Microsoft Edgeã§HSTSãšã©ãŒãçºçããŠããŸããïŒãããªæ©ã¿ãæ±ããŠããã®ã¯ããªãã ãã§ã¯ãããŸããããã®åä»ãªåé¡ã¯ãå®å
šãªãµã€ããžã®ã¢ã¯ã»ã¹ããããã¯ããæœåšçãªã»ãã¥ãªãã£æ»æã®å
åãèŠåããŸããã§ããå®å¿ãã ããïŒãã®ã¬ã€ãã§ã¯ãææ°ã®Edgeã¢ããããŒãã䜿ã£ãåããããããã©ãã«ã·ã¥ãŒãã£ã³ã°æé ãã玹ä»ããŸããæè¡çãªåé¡ã«é ãæ©ãŸããããšãªããã¹ã ãŒãºãªãã©ãŠãžã³ã°ãåãæ»ããæäŒããããŸããããããã£ããå®è·µããŠããªã³ã©ã€ã³ã®èªç±ãåãæ»ããŸããããð
Microsoft Edge ã®HSTS ãšã©ãŒãšã¯äœã§ãã?
HTTP Strict Transport SecurityïŒHSTSïŒã¯ãMicrosoft Edgeãªã©ã®ãã©ãŠã¶ã«HTTPSã®ã¿ã®äœ¿çšã匷å¶ããäžéè
æ»æïŒ man-in-the-middle attackïŒãé²ããŠã§ãã»ãã¥ãªãã£ããªã·ãŒã§ããEdgeãHSTSãšã©ãŒãã¹ããŒããå Žåããã©ãŠã¶ããµã€ãã®HSTSããªã·ãŒãæ€èšŒã§ããªãããšãæå³ããŸããããã¯ãèšŒææžã®äžäžèŽããããã¯ãŒã¯ã®äžå
·åãªã©ãåå ã§ããããšãå€ãã§ãã
ãã®ãšã©ãŒã¯ãæ¥ç¶ããã©ã€ããŒãã§ã¯ãããŸããããŸãã¯HSTSç¹æã®èŠåãšããŠè¡šç€ºãããéè¡ããŒã¿ã«ãªã©ã®ãµã€ããžã®ã¢ã¯ã»ã¹ã忢ããŸããæè¿ã®EdgeããŒãžã§ã³ïŒChromiumããŒã¹ïŒã§ã¯ãäŒæ¥ãããã¯ãŒã¯ãVPNæ¥ç¶æã«ããçºçããŸããéããã«ä¿®æ£ããããšã§ãããŒã¿ååãªã©ã®å®éã®è
åšããä¿è·ã§ããŸãããã©ãã«ã·ã¥ãŒãã£ã³ã°ã®æºåã¯ã§ããŸãããïŒâ
Microsoft Edge HSTS ãšã©ãŒã®äžè¬çãªåå ãšé¢é£ããã»ãã¥ãªãã£æ»æ
æ ¹æ¬åå ãç¹å®ããããšã§ãè§£æ±ºãæ©ãŸããŸããç°¡åã«ã説æããŸãã
| åå |
çç¶ |
ãªã¹ã¯ã¬ãã« |
| æéåã/ç¡å¹ãªSSLèšŒææž |
HSTS ã«é¢ãã ERR_SSL_PROTOCOL_ERROR |
é«â ïžïŒãã£ãã·ã³ã°ã®å±éºã«ãããããïŒ |
| ãããã·/VPNå¹²æž |
èªã¿èŸŒã¿ãé
ããHSTSããã³ãããç¹°ãè¿ã衚瀺ããã |
äžïŒMITMã®å¯èœæ§ããïŒ |
| å€ããšããžãã£ãã·ã¥/Cookie |
ãµã€ãåºæã®HSTSããã㯠|
äœïŒæ©æ¥ãªä¿®æ£ãå¿
èŠïŒ |
| ã·ã¹ãã ã¯ããã¯ã®åæã®åé¡ |
èšŒææžã®æ€èšŒã«å€±æããŸãã |
äžïŒãã¹ãŠã® HTTPS ã«åœ±é¿ïŒ |
| ãã«ãŠã§ã¢ãŸãã¯ãŠã€ã«ã¹å¯Ÿçã®ããã㯠|
äºæããªãã»ãã¥ãªãã£æ»æã®èŠå |
é«ðšïŒããã«ã¹ãã£ã³ïŒ |
ãããã®ããªã¬ãŒã¯ãæ»æè
ãHSTSãåœè£
ããŠã»ãã·ã§ã³ãä¹ã£åããªã©ãããåºç¯ãªã»ãã¥ãªãã£æ»æã«ã€ãªããããšããããããŸãããèªèº«ã®ããªã¬ãŒã«æ°ã¥ããŸãããïŒä»¥äžã®ä¿®æ£ããã°ã©ã ãã芧ãã ããïŒð
Microsoft Edge HSTS ãšã©ãŒã®ãã©ãã«ã·ã¥ãŒãã£ã³ã°æé
以äžã®å®èšŒæžã¿ã®æé ãé çªã«å®è¡ããŠãã ãããã»ãšãã©ã®ãŠãŒã¶ãŒã¯5å以å
ã«è§£æ±ºã§ããŸããææ°ã®Edgeå®å®çãªãªãŒã¹ã§ãã¹ãæžã¿ã§ãã
- 1ïžâ£ Edgeã®ãã£ãã·ã¥ãšHSTSããŒã¿ãæ¶å»ãã
Edgeãéã > èšå® > ãã©ã€ãã·ãŒãæ€çŽ¢ããµãŒãã¹ > æ¶å»ããããŒã¿ãéžæ > ãCookieãšãã®ä»ã®ãµã€ãããŒã¿ã+ããã£ãã·ã¥ãããç»åãšãã¡ã€ã«ããéžæ > ä»ããæ¶å»ã
ãã³ãïŒé åºãªHSTSã®å Žåã¯ãedge://net-internals/#hstsã¢ãã¬ã¹ããŒã«å
¥åããåé¡ã®ãããã¡ã€ã³ãæ€çŽ¢/åé€ããŠããªããŒãããŠãã ãããããã§è§£æ±ºïŒð
- 2ïžâ£ ã·ã¹ãã ã¯ããã¯ãåæãã
ã¿ã¹ã¯ããŒã®æèšãå³ã¯ãªã㯠> æ¥ä»/æå»ãèª¿æŽ > ãæå»ãèªåçã«èšå®ããããæå¹ã«ãããèšŒææžã¯æéã®ãããå«ããŸãã
- 3ïžâ£ å¹²æžããæ¡åŒµæ©èœ/ãããã·ãç¡å¹ã«ãã
edge://extensions/ > VPN/åºåãããã«ãŒããªãã«ããŸããWindowsã®èšå® > ãããã¯ãŒã¯ > ãããã· > æåãããã·ããªãã«ããŸãã
- 4ïžâ£ Edgeã®ãã©ã°ãšèšå®ããªã»ããããŸãã
ãedge://flags/ã>ããã¹ãŠãªã»ããããéžæããŸããæ¬¡ã«ããèšå®ã>ãèšå®ããªã»ããã>ãããã©ã«ãã«æ»ãããéžæããŸããEdgeãåèµ·åããŸãã
- 5ïžâ£ Windowsã»ãã¥ãªãã£ã¹ãã£ã³ãå®è¡ããŸãã
ãWindowsã»ãã¥ãªãã£ããæ€çŽ¢ããããŠã€ã«ã¹ãšè
åšã®é²æ¢ã>ãã¯ã€ãã¯ã¹ãã£ã³ããéžæããŸããã»ãã¥ãªãã£æ»æãæš¡å£ãããã«ãŠã§ã¢ãæé€ããŸãã
- ð§ 詳现ïŒEdge ãšèšŒææžãæŽæ°ããã«ã¯ãã
ãã«ãã>ãMicrosoft Edge ã«ã€ããŠïŒèªåæŽæ°ïŒããåç
§ããŠãã ãããèšŒææžã«é¢ããåé¡ã«ã€ããŠã¯ãMicrosoft ã®å
¬åŒã¬ã€ãããã«ãŒããããŠã³ããŒãããŠãã ããã
ç¹å®ã®ãµã€ãã§ãšã©ãŒãç¶ãå Žåã¯ãã詳现èšå®ã>ãç¶è¡ãã§äžæçã«ãã€ãã¹ããŠãã ããïŒã»ãã¥ãªãã£ãæåªå
ã«ãããããæ
éã«äœ¿çšããŠãã ããïŒããããã®æé ã§95%ã®ã±ãŒã¹ã解決ã§ããŸããèªä¿¡ãã€ããŸãããïŒæ¬¡ã¯èšå®ã®ã»ãã¥ãªãã£ã匷åããŸããããð
Edge ã®HSTS ãšã©ãŒã«é¢é£ããã»ãã¥ãªãã£æ»æã«å¯Ÿããé²åŸ¡
HSTSãšã©ãŒã¯çã®è
åšã瀺åããå¯èœæ§ããããŸããä¿è·ã匷å:
- 匷åãããã»ãã¥ãªãã£ãæå¹ã«ãã: èšå® > ãã©ã€ãã·ãŒ > ã»ãã¥ãªã㣠> 匷åãããä¿è· (å³å¯ã¢ãŒãã§ã¯å±éºãªããŠã³ããŒãããããã¯ãããŸã)ã
- ãã¹ã¯ãŒã ã¢ãã¿ãŒã®äœ¿çš: 䟵害ããããã°ã€ã³ãæ©æã«æ€åºããŸãã
- 宿çãªæŽæ°: Edge ã¯è匱æ§ãèªåçã«ä¿®æ£ããã®ã§ãç¶ç¶ããŠãã ããã
- ããããå Žæã§ã® Two-Factor : HSTS ãè¶
ããå±€å¥é²åŸ¡ã
| ç¹åŸŽ |
å©ç¹ |
| HSTS ã¹ãŒããŒãªããŒã(edge://flags/) |
æ°ããHSTSãã§ãã¯ã匷å¶ãã |
| è¿œè·¡é²æ¢ |
ã¯ãã¹ãµã€ããã©ãã«ãŒãããã㯠|
äŒæ¥ãŠãŒã¶ãŒã®æ¹ã¯ãMicrosoft Edge Enterprise ããã¥ã¡ã³ãããã°ã«ãŒãããªã·ãŒãã確èªãã ãããåžžã«èŠæãæ ãããç©æ¥µçãªè¡åãã»ãã¥ãªãã£æ»æã黿¢ããŸãã
ãŸãšã: åã³å®å
šã«ãã©ãŠãžã³ã°
Microsoft Edge HSTSãšã©ãŒã®ãã©ãã«ã·ã¥ãŒãã£ã³ã°ã¯ãããã¹ã¿ãŒããŸãããïŒããã§ããã©ãŠã¶ãå·§åŠãªã»ãã¥ãªãã£æ»æããå®ãããšãã§ããŸããããããã®æé ãä»ããå®è·µããŠãå®å¿ããŠããããµãŒãã£ã³ããæ¥œãã¿ãã ãããäžã®ã³ã¡ã³ãæ¬ã§ãæåäŸãå
±æããŠãã ãããããªãã¯ã©ã®ããã«è§£æ±ºããŸãããïŒå®å
šãªãã©ãŠãžã³ã°ãïŒð