ãã®æçš¿ã¯Keyfactorã®å¯çš¿ã«ãããã®ã§ãã
Dockerã¯ãææ°ã®ã¢ããªã±ãŒã·ã§ã³ã®éçºãšãããã€ã®æ¹æ³ã«é©åœããããããéçºè
ãã³ã³ããåãããã¢ããªã±ãŒã·ã§ã³ãããç°¡åãã€å¹ççã«äœæããã³ç®¡çã§ããããã«ããŸãããÂ
ãšã³ã¿ãŒãã©ã€ãºã»ã¬ãã«ã®ã»ãã¥ãªãã£ãŒãå ¬ééµåºç€ (PKI)ãããã³èšŒææžç®¡çã®äžçã«ããå Žåã¯ãPKI ãå®è£ ããããã®ãªãŒãã³ã»ãœãŒã¹ã»ããŒã«ã§ãã EJBCA ãæ¢ã«ãåããããããŸããã ãã®ããã°èšäºã§ã¯ãEJBCAãDockerã³ã³ãããšããŠãããã€ããã»ãã¥ãªãã£ãšèšŒææžç®¡çã®ããŒãºã«åãããŠã€ã³ãã©ã¹ãã©ã¯ãã£ã®ã»ããã¢ãããããã¢ãã³ã§å¹ççãã€æè»ã«ããæ¹æ³ã«ã€ããŠèª¬æããŸããÂ

EJBCAãDockerã³ã³ãããšããŠãããã€ããçç±
EJBCAã¯å ç¢ãªPKIããã³èšŒææžç®¡çãœãªã¥ãŒã·ã§ã³ã§ãããç¹ã«ãœãŒã¹ãããããã€ããå¿ èŠãããå Žåã¯ãèšå®ãšç®¡çãå°é£ãªå ŽåããããŸãã EJBCAãDockerã³ã³ãããšããŠãããã€ãããšãããã»ã¹ãç°¡çŽ åãããæ¬¡ã®ãããªããŸããŸãªã¡ãªãããåŸãããŸãã
- ããŒã¿ããªã㣠â Dockerã³ã³ããã¯è»œéã§ããŒã¿ãã«ã§ãã¢ããªã±ãŒã·ã§ã³ã®å®è¡ã«å¿ èŠãªãã¹ãŠã®ãœãããŠã§ã¢ãå«ãŸããŠããŸãã EJBCAã³ã³ããã€ã¡ãŒãžãäœæããããDockerããµããŒãããä»»æã®ã·ã¹ãã ã§å®è¡ããŠãç°å¢éã®äžè²«æ§ã確ä¿ã§ããŸãã
- ç°¡åãªã¹ã±ãŒãªã³ã° â ã³ã³ããã䜿çšãããšãEJBCA ã€ã³ã¹ã¿ã³ã¹ã®ã¹ã±ãŒãªã³ã°ãç°¡åã«ãªããŸãã è€æ°ã®ã³ã³ãããç°¡åã«ã¹ãã³ã¢ããã§ããKubernetesãªã©ã®ãªãŒã±ã¹ãã¬ãŒã·ã§ã³ããŒã«ãã¹ã±ãŒãªã³ã°ã管çã§ããŸãã
- å°å ¥ã®ç°¡çŽ å â EJBCAãDockerã³ã³ããã«çµã¿èŸŒããšãè€éãªã€ã³ã¹ããŒã«æé ããJavaãããŒã¿ããŒã¹ãã©ã€ããWildflyã¢ããªã±ãŒã·ã§ã³ãµãŒãããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãªã©ã®äŸåé¢ä¿ãæ°ã«ããããšãªããè¿ éã«ãããã€ããã³ã¢ããã°ã¬ãŒãã§ããŸãã EJBCA ã®ã€ã³ã¹ããŒã«ã«ã¯ãããããã¹ãŠã®ã³ã³ããŒãã³ããå¿ èŠã§ãããã³ã³ããã«ã¯ãããã®éèŠãªäŸåé¢ä¿ããã¹ãŠã€ã³ã¹ããŒã«ããã³æ§æãããŠããŸãã
ãªãŒãã³ãœãŒã¹ã®PKIãšEJBCAã®å©ç¹
PKIãœãªã¥ãŒã·ã§ã³ã®å®è£ ã«é¢ããŠã¯ãEJBCAã®ãªãŒãã³ãœãŒã¹ã®æ§è³ªã¯ãä»ã®ãœãããŠã§ã¢ããŒã«ããŠãŒãã£ãªãã£ãããæç¢ºãªå©ç¹ãæäŸããŸããOpenSSLãªã©ã®ããŒã«ã¯ããã¹ãã«ã¯é©ããŠãããããããŸããããæ¬çªç°å¢ã«ã¯äžååã§ããããšããããããŸãã ç¹å®ã®ãŠãŒã¹ ã±ãŒã¹ã«åãããŠèª¿æŽããã Microsoft PKI ãŸãã¯ãã®ä»ã® PKI ãµãŒãã¹ã¯å ç¢ã§ãããå€ãã®å Žåãæè»æ§ãã¹ã±ãŒã©ããªãã£ãçžäºéçšæ§ãããã³ã³ã³ãã©ã€ã¢ã³ã¹ã«å¶éããããŸãã
EJBCAã¯ãäžçã§æã䜿çšãããŠãããªãŒãã³ãœãŒã¹PKIã®1ã€ã§ãã GitHub ã®ã³ãŒãã䜿çšããŠãœãŒã¹ãããã«ãããããšããDocker ã³ã³ãããŒãšããŠãããã€ããããšãã§ããŸãã EJBCAã«æåŸ ã§ããå©ç¹ã¯æ¬¡ã®ãšããã§ãã
- å æ¬çãªæ©èœã»ãã â EJBCAã¯ãå€ãã®ãŠãŒã¹ã±ãŒã¹ã«ãããŠãèšŒææžã®çºè¡ã倱å¹ãéµç®¡çãªã©ãèšŒææžç®¡çã®ããã®å æ¬çãªæ©èœã»ãããæäŸããŸãã 1 ã€ã®ã€ã³ã¹ããŒã«ã§æ°çŸã® CA ãå®è¡ã§ããŸãã ããã¯ãããšãã°ããµãŒããŒã®ã€ã³ã¹ããŒã«ããšã« 1 ã€ã® CA ããå®è¡ã§ããªã Microsoft ADCS ãšæ¯èŒããŠå¹æçã§ãã EJBCA ã® 1 ã€ã®ã€ã³ã¹ããŒã«ã§ãè€æ°ã®ãŠãŒã¹ã±ãŒã¹ããµããŒãããããšãã§ããŸãã
- å ç¢ãªèªèšŒå± â EJBCAã¯ãæ¬æ ŒçãªèªèšŒå±(CA)ãç»é²å±ãããã³æ€èšŒæ©é¢ãšããŠæ©èœãããªã³ã©ã€ã³èšŒææžã¹ããŒã¿ã¹ãããã³ã«(OCSP)ãšèšŒææžå€±å¹ãªã¹ã(CRL)ã®äž¡æ¹ããµããŒãããæ¬æ ŒçãªPKIããµããŒãããããã«äžå¯æ¬ ã§ããÂ
- æ¡åŒµæ§ãšèªåå â æ¬çªç°å¢ã®ã·ããªãªã§ã¯ãEJBCAã«è² è·ãããããPKIæäœãæäŸããããã«ããå€ãã®ã€ã³ã¹ã¿ã³ã¹ãå¿ èŠãªå Žåãã¹ã±ãŒã©ããªãã£ãéèŠã§ãã EJBCAã¯ãDockerãªãŒã±ã¹ãã¬ãŒã·ã§ã³ããŒã«ãHelmãã£ãŒããããã³EJBCAãªãŒãã³ãœãŒã¹ã®Ansibleãã¬ã€ããã¯ã掻çšããããšã§ç°¡åã«æ¡åŒµã§ããPKIã€ã³ãã©ã¹ãã©ã¯ãã£ãçµç¹ã®èŠæ±ãåŠçã§ããããã«ããŸããÂ
- ãŠãŒã¶ãŒç®¡çãšããŒã«ããŒã¹ã®ã¢ã¯ã»ã¹å¶åŸ¡ â EJBCA ã¯ããŠãŒã¶ãŒç®¡çãšããŒã«ããŒã¹ã®ã¢ã¯ã»ã¹å¶åŸ¡ãæäŸããPKI å ã§ç¹å®ã®ã¿ã¹ã¯ãå®è¡ã§ãããŠãŒã¶ãŒãå®çŸ©ã§ããŸããÂ
- 掻çºãªã³ãã¥ããã£ãšãµããŒã â EJBCAã¯ãEJBCA Enterpriseãšãã£ã·ã§ã³ã®ã¢ã¯ãã£ããªãªãŒãã³ãœãŒã¹ã³ãã¥ããã£ãšãããã§ãã·ã§ãã«ãµããŒããªãã·ã§ã³ã®æ©æµãåããŠãããå¿ èŠãªãšãã«é©åãªãµããŒããèŠã€ããããšãã§ããŸãã EJBCA Enterprise ãšãã£ã·ã§ã³ã¯ããœãããŠã§ã¢ããã³ããŒããŠã§ã¢ ã¢ãã©ã€ã¢ã³ã¹ãCloud AWS ããã³ Azure Marketplace ãªãã·ã§ã³ãSaaS ãšããŠå©çšã§ããŸãã
- ã³ã³ãã©ã€ã¢ã³ã¹ãšç£æ» â EJBCAã¯ãã³ã³ãã©ã€ã¢ã³ã¹ãšç£æ»ã念é ã«çœ®ããŠèšèšãããŠãããèŠå¶èŠä»¶ãæºãããå ç¢ã§çœ²åãããç£æ»èšŒè·¡ãç¶æããã®ã«åœ¹ç«ã¡ãŸãã ããšãã°ãå CA ã«èšŒææžããªã·ãŒãé©çšããŠãéä¿¡ãããèšŒææžçœ²åèŠæ± (CSR) ã®çš®é¡ã« CA ã眲åã§ããªãããã«ããããšãã§ããŸãã
ã¯ãã
ã§ã¯ãEJBCAãDockerã³ã³ãããšããŠãããã€ããããã»ã¹ãèŠãŠãããŸãããã 詳现ã«ã€ããŠã¯ãYouTube㮠玹ä»ãã㪠ãã芧ãã ããã
ã¹ããã 1:Dockerãã€ã³ã¹ããŒã«ãã
ã·ã¹ãã ã« Dockerãã€ã³ã¹ããŒã«ãããŠãã å¿ èŠããããŸããÂ
ã¹ããã 2: EJBCA Docker ã€ã¡ãŒãžã®ãã«
EJBCAã¯å ¬åŒã®Dockerã€ã¡ãŒãžãæäŸããŠãããããç°¡åã«éå§ã§ããŸãã æ¬¡ã®ã³ãã³ãã䜿çšããŠã€ã¡ãŒãžããã«ã§ããŸãã
docker pull keyfactor/ejbca-ce:latest
ã¹ããã 3:EJBCAã³ã³ããã®å®è¡
EJBCAã€ã¡ãŒãžãã§ããã®ã§ããããã³ã³ãããšããŠå®è¡ã§ããŸãã
shellCopy code
docker run -d --rm --name ejbca-node1 -p 80:8080 -p 443:8443 -h "127.0.0.1" --memory="2048m" --memory-swap="2048m" --cpus="2" ejbca/ejbca-ce:8.0.0
ãã®ã³ãã³ãã¯ãEJBCA ã³ã³ãããããã¯ã°ã©ãŠã³ãã§èµ·åãã https://localhost:443/ejbca/adminweb ã§ã¢ã¯ã»ã¹ã§ããããã«ãªããŸãã
ã¹ããã 4: EJBCA Web ã³ã³ãœãŒã«ãžã®ã¢ã¯ã»ã¹
Web ãã©ãŠã¶ãŒãéã ãhttps://localhost/ejbca/adminweb ã«ããã²ãŒãã㊠EJBCA Web ã³ã³ãœãŒã«ã«ã¢ã¯ã»ã¹ããŸãã
ã«ã¹ã¿ã ã€ã³ã¹ããŒã«æ§æ
EJBCA ã€ã³ã¹ã¿ã³ã¹ãã«ã¹ã¿ãã€ãºããå¿ èŠãããå Žåã¯ãæ§æãã¡ã€ã«ãããŠã³ãããããã³ã³ããã§å€éšããŒã¿ããŒã¹ã䜿çšã§ããŸãã ãã®æé ã§ã¯ãç¹å®ã®ããŒãºã«åãã㊠PKI ã調æŽã§ããŸãã
PKI 管çè ãšããŠã® TLS èšŒææžã®çºè¡Â Â
ãã©ã€ããŒãTLSèšŒææžã¯ããšã³ã¿ãŒãã©ã€ãºãããã¯ãŒã¯ãããžãã¹ã¢ããªã±ãŒã·ã§ã³ãªã©ã®ã¯ããŒãºããããã¯ãŒã¯ç°å¢å ã®ãŠãŒã¶ãŒãããã€ã¹ãèªèšŒããäžã§éèŠãªåœ¹å²ãæãããŸãã ãããªãã¯ãã©ã¹ããäžèŠãªå Žåã¯ããã©ã€ããŒãTLSèšŒææžãéžæããã®ãæãã³ã¹ãå¹çãé«ã䟿å©ãªæ¹æ³ã§ãã ããããçå£ã«åãçµãããšãéèŠã§ãã PKI ãœãããŠã§ã¢ã®ã»ããã¢ãããšèšŒææžã®çºè¡ããã»ã¹ã¯ããã©ã€ããŒããªä¿¡é Œç°å¢ã§ãéèŠã§ãã Â
TLSã¯ã©ã€ã¢ã³ããŸãã¯ãµãŒããŒèšŒææžã¯ããã¹ããã©ã¯ãã£ã¹ã®ãããªãã¥ãŒããªã¢ã«ã«åŸã£ãŠç°¡åã«çæã§ããŸãã EJBCAã§ã¯ãå°èŠæš¡ããéå§ãããŠãŒã¹ã±ãŒã¹ã®é²åã«åãããŠæ¡åŒµããããšãã§ããŸãã ãã®ã·ãªãŒãºã¯ã EJBCAãDockerã³ã³ãããšããŠèšå®ããããã®ã¬ã€ãããå§ãŸããŸãã Webãµã€ãã§EJBCAã䜿çšããŠTLSèšŒææžãçºè¡ããæ¹æ³ã®è©³çްãšè¿œå ãªãã·ã§ã³ãèŠã€ããŠãã ããã
çµè«
EJBCA ã Docker ã³ã³ãããšããŠãããã€ãããšãPKI ã»ããã¢ããã®ç®¡çãç°¡çŽ åãããŸãã ç§»æ€æ§ãå颿§ãã¹ã±ãŒã©ããªãã£ãæäŸããã»ãã¥ãªãã£ãšèšŒææžç®¡çã®åŠçã容æã«ããŸãã ã»ãã¥ãªãã£ã®å°éå®¶ã§ããPKIãœãªã¥ãŒã·ã§ã³ã«åãçµãã§ããéçºè ã§ããDockerã䜿çšããŠEJBCAãå®è¡ããããšã§ãã¯ãŒã¯ãããŒãåçåããã»ãã¥ãªãã£ãã©ã¯ãã£ã¹ã匷åã§ããŸãã
ãã®ããã°èšäºã§ã¯ãEJBCAãDockerã³ã³ãããšããŠèšå®ããããã®åºæ¬ã«ã€ããŠèª¬æããPKI管çè ãTLSèšŒææžãçºè¡ããããã«ãœãããŠã§ã¢ãæ§æããæ¹æ³ã«ã€ããŠèª¬æããŸããã EJBCA ã®ããã¥ã¡ã³ããšãã¥ãŒããªã¢ã« ãããªã§ã補åãŸãã¯ã¯ãŒã¯ããŒãã®èšŒææžã®çºè¡ã«é¢ããããé«åºŠãªæ§æãšã¬ã€ãã³ã¹ã確èªããããšããå§ãããŸãã DockerãšEJBCAã®åã«ãããèªèšŒå±ãšPKIãå¹ççãã€å®å šã«å¶åŸ¡ã§ããŸãã
ãããEJBCAãšDockerã§ããžã¿ã«äžçãä¿è·ããŸãããã ãäžæãªç¹ãããå Žåãããçµéšãå ±æãããå Žåã¯ã Keyfactorãã£ã¹ã«ãã·ã§ã³ã®ããŒãžã§ãåãåãããã ããã
ããã«è©³ãã
- Docker Hub ã® EJBCA CE ã調ã¹ãŠãã ããã
- ãªãŒãã³ã»ãœãŒã¹ã®EJBCA PKI補åããŒãžã«ã¢ã¯ã»ã¹ããŠãã ããã
- ããã«ãŒã¯åããŠã§ãã? å§ããŸãããã