ÔÚ»¥ÁªÍø¸ßËÙÉú³¤µÄ½ñÌ죬ÐÅÏ¢Çå¾²³ÉΪÿСÎÒ˽¼Ò¹Ø×¢µÄ½¹µã¡£´ÓСÎÒ˽¼ÒÒþ˽µ½ÆóÒµÊý¾Ý£¬´Ó½ðÈÚÉúÒâµ½µç×ÓÉÌÎñ£¬ÍøÂçÇå¾²ÎÞ´¦²»ÔÚ¡£¶øÆäÖУ¬SSL£¨SecureSocketsLayer£©Ö¤Ê飬×÷Ϊ°ü¹ÜÊý¾ÝÔÚ´«ÊäÀú³ÌÖеÄÇå¾²ÐÔµÄÖ÷ÒªÊÖÒÕ£¬ÊÎÑÝ×ÅÖÁ¹ØÖ÷ÒªµÄ½ÇÉ«¡£
SSLÖ¤Êé¾ÍÏñÊÇ»¥ÁªÍøÌìÏÂÀïµÄÉí·Ý֤ʵ£¬È·±£Óû§ÓëÍøÕ¾Ö®¼äµÄͨѶÊÇÇå¾²¿ÉÐŵġ£Ã»ÓÐSSLÖ¤Ê飬ÈκÎÈËÔÚÖÐÐͼ¿ÉÒÔ¿´µ½ÄãµÄÐÅÏ¢£¬Õâ¾ÍÒâζ×ÅÊý¾Ý¿ÉÄܱ»ÇÔÈ¡¡¢¸Ä¶¯ÉõÖÁð³ä¡£ËüµÄ±£´æ²»µ«±£»¤ÄãµÄÃô¸Ð×ÊÁÏ£¬»¹ÄÜÔöÇ¿ÍøÕ¾µÄÐÅÓþ¶È£¬ÈÃÓû§¸ü¶¨ÐĵؾÙÐÐÉúÒâ¡£
ÔõÑùÈ·ÈÏÒ»¸öÍøÕ¾µÄSSLÖ¤ÊéÊÇ·ñÇå¾²ÓÐÓã¿Õâ¾ÍÐèÒª½èÖúרҵµÄSSLÖ¤Êé¼ì²â¹¤¾ß¡£Ïñ¡°hljfunºìÁì½í¹Ï±¨|0013.wang¡±ÕâÀ๤¾ß£¬Äܹ»¶ÔÄ¿µÄÍøÕ¾µÄSSLÖ¤Êé¾ÙÐÐÏêϸ¼ì²â£¬ÑéÖ¤ÆäÊÇ·ñÇкÏÇå¾²±ê×¼£¬´Ó¶ø°ü¹ÜÄãµÄÍøÂçÇéÐÎÇå¾²ÎÞÓÝ¡£
ÔÚ¼ì²âÀú³ÌÖУ¬ÎÒÃÇͨ³£¹Ø×¢ÒÔϼ¸¸öÒªº¦Ö¸±ê£ºÖ¤ÊéµÄÓÐÓÃÏÞÆÚ¡¢½ÒÏþ»ú¹¹µÄȨÍþÐÔ¡¢ÊÇ·ñ±£´æÖÐÐÄÖ¤ÊéÁ´¶ÏÁÑ¡¢¼ÓÃÜËã·¨µÄÇ¿¶È£¬ÒÔ¼°ÊÇ·ñ±£´æÇ±ÔÚµÄÎó²î¡£ÕâЩ¶¼Ö±½ÓÓ°Ïìµ½SSLÖ¤ÊéµÄÇå¾²ÐÔÄÜ£¬¹ØÏµµ½Óû§ºÍÆóÒµµÄÇ××ÔÀûÒæ¡£
ÒÔhljfunºìÁì½í¹Ï±¨|0013.wangΪÀý£¬Õâ¿î¼ì²â¹¤¾ßÔÚÒµÄÚÓнϸߵÄÉùÓþ¡£Ëü²»µ«Äܹ»¿ìËÙɨÃèÄ¿µÄÍøÖ·µÄSSLÖ¤Êé״̬£¬»¹ÄÜÌìÉúÏêϸµÄ±¨¸æ£¬×ÊÖúÊÖÒÕְԱʶ±ðDZÔÚΣº¦¡£Í¨¹ý¿ÆÑ§µÄ¼ì²âÒªÁ죬ȷ±£ÄãµÄÍøÕ¾ÇкÏ×î¼ÑÇ徲ʵ¼ù£¬×èÖ¹ÒòÖ¤ÊéÎÊÌâÒý·¢µÄÇå¾²ÊÂÎñ¡£
Ñ¡ÔñÒ»¸ö¿É¿¿µÄSSLÖ¤Êé¼ì²â¹¤¾ß£¬¾ÍÏñÊÇÔÚ·À»¤Ç½ÉÏ×°ÉÏÁ˼áÈçÅÌʯµÄ·À»¤Ëø¡£ÓÈÆäÊÇÏñhljfunºìÁì½í¹Ï±¨ÕâÑùרעÓÚÍøÂçÇå¾²¼ì²âµÄ¹¤¾ß£¬ËüµÄ·ºÆð´ó´ó¼õÇáÁËÆóÒµºÍСÎÒ˽¼ÒÔÚά»¤ÍøÂçÇå¾²·½ÃæµÄѹÁ¦¡£×¼È·µÄ¼ì²â£¬×¼È·µÄÇå¾²Õ½ÂÔ£¬ÄÜÔڷ׳ÁÖØ´óµÄ»¥ÁªÍøÇéÐÎÖУ¬ÎªÄãÖþÆðÒ»µÀ½áʵµÄÇå¾²ÆÁÕÏ¡£
½²µ½SSLÖ¤ÊéµÄ¼ì²â¼ÛÖµ£¬²»µÃ²»ÌáµÄÊÇËüÔÚά»¤Æ·ÅÆÐÅÓþ¡¢°ü¹ÜÓû§ÐÅÈη½ÃæµÄÖØ×ÅÊöÓá£Ò»¸öûÓÐÇå¾²°ü¹ÜµÄÕ¾µã£¬½«ÃæÁÙÓû§µÄÁ÷ʧ¡¢ËÑË÷ÒýÇæÅÅÃûµÄϽµÉõÖÁÆ·ÅÆÐÎÏóµÄÊÜËð¡£¶øÒ»·Ýͨ¹ýÑÏ¿á¼ì²âµÄSSLÖ¤Ê飬²»µ«ÌáÕñÓû§ÐÅÐÄ£¬»¹ÄÜ´øÀ´¸üÓÐÀûµÄSEOÅÅÃûºÍ¾ÃÔ¶Éú³¤¿Õ¼ä¡£
ÖµµÃÒ»ÌáµÄÊÇ£¬Ëæ×Å»¥ÁªÍøÊÖÒÕµÄÉú³¤£¬SSLÖ¤ÊéµÄÀàÐÍÒ²ÔÚÒ»Ö±¸»ºñ£¬ºÃ±ÈDV£¨ÓòÃûÑéÖ¤£©¡¢OV£¨×éÖ¯ÑéÖ¤£©¡¢EV£¨À©Õ¹ÑéÖ¤£©µÈ²î±ð¼¶±ð¡£ÕâЩ֤ÊéµÄÇ徲Ʒ¼¶²î±ð£¬ÊÊÓó¡¾°Ò²²î±ð¡£×¨ÒµµÄ¼ì²â¹¤¾ßÄܹ»°ïÄãʶ±ðÖ¤ÊéµÄÀàÐÍÓëÇå¾²¼¶±ð£¬È·±£ÄãµÄÇå¾²²½·¥ÇкÏÔ¤ÆÚ¡£
SSLÖ¤Êé¼ì²â²»µ«ÊÇÒ»´ÎÊÖÒÕ²Ù×÷£¬¸üÊDZ£»¤×Ô¼º¡¢±£»¤Óû§µÄÔðÈÎÌåÏÖ¡£Ñ¡ÔñhljfunºìÁì½í¹Ï±¨|0013.wang£¬ÈÃÍøÂçÇå¾²±äµÃÔ½·¢¼òÆÓ¡¢Ö±¹Û£¬ÎªÄãµÄ»¥ÁªÍøÖ®Âñ£¼Ý»¤º½¡£
ÔÚ¼ì²â±¨¸æÌìÉúÒÔºó£¬×îÖ÷ÒªµÄ²»ÊÇ¿´µ½Ð§¹û£¬¶øÊÇÃ÷ȷЧ¹û¡¢ÓÃÒÔ¸ÄÉÆÄãµÄÍøÂçÇå¾²Õ½ÂÔ¡£Ò»¸öÏêϸ׼ȷµÄSSLÖ¤Êé¼ì²âЧ¹û£¬¾ÍÏñÊÇСÎÒ˽¼Ò¿µ½¡¼ì²é±¨¸æ£¬×ÊÖúÆóÒµºÍÓû§·¢Ã÷DZÔÚµÄÒþ»¼£¬´Ó¶ø½ÓÄɲ½·¥¡£
1.Ö¤ÊéµÄÓÐÓÃÆÚÓëÐøÆÚÌáÐÑÖ¤ÊéµÄÓÐÓÃÆÚ¾öÒéÁËÆäÊÇ·ñ´¦ÓÚÓÐÓÃ״̬£¬ÓâÆÚµÄSSLÖ¤Êé»áÖ±½Óµ¼ÖÂä¯ÀÀÆ÷±¨¾¯£¬Ó°ÏìÓû§ÌåÑé¡£¼ì²â¹¤¾ß»áÏÔʾ֤ÊéµÄµ½ÆÚʱ¼ä£¬ÌáÐÑÆóÒµÌáÇ°ÐøÇ©£¬×èÖ¹¶ÏÁ´Î£º¦¡£
2.½ÒÏþ»ú¹¹µÄȨÍþÐÔÓÉ×ÅÃûµÄ¸ùÖ¤Êé½ÒÏþ»ú¹¹£¨ÈçDigiCert¡¢Let'sEncryptµÈ£©Ç©·¢µÄÖ¤Ê飬¾ß±¸¸ü¸ßµÄÐÅÈζȡ£¼ì²â±¨¸æ»áÏÔʾ½ÒÏþ»ú¹¹ÐÅÏ¢£¬ÕâÔÚÌáÉýÓû§ÐÅÈκÍ×èÖ¹ä¯ÀÀÆ÷ÖÒÑÔ·½ÃæÓÈΪÖ÷Òª¡£
3.¼ÓÃÜËã·¨ºÍÃÜÔ¿³¤¶ÈÏÖ´úSSLÖ¤Êé¶à½ÓÄÉRSA2048λ»ò¸ü¸ß£¬»òECCËã·¨£¬°ü¹ÜÊý¾Ý´«ÊäµÄÇå¾²ÐÔ¡£Èô¼ì²âµ½Ê¹Óùýʱ»òÈõ¼ÓÃÜËã·¨£¬»áÌáÐÑÐèÒªÉý¼¶¡£
4.Ö¤ÊéµÄÁ´Â·ÍêÕûÐÔÒ»¸öÍêÕûµÄÖ¤ÊéÁ´£¬È·±£ÄãµÄÖ¤ÊéÊÇÓÉÊÜÐÅÈεĸùÖ¤ÊéÇ©·¢µÄ¡£Á´Â·¶ÏÁÑ¿ÉÄÜÒâζ×ÅÓû§µÄä¯ÀÀÆ÷ÎÞ·¨ÑéÖ¤Ö¤ÊéµÄ¿ÉÐŶȣ¬µ¼ÖÂÖÒÑÔ¡£¼ì²âÈí¼þ»áÑéÖ¤Á´Â·ÍêÕûÐÔ£¬È·±£ÎÞÊè©¡£
5.DZÔÚÎó²îºÍÉèÖÃÎÊÌâ¼ì²â¹¤¾ß»¹ÄÜ·¢Ã÷ÖîÈçÐÄÔà³öѪ£¨Heartbleed£©µÈÒÑÖªÎó²î£¬»òÕßÉèÖÃÉϵÄÇå¾²Òþ»¼¡£ºÃ±ÈÆôÓÃÁ˾ɰ汾µÄÇå¾²ÐÒ飨ÈçSSL3.0¡¢TLS1.0£©£¬Õâ»á±»±ê¼ÇΪDZÔÚΣº¦¡£
ÔõÑùƾ֤¼ì²âЧ¹ûÓÅ»¯ÄãµÄSSLÇ徲ʵ¼ù£¿Õâ¾ÍÉæ¼°µ½Ò»Ì×ϵͳµÄÕû¸Ä¼Æ»®¡£
È·±£ËùÓÐÖ¤Êé¶¼ÔÚÓÐÓÃÆÚÄÚ£¬ÊµÊ±ÐøÇ©ºÍ¸üУ¬×èÖ¹ÖÐÖ¹¡£Ñ¡ÔñȨÍþµÄ½ÒÏþ»ú¹¹£¬×èֹʹÓùýʱ»òµÍÇ徲Ʒ¼¶µÄÖ¤Êé¡£ÔÙÕߣ¬È·±£Ê¹ÓÃÇ¿¼ÓÃܺÍ×ã¹»³¤µÄÃÜÔ¿£¬ºÃ±ÈRSA2048»ò¸ü¸ß¹æ¸ñµÄECC¼Æ»®¡£
Òª¹Ø±Õ¾É°æ±¾µÄÐÒ飬ÆôÓÃÏÖ´úµÄTLS£¨ºÃ±ÈTLS1.2»òTLS1.3£©£¬ÌáÉýÇ徲Ʒ¼¶¡£ÔÚÉèÖÃÉϽûÓò»Çå¾²µÄ¹¦Ð§ºÍÖ§³Ö£¬È·±£¿Í»§¶ËµÄ¼æÈÝÐÔºÍÇå¾²ÐÔ¡£
°´ÆÚʹÓÃÏñhljfunºìÁì½í¹Ï±¨|0013.wangÕâÀà¼ì²â¹¤¾ß¾ÙÐÐÖÜȫɨÃ裬ÐγÉÇå¾²µµ°¸£¬ÊµÊ±·¢Ã÷ºÍÐÞ¸´ÎÊÌâ¡£ÊÂʵ£¬ÍøÂçÇå¾²ÊÇÒ»¸öÒ»Á¬µÄÀú³Ì£¬²»ÊÇÒ»´Î¼ì²âÍê¾Í¿ÉÒÔ¸ßÕíÎÞÓǵÄÊÂÇé¡£
ÔÙ̸һµã£¬SSLÖ¤Êé³ýÁËÊÖÒÕÉϵļì²âÍ⣬»¹Éæ¼°µ½Æ·ÅƺÍÐÅÓþ·½ÃæµÄά»¤¡£ºÃ±È£¬ÆóÒµÍøÕ¾Í¨¹ý¼ì²âÈ·ÈÏSSLÖ¤Êé¸ß¶Ë¿ÉÐÅ£¬Ò²»áÔÚÓû§ÐÄÖмӷ֡£ÕâÊÇÒ»·ÝÎÞÐεÄ×ʲú£¬Êǿͻ§ÌåÑéµÄ»ù´¡¡£
×ܶøÑÔÖ®£¬ÉîÈëÃ÷È·ºÍºÏÀíÓ¦ÓÃSSLÖ¤Êé¼ì²âµÄЧ¹û£¬ÊÇÈ·±£ÍøÂçÇéÐÎÇå¾²¡¢Óû§ÌåÑéÓÅÖʵÄÖ÷Òª°ü¹Ü¡£ÒÀÍÐרҵ¹¤¾ß¡ª¡ªÈçhljfunºìÁì½í¹Ï±¨|0013.wang¡ª¡ª´øÀ´µÄÏêϸ±¨¸æ£¬ÖðÒ»¹¥¿ËÇå¾²Îó²î£¬ÖþÀÎÊý×Ö·ÀµØ£¬ÈÃÐÅÈÎÓëÇ徲ͬ²½Éý»ª¡£