããŠããã®ã§ã
1ãš2ãç¶ããŠèšèŒããããã¹ããã¡ã€ã«ãäœæããŸãã
ãã®ãã¡ã€ã«ãS3ãã±ããã«ã¢ããããŒãããããŒããã©ã³ãµãŒã®ãã©ã¹ãã¹ãã¢ã«ã»ããããŸãã
|
1 2 3 4 5 6 7 8 9 10 |
-----BEGIN CERTIFICATE----- MIIDxjCCAq6gAwIBAgIIRHX6qNsxp4MwDQYJKoZIhvcNAQELBQAwaTELMAkGA1UE ïŒäžç¥ïŒ /1bXUzUQBWAxrA== -----END CERTIFICATE----- -----BEGIN CERTIFICATE----- MIIDyjCCArKgAwIBAgIITe2N0nP5v0YwDQYJKoZIhvcNAQELBQAwaTELMAkGA1UE ïŒäžç¥ïŒ SQxo/NF6iU5xlSTa+1k= -----END CERTIFICATE----- |
ãµãŒããŒèšŒææžãæºåãã
HTTPSãªã¹ããŒãäœæããããã®ãµãŒããŒèšŒææžãACMã§äœæããŸãã
åå¥ã®è§£èª¬èšäºã¯ãããããããŸãã®ã§ãããã§ã¯å²æããŸãã
ãã¹ãç°å¢ãæºåãã
ããŒããã©ã³ãµãŒãæºåãã
æ€èšŒã®ç®çã«ç
§ãããããã¯ãšã³ããµãŒããŒã¯é
眮ãããåºå®ã¬ã¹ãã³ã¹ã§å®åå¿çãè¿ãããããã©ã«ãã«ãŒã«ãæ§æããŠããŸãã
äœæã«ãããããŒã«ãªããããªãã€ã³ãã ã解説ããŸãã
EC2ã³ã³ãœãŒã«ïŒããŒããã©ã³ãµãŒïŒãã©ã¹ãã¹ãã¢ãã®ãšããã«ãã©ã¹ãã¹ãã¢ãçšæããŠãããŸãã
ãã®ãªãœãŒã¹ãäœæããã®ã«ãèšŒææžã®é
ã§æºåããèšŒææžãã³ãã«ã䜿çšããŸãã
äœæãããã©ã¹ãã¹ãã¢ã¯ããŒããã©ã³ãµãŒã®ãªã¹ããŒã«é¢é£ä»ããŠãããŸãã
ã¯ã©ã€ã¢ã³ããæºåãã
ãã©ãŠã¶ã§ã¢ã¯ã»ã¹ããéã«ã¯ã©ã€ã¢ã³ãèšŒææžãæç€ºããå¿
èŠãããã®ã§ãèšŒææžæºåã®é
ã§èª¬æããèšŒææžã®ãã¡ãã¯ã©ã€ã¢ã³ãèšŒææžãèšŒææžã¹ãã¢ã«ã€ã³ããŒãããŠãããŸãã
ä»åã¯Firefoxãå©çšããŸããã®ã§ããã©ãŠã¶ãç¬èªã«æã£ãŠããèšŒææžã¹ãã¢ã«ã€ã³ããŒãããŠããŸãã
æ¥ç¶ããŠã¿ã
æ£ããèšŒææžãæç€ºããŠã¿ã
äœæããALBã«httpsã§ã¢ã¯ã»ã¹ããŠã¿ããšããã©ãŠã¶ãã¯ã©ã€ã¢ã³ãèšŒææžã®æç€ºãæ±ããŠããŸããã
ããã§é©åãªèšŒææžãéžæããŠéä¿¡ããã°ãµã€ããèŠãããããã«ãªããŸããã
ãŸããããã§ãèšŒææžãéä¿¡ããªãããæŒããšãã¡ãããšæ¥ç¶ãšã©ãŒã«ãªã£ãŠãããŸãã
æ¥ç¶äžã«ãšã©ãŒãçºçããŸãããPR_CONNECT_RESET_ERROR
ãšã©ãŒã³ãŒã: PR_CONNECT_RESET_ERROR
èšŒææžãéãå Žåã¯ã©ããªãã®ã
ä»åã¯ã¯ã©ã€ã¢ã³ãèšŒææžã3éå±€(ã«ãŒãèšŒææž - 眲åçšèšŒææž - ã¯ã©ã€ã¢ã³ãèšŒææž)ã§äœæããŠã¿ãŸããããå¥ã®èšŒææžãçšæããŠå®éšããŠã¿ãŸãããåã圹å²ãæã€å¥ã®èšŒææžãçšæããŸãã®ã§ã説æã®ããã«ããèšŒææžãã®æ«å°Ÿã«ã¢ã«ãã¡ããããæ¯ã£ãŠåŒã¶ããšã«ããŸãã
ALBã®ãã©ã¹ãã¹ãã¢ã«ã¯åŒãç¶ããã«ãŒãèšŒææžA - 眲åçšèšŒææžBãã®èšŒææžãã³ãã«ãèšå®ããŠããç¶æ
ã§ãã
- åœåæ§æïŒã«ãŒãèšŒææžA - 眲åçšèšŒææžB - ã¯ã©ã€ã¢ã³ãèšŒææžC
- 奿§æ1ïŒã«ãŒãèšŒææžA - 眲åçšèšŒææžD - ã¯ã©ã€ã¢ã³ãèšŒææžE
- 奿§æ2ïŒã«ãŒãèšŒææžF - 眲åçšèšŒææžG - ã¯ã©ã€ã¢ã³ãèšŒææžH
ããããã¢ã¯ã»ã¹ããŠã¿ããšããã奿§æ1ã¯ã¯ã©ã€ã¢ã³ãèªèšŒã«æåã奿§æ2ã¯ã¯ã©ã€ã¢ã³ãèªèšŒã«å€±æããçµæãšãªããŸããããªãã»ã©ã眲åçšèšŒææžãå€ãã£ããšããŠããã«ãŒãèšŒææžãåãã§ããã°èªèšŒãéãããšããæåã¿ããã§ãã
ãã°ã«ã¯ã©ãåºåãããã®ã
ãã°ãèŠãŠãããŸãããã
ãã°ã«ã¯æ¥ç¶ãã°ãšã¢ã¯ã»ã¹ãã°ã®2çš®é¡ããããŸããéåžžã ãšã¢ã¯ã»ã¹ãã°ã®ã¿ã䜿ãã±ãŒã¹ãå€ããšæããŸãããä»åã¯ã¯ã©ã€ã¢ã³ãèªèšŒã«é¢ããæ
å ±ããšãããã«æ¥ç¶ãã°ãåºåããŠããŸãã
ãŸãããã£ãŒã«ãã®åŸãã«ããçªå·ã¯åè¿°ã®ããã¥ã¡ã³ãã§èª¬æãããŠããåäœçœ®çªå·ã§ãããã¡ããããããŠæ²èŒããŠãããŸãã
åœåæ§æã§ã®ãã°
ãŸãã¯åœåæ§æã§ã®ãã°ã§ãã
æ¥ç¶ãã°ããèŠãŠãããŸãããã
tls_handshake_latency (7)ãã£ãŒã«ãã«ã¯ãã³ãã·ã§ã€ã¯ã«èŠããæéã衚瀺ãããŸãããã©ãŠã¶ãæäœããŠããåŽãšããŠã¯èšŒææžãéžæããŠãéä¿¡ãã¿ã³ããæŒããŸã§ã®æéã«è¿ãã§ãããconn_trace_id (12)ã¯æ¥ç¶ãã¬ãŒã¹IDãšãªã£ãŠãããããã¯AWSåŽãåæã«çºè¡ãããã®ã§ãããã¢ã¯ã»ã¹ãã°ãšã®é¢é£ä»ããããããã®ããŒæ å ±ãšãªããŸãã
| æ¥ç¶ãã°ã®ãã£ãŒã«ã | å€ |
|---|---|
tls_handshake_latency (7) |
4.135 |
leaf_client_cert_subject (8) |
CN=User2,OU=BLOG,O=SKYARCH,L=Minato,ST=Tokyo,C=JP |
leaf_client_cert_validity (9) |
NotBefore=2025-11-14T02:58:00Z;NotAfter=2026-11-14T02:58:00Z |
tls_verify_status (11) |
Success |
conn_trace_id (12) |
TID_7352613d18201b4ebfe802cf6ff3b501 |
察å¿ããã¢ã¯ã»ã¹ãã°ã«ããæ¥ç¶ãã°ãšå¯Ÿã«ãªãtrace_id (18)ãåºãŠããŸãã
ã¿ã€ã ã¹ã¿ã³ããã¯ã©ã€ã¢ã³ãIPãé§äœ¿ããŠãããããªãããã¶ãããã ãããªãããšããäžæ¯ãªçªãåããããããªããŠããã®ã¯è¯ãç¹ã§ããã
| ã¢ã¯ã»ã¹ãã°ã®ãã£ãŒã«ã | å€ |
|---|---|
trace_id (18) |
TID_7352613d18201b4ebfe802cf6ff3b501 |
奿§æ1ã§ã®ãã°
ã€ã¥ããŠå¥æ§æ1ã§ã®ãã°ã§ãã
tls_handshake_latency (7)ãã£ãŒã«ãã®æéãé·ããªã£ãŠããŸãããããããã£ããã£ããšã£ãŠããããã§ããããconn_trace_id (12)ã¯æ¥ç¶ããšã«åºæã®IDãçæãããã®ã§å ã»ã©ãšã¯å¥ã®IDã«ãªã£ãŠããããšãããããŸããleaf_client_cert_subject (8)ã®CNãDarkUserã«ãªã£ãŠããã®ã¯ããããããšã©ãŒã«ãªãã ãããšäºæž¬ããŠèšŒææžã«ã€ããååã§ãã(ç¬)ããŸããã®æåã«ãªã£ãŠããŸã£ãã®ã§ã远å ã§å¥æ§æ2ã詊ãããšã«ãªããŸãã...ã
| æ¥ç¶ãã°ã®ãã£ãŒã«ã | å€ |
|---|---|
tls_handshake_latency (7) |
24.160 |
leaf_client_cert_subject (8) |
CN=DarkUser,OU=BLOG,O=SKYARCH,L=Minato,ST=Tokyo,C=JP |
tls_verify_status (11) |
Success |
conn_trace_id (12) |
TID_13d9f0faef7c854182df2940cd675a6b |
ãã¡ããåãããæ¥ç¶ãã°ãšå¯Ÿã«ãªãtrace_id (18)ãåºãŠããŸãã
| ã¢ã¯ã»ã¹ãã°ã®ãã£ãŒã«ã | å€ |
|---|---|
trace_id (18) |
TID_13d9f0faef7c854182df2940cd675a6b |
奿§æ2ã§ã®ãã°
æåŸã«å¥æ§æ2ã§ã®ãã°ã§ãã
tls_handshake_latency (7)ãã£ãŒã«ãã¯-ã«ãªã£ãŠããŸãããtls_verify_status (11)ãFailedã«ãªã£ãŠããã®ã§ãã³ãã·ã§ã€ã¯ãšããŠã¯å€±æãã€ãŸãã¯ããã¥ã¡ã³ãã«èšèŒã®ããã³ãã·ã§ã€ã¯ãæ£åžžã«ç¢ºç«ãããŠããªãå Žåãã«è©²åœããããã§ãããconn_trace_id (12)ã¯æ¥ç¶ããšã«åºæã®IDãçæãããã®ã§å ã»ã©ãšã¯å¥ã®IDã«ãªã£ãŠããããšãããããŸãã
| æ¥ç¶ãã°ã®ãã£ãŒã«ã | å€ |
|---|---|
tls_handshake_latency (7) |
- |
leaf_client_cert_subject (8) |
CN=Alt User,OU=BLOG,O=SKYARCH,L=Minato,ST=Tokyo,C=JP |
tls_verify_status (11) |
Failed:ClientCertUntrusted |
conn_trace_id (12) |
TID_4d5d46d7c5d76642b793aa04a408f2b2 |
ãã®æ§æã§ã¯ãã³ãã·ã§ã€ã¯ã倱æããŠããã®ã§HTTPã¢ã¯ã»ã¹ã¯è¡ããããçµæãšããŠã¢ã¯ã»ã¹ãã°ã¯åºãŠããŸããã§ããã
ãŸãšã
ãããŸã§ã®EC2ã€ã³ã¹ã¿ã³ã¹ã§çµç«¯ããã¯ã©ã€ã¢ã³ãèªèšŒã«æ¯ã¹ãã°ã§ããããšã¯ãããŸã§å€ãã¯ãããŸããããåºæ¬çãªã¯ã©ã€ã¢ã³ãèªèšŒããããŒãžããµãŒãã¹ã§å®çŸã§ããããã«ãªã£ãã®ã¯éåžžã«äŸ¿å©ã§ããã
ãã©ã¹ãã¹ãã¢ã«ã¯å·è¡ãªã¹ã(CRL)ã®èšå®ãã§ããããã«ãªã£ãŠããŸãããä»åã¯ãäºç®ïŒãšãæéïŒã®åé¡ããèŠéããŸãã...ãã ãããã®ã¿ãŸãïŒ
æçš¿è ãããã£ãŒã«
- æ ¹ã£ãã¯ã€ã³ãã©å±ãªå€ãããããã
ææ°ã®æçš¿
AWS2025幎12æ4æ¥CloudFormationã®ããªããèªè倿Žã»ããã䜿ã£ãŠã¿ãïŒç¶ç·šïŒ
AWS2025幎11æ27æ¥CloudFormationã®ããªããèªè倿Žã»ããã䜿ã£ãŠã¿ã
AWS2025幎11æ21æ¥ãçç¯ãAWSããã¯ã¢ããã®ã¿ã°ã«ãããªãœãŒã¹å²ãåœãŠã§è»œãã¯ãŸã£ã
AWS2025幎11æ17æ¥ALBã§ãã©ã¹ãã¹ãã¢ã䜿ã£ãŠã¿ã




