ã€ãŸããMTA-STSã¯ãã¡ãŒã«ãã¡ãŒã«ãµãŒããŒéã§è»¢éããããšãã«ãã¡ãŒã«ãååïŒã€ãŸããMitMãšããŠãç¥ãããäžéæ»æïŒããããã«ä¿è·ããæ¹æ³ã§ããããã¯ãé»åã¡ãŒã«ãããã³ã«ã®ç¶æ¿ãããã¢ãŒããã¯ãã£äžã®åé¡ãéšåçã«è§£æ±ºããæ¯èŒçæè¿ã®RFC 8461æšæºã§èª¬æãããŠããŸããMail.ruMailã¯ããã®æšæºãå®è£ ãããã·ã¢ã®ã€ã³ã¿ãŒãããã§æåã®äž»èŠãªéµäŸ¿ãµãŒãã¹ã§ãããããŠããã詳现ã«ã¯ãããã¯ãã§ã«ã«ããã®äžã«ãããŸãã
MTA-STSã¯ã©ã®ãããªåé¡ã解決ããŸããïŒ
ãããŸã§ãé»åã¡ãŒã«ãããã³ã«ïŒSMTPãPOP3ãIMAPïŒã¯æ å ±ãå¹³æã§éä¿¡ããŠãããããããšãã°éä¿¡ãã£ãã«ã«ã¢ã¯ã»ã¹ãããšãã«æ å ±ãååããããšãã§ããŸããã
ãããŠãŒã¶ãŒããå¥ã®ãŠãŒã¶ãŒã«ã¬ã¿ãŒãé ä¿¡ããã¡ã«ããºã ã¯æ¬¡ã®ããã«ãªããŸãããã
ãŸã§ãMitMæ»æã¯ãã¡ãŒã«ãéä¿¡ããããã¹ãŠã®å Žæã§å¯èœã§ããã
RFC 8314ã§ã¯ããŠãŒã¶ãŒã®ã¡ãŒã«ããã°ã©ã ïŒMUAïŒãšã¡ãŒã«ãµãŒããŒéã§TLSã匷å¶çã«äœ¿çšããå¿ èŠããããŸãããµãŒããŒãšäœ¿çšããã¡ãŒã«ã¢ããªã±ãŒã·ã§ã³ãRFC8314ã«æºæ ããŠããå Žåã¯ããŠãŒã¶ãŒãšã¡ãŒã«ãµãŒããŒéã®Man-in-the-Middleæ»æã®å¯èœæ§ãïŒå€§å¹ ã«ïŒæé€ã§ããŸãã
äžè¬çãªæ £è¡ïŒRFC 8314ã§æšæºåïŒãé å®ããããšã§ããŠãŒã¶ãŒã«è¿ãæ»æãæé€ããŸãã
Mail.ruã¡ãŒã«ãµãŒããŒã¯ãæšæºãæ¡çšãããåããRFC 8314ã«æºæ ããŠããŸãããå®éãããã¯ãã§ã«åãå ¥ããããŠãããã©ââã¯ãã£ã¹ããã£ããã£ããã ãã§ããããã以äžäœãæ§æããå¿ èŠã¯ãããŸããã§ããããã ããã¡ãŒã«ãµãŒããŒã§å®å šã§ãªããããã³ã«ãä»ããŠãŠãŒã¶ãŒãèš±å¯ããå Žåã¯ãå¿ ããã®æšæºã®æšå¥šäºé ãå®è£ ããŠãã ãããã»ãšãã©ã®å ŽåããµããŒãããŠããå Žåã§ããå°ãªããšãäžéšã®ãŠãŒã¶ãŒã¯æå·åãªãã§ã¡ãŒã«ãæäœããŸãã
ã¡ãŒã«ã¯ã©ã€ã¢ã³ãã¯ãåžžã«åãçµç¹ã®åãã¡ãŒã«ãµãŒããŒã§åäœããŸãããŸãããã¹ãŠã®ãŠãŒã¶ãŒã«å®å šãªæ¹æ³ã§æ¥ç¶ããããã«åŒ·å¶ããå®å šã§ãªãæ¥ç¶ãæè¡çã«äžå¯èœã«ããããšãã§ããŸãïŒããã¯ãŸãã«RFC 8314ãèŠæ±ãããã®ã§ãïŒãããã¯æã é£ããã§ãããå®çŸå¯èœã§ããã¡ãŒã«ãµãŒããŒéã®ãã©ãã£ãã¯ã¯ããã«è€éã§ãããµãŒããŒã¯ããŸããŸãªçµç¹ã«å±ããŠããããã»ããã¢ã³ããã©ãŒã²ãããã¢ãŒãã§äœ¿çšãããããšããããããŸããããã«ãããæ¥ç¶ãåæããã«äžåºŠã«å®å šãªãããã³ã«ã«åãæ¿ããããšã¯ã§ããŸããã SMTPã¯é·ãéSTARTTLSæ¡åŒµæ©èœãæäŸããŠããŸãããããã«ãããæå·åããµããŒããããµãŒããŒãTLSã«åãæ¿ããããšãã§ããŸãããããããã©ãã£ãã¯ã«åœ±é¿ãäžããèœåãæã€æ»æè ãã®ã³ãã³ãã®ãµããŒãã«é¢ããæ å ±ããã«ããããããµãŒããŒã«ãã¬ãŒã³ããã¹ããããã³ã«ã䜿çšããŠéä¿¡ãããããšãã§ããŸãïŒããããããŠã³ã°ã¬ãŒãæ»æ-ãããã³ã«ããŒãžã§ã³ãããŠã³ã°ã¬ãŒãããæ»æïŒãåãçç±ã§ãSTARTTLSã®å ŽåãèšŒææžã®ã³ã³ãã©ã€ã¢ã³ã¹ã¯éåžžãã§ãã¯ãããŸããïŒä¿¡é Œã§ããªãèšŒææžã¯ååçãªæ»æããä¿è·ã§ããŸããããã¯ãã¯ãªã¢ããã¹ãã§é»åã¡ãŒã«ãéä¿¡ãããããæªãããšã§ã¯ãããŸããïŒããããã£ãŠãSTARTTLSã¯ååçãªçèŽããã®ã¿ä¿è·ããŸãã
MTA-STSã¯ãæ»æè ããã©ãã£ãã¯ã«ç©æ¥µçã«åœ±é¿ãäžããããšãã§ããå Žåã«ãã¡ãŒã«ãµãŒããŒéã®ã¡ãã»ãŒãžãååããåé¡ãéšåçã«æé€ããŸããåä¿¡è ã®ãã¡ã€ã³ãMTA-STSããªã·ãŒãå ¬éããéä¿¡è ã®ãµãŒããŒãMTA-STSããµããŒãããŠããå ŽåãTLSæ¥ç¶ãä»ããŠã®ã¿ãããªã·ãŒã§å®çŸ©ããããµãŒããŒã«ã®ã¿ããµãŒããŒèšŒææžãæ€èšŒãããç¶æ ã§ã®ã¿é»åã¡ãŒã«ãéä¿¡ãããŸãã
ãªãéšåçã«ïŒMTA-STSã¯ãäž¡æ¹ã®åœäºè ããã®æšæºã®å®è£ ãåŠçããå Žåã«ã®ã¿æ©èœããMTA-STSã¯ãæ»æè ããããªãã¯CAã®1ã€ã§æå¹ãªãã¡ã€ã³èšŒææžãååŸããæ©äŒãããã·ããªãªããä¿è·ããŸããã
MTA-STSã®ããã¿
åä¿¡è
- ã¡ãŒã«ãµãŒããŒäžã®æå¹ãªèšŒææžã䜿çšããŠSTARTTLSã®ãµããŒããæ§æããŸãã
- HTTPSãä»ããŠMTA-STSããªã·ãŒãå
¬éã
https://mta-sts.mail.ru/.well-known/mta-sts.txtãŸããããšãã°ãç¹å¥ãªmta-stsãã¡ã€ã³ãšç¹å¥ãªæ¢ç¥ã®ãã¹ãå ¬éã«äœ¿çšãããŸããããªã·ãŒã«ã¯ããã®ãã¡ã€ã³ã®ã¡ãŒã«ãåä¿¡ããæš©éãæã€ã¡ãŒã«ãµãŒããŒïŒmxïŒã®ãªã¹ããå«ãŸããŠããŸãã - ç¹å¥ãª_mta-stsTXTã¬ã³ãŒããããªã·ãŒããŒãžã§ã³ãšãšãã«DNSã«å
¬éããŸããããªã·ãŒã倿Žãããå Žåããã®ã¬ã³ãŒããæŽæ°ããå¿
èŠããããŸãïŒããã«ãããéä¿¡è
ã«ããªã·ãŒãåèŠæ±ããããã«éç¥ãããŸãïŒãäŸãã°ã
_mta-sts.mail.ru. TXT "v=STSv1; id=20200303T120000;"
éä¿¡
è éä¿¡è ã¯ã_mta-sts DNSã¬ã³ãŒããå©çšå¯èœãªå Žåã¯ãããèŠæ±ããHTTPSãä»ããŠããªã·ãŒèŠæ±ãè¡ããŸãïŒèšŒææžã®æ€èšŒïŒãçµæã®ããªã·ãŒã¯ãã£ãã·ã¥ãããŸãïŒæ»æè ãããªã·ãŒãžã®ã¢ã¯ã»ã¹ããããã¯ããããDNSã¬ã³ãŒãã倿Žããå ŽåïŒã
ã¡ãŒã«ãéä¿¡ãããšããæ¬¡ã®ããšããã§ãã¯ãããŸãã
- ã¡ãŒã«ã®é ä¿¡å ã®ãµãŒããŒãããªã·ãŒã«å«ãŸããŠããŸãã
- ãµãŒããŒã¯TLSïŒSTARTTLSïŒã䜿çšããŠã¡ãŒã«ãåãå ¥ããæå¹ãªèšŒææžãæã£ãŠããŸãã
MTA-STSã®å©ç¹
MTA-STSã¯ãã»ãšãã©ã®çµç¹ã§ãã§ã«å®è£ ãããŠãããã¯ãããžïŒSMTP + STARTTLSãHTTPSãDNSïŒã䜿çšããŸããåä¿¡è åŽã§ã®å®è£ ã«ã¯ãæšæºã®ç¹å¥ãªãœãããŠã§ã¢ãµããŒãã¯å¿ èŠãããŸããã
MTA-STSã®ãã¡ãªãã
Webããã³ã¡ãŒã«ãµãŒããŒèšŒææžã®æå¹æ§ãååã®å¯Ÿå¿ãããã³ã¿ã€ã ãªãŒãªæŽæ°ãç£èŠããå¿ èŠããããŸããèšŒææžã«åé¡ããããšãã¡ãŒã«ãé ä¿¡ã§ããªããªããŸãã
éä¿¡è åŽã§ã¯ãMTA-STSããªã·ãŒããµããŒãããMTAãå¿ èŠã§ãããçŸåšãMTA-STSã¯MTAã§ã¯ãµããŒããããŠããŸããã
MTA-STSã¯ãä¿¡é Œãããã«ãŒãCAã®ãªã¹ãã䜿çšããŸãã
MTA-STSã¯ãæ»æè ãæå¹ãªèšŒææžã䜿çšããæ»æããä¿è·ããŸãããã»ãšãã©ã®å ŽåããµãŒããŒã®è¿ãã®MitMã¯ãèšŒææžãçºè¡ããå¯èœæ§ãæå³ããŸãããã®ãããªæ»æã¯ãèšŒææžã®éææ§ãéããŠæ€åºã§ããŸãããããã£ãŠãäžè¬ã«ãMTA-STSã¯ãã©ãã£ãã¯ã®ååã®å¯èœæ§ã軜æžããŸãããå®å šã«æé€ããããã§ã¯ãããŸããã
æåŸã®2ã€ã®ãã€ã³ãã«ãããMTA-STSã¯ç«¶åããSMTPã®DANEæšæºïŒRFC 7672ïŒãããå®å šæ§ãäœããªããŸãããæè¡çã«ã¯å®å šæ§ãé«ããªããŸããMTA-STSã®å ŽåãèŠæ Œã®å®è£ ã«èµ·å ããæè¡çãªåé¡ã«ãããã¬ã¿ãŒãé ä¿¡ãããªãå¯èœæ§ã¯äœãã§ãã
ç«¶åããæšæº-DANE
DANEã¯DNSSECã䜿çšããŠèšŒææžæ å ±ãå ¬éããå€éšCAãžã®ä¿¡é Œãå¿ èŠãšããªããããã¯ããã«å®å šã§ãããã ããDNSSECã®äœ¿çšã¯ãæ°å¹Žéã®äœ¿çšã®çµ±èšã«äŸåããŠããå Žåãæè¡çãªé害ã«ã€ãªããå¯èœæ§ãå€§å¹ ã«é«ããªããŸãïŒãã ããDNSSECãšãã®æè¡ãµããŒãã®ä¿¡é Œæ§ã«ã¯äžè¬ã«ååããªåŸåããããŸãïŒãåä¿¡è åŽã®SMTPã«DANEãå®è£ ããã«ã¯ãDNSãŸãŒã³ã«DNSSECãååšããããšãå¿ é ã§ãããDANEã®å ŽåãDNSSECã«ã·ã¹ãã äžã®åé¡ãããNSEC / NSEC3ãæ£ãããµããŒãããããšãäžå¯æ¬ ã§ãã
DNSSECããšã©ãŒã§æ§æãããŠããå Žåãéä¿¡åŽãDANEããµããŒãããŠããã°ãåä¿¡åŽãDANEã«ã€ããŠäœãç¥ããªããŠããã¡ãŒã«é ä¿¡ã®æåŠã«ã€ãªããå¯èœæ§ããããŸãããããã£ãŠãDANEã¯ããå€ããããå®å šãªæšæºã§ãããéä¿¡è åŽã®äžéšã®ãµãŒããŒãœãããŠã§ã¢ã§ãã§ã«ãµããŒããããŠããŸãããå®éã«ã¯ãã®æµžéã¯éèŠã§ã¯ãªããDNSSECãå®è£ ããå¿ èŠããããããå€ãã®çµç¹ã¯ãããå®è£ ããæºåãã§ããŠããŸãããããã«ãããDANEã®å®è£ ãå€§å¹ ã«é ããªããŸãããæšæºãååšããŠãããã¹ãŠã®ãããã®å¹Žã
DANEãšMTA-STSã¯äºãã«ç«¶åãããäžç·ã«äœ¿çšã§ããŸãã
Mail.ruMailã®MTA-STSãµããŒããšã¯
Mail.ruã¯ãããªãåãããã¹ãŠã®äž»èŠãªãã¡ã€ã³ã®MTA-STSããªã·ãŒãå ¬éããŠããŸããçŸåšãæšæºã®ã¯ã©ã€ã¢ã³ãåŽãå®è£ ããŠããŸãããã®èšäºã®å·çæç¹ã§ã¯ãããªã·ãŒã¯éããããã³ã°ã¢ãŒãã§é©çšããïŒé ä¿¡ãããªã·ãŒã«ãã£ãŠãããã¯ãããŠããå Žåãã¬ã¿ãŒã¯ããªã·ãŒãé©çšããã«ãããã¯ã¢ããããµãŒããŒãä»ããŠé ä¿¡ãããŸãïŒãããããã³ã°ã¢ãŒãã¯ãçºä¿¡SMTPãã©ãã£ãã¯ã®ããäžéšã«å¯ŸããŠãåŸã ã«ãã©ãã£ãã¯ã®100ïŒ ã«å¯ŸããŠåŒ·å¶ãããŸããããªã·ãŒã®é©çšããµããŒããããŠããŸãã
ä»ã«èª°ãæšæºããµããŒãããŠããŸãã
ãããŸã§ã®ãšãããMTA-STSããªã·ãŒã¯ã¢ã¯ãã£ããã¡ã€ã³ã®çŽ0.05ïŒ ãå ¬éããŠããŸãããããã§ãã倧éã®ã¡ãŒã«ãã©ãã£ãã¯ããã§ã«ä¿è·ããŠããããã§ãããã®èŠæ Œã¯ãGoogleãComcastãããã³éšåçã«VerizonïŒAOLãYahooïŒãªã©ã®äž»èŠãªãã¬ãŒã€ãŒã«ãã£ãŠãµããŒããããŠããŸããä»ã®å€ãã®éµäŸ¿ãµãŒãã¹ã¯ãæšæºã®ãµããŒããè¿ãå°æ¥å®è£ ãããããšãçºè¡šããŸããã
ããã¯ç§ã«ã©ã®ããã«åœ±é¿ããŸããïŒ
ãã¡ã€ã³ãMTA-STSããªã·ãŒãå ¬éããŠããªãå Žåã¯äœããããŸãããããªã·ãŒãå ¬éãããšãã¡ãŒã«ãµãŒããŒãŠãŒã¶ãŒãžã®ã¡ãã»ãŒãžãååãããªãããã«ä¿è·ãããŸãã
MTA-STSãå®è£ ããã«ã¯ã©ãããã°ããã§ããïŒ
åä¿¡è åŽã§ã®MTA-STSãµããŒã
HTTPSããã³DNSã¬ã³ãŒããä»ããŠããªã·ãŒãå ¬éããMTAã§STARTTLSã®ä¿¡é Œã§ããCAã®1ã€ããæå¹ãªèšŒææžãæ§æïŒæå·åããŸãããïŒããã ãã§ååã§ãïŒSTARTTLSã¯ãã¹ãŠã®ææ°ã®MTAã§ãµããŒããããŸãïŒãMTAããã®ç¹å¥ãªãµããŒãã¯å¿ èŠãããŸããã ..ã
ã¹ããããã€ã¹ãããã§ã次ã®ããã«ãªããŸãã
- MTAïŒpostfixãeximãsendmailãMicrosoft Exchangeãªã©ïŒã§STARTTLSãæ§æããŸãã
- , ( CA, , MX-, ).
- TLS-RPT , ( TLS). ( example.com):
smtp._tls.example.com. 300 IN TXT «v=TLSRPTv1;rua=mailto:tlsrpt@example.com»
TLS SMTPtlsrpt@exmple.com.
, . - MTA-STS HTTPS. CRLF .
https://mta-sts.example.com/.well-known/mta-sts.txt
:
version: STSv1 mode: enforce mx: mxs.mail.ru mx: emx.mail.ru mx: mx2.corp.mail.ru max_age: 86400
version (STSv1), Mode , testing â ( ), enforce â «» . mode: testing, , mode: enforce.
mx , ( , mx). Max_age ( DNS- , mta-sts DNS). - TXTã¬ã³ãŒããDNSã«å
¬éããŸãã
_mta-sts.example.com. TXT âv=STSv1; id=someid;â
idãã£ãŒã«ãã§ã¯ãä»»æã®èå¥åïŒã¿ã€ã ã¹ã¿ã³ããªã©ïŒã䜿çšã§ããŸããããªã·ãŒã倿Žãããšã倿Žããå¿ èŠããããŸããããã«ãããéä¿¡è ã¯ããã£ãã·ã¥ãããããªã·ãŒãåèŠæ±ããå¿ èŠãããããšãçè§£ã§ããŸãïŒèå¥åããã£ãã·ã¥ãããããªã·ãŒãšç°ãªãå ŽåïŒã
éä¿¡è ã§ã®MTA-STSã®ãµããŒã
æªãã§ãããæšæºã¯æ°é®®ã§ãã
- Exim-çµã¿èŸŒã¿ã®ãµããŒãã¯ãããŸããããµãŒãããŒãã£ã®ã¹ã¯ãªããããããŸãhttps://github.com/Bobberty/MTASTS-EXIM-PERL
- Postfix-çµã¿èŸŒã¿ã®ãµããŒãã¯ãããŸãããHabréhttps ïŒ //habr.com/en/post/424961/ã§è©³çްã«èª¬æãããŠãããµãŒãããŒãã£ã®ã¹ã¯ãªããããããŸãã
ãå¿ é TLSãã®ããšãããšããŠ
èŠå¶åœå±ã¯æè¿ã¡ãŒã«ã»ãã¥ãªãã£ã«çŠç¹ãåãããŠããŸãïŒãããŠããã¯è¯ãããšã§ãïŒãããšãã°ãDMARCã¯ç±³åœã®ãã¹ãŠã®æ¿åºæ©é¢ã«çŸ©åä»ããããŠãããéèã»ã¯ã¿ãŒã§ãŸããŸãå¿ èŠãšãããŠããŸããèŠå¶åºåã§ã¯ãèŠæ Œã®æ®åçã¯90ïŒ ã«éããŸããçŸåšãäžéšã®èŠå¶åœå±ã¯ãåå¥ã®ãã¡ã€ã³ã§ãå¿ é TLSãã®å®è£ ãèŠæ±ããŠããŸãããåæã«ããå¿ é TLSããä¿èšŒããã¡ã«ããºã ã¯å®çŸ©ãããŠããããå®éã«ã¯ããã®èšå®ã¯ã次ã®ãããªã¡ã«ããºã ã§ãã§ã«æäŸãããŠããå®éã®æ»æããæå°éã«ããä¿è·ããªãæ¹æ³ã§å®è£ ãããããšããããããŸãã DANEãŸãã¯MTA-STSã
èŠå¶åœå±ãåå¥ã®ãã¡ã€ã³ã§ãå¿ é TLSãã®å®è£ ãèŠæ±ããå ŽåãMTA-STSãŸãã¯ãã®éšåçãªåçç©ãæé©ãªã¡ã«ããºã ãšããŠæ€èšããããšããå§ãããŸããããã«ããããã¡ã€ã³ããšã«åå¥ã«å®å šãªèšå®ãè¡ãå¿ èŠããªããªããŸããMTA-STSã®ã¯ã©ã€ã¢ã³ãåŽã®å®è£ ã«åé¡ãããå ŽåïŒãããã³ã«ãåºããµããŒãããããŸã§ããããããããªãã§ãããïŒããã®ã¢ãããŒãããå§ãããŸãã
- MTA-STSããªã·ãŒãDANEã¬ã³ãŒããå ¬éããŸãïŒãã¡ã€ã³ã§DNSSECããã§ã«æå¹ã«ãªã£ãŠããå Žåã«ã®ã¿DANEã远å ãããããã®å ŽåãMTA-STSã远å ããã®ãçã«ããªã£ãŠããŸãïŒãããã«ãããæ¹åã®ãã©ãã£ãã¯ãä¿è·ãããä»ã®ã¡ãŒã«ãµãŒãã¹ã«å¿ é ã®TLSãæ§æããããã«äŸé Œããå¿ èŠããªããªããŸããéµäŸ¿ãµãŒãã¹ããã§ã«MTA-STSããã³/ãŸãã¯DANEããµããŒãããŠããå Žåã¯ããã¡ã€ã³ã«å¯ŸããŠã
- «» MTA-STS , MX TLS-. MTA-STS, , , . TLS STARTTLS.