- X: ãèªèº«ã®Podçªå·
- èªèšŒå±(蚌ææžãµãŒããŒ)圹: WinSrv1(WSrv1-yyMMddX)
- HTTPS WebãµãŒããŒåœ¹: WinSrv2(WSrv2-yyMMddX)
- ã¯ã©ã€ã¢ã³ã ãã¹ã¯ãããç°å¢: WinClient(WC1-yyMMddX)
- æé äŸã®ç»åã¯pod255ã«æºæ ãããã©ã¡ãŒã¿ã®ãã®ã§ã
- æé å ã®Xè¡šèšã¯ãèªèº«ã®podçªå·ã«èªã¿æ¿ããŠãã ãã
-
Windows èªèšŒå±(WinSrv1)ã®ç®¡çç»é¢ã«æ¥ç¶ãã
-
圹å²ãšæ©èœã®è¿œå ãŠã£ã¶ãŒããéå§ãã
- [ã¹ã¿ãŒãã¡ãã¥ãŒ]ãã¯ãªãã¯ãã
- ã¹ã¿ãŒãã¡ãã¥ãŒå ã®[ãµãŒã㌠ãããŒãžã£ãŒ]ãã¯ãªãã¯ãããµãŒããŒãããŒãžã£ãèµ·åãã
- ãµãŒããŒãããŒãžã£ãŒã®ããã·ã¥ããŒãç»é¢å ã®[圹å²ãšæ©èœã®è¿œå ]ãã¯ãªãã¯ãã
- [圹å²ãšæ©èœã®è¿œå ãŠã£ã¶ãŒã]ãŠã£ã³ããŠãèµ·åããããšã確èªãã
-
Active Directory蚌ææžãµãŒãã¹ã®åœ¹å²ãè¿œå ãã
-
[圹å²ãšæ©èœã®è¿œå ãŠã£ã¶ãŒã]ãŠã£ã³ããŠã®[éå§ããåã«]ç»é¢ã§ã[次ãž]ãã¯ãªãã¯ãã
-
[ã€ã³ã¹ããŒã«ã®çš®é¡]ç»é¢ã§ã[次ãž]ãã¯ãªãã¯ãã
-
[ãµãŒããŒã®éžæ]ç»é¢ã§ã[次ãž]ãã¯ãªãã¯ãã
-
[ãµãŒããŒã®åœ¹å²]ç»é¢ã§ã以äžã®ãã©ã¡ãŒã¿ãéžæãã
- Active Directory蚌ææžãµãŒãã¹
ãè£è¶³ã
"Active Directory蚌ææžãµãŒãã¹"ã®ãã§ãã¯ãã€ãããšã[Active Directory蚌ææžãµãŒãã¹ã«å¿ èŠãªæ©èœãè¿œå ããŸããïŒ]ã®ç¢ºèªãããã¢ããã衚瀺ãããŸãã
[Active Directory蚌ææžãµãŒãã¹ã«å¿ èŠãªæ©èœãè¿œå ããŸããïŒ]ãŠã£ã³ããŠã§ã[æ©èœã®è¿œå ] ãã¯ãªãã¯ããŸãã -
[ãµãŒããŒã®åœ¹å²]ç»é¢ã§ãäžã®ãã©ã¡ãŒã¿ãéžæããããšã確èªãã[次ãž]ãã¯ãªãã¯ãã
-
[æ©èœã®éžæ]ç»é¢ã§ã[次ãž]ãã¯ãªãã¯ãã
-
[AD CS]ç»é¢ã§ã[次ãž]ãã¯ãªãã¯ãã
-
[圹å²ãµãŒãã¹]ç»é¢ã§ã以äžã®ãã©ã¡ãŒã¿ãéžæãã
- 蚌ææ©é¢
- ãªã³ã©ã€ã³ã¬ã¹ãã³ããŒ
- ãããã¯ãŒã¯ããã€ã¹ç»é²ãµãŒãã¹
- 蚌ææ©é¢Webç»é²
- 蚌ææžã®ç»é²WebãµãŒãã¹
- 蚌ææžã®ç»é²ããªã·ãŒWebãµãŒãã¹
ãè£è¶³ã
"蚌ææ©é¢Webç»é²"ã®ãã§ãã¯ãã€ãããšã[蚌ææ©é¢Webç»é² ã«å¿ èŠãªæ©èœãè¿œå ããŸããïŒ]ã®ç¢ºèªãããã¢ããã衚瀺ãããŸãã
[蚌ææ©é¢Webç»é² ã«å¿ èŠãªæ©èœãè¿œå ããŸããïŒ]ãŠã£ã³ããŠã§ã[æ©èœã®è¿œå ] ãã¯ãªãã¯ããŸãã -
[圹å²ãµãŒãã¹]ç»é¢ã§ã[次ãž]ãã¯ãªãã¯ãã
-
[WebãµãŒããŒã®åœ¹å²(IIS)]ç»é¢ã§ã[次ãž]ãã¯ãªãã¯ãã
-
[圹å²ãµãŒãã¹ã®éžæ]ç»é¢ã§ã[次ãž]ãã¯ãªãã¯ãã
-
[確èª]ç»é¢ã§ã[ã€ã³ã¹ããŒã«]ãã¯ãªãã¯ãã
-
[çµæ]ç»é¢ã§ãã€ã³ã¹ããŒã«é²æã瀺ãããã°ã¬ã¹ããŒãå³ç«¯ã«å°éãããŸã§æ°åéåŸ æ©ãã
-
[çµæ]ç»é¢ã§ãã€ã³ã¹ããŒã«ãæ£åžžã«å®äºããããšã確èªãã[éãã]ãã¯ãªãã¯ãã
-
-
Windows èªèšŒå±(WinSrv1)ã®ç®¡çç»é¢ã«æ¥ç¶ãã
-
Active Directory蚌ææžãµãŒãã¹æ§æãŠã£ã¶ãŒããéå§ãã
- ãµãŒããŒãããŒãžã£ãèµ·åãã
- ãµãŒããŒãããŒãžã£ãŒã®ããã·ã¥ããŒãç»é¢äžéšã®éç¥ã¢ã€ã³ã³ãã¯ãªãã¯ãã"å±éåŸæ§æ"ã®[察象ãµãŒããŒã«Active Directory蚌ææžãµãŒãã¹ãæ§æãã]ãã¯ãªãã¯ãã
- [AD CSã®æ§æ]ãŠã£ã³ããŠãèµ·åããããšã確èªãã
-
AD CS(Active Directory蚌ææžãµãŒãã¹)ãæ§æãã
-
[AD CSæ§æ]ãŠã£ã³ããŠã®[è³æ Œæ å ±]ç»é¢ã§ã[次ãž]ãã¯ãªãã¯ãã
-
[AD CSæ§æ]ãŠã£ã³ããŠã®[圹å²ãµãŒãã¹]ç»é¢ã§ã以äžã®ãã©ã¡ãŒã¿ãéžæãã
æ§æãã圹å²ãµãŒãã¹ã®éžæ:
- 蚌ææ©é¢
- 蚌ææ©é¢Webç»é²
- ãªã³ã©ã€ã³ã¬ã¹ãã³ããŒ
- ãããã¯ãŒã¯ããã€ã¹ç»é²ãµãŒãã¹
- 蚌ææžã®ç»é²WebãµãŒãã¹
- 蚌ææžã®ç»é²ããªã·ãŒWebãµãŒãã¹
-
[AD CSæ§æ]ãŠã£ã³ããŠã®[圹å²ãµãŒãã¹]ç»é¢ã§ã[次ãž]ãã¯ãªãã¯ãã
-
[AD CSæ§æ]ãŠã£ã³ããŠã®[ã»ããã¢ããã®çš®é¡]ç»é¢ã§ã以äžã®ãã©ã¡ãŒã¿ãéžæãã
- ãšã³ã¿ãŒãã©ã€ãºCA
- ã¹ã¿ã³ãã¢ãã³CA
-
[AD CSæ§æ]ãŠã£ã³ããŠã®[ã»ããã¢ããã®çš®é¡]ç»é¢ã§ã[次ãž]ãã¯ãªãã¯ãã
-
[AD CSæ§æ]ãŠã£ã³ããŠã®[CAã®çš®é¡]ç»é¢ã§ã以äžã®ãã©ã¡ãŒã¿ãéžæãã
- ã«ãŒãCA
- äžäœCA
-
[AD CSæ§æ]ãŠã£ã³ããŠã®[CAã®çš®é¡]ç»é¢ã§ã[次ãž]ãã¯ãªãã¯ãã
-
[AD CSæ§æ]ãŠã£ã³ããŠã®[ç§å¯ããŒ]ç»é¢ã§ã以äžã®ãã©ã¡ãŒã¿ãéžæãã
- æ°ããç§å¯ããŒãäœæãã
- æ¢åã®ç§å¯ããŒã䜿çšãã
- 蚌ææžãéžæããé¢é£ä»ããããŠããç§å¯ããŒã䜿çšãã
- ãã®ã³ã³ãã¥ãŒã¿ãŒã®æ¢åã®ç§å¯ããŒãéžæãã
-
[AD CSæ§æ]ãŠã£ã³ããŠã®[ç§å¯ããŒ]ç»é¢ã§ã[次ãž]ãã¯ãªãã¯ãã
-
[AD CSæ§æ]ãŠã£ã³ããŠã®[æå·å]ç»é¢ã§ã以äžã®ãã©ã¡ãŒã¿ãéžæãã
æå·åãããã€ããŒã®éžæ:
RSA#Microsoft Software Key Storage Privoder ããŒé·ã®éžæ:
2048 ãã®CAããçºè¡ããã蚌ææžã®çœ²åã«äœ¿çšããããã·ã¥ã¢ã«ãŽãªãºã ãéžæ:
SHA256 - CAãç§å¯ããŒã«ã¢ã¯ã»ã¹ãããšãã«ã管çè ã«ããæäœãèš±å¯ãã
-
[AD CSæ§æ]ãŠã£ã³ããŠã®[æå·å]ç»é¢ã§ã[次ãž]ãã¯ãªãã¯ãã
-
[AD CSæ§æ]ãŠã£ã³ããŠã®[CAã®åå]ç»é¢ã§ã以äžã®ãã©ã¡ãŒã¿ãå ¥åãã
ãã®CAã®å ±éå:
WinCA èå¥åã®ãµãã£ãã¯ã¹:
DC=example, DC=local èå¥åã®ãã¬ãã¥ãŒ:
CN=WinCA, DC=example, DC=local -
[AD CSæ§æ]ãŠã£ã³ããŠã®[CAã®åå]ç»é¢ã§ã[次ãž]ãã¯ãªãã¯ãã
-
[AD CSæ§æ]ãŠã£ã³ããŠã®[æå¹æé]ç»é¢ã§ã以äžã®ãã©ã¡ãŒã¿ãå ¥åãã
ãã®èšŒææ©é¢(CA)ã«å¯ŸããŠçæããã蚌ææžã®æå¹æéãéžæ:
5 幎é -
[AD CSæ§æ]ãŠã£ã³ããŠã®[æå¹æé]ç»é¢ã§ã[次ãž]ãã¯ãªãã¯ãã
-
[AD CSæ§æ]ãŠã£ã³ããŠã®[CAããŒã¿ããŒã¹]ç»é¢ã§ã以äžã®ãã©ã¡ãŒã¿ãå ¥åãã
蚌ææžããŒã¿ããŒã¹ã®å Žæ:
C:\Windows\system32\CertLog 蚌ææžããŒã¿ããŒã¹ã®ãã°ã®å Žæ:
C:\Windows\system32\CertLog -
[AD CSæ§æ]ãŠã£ã³ããŠã®[CAããŒã¿ããŒã¹]ç»é¢ã§ã[次ãž]ãã¯ãªãã¯ãã
-
[AD CSæ§æ]ãŠã£ã³ããŠã®[確èª]ç»é¢ã§ã[æ§æ]ãã¯ãªãã¯ãã
-
[AD CSæ§æ]ãŠã£ã³ããŠã®[çµæ]ç»é¢ã§ã[éãã]ãã¯ãªãã¯ãã
-
-
Windows èªèšŒå±(WinSrv1)ã®ç®¡çç»é¢ã«æ¥ç¶ãã
-
蚌ææ©é¢ç®¡çã³ã³ãœãŒã«ãèµ·åã§ããããšã確èªãã
-
èªèšŒå±ãšããŠã®èªå·±çœ²å蚌ææž(ã«ãŒã蚌ææž)ãäœæãããŠããããšã確èªãã
-
[蚌ææž]管çã³ã³ãœãŒã«ãèµ·åãã
-
Windows ã¹ã¿ãŒãã¡ãã¥ãŒãå³ã¯ãªãã¯ããã³ã³ããã¹ãã¡ãã¥ãŒå ã®[ãã¡ã€ã«åãæå®ããŠå®è¡]ãã¯ãªãã¯ãã
-
[ãã¡ã€ã«åãæå®ããŠå®è¡]ãŠã£ã³ããŠãèµ·åããããšã確èªãã
-
[ãã¡ã€ã«åãæå®ããŠå®è¡]ãŠã£ã³ããŠã§ã以äžã®ãã©ã¡ãŒã¿ãå ¥åãã
åå:
certlm.msc -
[ãã¡ã€ã«åãæå®ããŠå®è¡]ãŠã£ã³ããŠã§ã[OK]ãã¯ãªãã¯ãã
-
[ãŠãŒã¶ãŒã¢ã«ãŠã³ãå¶åŸ¡]ã®ãããã¢ããã§ã[ã¯ã]ãã¯ãªãã¯ãã
-
[蚌ææž]管çã³ã³ãœãŒã«ãèµ·åããããšã確èªãã
-
-
Windows Server 1ãææããŠããé»å蚌ææžã確èªãã
- å·ŠåŽã³ã³ãœãŒã«ããªãŒã®[蚌ææž - ããŒã«ã« ã³ã³ãã¥ãŒã¿ãŒ]-[å人]-[蚌ææž]ãã¯ãªãã¯ãã
- ãŠã£ã³ããŠå³åŽãã€ã³ã®èšŒææžã®äžèŠ§ãåç §ããçºè¡è ã "WinCA" ã§ãã蚌ææžãã¯ãªãã¯ããŠéžæãã
- "WinCA" ã®èšŒææžãå³ã¯ãªãã¯ããã³ã³ããã¹ãã¡ãã¥ãŒå
ã®[éã]ãã¯ãªãã¯ãã
- [蚌ææž]ãŠã£ã³ããŠã衚瀺ãããããšã確èªãã
- å·ŠåŽã³ã³ãœãŒã«ããªãŒã®[蚌ææž - ããŒã«ã« ã³ã³ãã¥ãŒã¿ãŒ]-[å人]-[蚌ææž]ãã¯ãªãã¯ãã
-
蚌ææžã®ãã©ã¡ãŒã¿ã確èªãã
-
[蚌ææž]ãŠã£ã³ããŠã®[å šè¬]ã¿ãã«èšèŒãããŠãããã©ã¡ãŒã¿ã確èªãã
ã確èªãã€ã³ãã
- çºè¡å ã "WinCA" ã§ããããš
- çºè¡è ã "WinCA" ã§ããããš
- "ãã®èšŒææžã«å¯Ÿå¿ããç§å¯ããŒãæã£ãŠããŸã"ãšè¡šèšãããŠããããš
-
[蚌ææž]ãŠã£ã³ããŠã®[詳现]ã¿ãã«èšèŒãããŠãããã©ã¡ãŒã¿ã確èªãã
ã確èªãã€ã³ãã
- æå¹æéã®éå§ ã çŸåšæ¥æãããåã§ããããš
- æå¹æéã®çµäº ã çŸåšæ¥æãããåŸã§ããããš
- çºè¡è ã "WinCA, example, local" ã§ããããš
- ãµããžã§ã¯ã ã "WinCA, example, local" ã§ããããš
-
[蚌ææž]ãŠã£ã³ããŠã®[蚌æã®ãã¹]ã¿ãã«èšèŒãããŠãããã©ã¡ãŒã¿ã確èªãã
ã確èªãã€ã³ãã
- "WinCA"ã®"蚌ææžã®ç¶æ "ã "ãã®èšŒææžã¯åé¡ãããŸããã" ã§ããããš
-
-
-
蚌ææ©é¢Webç»é²ãµãŒãã¹ãèµ·åããŠããããšã確èªãã
-
IIS管çã³ã³ãœãŒã«ãèµ·åãã
- ãµãŒããŒãããŒãžã£ãŒãŠã£ã³ããŠå³äžã®[ããŒã«]ãã¯ãªãã¯ãã
- ã¡ãã¥ãŒå ã®[ã€ã³ã¿ãŒããã ã€ã³ãã©ã¡ãŒã·ã§ã³ ãµãŒãã¹(IIS) ãããŒãžã£ãŒ]ãã¯ãªãã¯ããIIS管çã³ã³ãœãŒã«ãèµ·åãã
- [ã€ã³ã¿ãŒããã ã€ã³ãã©ã¡ãŒã·ã§ã³ ãµãŒãã¹(IIS) ãããŒãžã£ãŒ]ãèµ·åããããšã確èªãã
-
CertSrvã¢ããªã±ãŒã·ã§ã³ãåäœããŠããããšã確èªãã
-
å·ŠåŽã³ã³ãœãŒã«ããªãŒã®[ïŒãµãŒããŒåïŒ]-[ãµã€ã]-[Default Web Site]-[CertSrv]ãã¯ãªãã¯ãã
-
ãŠã£ã³ããŠå³åŽãã€ã³ã®[ã¢ããªã±ãŒã·ã§ã³ã®ç®¡ç]ã¡ãã¥ãŒã®[*:80(http)åç §]ãã¯ãªãã¯ãã
-
Webãã©ãŠã¶(Microsoft Edge)ãèµ·åããããšã確èªãã
ãè£è¶³ã
Webãã©ãŠã¶(Microsoft Edge)ã®èµ·åæã« "Microsoft Edgeãžãããã" ã®Welcomeãããã¢ããã衚瀺ãããŸãã
Edgeã®ã¢ã«ãŠã³ãããŠãŒã¶ãŒããŒã¿ã®ç»é²ãªã©ã®Edgeã®ãããã¡ã€ã«ã¯æŒç¿ã«ã¯é¢ä¿ãããŸããã
ä»»æã®æäœã§ãããã¢ãããçµäºããŠãæŒç¿ãç¶è¡ããŠãã ããã
-
-
蚌ææ©é¢Webç»é²ãµãŒãã¹ã®Webã¢ããªã±ãŒã·ã§ã³ã«ã¢ã¯ã»ã¹ã§ããããšã確èªãã
-
-
HTTPS WebãµãŒããŒ(WinSrv2)ã®ç®¡çç»é¢ã«æ¥ç¶ãã
-
[蚌ææž]管çã³ã³ãœãŒã«ãèµ·åãã
-
Windows ã¹ã¿ãŒãã¡ãã¥ãŒãå³ã¯ãªãã¯ããã³ã³ããã¹ãã¡ãã¥ãŒå ã®[ãã¡ã€ã«åãæå®ããŠå®è¡]ãã¯ãªãã¯ãã
-
[ãã¡ã€ã«åãæå®ããŠå®è¡]ãŠã£ã³ããŠãèµ·åããããšã確èªãã
-
[ãã¡ã€ã«åãæå®ããŠå®è¡]ãŠã£ã³ããŠã§ã以äžã®ãã©ã¡ãŒã¿ãå ¥åãã
åå:
certlm.msc -
[ãã¡ã€ã«åãæå®ããŠå®è¡]ãŠã£ã³ããŠã§ã[OK]ãã¯ãªãã¯ãã
-
[ãŠãŒã¶ãŒã¢ã«ãŠã³ãå¶åŸ¡]ã®ãããã¢ããã§ã[ã¯ã]ãã¯ãªãã¯ãã
-
[蚌ææž]管çã³ã³ãœãŒã«ãèµ·åããããšã確èªãã
-
-
ã«ã¹ã¿ã èŠæ±ã®äœæãŠã£ã¶ãŒããèµ·åãã
- å·ŠåŽã³ã³ãœãŒã«ããªãŒã®[蚌ææž - ããŒã«ã« ã³ã³ãã¥ãŒã¿ãŒ]-[å人]-[蚌ææž]ãã¯ãªãã¯ãã
- å·ŠåŽã³ã³ãœãŒã«ããªãŒã®[蚌ææž - ããŒã«ã« ã³ã³ãã¥ãŒã¿ãŒ]-[å人]-[蚌ææž]ãå³ã¯ãªãã¯ããã³ã³ããã¹ãã¡ãã¥ãŒå
ã®[ãã¹ãŠã®ã¿ã¹ã¯]-[詳现èšå®æäœ]-[ã«ã¹ã¿ã èŠæ±ã®äœæ]ãã¯ãªãã¯ãã
- [蚌ææžã®ç»é²]ãŠã£ã³ããŠã衚瀺ãããããšã確èªãã
-
ã«ã¹ã¿ã èŠæ±ãäœæãã
-
[蚌ææžã®ç»é²]ãŠã£ã³ããŠã®[éå§ããåã«]ç»é¢ã§ã[次ãž]ãã¯ãªãã¯ãã
-
[蚌ææžã®ç»é²]ãŠã£ã³ããŠã®[蚌ææžã®ç»é²ããªã·ãŒã®éžæ]ç»é¢ã§ã[次ãž]ãã¯ãªãã¯ãã
-
[蚌ææžã®ç»é²]ãŠã£ã³ããŠã®[ã«ã¹ã¿ã èŠæ±]ç»é¢ã§ã[次ãž]ãã¯ãªãã¯ãã
-
[蚌ææžã®ç»é²]ãŠã£ã³ããŠã®[蚌ææžæ å ±]ç»é¢ã§ã[詳现]ã®å±éãã¿ã³ãã¯ãªãã¯ãã
-
[蚌ææžã®ç»é²]ãŠã£ã³ããŠã®[蚌ææžæ å ±]ç»é¢ã§ã[ããããã£]ãã¯ãªãã¯ãã
-
[蚌ææžã®ããããã£]ãŠã£ã³ããŠã衚瀺ãããããšã確èªãã
-
[蚌ææžã®ããããã£]ãŠã£ã³ããŠã®[å šè¬]ã¿ãã§ã以äžã®ãã©ã¡ãŒã¿ãå ¥åãã
ãã¬ã³ããªå:
HttpsCert 説æ:
| <空æ¬> | -
[蚌ææžã®ããããã£]ãŠã£ã³ããŠã®[å šè¬]ã¿ãã§ã[é©çš]ãã¯ãªãã¯ãã
-
[蚌ææžã®ããããã£]ãŠã£ã³ããŠã®[ãµããžã§ã¯ã]ã¿ããã¯ãªãã¯ããŠéžæãã
-
[蚌ææžã®ããããã£]ãŠã£ã³ããŠã®[ãµããžã§ã¯ã]ã¿ãã§ã以äžã®ãã©ã¡ãŒã¿ãå ¥åãã
å ±éå:
CN=WinSrv2.example.local å¥å:
DNS Web1.example.local IPã¢ãã¬ã¹(v4) 10.X.2.105 詳现æé :
- "ãµããžã§ã¯ãå" ã® "çš®é¡" ã§ã "å ±éå" ãéžæãã
- "ãµããžã§ã¯ãå" ã® "å€" ã«ã"WinSrv2.example.local" ãå ¥åãã
- "ãµããžã§ã¯ãå" ã® [è¿œå ] ãã¯ãªãã¯ãã
- "ãµããžã§ã¯ãå" ãšã㊠"CN=WinSrv2.example.local" ãè¿œå ãããããšã確èªãã
- "å¥å" ã® "çš®é¡" ã§ã "DNS" ãéžæãã
- "å¥å" ã® "å€" ã«ã"Web1.example.local" ãå ¥åãã
- "å¥å" ã® [è¿œå ] ãã¯ãªãã¯ãã
- "å¥å" ãšã㊠"DNS Web1.example.local" ãè¿œå ãããããšã確èªãã
- "å¥å" ã® "çš®é¡" ã§ã "IPã¢ãã¬ã¹(v4)" ãéžæãã
- "å¥å" ã® "å€" ã«ã"10.X.2.105" ãå ¥åãã
- "å¥å" ã® [è¿œå ] ãã¯ãªãã¯ãã
- "å¥å" ãšã㊠"IPã¢ãã¬ã¹(v4) 10.X.2.105" ãè¿œå ãããããšã確èªãã
-
[蚌ææžã®ããããã£]ãŠã£ã³ããŠã®[ãµããžã§ã¯ã]ã¿ãã§ã[é©çš]ãã¯ãªãã¯ãã
-
[蚌ææžã®ããããã£]ãŠã£ã³ããŠã®[æ¡åŒµæ©èœ]ã¿ããã¯ãªãã¯ããŠéžæãã
-
[蚌ææžã®ããããã£]ãŠã£ã³ããŠã®[æ¡åŒµæ©èœ]ã¿ãã®[ããŒäœ¿çšæ³]ã®å±éãã¿ã³ãã¯ãªãã¯ãã
-
[蚌ææžã®ããããã£]ãŠã£ã³ããŠã®[æ¡åŒµæ©èœ]ã¿ãã®[ããŒäœ¿çšæ³]ã§ã以äžã®ãã©ã¡ãŒã¿ãéžæãã
éžæããããªãã·ã§ã³ ããžã¿ã«çœ²å ããŒã®æå·å 詳现æé :
- "ããŒäœ¿çšæ³" ã® "å©çšå¯èœãªãªãã·ã§ã³" ã§ã "ããžã¿ã«çœ²å" ãã¯ãªãã¯ããŠéžæãã
- "ããŒäœ¿çšæ³" ã® [è¿œå ] ãã¯ãªãã¯ãã
- "ããŒäœ¿çšæ³" ã® "å©çšå¯èœãªãªãã·ã§ã³" ã§ã "ããŒã®æå·å" ãã¯ãªãã¯ããŠéžæãã
- "ããŒäœ¿çšæ³" ã® [è¿œå ] ãã¯ãªãã¯ãã
-
[蚌ææžã®ããããã£]ãŠã£ã³ããŠã®[æ¡åŒµæ©èœ]ã¿ãã®[æ¡åŒµããŒäœ¿çšæ³]ã®å±éãã¿ã³ãã¯ãªãã¯ãã
-
[蚌ææžã®ããããã£]ãŠã£ã³ããŠã®[æ¡åŒµæ©èœ]ã¿ãã®[æ¡åŒµããŒäœ¿çšæ³]ã§ã以äžã®ãã©ã¡ãŒã¿ãéžæãã
éžæããããªãã·ã§ã³ ãµãŒããŒèªèšŒ 詳现æé :
- "æ¡åŒµããŒäœ¿çšæ³" ã® "å©çšå¯èœãªãªãã·ã§ã³" ã§ã "ãµãŒããŒèªèšŒ" ãã¯ãªãã¯ããŠéžæãã
- "æ¡åŒµããŒäœ¿çšæ³" ã® [è¿œå ] ãã¯ãªãã¯ãã
-
[蚌ææžã®ããããã£]ãŠã£ã³ããŠã®[æ¡åŒµæ©èœ]ã¿ãã§ã[é©çš]ãã¯ãªãã¯ãã
-
[蚌ææžã®ããããã£]ãŠã£ã³ããŠã®[ç§å¯ããŒ]ã¿ããã¯ãªãã¯ããŠéžæãã
-
[蚌ææžã®ããããã£]ãŠã£ã³ããŠã®[ç§å¯ããŒ]ã¿ãã®[ããŒã®ãªãã·ã§ã³]ã®å±éãã¿ã³ãã¯ãªãã¯ãã
-
[蚌ææžã®ããããã£]ãŠã£ã³ããŠã®[ç§å¯ããŒ]ã¿ãã®[ããŒã®ãªãã·ã§ã³]ã§ã以äžã®ãã©ã¡ãŒã¿ãéžæãã
ããŒã®ãµã€ãº:
2048 - ç§å¯ããŒããšã¯ã¹ããŒãå¯èœã«ãã
- ç§å¯ããŒã®ã¢ãŒã«ã€ããèš±å¯ãã
- 匷åãªç§å¯ããŒã®ä¿è·
-
[蚌ææžã®ããããã£]ãŠã£ã³ããŠã®[ç§å¯ããŒ]ã¿ãã®[ããã·ã¥ã¢ã«ãŽãªãºã ã®éžæ]ã®å±éãã¿ã³ãã¯ãªãã¯ãã
-
[蚌ææžã®ããããã£]ãŠã£ã³ããŠã®[ç§å¯ããŒ]ã¿ãã®[ããã·ã¥ã¢ã«ãŽãªãºã ã®éžæ]ã§ã以äžã®ãã©ã¡ãŒã¿ãéžæãã
ããã·ã¥ã¢ã«ãŽãªãºã :
sha256 -
[蚌ææžã®ããããã£]ãŠã£ã³ããŠã®[ç§å¯ããŒ]ã¿ãã§ã[é©çš]ãã¯ãªãã¯ãã
-
[蚌ææžã®ããããã£]ãŠã£ã³ããŠã§ã[OK]ãã¯ãªãã¯ãã
-
[蚌ææžã®ç»é²]ãŠã£ã³ããŠã®[蚌ææžæ å ±]ç»é¢ã§ã[次ãž]ãã¯ãªãã¯ãã
-
[蚌ææžã®ç»é²]ãŠã£ã³ããŠã®[ãªãã©ã€ã³èŠæ±ãä¿åããå Žæãæå®ããŠãã ãã]ç»é¢ã§ã以äžã®ãã©ã¡ãŒã¿ãå ¥åãã
ãã¡ã€ã«å:
C:\Share\HttpsCert.csr ãã¡ã€ã«åœ¢åŒ:
- Base64
- ãã€ããª
-
[蚌ææžã®ç»é²]ãŠã£ã³ããŠã®[ãªãã©ã€ã³èŠæ±ãä¿åããå Žæãæå®ããŠãã ãã]ç»é¢ã§ã[å®äº]ãã¯ãªãã¯ãã
-
-
蚌ææžçœ²åèŠæ±(CSRãã¡ã€ã«)ãäœæãããŠããããšã確èªãã
-
(ãªãã·ã§ã³.çç¥å¯) "HttpsCert.csr" ãã¡ã€ã«ãã¡ã¢åž³(notepad)ã§éããBase64ãšã³ã³ãŒãããã蚌ææžçœ²åèŠæ±ãèšè¿°ãããŠããããšã確èªãã
-
(ãªãã·ã§ã³.çç¥å¯) ç§å¯ããŒã "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys" ãã©ã«ãã«ä¿åãããŠããããšã確èªãã
-
HTTPS WebãµãŒããŒ(WinSrv2)ã®ç®¡çç»é¢ã«æ¥ç¶ãã
-
蚌ææ©é¢Webç»é²ãµãŒãã¹ã«ã¢ã¯ã»ã¹ãã
-
蚌ææ©é¢Webç»é²ãµãŒãã¹ã§ã蚌ææžã®çºè¡ãèŠæ±ãã
-
[蚌ææžãèŠæ±ãã]ãã¯ãªãã¯ãã
-
[蚌ææžã®èŠæ±ã®è©³çŽ°èšå®]ãã¯ãªãã¯ãã
-
[蚌ææžã®èŠæ±ãŸãã¯æŽæ°èŠæ±ã®éä¿¡]ããŒãžã§ã以äžã®ãã©ã¡ãŒã¿ãå ¥åãã
ä¿åãããèŠæ±:
<"C:\Share\HttpsCert.csr"ãã¡ã€ã«ã®äžèº«ã®æååå šæã貌ãä»ãã> è¿œå å±æ§:
<空æ¬> æé :
- ã¡ã¢åž³(notepad)ãèµ·åãã"C:\Share\HttpsCert.csr" ãã¡ã€ã«ãéã
- å é ã®"-----BEGIN NEW CERTIFICATE REQUEST-----"è¡ãããæ«å°Ÿã®"-----END NEW CERTIFICATE REQUEST-----"è¡ãŸã§ã®å šæãã³ããŒãã
- WebããŒãžã®ãã©ãŒã ã«è²Œãã€ãã
-
[蚌ææžã®èŠæ±ãŸãã¯æŽæ°èŠæ±ã®éä¿¡]ããŒãžã§ã[éä¿¡>]ãã¯ãªãã¯ãã
-
[ä¿çäžã®èšŒææž]ããŒãžã§ã"èŠæ±ID" ã®æ°åã確èªãã
ãè£è¶³ã
ç»åäŸã®å ŽåãèŠæ±IDã¯2ã§ãã
ãã®èŠæ±IDã®æ°åã¯ã次æé ã®èšŒææžçºè¡æäœã®éã«å¿ èŠã§ãã
-
-
Windows èªèšŒå±(WinSrv1)ã®ç®¡çç»é¢ã«æ¥ç¶ãã
-
蚌ææ©é¢ç®¡çã³ã³ãœãŒã«ãèµ·åãã
- ãµãŒããŒãããŒãžã£ãŒãŠã£ã³ããŠå³äžã®[ããŒã«]ãã¯ãªãã¯ãã
- ã¡ãã¥ãŒå ã®[蚌ææ©é¢]ãã¯ãªãã¯ãã蚌ææ©é¢ç®¡çã³ã³ãœãŒã«ãèµ·åãã
- [蚌ææ©é¢]管çã³ã³ãœãŒã«ãèµ·åããããšã確èªãã
-
蚌ææžã®èŠæ±ãæ¿èªãã
-
å·ŠåŽã³ã³ãœãŒã«ããªãŒã®[蚌ææ©é¢]-[WinCA]-[ä¿çäžã®èŠæ±]ãã¯ãªãã¯ããŠéžæãã
-
å³åŽãã€ã³ã®èšŒææžã®èŠæ±ã®äžèŠ§ãããåã®æäœ(蚌ææ©é¢Webç»é²ãµãŒãã¹ã§ã蚌ææžã®çºè¡ãèŠæ±ãã)ã§éä¿¡ãããèŠæ±ãã¯ãªãã¯ããŠéžæãã
ãè£è¶³ã
èŠæ±IDã®æ°åãåç §ããåã®äœæ¥ã§è¡šç€ºãããIDãšåèŽãããã®ãéžæãã -
該åœããèŠæ±ãå³ã¯ãªãã¯ããã³ã³ããã¹ãã¡ãã¥ãŒå ã®[ãã¹ãŠã®ã¿ã¹ã¯]-[çºè¡]ãã¯ãªãã¯ãã
-
-
蚌ææžãçºè¡ãããããšã確èªãã
-
å·ŠåŽã³ã³ãœãŒã«ããªãŒã®[蚌ææ©é¢]-[WinCA]-[çºè¡ãã蚌ææž]ãã¯ãªãã¯ããŠéžæãã
-
å³åŽãã€ã³ã®çºè¡ãã蚌ææžã®äžèŠ§ãããåã®æäœ(蚌ææ©é¢Webç»é²ãµãŒãã¹ã§èšŒææžã®çºè¡ãèŠæ±ãã)ã§éä¿¡ãããèŠæ±ãã¯ãªãã¯ããŠéžæãã
ãè£è¶³ã
èŠæ±IDã®æ°åãåç §ããåã®äœæ¥ã§è¡šç€ºãããIDãšåèŽãããã®ãéžæãã -
該åœããèŠæ±ãå³ã¯ãªãã¯ããã³ã³ããã¹ãã¡ãã¥ãŒå ã®[éã]ãã¯ãªãã¯ãã
-
[蚌ææž]ãŠã£ã³ããŠã衚瀺ãããããšã確èªãã
-
[蚌ææž]ãŠã£ã³ããŠã®[å šè¬]ã¿ãã®ãã©ã¡ãŒã¿ã確èªãã
ã確èªãã€ã³ãã
- çºè¡å ã "WinSrv2.example.local" ã§ããããš
- çºè¡è ã "WinCA" ã§ããããš
- çŸåšã®æ¥ä»ãšæå»ããæå¹æéã®ç¯å²å ã§ããããš
-
[蚌ææž]ãŠã£ã³ããŠã®[å šè¬]ã¿ãã§ã[OK]ãã¯ãªãã¯ãã
-
-
HTTPS WebãµãŒããŒ(WinSrv2)ã®ç®¡çç»é¢ã«æ¥ç¶ãã
-
蚌ææ©é¢Webç»é²ãµãŒãã¹ã«ã¢ã¯ã»ã¹ãã
-
蚌ææžããã¡ã€ã«ãšããŠããŠã³ããŒããã
-
[ä¿çäžã®èšŒææžã®èŠæ±ã®ç¶æ ]ãã¯ãªãã¯ãã
-
[ä¿çäžã®èšŒææžã®èŠæ±ã®ç¶æ ]ããŒãžã§ã[ä¿åãããèŠæ±èšŒææž]ãã¯ãªãã¯ãã
-
[蚌ææžã¯çºè¡ãããŸãã]ããŒãžã§ã以äžã®ãã©ã¡ãŒã¿ãéžæãã
- DERãšã³ã³ãŒã
- Base64ãšã³ã³ãŒã
-
[蚌ææžã¯çºè¡ãããŸãã]ããŒãžã§ã[蚌ææžã®ããŠã³ããŒã]ãã¯ãªãã¯ãã
-
ãã¡ã€ã«ã®ããŠã³ããŒããå®äºãããŸã§åŸ æ©ãã
ãè£è¶³ã
Webãã©ãŠã¶ã®ã»ãã¥ãªãã£æ©èœã«ããã蚌ææžãã¡ã€ã«ã®ããŠã³ããŒããä¿çãããå ŽåããããŸãã
ããŠã³ããŒãåŠçãéå§ãããªãå Žåã¯ãWebãã©ãŠã¶ã®ç»é¢å ã®èŠåã®ãããã¢ããã§ãã¡ã€ã«ã®ããŠã³ããŒããèš±å¯ããæäœãéžæããŠãã ããã -
ããŠã³ããŒããã©ã«ã(C:\Users\admin\Downloads)ãéãã"certnew.cer" ãã¡ã€ã«ãä¿åãããŠããããšã確èªãã
-
ããŠã³ããŒããã"certnew.cer"ãã¡ã€ã«(ãµãŒããŒèšŒææž)ã®ååãã"ServerCrt.cer" ã«å€æŽãã
ãè£è¶³ã
ãã®åŸã®æé ã§ãå¥ã®èšŒææžãããŠã³ããŒãããŸãã
ãã¡ã€ã«ã®æ··åãé¿ãããããããŸããŠã³ããŒããããã¡ã€ã«ã®ååãå€æŽããŠãã ããã
-
-
HTTPS WebãµãŒããŒ(WinSrv2)ã®ç®¡çç»é¢ã«æ¥ç¶ãã
-
[蚌ææž]管çã³ã³ãœãŒã«ãèµ·åãã
-
Windows ã¹ã¿ãŒãã¡ãã¥ãŒãå³ã¯ãªãã¯ããã³ã³ããã¹ãã¡ãã¥ãŒå ã®[ãã¡ã€ã«åãæå®ããŠå®è¡]ãã¯ãªãã¯ãã
-
[ãã¡ã€ã«åãæå®ããŠå®è¡]ãŠã£ã³ããŠãèµ·åããããšã確èªãã
-
[ãã¡ã€ã«åãæå®ããŠå®è¡]ãŠã£ã³ããŠã§ã以äžã®ãã©ã¡ãŒã¿ãå ¥åãã
åå:
certlm.msc -
[ãã¡ã€ã«åãæå®ããŠå®è¡]ãŠã£ã³ããŠã§ã[OK]ãã¯ãªãã¯ãã
-
[ãŠãŒã¶ãŒã¢ã«ãŠã³ãå¶åŸ¡]ã®ãããã¢ããã§ã[ã¯ã]ãã¯ãªãã¯ãã
-
[蚌ææž]管çã³ã³ãœãŒã«ãèµ·åããããšã確èªãã
-
-
蚌ææžã®ã€ã³ããŒããŠã£ã¶ãŒããå®è¡ãã
-
å·ŠåŽã³ã³ãœãŒã«ããªãŒã®[蚌ææž - ããŒã«ã« ã³ã³ãã¥ãŒã¿ãŒ]-[å人]-[蚌ææž]ãã¯ãªãã¯ããŠéžæãã
-
å·ŠåŽã³ã³ãœãŒã«ããªãŒã®[蚌ææž - ããŒã«ã« ã³ã³ãã¥ãŒã¿ãŒ]-[å人]-[蚌ææž]ãå³ã¯ãªãã¯ããã³ã³ããã¹ãã¡ãã¥ãŒå ã®[ãã¹ãŠã®ã¿ã¹ã¯]-[ã€ã³ããŒã]ãã¯ãªãã¯ãã
-
[蚌ææžã®ã€ã³ããŒããŠã£ã¶ãŒã]ãŠã£ã³ããŠã衚瀺ãããããšã確èªãã
-
[蚌ææžã®ã€ã³ããŒããŠã£ã¶ãŒã]ãŠã£ã³ããŠã®[蚌ææžã®ã€ã³ããŒããŠã£ã¶ãŒãã®éå§]ç»é¢ã§ã[次ãž]ãã¯ãªãã¯ãã
-
[蚌ææžã®ã€ã³ããŒããŠã£ã¶ãŒã]ãŠã£ã³ããŠã®[ã€ã³ããŒããã蚌ææžãã¡ã€ã«]ç»é¢ã§ã以äžã®ãã©ã¡ãŒã¿ãå ¥åãã
ãã¡ã€ã«å:
C:\Users\admin\Downloads\ServerCrt.cer -
[蚌ææžã®ã€ã³ããŒããŠã£ã¶ãŒã]ãŠã£ã³ããŠã®[ã€ã³ããŒããã蚌ææžãã¡ã€ã«]ç»é¢ã§ã[次ãž]ãã¯ãªãã¯ãã
-
[蚌ææžã®ã€ã³ããŒããŠã£ã¶ãŒã]ãŠã£ã³ããŠã®[蚌ææžã¹ãã¢]ç»é¢ã§ã以äžã®ãã©ã¡ãŒã¿ãéžæãã
- 蚌ææžã®çš®é¡ã«åºã¥ããŠãèªåçã«èšŒææžã¹ãã¢ãéžæãã
- 蚌ææžããã¹ãŠæ¬¡ã®ã¹ãã¢ã«é 眮ãã
蚌ææžã¹ãã¢:
å人 -
[蚌ææžã®ã€ã³ããŒããŠã£ã¶ãŒã]ãŠã£ã³ããŠã®[蚌ææžã¹ãã¢]ç»é¢ã§ã[次ãž]ãã¯ãªãã¯ãã
-
[蚌ææžã®ã€ã³ããŒããŠã£ã¶ãŒã]ãŠã£ã³ããŠã®[蚌ææžã®ã€ã³ããŒããŠã£ã¶ãŒãã®å®äº]ç»é¢ã§ã[å®äº]ãã¯ãªãã¯ãã
-
[蚌ææžã®ã€ã³ããŒããŠã£ã¶ãŒã]ã®ãããã¢ãããšããŠã"æ£ããã€ã³ããŒããããŸãã"ã®ã¹ããŒã¿ã¹ãéç¥ãããã®ã確èªãã
-
[蚌ææžã®ã€ã³ããŒããŠã£ã¶ãŒã]ã®ãããã¢ããã§ã[OK]ãã¯ãªãã¯ãã
-
-
ã€ã³ããŒãããã蚌ææžã®ãã©ã¡ãŒã¿ãã¹ããŒã¿ã¹ã確èªãã
- ãµãŒããŒèšŒææžã"å人"ã¹ãã¢ã«ã€ã³ããŒããããŠããããšã確èªãã
- ãµãŒããŒèšŒææžã®æ€èšŒã«å€±æããç¶æ
ã§ããããšã確èªãã
-
å³åŽãã€ã³ã®ææãã蚌ææžäžèŠ§ã®äžã®[WinSrv2.example.local]ãã¯ãªãã¯ããŠéžæãã
-
å³åŽãã€ã³ã®ææãã蚌ææžäžèŠ§ã®äžã®[WinSrv2.example.local]ãå³ã¯ãªãã¯ããã³ã³ããã¹ãã¡ãã¥ãŒå ã®[éã]ãã¯ãªãã¯ãã
-
蚌ææžã®ã¹ããŒã¿ã¹ã確èªãã
ã確èªãã€ã³ãã
- 蚌ææž(ã®å ¬ééµ)ã«å¯Ÿå¿ããç§å¯éµãä¿æããŠããããš
- 蚌ææžã®æ€èšŒã«å€±æããŠããããš
ãè£è¶³ã
ãã®ãµãŒããŒã§CSR(蚌ææžçœ²åèŠæ±)ãäœæãã段éã§ã蚌ææžã«å¯Ÿå¿ããç§å¯éµãèªåçã«äœæãããŠããŸãã ãã ãã蚌ææžãçºè¡ããèªèšŒå±(CA)ã®åŠ¥åœæ§ãæ€èšŒããCA蚌ææžãä¿æããŠããªããããã€ã³ããŒããããµãŒããŒèšŒææžã¯çŸæç¹ã§ã¯ç¡å¹ãªç¶æ ã§ãã
-
-
HTTPS WebãµãŒããŒ(WinSrv2)ã®ç®¡çç»é¢ã«æ¥ç¶ãã
-
蚌ææ©é¢Webç»é²ãµãŒãã¹ã«ã¢ã¯ã»ã¹ãã
- WinSrv2ã§Webãã©ãŠã¶(Google Chrome)ãèµ·åãã
- Webãã©ãŠã¶ã®ã¢ãã¬ã¹æ¬ã« [http:/AD.example.local/certsrv] ãšå ¥åãã[Enter]ããŒãæŒäžãã
- 蚌ææ©é¢Webç»é²ãµãŒãã¹ã«ã¢ã¯ã»ã¹ããããšã確èªãã
-
ã«ãŒãCA蚌ææžããã¡ã€ã«ãšããŠããŠã³ããŒããã
-
[CA蚌ææžã蚌ææžãã§ãŒã³ããŸãã¯CRLã®ããŠã³ããŒã]ãã¯ãªãã¯ãã
-
[CA蚌ææžã蚌ææžãã§ãŒã³ããŸãã¯CRLã®ããŠã³ããŒã]ããŒãžã§ã[CA蚌ææžã®ããŠã³ããŒã]ãã¯ãªãã¯ãã
-
ããŠã³ããŒããã©ã«ã(C:\Users\admin\Downloads)ãéãã"certnew.cer" ãã¡ã€ã«ãä¿åãããŠããããšã確èªãã
-
ããŠã³ããŒããã"certnew.cer"ãã¡ã€ã«(ã«ãŒãCA蚌ææž)ã®ååãã"RootCaCrt.cer" ã«å€æŽãã
ãè£è¶³ã
蚌ææžãã¡ã€ã«ã®æ··åãé¿ãããããããŸããŠã³ããŒããããã¡ã€ã«ã®ååãå€æŽããŠãã ããã
-
-
蚌ææžã®ã€ã³ããŒã ãŠã£ã¶ãŒããå®è¡ãã
-
å·ŠåŽã³ã³ãœãŒã«ããªãŒã®[蚌ææž - ããŒã«ã« ã³ã³ãã¥ãŒã¿ãŒ]-[ä¿¡é Œãããã«ãŒã蚌ææ©é¢]-[蚌ææž]ãã¯ãªãã¯ããŠéžæãã
-
å·ŠåŽã³ã³ãœãŒã«ããªãŒã®[蚌ææž - ããŒã«ã« ã³ã³ãã¥ãŒã¿ãŒ]-[ä¿¡é Œãããã«ãŒã蚌ææ©é¢]-[蚌ææž]ãå³ã¯ãªãã¯ããã³ã³ããã¹ãã¡ãã¥ãŒå ã®[ãã¹ãŠã®ã¿ã¹ã¯]-[ã€ã³ããŒã]ãã¯ãªãã¯ãã
-
[蚌ææžã®ã€ã³ããŒããŠã£ã¶ãŒã]ãŠã£ã³ããŠã衚瀺ãããããšã確èªãã
-
[蚌ææžã®ã€ã³ããŒããŠã£ã¶ãŒã]ãŠã£ã³ããŠã®[蚌ææžã®ã€ã³ããŒããŠã£ã¶ãŒãã®éå§]ç»é¢ã§ã[次ãž]ãã¯ãªãã¯ãã
-
[蚌ææžã®ã€ã³ããŒããŠã£ã¶ãŒã]ãŠã£ã³ããŠã®[ã€ã³ããŒããã蚌ææžãã¡ã€ã«]ç»é¢ã§ã以äžã®ãã©ã¡ãŒã¿ãå ¥åãã
ãã¡ã€ã«å:
C:\Users\admin\Downloads\RootCaCrt.cer -
[蚌ææžã®ã€ã³ããŒããŠã£ã¶ãŒã]ãŠã£ã³ããŠã®[ã€ã³ããŒããã蚌ææžãã¡ã€ã«]ç»é¢ã§ã[次ãž]ãã¯ãªãã¯ãã
-
[蚌ææžã®ã€ã³ããŒããŠã£ã¶ãŒã]ãŠã£ã³ããŠã®[蚌ææžã¹ãã¢]ç»é¢ã§ã以äžã®ãã©ã¡ãŒã¿ãéžæãã
- 蚌ææžã®çš®é¡ã«åºã¥ããŠãèªåçã«èšŒææžã¹ãã¢ãéžæãã
- 蚌ææžããã¹ãŠæ¬¡ã®ã¹ãã¢ã«é 眮ãã
蚌ææžã¹ãã¢:
ä¿¡é Œãããã«ãŒã蚌ææ©é¢ -
[蚌ææžã®ã€ã³ããŒããŠã£ã¶ãŒã]ãŠã£ã³ããŠã®[蚌ææžã¹ãã¢]ç»é¢ã§ã[次ãž]ãã¯ãªãã¯ãã
-
[蚌ææžã®ã€ã³ããŒããŠã£ã¶ãŒã]ãŠã£ã³ããŠã®[蚌ææžã®ã€ã³ããŒããŠã£ã¶ãŒãã®å®äº]ç»é¢ã§ã[å®äº]ãã¯ãªãã¯ãã
-
[蚌ææžã®ã€ã³ããŒããŠã£ã¶ãŒã]ã®ãããã¢ãããšããŠã"æ£ããã€ã³ããŒããããŸãã"ã®ã¹ããŒã¿ã¹ãéç¥ãããã®ã確èªãã
-
[蚌ææžã®ã€ã³ããŒããŠã£ã¶ãŒã]ã®ãããã¢ããã§ã[OK]ãã¯ãªãã¯ãã
-
-
ã€ã³ã¹ããŒã«ãããã«ãŒãCA蚌ææžã®ã¹ããŒã¿ã¹ã確èªãã
-
ãµãŒããŒèšŒææžã®ã¹ããŒã¿ã¹ã確èªãã
-
å·ŠåŽã³ã³ãœãŒã«ããªãŒã®[蚌ææž - ããŒã«ã« ã³ã³ãã¥ãŒã¿ãŒ]-[å人]-[蚌ææž]ãã¯ãªãã¯ããŠéžæãã
-
å³åŽãã€ã³ã®ææãã蚌ææžäžèŠ§ã®äžã®[WinSrv2.example.local]ãã¯ãªãã¯ããŠéžæãã
-
å³åŽãã€ã³ã®ææãã蚌ææžäžèŠ§ã®äžã®[WinSrv2.example.local]ãå³ã¯ãªãã¯ããã³ã³ããã¹ãã¡ãã¥ãŒå ã®[éã]ãã¯ãªãã¯ãã
-
蚌ææžã®ã¹ããŒã¿ã¹ã確èªãã
ã確èªãã€ã³ãã
- 蚌ææžã®æ€èšŒã«æåããããš
ãè£è¶³ã
WinSrv1ã«æ§ç¯ããWinCAèªèšŒå±(ã«ãŒãCA)ã®èšŒææžã"ä¿¡é Œãããã«ãŒã蚌ææ©é¢"ã¹ãã¢ã«ã€ã³ã¹ããŒã«ããããšã§ããµãŒããŒèšŒææžã®åŠ¥åœæ§æ€èšŒã«æåããç¶æ ã«ãªããŸããã
-
-
HTTPS WebãµãŒããŒ(WinSrv2)ã®ç®¡çç»é¢ã«æ¥ç¶ãã
-
IIS管çã³ã³ãœãŒã«ãèµ·åãã
- ãµãŒããŒãããŒãžã£ãŒãŠã£ã³ããŠå³äžã®[ããŒã«]ãã¯ãªãã¯ãã
- ã¡ãã¥ãŒå ã®[ã€ã³ã¿ãŒããã ã€ã³ãã©ã¡ãŒã·ã§ã³ ãµãŒãã¹(IIS) ãããŒãžã£ãŒ]ãã¯ãªãã¯ããIIS管çã³ã³ãœãŒã«ãèµ·åãã
- [ã€ã³ã¿ãŒããã ã€ã³ãã©ã¡ãŒã·ã§ã³ ãµãŒãã¹(IIS) ãããŒãžã£ãŒ]ãèµ·åããããšã確èªãã
-
"Default Web Site" ãµã€ãã«æ°ãããã€ã³ããè¿œå ãã
-
å·ŠåŽã³ã³ãœãŒã«ããªãŒã®[ïŒãµãŒããŒåïŒ]-[ãµã€ã]-[Default Web Site]ãã¯ãªãã¯ãã
-
å·ŠåŽã³ã³ãœãŒã«ããªãŒã®[ïŒãµãŒããŒåïŒ]-[ãµã€ã]-[Default Web Site]ãå³ã¯ãªãã¯ããã³ã³ããã¹ãã¡ãã¥ãŒå ã®[ãã€ã³ãã®ç·šé]ãã¯ãªãã¯ãã
-
[ãµã€ã ãã€ã³ã]ãŠã£ã³ããŠã衚瀺ãããããšã確èªãã
-
[ãµã€ã ãã€ã³ã]ãŠã£ã³ããŠã§ã[è¿œå ]ãã¯ãªãã¯ãã
-
[ãµã€ã ãã€ã³ãã®è¿œå ]ãŠã£ã³ããŠã衚瀺ãããããšã確èªãã
-
[ãµã€ã ãã€ã³ãã®è¿œå ]ãŠã£ã³ããŠã§ã以äžã®ãã©ã¡ãŒã¿ãå ¥åãã
çš®é¡:
https IPã¢ãã¬ã¹:
æªäœ¿çšã®IPã¢ãã¬ã¹ãã¹ãŠ ããŒã:
443 ãã¹ãå:
<空æ¬> - ãµãŒããŒå衚瀺ãèŠæ±ãã
- TLS 1.3 over TCPãç¡å¹ã«ãã
- QUICãç¡å¹ã«ãã
- ã¬ã¬ã·TLSãç¡å¹ã«ãã
- HTTP/2ãç¡å¹ã«ãã
- OCSPã¹ããŒããªã³ã°ãç¡å¹ã«ãã
SSL蚌ææž:
HttpsCert -
[ãµã€ã ãã€ã³ãã®è¿œå ]ãŠã£ã³ããŠã§ã[OK]ãã¯ãªãã¯ãã
-
[ãµã€ã ãã€ã³ã]ãŠã£ã³ããŠã§ã[éãã]ãã¯ãªãã¯ãã
-
-
"Default Web Site" ãµã€ãã®ãã€ã³ãã確èªãã
-
Clientã®Webãã©ãŠã¶ããWebã¢ã¯ã»ã¹ãã
- æäœã³ã³ãã¥ãŒã¿ãå€æŽãããããæŒç¿ç°å¢ã®ãããããŒãžã«æ»ã
- Windows Client(WinClient)ã®ç®¡çç»é¢ã« "admin" ã§æ¥ç¶ãã
-
WebãµãŒãã¹ã«HTTPSã§æ¥ç¶ãã
-
WinClientã§Webãã©ãŠã¶(Google Chrome)ãèµ·åãã
-
Webãã©ãŠã¶ã®ã¢ãã¬ã¹æ¬ã« [https://web1.example.local/web1] ãšå ¥åãã[Enter]ããŒãæŒäžãã
ã泚æã
ãããã³ã«ã¹ããŒã ã®æå®ã«æ³šæããŠãã ããã
ããã§ã¯ http ã§ã¯ãªã https ãæå®ããŸãã -
ã»ãã¥ãªãã£èŠå(Cert Authority Invalid)ã衚瀺ãããããšã確èªãã
ãè£è¶³ã
ãã®èŠåã¯ãWebãµãŒããŒãæ瀺ãããµãŒããŒèšŒææžã®æ€èšŒãã§ããªãããšãéç¥ããŸãã
ãµãŒããŒèšŒææžã«çœ²åããCAã®èšŒææž(ã«ãŒãCA蚌ææž)ããClientãä¿æããŠããªãããšãåå ã§ãã
ãã®åŸæé ã§ã«ãŒãCA蚌ææžãClientã«ã€ã³ã¹ããŒã«ããããšã§ãåå ã解æ¶ãããŠããã®èŠåã¯è¡šç€ºãããªããªããŸãã -
ç»é¢äžéšã®[詳现èšå®] ãã¯ãªãã¯ãã
-
[web1.example.localã«ã¢ã¯ã»ã¹ãã (å®å šã§ã¯ãããŸãã)] ãã¯ãªãã¯ãã
-
èªèšŒæ å ±ãå ¥åãããããã¢ããã衚瀺ãããããšã確èªãã以äžã®ãã©ã¡ãŒã¿ãå ¥åãã
é ç® ãã©ã¡ãŒã¿ ãŠãŒã¶ãŒå Tom ãã¹ã¯ãŒã Pa$$w0rd -
äžã®ãã©ã¡ãŒã¿ãå ¥åãã[ãã°ã€ã³]ãã¯ãªãã¯ãã
-
åºæ¬èªèšŒãçµãŠãWebã³ã³ãã³ããå©çšã§ããããšã確èªãã
ãè£è¶³ã
Webãã©ãŠã¶äžéšã®ã¢ãã¬ã¹æ¬ã®å·Šã«ãããŠããµãŒããŒèšŒææžã«ã€ããŠã®èŠåã衚瀺ãããŠããããšã«æ³šç®ããŠãã ããã
HTTPSéä¿¡ã«ãããŠãµãŒããŒãæ瀺ãããµãŒããŒèšŒææžã«äžå¯©ãªç®æãããå ŽåãWebãã©ãŠã¶ã¯ãŠãŒã¶ãŒã«ãã®æšãèŠåããŸãã
-
-
ãµãŒããŒèšŒææžã®æ€èšŒã«å€±æããŠããããšã確èªãã
ãè£è¶³ã
Webãã©ãŠã¶ãããµãŒããŒèšŒææžããã¡ã€ã«ãšããŠãšã¯ã¹ããŒã(ããŠã³ããŒã)ããŠåç §ããããšã§ãClientããµãŒããŒèšŒææžãã©ã®ããã«èªèããŠããç¶æ ã§ãããã確èªããŸãã- Webãã©ãŠã¶äžéšã®ã¢ãã¬ã¹æ¬ã®å·Šã® [ä¿è·ãããŠããªãéä¿¡] ãã¯ãªãã¯ãã
- ã¡ãã¥ãŒå
ã® [蚌ææžãç¡å¹ã§ã] ãã¯ãªãã¯ãã
- [詳现]ã¿ãã®[ãšã¯ã¹ããŒã]ãã¯ãªãã¯ãã
- ä»»æã®ãã©ã«ã(äŸ:ãã¹ã¯ããããªã©)ã«ãã¡ã€ã«ãä¿åãã
- ä¿åããããã¡ã€ã«(ãµãŒããŒèšŒææž)ãå³ã¯ãªãã¯ããã³ã³ããã¹ãã¡ãã¥ãŒå
ã®[éã]ãã¯ãªãã¯ãã
- ClientããµãŒããŒèšŒææžã®æ€èšŒã«å€±æããç¶æ
ã§ããããšã確èªãã
-
Windows èªèšŒå± å Œ Active Directory ãã¡ã€ã³ã³ã³ãããŒã©ãŒ ãµãŒã㌠(WinSrv1)ã®ç®¡çç»é¢ã«æ¥ç¶ãã
-
Active Directory ãã¡ã€ã³ ã¡ã³ããŒã«é åžããã«ãŒã蚌ææžãã¡ã€ã«ãæºåãã
-
蚌ææ©é¢ç®¡çã³ã³ãœãŒã«ãèµ·åãã
- ãµãŒããŒãããŒãžã£ãŒãŠã£ã³ããŠå³äžã®[ããŒã«]ãã¯ãªãã¯ãã
- ã¡ãã¥ãŒå ã®[蚌ææ©é¢]ãã¯ãªãã¯ãã蚌ææ©é¢ç®¡çã³ã³ãœãŒã«ãèµ·åãã
- [蚌ææ©é¢]管çã³ã³ãœãŒã«ãèµ·åããããšã確èªãã
-
ã«ãŒã蚌ææžããã¡ã€ã«ãšããŠä¿åãã
-
[蚌ææ©é¢]管çã³ã³ãœãŒã«ã®å·ŠåŽã³ã³ãœãŒã«ããªãŒã®[WinCA]ãã¯ãªãã¯ããŠéžæãã
-
[WinCA]ãå³ã¯ãªãã¯ããã³ã³ããã¹ãã¡ãã¥ãŒå ã®[ããããã£]ãã¯ãªãã¯ãã
-
[WinCAã®ããããã£]ãŠã£ã³ããŠã衚瀺ãããããšã確èªãã
-
[WinCAã®ããããã£]ãŠã£ã³ããŠã®[å šè¬]ã¿ãã®[蚌ææžã®è¡šç€º]ãã¯ãªãã¯ãã
-
[蚌ææž]ãŠã£ã³ããŠã衚瀺ãããããšã確èªãã
-
[蚌ææž]ãŠã£ã³ããŠã®[詳现]ã¿ããã¯ãªãã¯ããŠéžæãã
-
[蚌ææž]ãŠã£ã³ããŠã®[詳现]ã¿ãã®[ãã¡ã€ã«ã«ã³ããŒ]ãã¯ãªãã¯ãã
-
[蚌ææžã®ãšã¯ã¹ããŒã ãŠã£ã¶ãŒã]ãèµ·åããããšã確èªãã
-
[蚌ææžã®ãšã¯ã¹ããŒã ãŠã£ã¶ãŒã]ã®[蚌ææžã®ãšã¯ã¹ããŒã ãŠã£ã¶ãŒãã®éå§]ç»é¢ã§ã[次ãž]ãã¯ãªãã¯ãã
-
[蚌ææžã®ãšã¯ã¹ããŒã ãŠã£ã¶ãŒã]ã®[ãšã¯ã¹ããŒã ãã¡ã€ã«ã®åœ¢åŒ]ç»é¢ã§ã[次ãž]ãã¯ãªãã¯ãã
-
[蚌ææžã®ãšã¯ã¹ããŒã ãŠã£ã¶ãŒã]ã®[ãšã¯ã¹ããŒããããã¡ã€ã«]ç»é¢ã§ããã¹ã¯ãããããã¡ã€ã«ã®ä¿åå ãšããŠæå®ãã
ãã¡ã€ã«å:
C:\User\admin\Desktop\RootCaCrt.cer -
[蚌ææžã®ãšã¯ã¹ããŒã ãŠã£ã¶ãŒã]ã®[ãšã¯ã¹ããŒããããã¡ã€ã«]ç»é¢ã§ã[次ãž]ãã¯ãªãã¯ãã
-
[蚌ææžã®ãšã¯ã¹ããŒã ãŠã£ã¶ãŒã]ã®[蚌ææžãšã¯ã¹ããŒã ãŠã£ã¶ãŒãã®å®äº]ç»é¢ã§ã[å®äº]ãã¯ãªãã¯ãã
-
[蚌ææžã®ãšã¯ã¹ããŒã ãŠã£ã¶ãŒã]ãããã¢ããã§ã[OK]ãã¯ãªãã¯ãã
-
ã«ãŒãCA蚌ææžããã¡ã€ã«ãšããŠãã¹ã¯ãããã«ä¿åãããããšã確èªãã
ãè£è¶³ã
蚌ææžããã¡ã€ã«ãšããŠå ¥æããã«ã¯ããŸããŸãªæé ããããŸããããããã®æé ã§ãå šãåäžã®èšŒææžãå ¥æã§ããŸãã
PKIç°å¢ã«ãããŠå³éã«ä¿è·ãããã®ã¯ã蚌ææž(ã®å ¬ééµ)ãšãã¢ã«ãªãç§å¯éµã®ããŒã¿ã®ã¿ã§ãã
蚌ææžãšç§å¯éµãã»ããã«ããŠãšã¯ã¹ããŒãããããšãå¯èœã§ãããã»ãã¥ãªãã£ãªã¹ã¯ãèªèããæ éãªæäœãå¿ èŠã§ãã -
-
-
[ã°ã«ãŒãããªã·ãŒã®ç®¡ç]ãèµ·åãã
- ãµãŒããŒãããŒãžã£ãŒãŠã£ã³ããŠå³äžã®[ããŒã«]ãã¯ãªãã¯ãã
- ã¡ãã¥ãŒå ã®[ã°ã«ãŒãããªã·ãŒã®ç®¡ç]ãã¯ãªãã¯ãã[ã°ã«ãŒãããªã·ãŒã®ç®¡ç]ãèµ·åãã
-
"ClientComputers" OUã«ãªã³ã¯ãããæ°ããã°ã«ãŒãããªã·ãŒãªããžã§ã¯ã "DeployRootCA" ãäœæãã
-
[ClientComputers]ãã¯ãªãã¯ããŠéžæãã
-
[ClientComputers]ãå³ã¯ãªãã¯ããã³ã³ããã¹ãã¡ãã¥ãŒã®[ãã®ãã¡ã€ã³ã«GPOãäœæãããã®ã³ã³ãããŒã«ãªã³ã¯ãã]ãã¯ãªãã¯ãã
-
[æ°ããGPO]ãŠã£ã³ããŠã衚瀺ãããããšã確èªãã
-
[æ°ããGPO]ãŠã£ã³ããŠã§ã以äžã®ãã©ã¡ãŒã¿ãå ¥åãã
é ç® ãã©ã¡ãŒã¿ åå DeployRootCA ãœãŒã¹ã¹ã¿ãŒã¿ãŒ GPO (ãªã) -
[æ°ããGPO]ãŠã£ã³ããŠã§ã[OK]ãã¯ãªãã¯ãã
-
å³åŽãã€ã³ã®ã°ã«ãŒãããªã·ãŒãªããžã§ã¯ãã®äžèŠ§ãåç §ãã[DeployRootCA]ãäœæãããŠããããšã確èªãã
ãè£è¶³ã
[ã°ã«ãŒãããªã·ãŒãªããžã§ã¯ã(GPO)ãžã®ãªã³ã¯ãéžæããŸããã~]ã®ãããã¢ããã衚瀺ãããå Žåã¯ã[OK]ãã¯ãªãã¯ãã -
-
[ã°ã«ãŒãããªã·ãŒç®¡çãšãã£ã¿ãŒ]ãèµ·åãã
- ã°ã«ãŒãããªã·ãŒãªããžã§ã¯ãã®äžèŠ§ãåç §ãã[DeployRootCA]ãã¯ãªãã¯ããŠéžæãã
- [DeployRootCA]ãå³ã¯ãªãã¯ããã³ã³ããã¹ãã¡ãã¥ãŒã®[ç·šé]ãã¯ãªãã¯ãã
- [ã°ã«ãŒãããªã·ãŒç®¡çãšãã£ã¿ãŒ]ãèµ·åããããšã確èªãã
-
ã°ã«ãŒãããªã·ãŒãªããžã§ã¯ã("DeployRootCA")ãç·šéãã
- [ã°ã«ãŒãããªã·ãŒç®¡çãšãã£ã¿ãŒ]ã®å·ŠåŽã³ã³ãœãŒã«ããªãŒã®[ã³ã³ãã¥ãŒã¿ãŒã®æ§æ]-[ããªã·ãŒ]-[Windowsã®èšå®]-[ã»ãã¥ãªãã£ã®èšå®]-[å ¬éããŒã®ããªã·ãŒ]-[ä¿¡é Œãããã«ãŒã蚌ææ©é¢]ãã¯ãªãã¯ããŠéžæãã
- å·ŠåŽã³ã³ãœãŒã«ããªãŒã®[ä¿¡é Œãããã«ãŒã蚌ææ©é¢]ãå³ã¯ãªãã¯ããã³ã³ããã¹ãã¡ãã¥ãŒå
ã®[ã€ã³ããŒã]ãã¯ãªãã¯ãã
- [蚌ææžã®ã€ã³ããŒããŠã£ã¶ãŒã]ãèµ·åããããšã確èªãã
- [蚌ææžã®ã€ã³ããŒããŠã£ã¶ãŒã]ã®[蚌ææžã®ã€ã³ããŒã ãŠã£ã¶ãŒãã®éå§]ç»é¢ã§ã[次ãž]ãã¯ãªãã¯ãã
- [蚌ææžã®ã€ã³ããŒããŠã£ã¶ãŒã]ã®[ã€ã³ããŒããã蚌ææžãã¡ã€ã«]ç»é¢ã§ããã¹ã¯ãããã«ä¿åããã«ãŒãCA蚌ææžãã¡ã€ã«ãæå®ãã
- [蚌ææžã®ã€ã³ããŒããŠã£ã¶ãŒã]ã®[ã€ã³ããŒããã蚌ææžãã¡ã€ã«]ç»é¢ã§ã[次ãž]ãã¯ãªãã¯ãã
- [蚌ææžã®ã€ã³ããŒããŠã£ã¶ãŒã]ã®[蚌ææžã¹ãã¢]ç»é¢ã§ã[次ãž]ãã¯ãªãã¯ãã
- [蚌ææžã®ã€ã³ããŒããŠã£ã¶ãŒã]ã®[蚌ææžã®ã€ã³ããŒã ãŠã£ã¶ãŒãã®å®äº]ç»é¢ã§ã[å®äº]ãã¯ãªãã¯ãã
- [蚌ææžã®ã€ã³ããŒããŠã£ã¶ãŒã]ãããã¢ããã§ã[OK]ãã¯ãªãã¯ãã
- [ã°ã«ãŒãããªã·ãŒç®¡çãšãã£ã¿ãŒ]ã®[ä¿¡é Œãããã«ãŒã蚌ææ©é¢]ã®äžèŠ§ã«ã[WinCA]ã衚瀺ãããŠããããšã確èªãã
- [ã°ã«ãŒãããªã·ãŒç®¡çãšãã£ã¿ãŒ]ãçµäºãã
-
Clientã§ã°ã«ãŒãããªã·ãŒãæŽæ°ãã
-
æäœã³ã³ãã¥ãŒã¿ãå€æŽãããããæŒç¿ç°å¢ã®ãããããŒãžã«æ»ã
-
Windows Client(WinClient)ã®ç®¡çç»é¢ã« "admin" ã§æ¥ç¶ãã
-
Windows PowerShellã§ã°ã«ãŒãããªã·ãŒã®å³æé©çšã³ãã³ããå®è¡ãã
-
Windowsã¹ã¿ãŒãã¡ãã¥ãŒãå³ã¯ãªãã¯ããã³ã³ããã¹ã ã¡ãã¥ãŒå ã®[Windows PowerShell(管çè )]ãã¯ãªãã¯ãã
-
[ãŠãŒã¶ãŒ ã¢ã«ãŠã³ãå¶åŸ¡]ã®ãããã¢ããã§[ã¯ã]ãã¯ãªãã¯ãã
-
Windows PowerShellã§ä»¥äžã®ã³ãã³ããå®è¡ããã°ã«ãŒãããªã·ãŒãªããžã§ã¯ããå³æé©çšãã
ïŒ gpupdate /force
-
-
-
(ãªãã·ã§ã³.çç¥å¯) Clientã«é©çšãããã°ã«ãŒãããªã·ãŒã確èªãã
-
Windows PowerShellã§ä»¥äžã®ã³ãã³ããå®è¡ããã°ã«ãŒãããªã·ãŒãªããžã§ã¯ãã®é©çšç¶æ ãã¬ããŒããã¡ã€ã«ãšããŠãã¹ã¯ãããã«åºåãã
ïŒ gpresult /h C:\report\RootCaCrtUpdate.html
ãè£è¶³ã
C:\reportãã©ã«ããActive Directoryã°ã«ãŒãããªã·ãŒã®æŒç¿ã§äœæããŠããªãå Žåã¯ãäžã®ã³ãã³ããå®è¡ããåã«äœæããŠãã ãã -
çæãããã¬ããŒããã¡ã€ã«("C:\report\RootCaCrtUpdate.html")ãåç §ããé©çšãããã°ã«ãŒãããªã·ãŒã調æ»ãã
ãè£è¶³ã
[ã³ã³ãã¥ãŒã¿ã®è©³çŽ°]-[èšå®]-[ããªã·ãŒ]-[Windowsã®èšå®]-[ã»ãã¥ãªãã£ã®èšå®]-[å ¬éããŒã®ããªã·ãŒ/ä¿¡é Œãããã«ãŒã蚌ææ©é¢] ã«ãã°ã«ãŒãããªã·ãŒã§é åžãããã«ãŒãCA蚌ææžã衚瀺ãããŸãã
-
-
WebãµãŒãã¹ã«HTTPSã§æ¥ç¶ãã
-
WinClientã§Webãã©ãŠã¶(Google Chrome)ãèµ·åãã
-
Webãã©ãŠã¶ã®ã¢ãã¬ã¹æ¬ã« [https://web1.example.local/web1] ãšå ¥åãã[Enter]ããŒãæŒäžãã
ã泚æã
ãããã³ã«ã¹ããŒã ã®æå®ã«æ³šæããŠãã ããã
ããã§ã¯ http ã§ã¯ãªã https ãæå®ããŸãã -
èªèšŒæ å ±ãå ¥åãããããã¢ããã衚瀺ãããããšã確èªãã以äžã®ãã©ã¡ãŒã¿ãå ¥åãã
é ç® ãã©ã¡ãŒã¿ ãŠãŒã¶ãŒå Tom ãã¹ã¯ãŒã Pa$$w0rd -
äžã®ãã©ã¡ãŒã¿ãå ¥åãã[ãã°ã€ã³]ãã¯ãªãã¯ãã
-
åºæ¬èªèšŒãçµãŠãWebã³ã³ãã³ããå©çšã§ããããšã確èªãã
ãè£è¶³ã
WebãµãŒããŒèšŒææžãçºè¡ããWinCAã®ã«ãŒãCA蚌ææžãã€ã³ããŒãããããšã§ã蚌ææžã«ã€ããŠã®èŠåã衚瀺ãããªãç¶æ ã«ãªã£ãããšã確èªããŠãã ããã
-
ãããŸã§ã®æé ã§ã以äžã®é ç®ãåŠç¿ã§ããŸããã
- Windows Serverã§èªèšŒå±(蚌ææ©é¢)ãæ§ç¯ãã
- 眲åæ眲åèŠæ±(CSR)ãäœæãã蚌ææžã®çºè¡ãèŠæ±ãã
- 眲åæ眲åèŠæ±(CSR)ã«åºã¥ããŠãèªèšŒå±(蚌ææ©é¢)ãã蚌ææžãçºè¡ãã
- 蚌ææžãã€ã³ããŒãããWebãµãŒããŒã§SSLéä¿¡(HTTPS)ãæå¹åãã
- ã«ãŒãCA蚌ææžãã°ã«ãŒãããªã·ãŒã§ã¡ã³ããŒã³ã³ãã¥ãŒã¿ã«é åžãã