SSL ¥ê¥Ð¡¼¥¹¥×¥í¥­¥·¤Î¹½ÃÛ

ºÇ½ª¹¹¿·Æü¡§2004ǯ6·î19Æü

¡ÚSquid Home¤Ø¡Û

Squid¤ÏSSL¤ò»È¤Ã¤¿¥ê¥Ð¡¼¥¹¥×¥í¥­¥·¤â¹½À®¤Ç¤­¤ë¤è¤¦¤Ë¤Ê¤Ã¤Æ¤¤¤Þ¤¹¡£¡¡¤³¤Î»ö¤Ï¡¢Web¥µ¡¼¥Ð¤Î´ÉÍý¼Ô¤Ë¤È¤Ã¤Æ¤Ï´î¤Ð¤·¤¤»ö¤À¤È¤¤¤¨¤Þ¤¹¡£¡¡¤Ê¤¼¤Ê¤é¡¢¤³¤Îµ¡Ç½¤Ë¤è¤Ã¤Æ£±¤Ä¤Î¥µ¥¤¥È¾ÚÌÀ½ñ¤ò»È¤Ã¤ÆÊ£¿ô¤ÎWeb¥µ¡¼¥Ð¤¬Æ±»þ¤ËSSL¤Ë¤è¤ë°Å¹æ²½¤Î²¸·Ã¤ò¼õ¤±¤ë»ö¤ò°ÕÌ£¤¹¤ë¤«¤é¤Ç¤¹¡£¡¡
SSL¥ê¥Ð¡¼¥¹¥×¥í¥­¥·¤ò»È¤Ã¤¿¹½À®¤Ï¤ª¤ª¤è¤½°Ê²¼¤Î¤è¤¦¤Ê¹½À®¤Ë¤Ê¤ê¤Þ¤¹¡£

  1. Î㤨¤Ð¡¢¥¯¥é¥¤¥¢¥ó¥È¡Ê¥Ö¥é¥¦¥¶¡Ë¤¬ HTTPS¤Ë¤Æ"www2.hogehoge.jp" ¤ò¸Æ¤Ó½Ð¤¹¡£ ----- ­¡
  2. ¸ø³«DNS¤Ë¤Æ¡¢¾åµ­¥µ¥¤¥È¤Î¥¢¥É¥ì¥¹¤È¤·¤Æ Squid ¤Î¥¢¥É¥ì¥¹¤òÊÖ¤¹¡£ ¤³¤Î·ë²Ì¥¯¥é¥¤¥¢¥ó¥È¤Ï Squid¤ÈSSL¤Ë¤è¤ëÀܳ¤¬³«»Ï¤µ¤ì¤ë¡£ ----- ­¢
  3. Squid ¤Ï¥¯¥é¥¤¥¢¥ó¥È¤¬Í׵ᤷ¤¿URL¤òȽÃǤ·¤Æ¡¢¤½¤Î¥µ¥¤¥È¤Î¼ÂÂΤΥ¢¥É¥ì¥¹¤òÆâÉôDNS¤Ë¤Æ²ò·è¤·¡¢¼ÂºÝ¤Î "www2.hogehoge.jp" ¤ØÄ̾ï¤ÎHTTP¤Ë¤Æ¥ê¥¯¥¨¥¹¥È¤ò¹Ô¤¦¡£ ----- ­£
  4. www2 ¤Ï¥ª¥Ö¥¸¥§¥¯¥È¤òSquid¤ØÅϤ¹¡£¡¡¤³¤Î·ë²Ì¤òSquid¤Ï¥¯¥é¥¤¥¢¥ó¥È¤ØÊֵѤ¹¤ë¡£ -----­¤


¾åµ­¤ÎÎ㤫¤éȽ¤ë¤è¤¦¤Ë¡¢¥¯¥é¥¤¥ó¥È¤ÈSquid¤Î´Ö¤ÏSSL¤Ë¤è¤Ã¤ÆÀܳ¤¬³«»Ï¤µ¤ì¤ë»ö¤Ç¡¢°ÂÁ´¤ÊÀܳ¤¬³ÎÊݤµ¤ì¤Þ¤¹¡£¡¡Squid ¤Ï¡¢¥¯¥é¥¤¥¢¥ó¥È¤«¤é¤Î¥ê¥¯¥¨¥¹¥È¤µ¤ì¤¿URL¤òȽÃǤ·¤Æ¼ÂÂΤΥµ¡¼¥Ð¤«¤é¥³¥ó¥Æ¥ó¥Ä¤òÄ̾ï¤ÎHTTP¤Ë¤Æ¼è¤ê½Ð¤¹¤è¤¦¤Ë¤Ê¤ê¤Þ¤¹¡£¡¡¤Ç¤¹¤«¤é¡¢¥ë¡¼¥¿¤ä¥Õ¥¡¥¤¥ä¡¼¥¦¥©¡¼¥ë¤Ç¼ÂÂΤÎWeb¥µ¡¼¥Ð¤ØÄ¾ÀÜ¥¢¥¯¥»¥¹¤µ¤»¤Ê¤¤¤è¤¦¤ÊÀßÄê¤ò¹Ô¤¦¤³¤È¤Ç¡¢°ÂÁ´¤«¤Ä¹â®¤ÊSSL¥»¥Ã¥·¥ç¥ó¤¬²Äǽ¤Ë¤Ê¤ê¤Þ¤¹¡£


°Ê²¼¤Ç¤Ï¡¢¼ÂºÝ¤ËSSL¥ê¥Ð¡¼¥¹¥×¥í¥­¥·¤Î¹½ÃÛ¼ê½ç¤òÀâÌÀ¤·¤Þ¤¹¡£

  1. ¡Ö¥µ¥¤¥È¾ÚÌÀ½ñ¡×¤È¡Ö¥×¥é¥¤¥Ù¡¼¥È¥­¡¼¡×¤ÎÆþ¼ê
    SSL¤òÍøÍѤ¹¤ë°Ù¤Ë¡¢¥µ¥¤¥È¾ÚÌÀ½ñ¤ÎÆþ¼ê¤È¥×¥é¥¤¥Ù¡¼¥È¥­¡¼À¸À®¤ò¹Ô¤Ã¤Æ¤¯¤À¤µ¤¤¡£¡¡¥µ¥¤¥È¾ÚÌÀ½ñ¤ÏÀµ¼°¤Ê±¿ÍѤò¹Ô¤¦¤Ê¤é¥Ù¥ê¥µ¥¤¥ó¤Ê¤É¤Î¸ø¼°¤ÎCA¤«¤éÆþ¼ê¤¹¤ë¤ÈÎɤ¤¤Ç¤·¤ç¤¦¡£¡¡¤Þ¤¿¥Æ¥¹¥È±¿ÍѤä¼ÒÆâ¤À¤±¤Ç¤ÎÍøÍѤʤéOpenSSL¤Ê¤É¤Ë¤è¤Ã¤Æ¼«Á°¤ÇCA¤òΩ¤Æ¤Æ¡¢¤³¤ì¤ò»È¤Ã¤Æ¥µ¥¤¥È¾ÚÌÀ½ñ¤òºî¤Ã¤Æ¤âÎɤ¤¤Ç¤·¤ç¤¦¡£¡¡¥µ¥¤¥È¾ÚÌÀ½ñ¤È¥×¥é¥¤¥Ù¡¼¥È¥­¡¼¤ÎÀ¸À®ÊýË¡¤Ï¡¢¥¤¥ó¥¿¡¼¥Í¥Ã¥È¾å¤Ç"Apache SSL"¤Ê¤É¤Î¥­¡¼¥ï¡¼¥É¤ò¸¡º÷¤¹¤ì¤Ð¤½¤ÎÊýË¡¤¬Â¿¤¯µ­½Ò¤µ¤ì¤Æ¤¤¤ë¤Î¤Ç¤½¤ì¤é¤ò»²¾È¤·¤Æ¤¯¤À¤µ¤¤¡£

  2. squid.conf ¤Î¼¡¤Î¹àÌܤòÊÔ½¸¤·¤Þ¤¹¡£

    http_port 80
    https_port 443 cert=/etc/squid/ssl/newcert.pem key=/etc/squid/ssl/private.key
    http_access allow all
    visible_hostname www.robata.org
    httpd_accel_host virtual
    httpd_accel_port 80
    httpd_accel_uses_host_header on


    ¡ÊÀßÄêÆâÍÆ²òÀâ¡Ë
    http_port Squid ¤¬HTTP¤Î¥ê¥¯¥¨¥¹¥ÈÂÔ¤Á¼õ¤±¤ë¥Ý¡¼¥È¤Ç¤¹¡£ HTTP¤Ç¥ê¥¯¥¨¥¹¥È¤¬Í褿¾ì¹ç¤ÏÄ̾ï¤Î¥ê¥Ð¡¼¥¹¥×¥í¥­¥·¤È¤·¤Æµ¡Ç½¤·¤Þ¤¹¡£
    https_port HTTPS¤Î¥ê¥¯¥¨¥¹¥È¤òÂÔ¤Á¼õ¤±¤ë¥Ý¡¼¥ÈÈÖ¹æ¤È¡¢¥µ¥¤¥È¾ÚÌÀ½ñ¡Ênewcert.pem)¤ª¤è¤Ó¥×¥é¥¤¥Ù¡¼¥È¥­¡¼¡Êprivate.key¡Ë¤ÎÃÖ¤¤¤Æ¤¢¤ë¾ì½ê¤ò»ØÄꤷ¤Þ¤¹¡£
    http_access HTTP¤ª¤è¤ÓHTTPS¤Î¥ê¥¯¥¨¥¹¥È¤òµö²Ä¤¹¤ë¥¢¥¯¥»¥¹¥ë¡¼¥ë¤òÀßÄꤷ¤Þ¤¹¡£¤³¤³¤Ç¤ÏÀâÌÀ¤ò´Êñ¤Ë¤¹¤ë°Ù¤ËÁ´¤Æ¤Î¥¯¥é¥¤¥¢¥ó¥È¤«¤é¤òµö²Ä¤·¤Æ¤¤¤Þ¤¹¡£
    visible_hostname Squid¤Ë³ä¤êÅö¤Æ¤ëɽ¼¨¾å¤Î¥µ¡¼¥Ð̾¤Ç¤¹¡£¡¡»ØÄ꤬¤Ê¤¤¤Èµ¯Æ°¤Ç¤­¤Þ¤»¤ó¡£
    httpd_accel_host ¥¢¥¯¥»¥é¥ì¡¼¥¿¤È¤·¤Æ¥Ð¡¼¥Á¥ã¥ë¥Û¥¹¥È¡ÊÊ£¿ô¤Î¥µ¡¼¥Ð¡Ë¤ò¥µ¥Ý¡¼¥È¤·¤Þ¤¹¡£
    httpd_accel_port ¼ÂÂΤΥµ¡¼¥Ð¤Ø¥ê¥¯¥¨¥¹¥È¤òÁ÷¤ëºÝ¤ÎÁ÷¤êÀè¥Ý¡¼¥ÈÈÖ¹æ¤Ç¤¹¡£
    httpd_accel_uses_host_header URL¤òȽÃǤ·¤Æ¥ê¥¯¥¨¥¹¥ÈÀè¤òÊѤ¨¤ë¤Î¤Ç on ¤ò»ØÄꤷ¤Þ¤¹¡£


  3. Squid ¾å¤Ç DNS ¤òµ¯Æ°¤¹¤ë¤« HOSTS ¤òÀßÄꤷ¤Þ¤¹¡£
    Squid ¤ËÍ褿¥ê¥¯¥¨¥¹¥È¤ÎURL¤ò¸«¤Æ¼ÂºÝ¤Î¥µ¡¼¥Ð¤Î¥¢¥É¥ì¥¹¤ò¸¡º÷¤¹¤ëɬÍפ¬¤¢¤ê¤Þ¤¹¡£¡¡¤³¤Î°Ù¤Ë¤Ï¡¢Squid¤ÎHOSTS¥Õ¥¡¥¤¥ë¤Ë¼ÂºÝ¤Î¥µ¡¼¥Ð¤Î¥¢¥É¥ì¥¹¤òÅÐÏ¿¤¹¤ë¤«¡¢SquidÍÑ¤ÎÆâÉôDNS¤ò¹½ÃÛ¤¹¤ë¤ÈÎɤ¤¤Ç¤·¤ç¤¦¡£

  4. ¸ø³«DNS ¤Î¥¢¥É¥ì¥¹¤ò Squid ¤Ø½¸¤á¤ë¤è¤¦¤ËÀßÄꤹ¤ë¡£
    ¸ø³«DNS ¤òÊÔ½¸¤·¤Æ¡¢¥ê¥Ð¡¼¥¹¥×¥í¥­¥·¤ò»È¤Ã¤Æ¥¢¥¯¥»¥¹¤µ¤»¤ë¥µ¡¼¥Ð¤Î¥¢¥É¥ì¥¹¤òÁ´¤ÆSquid¤Î¥¢¥É¥ì¥¹¤ØÊѹ¹¤·¤Þ¤¹¡£¤³¤Î·ë²Ì¡¢¥¯¥é¥¤¥¢¥ó¥È¤«¤éWeb¥µ¡¼¥Ð¤Ø¤Î¥ê¥¯¥¨¥¹¥È¤Ï¤¹¤Ù¤Æ Squid ¤¬ºÇ½é¤Ë¼õ¤±¼è¤ë¤è¤¦¤Ë¤Ê¤ê¤Þ¤¹¡£


¡ÚSquid Home¤Ø¡Û

Copyright© 1998-2003 ROBATA.ORG