RAS Secure Gateway ãæ§æããŠãSSL æå·åã䜿çšããã«ã¯ãçºçããå¯èœæ§ã®ãããã©ãããã»ãã¥ãªãã£ã®åé¡ãåé¿ããããã« SSL ãµãŒããŒã®æ§ææ¹æ³ã«æ³šæããå¿ èŠããããŸããå ·äœçã«ã¯ã次㮠SSL ã³ã³ããŒãã³ããã¬ãŒãã£ã³ã°ããæ§æãé©åã§ãããã©ãããç¹å®ããå¿ èŠããããŸãã
æå¹ã§ä¿¡é Œã§ããèšŒææžã
ãããã³ã«ãéµã®äº€æãæå·ããµããŒããããŠããå¿ èŠããããŸãã
SSL ã«ã€ããŠç¹å®ã®ç¥èããªãå Žåãæ»å®ãè¡ãã®ã¯å°é£ãããããŸãããQualys SSL Labs ã® SSL Server Test ã®äœ¿çšããå§ãããã®ã¯ãã®ããã§ããããã¯ãå ¬è¡ã€ã³ã¿ãŒãããã§ SSL ãŠã§ããµãŒããŒã®æ§æã®åæãå®è¡ããç¡æã®ãªã³ã©ã€ã³ãµãŒãã¹ã§ããRAS Secure Gateway ã§ãã¹ããå®è¡ããã«ã¯ãå ¬è¡ã€ã³ã¿ãŒãããã«ãããäžæçã«ç§»åããå¿ èŠãçããå ŽåããããŸãã
ãã¹ãã¯æ¬¡ã® URL ã§å®è¡ã§ããŸããhttps://www.ssllabs.com/ssltest/
次㮠URL ã§ãæ»å®ã«äœ¿çšãããã¡ãœããã«ã€ããŠèª¬æããŠãã Qualys SSL Labs ã®è³æãåç §ã§ããŸããhttps://github.com/ssllabs/research/wiki/SSL-Server-Rating-Guide
Parallels RAS ãŠãŒã¶ãŒãš RAS Secure Gateway éã®ãã©ãã£ãã¯ã¯æå·åã§ããŸãã[SSL/TLS] ã¿ãã§ã¯ãããŒã¿æå·åãªãã·ã§ã³ãæ§æã§ããŸãã
ãµã€ãã®ããã©ã«ãå€ã䜿çš
ãµã€ãã®ããã©ã«ãèšå®ã䜿çšããã«ã¯ã[ããã©ã«ãèšå®ãç¶æ¿] ãªãã·ã§ã³ãã¯ãªãã¯ããŸããåºæã®èšå®ãæå®ããã«ã¯ããªãã·ã§ã³ãã¯ãªã¢ããŸãã詳现ã«ã€ããŠã¯ãããµã€ãã®ããã©ã«ãå€ïŒã²ãŒããŠã§ã€ïŒããåç §ããŠãã ããã
HSTS ãé©çš
HSTS ã»ã¯ã·ã§ã³ã® [æ§æ] ãã¿ã³ã«ãã£ãŠãHTTP Strict Transport SecurityïŒHSTSïŒãé©çšã§ããŸããããã¯ãå®å šãª HTTPS æ¥ç¶ã®ã¿ã䜿çšããŠãŠã§ããã©ãŠã¶ãŒã«ãŠã§ããµãŒããŒãšéä¿¡ãããã¡ã«ããºã ã§ããHSTS ã RAS Secure Gateway ã«é©çšããããšããã¹ãŠã®ãŠã§ããªã¯ãšã¹ãã HTTPS ã䜿çšããããã«åŒ·å¶ãããŸããããã¯ç¹ã« RAS ãŠãŒã¶ãŒããŒã¿ã«ã«åœ±é¿ããã»ãã¥ãªãã£äžã®çç±ããé垞㯠HTTPS ãªã¯ãšã¹ãã®ã¿ãåãä»ããŸãã
[æ§æ] ãã¿ã³ãã¯ãªãã¯ãããšã[HSTS èšå®] ãã€ã¢ãã°ãéããŸãããã®ãã€ã¢ãã°ã§ã¯ã次ã®å 容ãæå®ã§ããŸãã
HTTP Strict Transport SecurityïŒHSTSïŒãé©çšãã: Secure Gateway ã«å¯ŸããHSTS ãæå¹åãŸãã¯ç¡å¹åããŸãã
æå€§æé: HSTS ã®æå€§æéãæå®ããŸããããã¯ããŠã§ããã©ãŠã¶ãŒãš Secure Gateway ãšã®éä¿¡ã«å¿ ã HTTPS ã䜿çšããããšããèšå®ãé©çšãããïŒæåäœã®ïŒæéã§ããããã©ã«ãå€ïŒããã³æšå¥šå€ïŒã¯ 12 ãæã§ããèšå®å¯èœãªå€ã¯ 4ã120 ãæã§ãã
ãµããã¡ã€ã³ãå«ã: ãµããã¡ã€ã³ãå«ãããã©ãããæå®ããŸãïŒãµããã¡ã€ã³ãããå ŽåïŒã
äºåèªã¿èŸŒã¿: HSTS ã®äºåèªã¿èŸŒã¿ãæå¹åãŸãã¯ç¡å¹åããŸããããã¯ãSSL/TLS ããµã€ãã§é©çšãããã¹ãã®ãªã¹ãããŠã§ããã©ãŠã¶ãŒã«ããŒãã³ãŒãã£ã³ã°ãããã¡ã«ããºã ã§ãããªã¹ã㯠Google ã«ããã³ã³ãã€ã«ãããChromeãFirefoxãSafariãInternet Explorer 11ãEdge ãšãã£ããã©ãŠã¶ãŒã«ãã䜿çšãããŸããHSTS ã®ããªããŒãã䜿çšããããšããŠã§ããã©ãŠã¶ãŒã¯ HTTP ã䜿çšããŠãªã¯ãšã¹ããéä¿¡ãããåžžã« HTTPS ã䜿çšãããŸãã以äžã«éèŠãªæ³šæç¹ããããŸãã®ã§ãã¡ãããèªã¿ãã ããã
泚: HSTS ã®ããªããŒãã䜿çšããã«ã¯ãChrome ã® HSTS ããªããŒããªã¹ãã«å«ãããã¡ã€ã³åãéä¿¡ããå¿ èŠããããŸãããã¡ã€ã³ã¯ãªã¹ãã䜿çšãããŠã§ããã©ãŠã¶ãŒã«ããŒãã³ãŒããããŸããéèŠ: ããªããŒããªã¹ããžå«ããã¢ã¯ã·ã§ã³ã¯ç°¡åã«ã¯åãæ¶ããŸããããµã€ãå šäœããã³ãã®ãã¹ãŠã®ãµããã¡ã€ã³ã§é·æçã«ïŒéåžž 1ã2 幎ïŒHTTPS ããµããŒãã§ããããšã確å®ãªå Žåã«ã®ã¿ããªã¯ãšã¹ããå«ããŠãã ããã
次ã®èŠä»¶ã«ã泚æããŠãã ããã
ãŠã§ããµã€ãã«æå¹ãª SSL èšŒææžãååšããŠããå¿ èŠããããŸãããSSL ãµãŒããŒæ§æããåç §ããŠãã ããã
ãã¹ãŠã®ãµããã¡ã€ã³ïŒãµããã¡ã€ã³ãããå ŽåïŒã SSL èšŒææžã§ã«ããŒãããŠããå¿ èŠããããŸããã¯ã€ã«ãã«ãŒãèšŒææžãèŠæ±ããããšãæ€èšããŠãã ããã
SSL ã®æ§æ
ããã©ã«ãã§ã¯ãã²ãŒããŠã§ã€ã®ã€ã³ã¹ããŒã«æã«ãèªå·±çœ²åèšŒææžã RAS Secure Gateway ã«å²ãåœãŠãããŸããRAS Secure Gateway ããšã«å°çšã®èšŒææžã®å²ãåœãŠãå¿ èŠã§ãããŸããã»ãã¥ãªãã£èŠåãåé¿ãããããã¯ã©ã€ã¢ã³ãåŽã®ä¿¡é Œã§ããã«ãŒãèªèšŒå±ã«è¿œå ããå¿ èŠããããŸãã
SSL èšŒææžã¯ãRAS Console ã® [ãã¡ãŒã ] > [ãµã€ã] > [èšŒææž] ãµãã«ããŽãªãŒã䜿çšããŠäœæã§ããŸããäœæãããèšŒææžã¯ãRAS Secure Gateway ã«å²ãåœãŠãããšãã§ããŸããèšŒææžã®äœæãšç®¡çã«ã€ããŠã¯ããSSL èšŒææžã®ç®¡çãã®ç« ãåç §ããŠãã ããã
Secure Gateway ã« SSL ãæ§æããæ¹æ³:
[SSL æå¹å] ãªãã·ã§ã³ãéžæããããŒãçªå·ãæå®ããŸãïŒããã©ã«ã㯠443ïŒã
[èš±å¯ããã SSL ããŒãžã§ã³] ããããããŠã³ãªã¹ãã§ãRAS Secure Gateway ãåãä»ãããã SSL ããŒãžã§ã³ãéžæããŸãã
[æå·åŒ·åºŠ] ãã£ãŒã«ãã§ãåžæããæå·åŒ·åºŠãéžæããŸãã
[æå·] ãã£ãŒã«ãã«æå·ãæå®ããŸãã匷ãæå·ã䜿çšããã°ãæå·åã®åŒ·åºŠãå¢ããç Žãã®ã«å¿ èŠãªåŽåãå¢å€§ããŸã
[ãµãŒããŒç°å¢ã«å¿ããŠæå·ã䜿çš] ãªãã·ã§ã³ã¯ãããã©ã«ãã§æå¹ã«ãªã£ãŠããŸãããã®ãªãã·ã§ã³ãç¡å¹ã«ããããšã§ãã¯ã©ã€ã¢ã³ãã®ç°å¢èšå®ã䜿çšããããšãã§ããŸãã
[èšŒææž] ããããããŠã³ãªã¹ãã§ä»»æã®èšŒææžãéžæããŸããæ°èŠèšŒææžã®äœææ¹æ³ãšãªã¹ããžã®è¡šç€ºæ¹æ³ã«ã€ããŠã¯ããSSL èšŒææžã®ç®¡çããåç §ããŠãã ããã
[äžèŽããäœ¿çšæ¹æ³ãã¹ãŠ] ãªãã·ã§ã³ã§ã¯ãæ§æããããã¹ãŠã®èšŒææžã Secure Gateway ã«ãã£ãŠäœ¿çšãããŸããèšŒææžãäœæããå Žåãâã²ãŒããŠã§ã€âãâHALBâãŸãã¯ãã®äž¡æ¹ãéžæã§ããå Žæã§â䜿çšâããããã£ãæå®ããŸãããã®ããããã£ã§ [ã²ãŒããŠã§ã€] ãªãã·ã§ã³ãéžæãããŠããã°ãSecure Gateway ã«äœ¿çšã§ããŸãããã®ãªãã·ã§ã³ãéžæããŠããŠããäžèŽããèšŒææžãååšããªãå Žåã«ã¯ãèŠåã衚瀺ãããå ã«èšŒææžãäœæããããšã«ãªããŸãã
Parallels Client ã®æ¥ç¶ã®æå·å
ããã©ã«ãã§ãæå·åãããæ¥ç¶ã®ã¿ã€ãã¯ãSecure Gateway ãšããã¯ãšã³ããµãŒããŒã®éã®æ¥ç¶ã ãã§ããParallels Client ãš Secure Gateway ã®éã®æ¥ç¶ãæå·åããã«ã¯ãã¯ã©ã€ã¢ã³ãåŽã§ãæ¥ç¶ããããã£ãæ§æããå¿ èŠããããŸãããããè¡ãã«ã¯ãParallels Client ã§ãæ¥ç¶ããããã£ãéããæ¥ç¶ã¢ãŒãã [ã²ãŒããŠã§ã€ SSL] ã«èšå®ããŸãã
Parallels Client ã®æ§æãç°¡çŽ åããããã«ãåºãå©çšãããŠãããµãŒãããŒãã£ã®ä¿¡é Œã§ããèªèšŒå±ã«ãã£ãŠçºè¡ãããèšŒææžã䜿çšããããšããå§ãããŸãããªããRAS ãŠãŒã¶ãŒããŒã¿ã«ã«æ¥ç¶ããéã¯ãäžéšã®ãŠã§ããã©ãŠã¶ãŒïŒChromeãEdge ãªã©ïŒã§ Windows èšŒææžã¹ãã¢ã䜿çšãããŸãã
Parallels Client ã®æ§æ
èšŒææžãèªå·±çœ²åãããŠããå ŽåããŸãã¯ãšã³ã¿ãŒãã©ã€ãº CA ã«ãã£ãŠçºè¡ãããèšŒææžã®å ŽåãParallels Client ã¯ä»¥äžã®ããã«æ§æããå¿ èŠããããŸãã
Base-64 ã§ãšã³ã³ãŒãããã X.509ïŒ.CERïŒåœ¢åŒã§èšŒææžããšã¯ã¹ããŒãããŸãã
ã¡ã¢åž³ãã¯ãŒãããããªã©ã®ããã¹ããšãã£ã¿ãŒã§ãšã¯ã¹ããŒãããèšŒææžãéããå 容ãã¯ãªããããŒãã«ã³ããŒããŸãã
ã¯ã©ã€ã¢ã³ãåŽã§ä¿¡é Œã§ããèªèšŒå±ã®ãªã¹ããå«ãèšŒææžã远å ããParallels Client ãçµç¹ã®èªèšŒå±ããçºè¡ãããèšŒææžãš SSL ã§æ¥ç¶ã§ããããã«ããã«ã¯ïœ€æ¬¡ã®æäœãå®è¡ããŸãã
ã¯ã©ã€ã¢ã³ãåŽã®ãã£ã¬ã¯ããªâC:\Program Files\Parallels\Remote Application Server Client\âã«ãtrusted.pem ãšãããã¡ã€ã«ãååšããŠããå¿
èŠããããŸãããã®ãã¡ã€ã«ã«ã¯ãå
±éã®ä¿¡é Œã§ããèªèšŒå±ã®èšŒææžãå«ãŸããŠããŸãã
ãšã¯ã¹ããŒããããèšŒææžã®å 容ã貌ãä»ããŸãïŒä»ã®èšŒææžã®ãªã¹ãã«æ·»ä»ãããŠããŸãïŒã
RDP-UDP æ¥ç¶ã®ä¿è·
éåžžãParallels Client 㯠RAS Secure Gateway ãš TCP æ¥ç¶çµç±ã§éä¿¡ããŸããæè¿ã® Windows ã¯ã©ã€ã¢ã³ãã§ããUDP æ¥ç¶ã䜿çšã㊠WAN ã®ããã©ãŒãã³ã¹ãåäžããããšãã§ããŸããUDP æ¥ç¶ã SSL ã§ä¿è·ããã«ã¯ãDTLS ã䜿çšããå¿ èŠããããŸãã
RAS Secure Gateway ã§ DTLS ã䜿çšããã«ã¯ãæ¬¡ã®æäœãå®è¡ããŸãã
[SSL/TLS] ã¿ãã§ã[ããŒãã§ SSL æå¹å] ãªãã·ã§ã³ãéžæãããŠããããšã確èªããŸãã
[ãããã¯ãŒã¯] ã¿ãã§ã[RDP UDP ããŒã¿ãã³ããªã³ã°ãæå¹å] ãªãã·ã§ã³ãéžæãããŠããããšã確èªããŸãã
Parallels Client ã¯ã[ã²ãŒããŠã§ã€ SSL ã¢ãŒã] ã䜿çšããããæ§æããå¿ èŠããããŸãããã®ãªãã·ã§ã³ã¯ãã¯ã©ã€ã¢ã³ãåŽã® [æ¥ç¶èšå®] > [æ¥ç¶ã¢ãŒã] ããããããŠã³ãªã¹ãã§èšå®ã§ããŸãã
äžèšãªãã·ã§ã³ãé©åã«èšå®ããããšãTCP ããã³ UDP æ¥ç¶ã SSL äžã§ãã³ããªã³ã°ãããŸãã