ç®æ¬¡
å®çŸ©
SSTP (Secure Socket Tunneling Protocol) ã¯ãä»®æ³ãã©ã€ããŒããããã¯ãŒã¯ïŒVPNïŒæ¥ç¶ã§ãã䜿çšããããããã³ã«ã§ãããã®ãããã³ã«ã¯Microsoft瀟ã«ãã£ãŠéçºãããã®ã§ãLinuxãããWindowsç°å¢ã§ããäžè¬çã«äœ¿ãããŠããŸããWindowsã§å©çšå¯èœãªPPTPãL2TP/IPSecãªã©ã®å®å šã§ãªããªãã·ã§ã³ã眮ãæããããã«ãMicrosoftã¯ãã®æè¡ãéçºããŸãããWindowsã®ããã©ã«ãã®VPNæ¥ç¶ã¯ãã»ãšãã©ãSSTPã䜿çšããŠããŸãããVPNãããã€ããŒãšãŠãŒã¶ãŒãšç®¡çè ã®ã»ããã¢ããã®å®¹æããããã®ãããã³ã«ã決å®ä»ããŠããŸãã
ç¡æãã©ã€ã¢ã«
ç¡æãã©ã€ã¢ã«ã®ãç³ãèŸŒã¿æé
- åŒç€Ÿã®ãµã€ããŒã»ãã¥ãªã㣠ãšãã¹ããŒãã貎瀟ã«äŒºããã»ãã¥ãªãã£ç°å¢ãè©äŸ¡ããŠãè åšãªã¹ã¯ã蚺æããŸãã
- 24 æé以å ã«æå°éã®æ§æã§ã30 æ¥éãå©çšããã ãããã«ãŒããã€ã³ãã®ãœãªã¥ãŒã·ã§ã³ãå°å ¥ããŸãã
- ãã«ãŒããã€ã³ãã®ãã¯ãããžãŒãå®éã«ãäœéšããã ããŸãã
- çµç¹ãæã€ã»ãã¥ãªãã£ã®è匱æ§ã«é¢ããã¬ããŒãããæäŸããŸãããã®ã¬ããŒãã¯ããµã€ããŒã»ãã¥ãªãã£æ»æã®å¯Ÿå¿ã«çŽã¡ã«ã掻çšããã ãããšãã§ããŸãã
ãã©ãŒã ã«å¿ èŠäºé ããå ¥åã®äžããç³èŸŒã¿ãã ããã远ã£ãŠãæ åœè ãããé£çµ¡ãããŠããã ããŸãã
Proofpointã®æ åœè ããŸããªããé£çµ¡ããããŸãã
SSTPã®çšéãšä»çµã¿
VPNæ¥ç¶ã«ã¯ãã¯ã©ã€ã¢ã³ããšãµãŒããŒãå¿ èŠã§ããã¯ã©ã€ã¢ã³ããšãµãŒããŒã®äž¡æ¹ãããããã³ã«ã«ãåæãããæ¥ç¶ããµããŒãããå¿ èŠããããŸããåŸæ¥ã® PPTP (Point-to-Point Tunneling Protocol) æ¥ç¶ã§ã¯ SSL/TLS ã䜿çšãããŠããŸãããããã§ãããŒã¿è»¢éã®ã»ãã¥ãªãã£ãåäžãããç¹å®ã®ããŒãããããã¯ãããã¡ã€ã¢ãŠã©ãŒã«ã«ããå¶éãåé¿ããããã«ãSSTP ãå°å ¥ãããŸãããPPTPãšã¯ç°ãªããSSTPã¯SSL/TLSãå®å šãªéµã®æå·åéä¿¡ãããã³æå·åããã転éã䜿çšããŸãã
SSTPã¯ã»ãã¥ã¢ãªæ¥ç¶ã«äœ¿çšããããã®èåŸã«ããæè¡ã¯SSL/TLSãã³ãã·ã§ã€ã¯ãå©çšããŠããŸããSSL/TLSãšåãããŒãïŒããŒã443ïŒã䜿çšããããã€ã¹ã®ä»£ããã«ãŠãŒã¶ãŒèªèšŒã«ããæ¥ç¶ãåºæ¬ãšããŸããåºæ¬çãªSSL/TLSæ¥ç¶ãããã»ãã¥ãªãã£ãåäžãããå¿ èŠãããã€ã³ã¿ãŒãããæ¥ç¶ã§äººæ°ããããŸããæå·åã©ã€ãã©ãªã®ãŽãŒã«ãã¹ã¿ã³ããŒããšèšãããOpenVPNèŠæ Œãšæ¯èŒãããããšãå€ããããŸãã
SSTP VPNãããã³ã«ã®å®å šæ§
Windows Vistaã«SSTPæšæºãå°å ¥ãããWindows 7ã8ã10ã§ãä¿¡é Œã§ããã»ãã¥ã¢ãªãããã³ã«ãšããŠåç¶ããŠããŸããWindows OSã䜿çšããå ŽåãæšæºæèŒã®ã©ã€ãã©ãªã«ããã䟿å©ã«äœ¿çšã§ããçèŽããã®ä»ã®ãµã€ãã¢ã¿ãã¯ã«å¯ŸããŠå®å šã§ãã2æ ç¹éã®æå·åéä¿¡ã«äŸåããå€ãã®çµç¹ã§éžã°ããŠãããªãœãŒã¹ã§ãã
SSL/TLSã¯SSTPãããã³ã«ã¹ã€ãŒãã®äžéšã§ãããããŒã¿ãæå·åããããã«äœ¿çšããæå·ã©ã€ãã©ãªãšããŒãžã§ã³ãèæ ®ããå¿ èŠããããŸããSSTPã¯æšæºèŠæ ŒãšãããŠããAESæå·åã䜿çšãããããå®å šãªéžæè¢ãšèšããŸããçŸåšãæå·åŠçã«å®å šãšãããŠããAESæå·åæ¹åŒã§256ãããã®æå·åã䜿çšããŸããAES-256æå·åã¯ã¹ããŒããé ãããšããããŸãããSSTPã¯ãã³ãã«éä¿¡ãšæå·åéä¿¡ã®ããã®é«éãªãããã³ã«ãšèŠãªãããŠããŸãã
SSTP VPNãžã®æ¥ç¶æ¹æ³
VPNãµãŒãã¹ãå¥çŽããããè·å Žã«èšçœ®ããããããšãWindowsã®SSTPãå©çšã§ããå ŽåããããŸããSSTPãå©çšå¯èœãã©ããã¯ããããã€ããŒãã·ã¹ãã 管çè ã«ç¢ºèªããå¿ èŠããããŸããWindows 10ã§SSTP VPNãèšå®ããã«ã¯ã以äžã®äžè¬çãªæé ã«åŸããŸãã
- ãŸãããããã¯ãŒã¯ã®èšå®ã«ã¢ã¯ã»ã¹ããŸãã
- æ€çŽ¢ããŒã«ããããã¯ãŒã¯ãšã€ã³ã¿ãŒãããããšå ¥åããããWindowsã®ã³ã³ãããŒã«ããã«ããèšå®ãéããŠãã ããã
- ã³ã³ãããŒã«ããã«ã®ãªãã·ã§ã³ãªã¹ãã衚瀺ãããããããããã¯ãŒã¯ãšã€ã³ã¿ãŒãããããã¯ãªãã¯ããŸãã
- 以äžã®ãããªèšå®ç»é¢ã衚瀺ãããŸãã
- å·ŠåŽã®ããã«ã«ããVPNãªãã·ã§ã³ãã¯ãªãã¯ãããšããã®ãããªèšå®ç»é¢ã衚瀺ãããŸãã
- ãŠã£ã³ããŠã®äžéšã«ãããVPNæ¥ç¶ã远å ããããã¯ãªãã¯ããŸãããããšãVPNæ¥ç¶ãèšå®ããç»é¢ã衚瀺ãããŸããæ¥ç¶ã®èšå®ã¯ããµãŒãã¹ãããã€ããŒãè·å Žã®èšå®ã«ãã£ãŠç°ãªãããšã«æ³šæããŠãã ããã
- 以äžã®ãããªç»é¢ã衚瀺ãããŸãã
- ããµã€ã³ã€ã³æ å ±ãèšæ¶ãããã«ãã§ãã¯ãå ¥ããŠãããªããšãã³ã³ãã¥ãŒã¿ãŒãåèµ·åãããã³ã«VPNèšå®ããçŽãå¿ èŠããããŸãã
- ãããã®èšå®ãä¿åãããšãWindowsã®ãã¹ã¯ãããäžã«VPNãèšå®ãããæ©å¯æ§ã®é«ããµãŒããŒã«æ¥ç¶ãããã³ã«äœ¿çšã§ããããã«ãªããŸãã
å ¬å ±ã®Wi-Fiãå©çšãããšãã¯ããã€ã§ãVPNããªã³ã«ããå¿ èŠããããŸããSSL/TLSæå·åã ãã§ããæ»æè ãããªãã®æ¥ç¶ãä¹ã£åããããŒã¿ãçèŽã§ãããšããããã§ã¯ãããŸãããVPNã¯ãããªãã®ããŒã¿ãããã±ãŒãžåããããªãã®ã³ã³ãã¥ãŒã¿ãŒãããµãŒããŒãŸã§ããã³ãã«åãããããšã§ãããªãã®æ¥ç¶ã«ä¿è·ãå ããŸããããæ»æè ãããªãã®ããŒã¿ãçèŽãããšããŠãããµãŒããŒã®SSL/TLSã®ããŒãžã§ã³ãå€ããæå·åŠçã«å®å šã§ãªãã«ãããããããæå·åãããããŒã¿ãç·åœããïŒãã«ãŒããã©ãŒã¹ïŒã§è§£èªããããšã¯ã§ããªãã®ã§ãã
PPTPãšã¯ïŒSSTPãšã®éã
PPTP (Point-to-Point Tunneling Protocol) ã¯å€ããæ§åŒã®VPNãããã€ããŒã§äœ¿ãããŠããŸãããŸããããæ°ããSSTPãªãã·ã§ã³ã«ã¯ããã€ãã®å©ç¹ã𿬠ç¹ããããŸããPPTPã¯äŸç¶ãšããŠå®å šã§ãããã»ããã¢ãããç°¡åã§ããå€ããããã³ã«ãªã®ã§ãSSTPã®ãããªæ°ãããããã³ã«ãããä¿¡é Œæ§ãé«ãå®å®ããŠããŸãã
PPTPã®äž»ãªå©ç¹ã¯ãåºããµããŒããããŠããããšã§ããå¹ åºãVPNãããã€ããŒããéžæããå¿ èŠãããå ŽåãPPTPããµããŒãããŠããããã€ã¹ã§ããã°ãéžæããVPNãµãŒããŒã«åé¡ãªãæ¥ç¶ããããšãã§ããŸããå€ããããã³ã«ãªã®ã§ãPPTPã®éçºè ã¯æé©åããã®ã«ååãªæéããããå¹ççãªæ¹æ³ãèŠã€ããããšãã§ããã®ã§ãé床ã®é¢ã§ãåªããŠããã®ã§ãã
PPTPã®æã倧ããªæ¬ ç¹ã¯ãã€ã³ã¿ãŒããããµãŒãã¹ãããã€ããè·å Žã®ç®¡çè ããããã¯ã§ããããšã§ããããããWebã¢ããªã±ãŒã·ã§ã³ã§äœ¿çšãããSSL/TLSããŒãã§ãã443çªããŒããSSTPã¯äœ¿çšããŸãããã®ãããéåžžãè·å Žç°å¢ãå«ãã©ã®ãããã¯ãŒã¯ã§ããããã¯ãããããšã¯ãããŸãããSSTP VPNã¯ãã©ã®ãããªãããã¯ãŒã¯ã§ãã管çè ã«ããå¶éãå¿é ããããšãªã䜿çšããããšãã§ããŸãã
SSTPã奜ããŠãŒã¶ãŒã«ãšã£ãŠã®äž»ãªæ¬ ç¹ã¯ãMicrosoftç€ŸãææããŠãããããéææ§ãäœãããšã§ããSSTPã¯ãWindows OSã®ä»»æã®ããŒãžã§ã³ã«ç°¡åã«çµ±åãããŠããŸãããã®å©ç¹ã¯ãWindowsããã€ã¹ã«ã®ã¿æ©èœãããããLinuxãŠãŒã¶ãŒã«ã¯ãã®å©ç¹ããªããSSTPãšPPTPã®ã©ã¡ããããéžã¹ãªãã®ã§ããã°ãéåžžã¯PPTPã奜ãŸããŸãã
OpenVPNãšã¯ïŒSSTPãšã®éã
SSTPãOpenVPNãPPTPã®3ã€ã®ãããã³ã«ã®ãã¡ãOpenVPNãæãæ°ããã§ããLinuxç°å¢ã§ã¯äžè¬çãªOpenSSLã©ã€ãã©ãªã䜿çšããŠããŸããOpenSSLã¯ãã»ãã¥ãªãã£è匱æ§ãHeartbleedãã®åå ãšãªã£ããªãŒãã³ãœãŒã¹ã®ã©ã€ãã©ãªã§ããããã§ããè²¢ç®è ã«ããã³ãŒãã®æŽæ°ãšã¬ãã¥ãŒã«ãããOpenVPNãšãã®OpenSSLã©ã€ãã©ãªã¯ã仿¥ã®åžå Žã§æãå®å šãªéžæè¢ã®1ã€ã«ãªã£ãŠããŸãã
OpenVPNã¯ãå¯Ÿç§°éµæå·ã®æšæºèŠæ Œã§ããAESæå·ã䜿çšããŠããŸããä»ã®2ã€ã®ãªãã·ã§ã³ãããã¯ããã«ä¿¡é Œæ§ãé«ããã»ãšãã©ã®ãããã€ããŒããµããŒãããŠããŸãããã®ãããã³ã«ã®å¯äžã®æ¬ ç¹ã¯ãç°å¢ãèšå®ããããã«æè¡çãªçµéšãå¿ èŠãªããšã§ãããŸããSSTPãšåæ§ã«ãã¡ã€ã¢ãŠã©ãŒã«ã®å¶éãåé¿ããããšãã§ããŸãã
SSTPãšæ¯èŒããŠãOpenVPNã¯ããåºã䜿çšãããåãå ¥ããããŠããŸããããã®èšå®ã«äžæ £ããªãŠãŒã¶ãŒã«ã¯æè¡çã«é£ãããããããããŸãããSSTPã¯èšå®ãç°¡åã§ãWindowsãšç°¡åã«çµ±åã§ãããããMicrosoftç°å¢ã§ã¯OpenVPNãããSSTPãéžæãããããšãå€ãããã§ãã