ãã®æŽæ°å±¥æŽãã¡ã€ã«ã®ææ°çã¯ãhttps://github.com/IPA-CyberLab/IPA-DN-ThinLib/ ãåç §ããŠãã ããã
** BETA VERSION UNDER DEVELOPMENT, INCOMPLETE AND BUGGY. USE AT YOUR OWN RISK. Ver 1.0 is scheduled to be released during November 2021. We strongly recommend that you wait until Ver 1.0 is released. ** - This Git repository contains the source code and documentation for the open source version of the Thin Telework System which is under development. 2021-10-31 by Daiyuu Nobori.
rc3 ã«ã¯ãæ¬¡ã®æ©èœã远å äºå®ã§ããããã¯ãã·ã³ã»ãã¬ã¯ãŒã¯ã·ã¹ãã ã®äžå¿ã®å®æçã®ãªãªãŒã¹åã«ããããæåŸã®éèŠãªæ©èœè¿œå ãšãªãäºå®ã§ãã
- ZTTP (Zero Trust Tunneling Protocol) ãå®è£ ããäºå®ã§ããZTTP ã¯ãæè¿ã®ãŒããã©ã¹ã補åãšããŠæµè¡ãå§ããŠãããã¯ã©ãŠãå HTTPS ãããã·ãµãŒããŒæ©èœ (SSL éä¿¡ãäžéè æ»æã®ææ³ãçšããŠåŸ©å·åãããã®) ã«ãããŠãã·ã³ã»ãã¬ã¯ãŒã¯ã·ã¹ãã ã®éä¿¡ãäžæ£ãªéä¿¡ã§ãããšã¿ãªãããŠæ€åºããã鮿ãããŠããŸããªã¹ã¯ãåé¿ããããã«ãéä¿¡å 容ãäºéã« SSL ã§æå·åããããšã«ãããå€åŽã® SSL ãäžéçã«è§£èªãããŠããå åŽã® SSL ã®å 容ã»å±æ§ãå šãåãããªãããã«ããããã®æ©èœã§ããããã«ãããäžéšã®äŒæ¥ã§å©çšãããŠãã HTTPS ãããã·ãµãŒããŒã«ãããŠãã·ã³ã»ãã¬ã¯ãŒã¯ã·ã¹ãã ã®éä¿¡ãããŸã確ç«ããªãåé¡ã解決ããããšãã§ããŸããZTTP ã¯ãããã©ã«ãã§ OFF ã«ãªã£ãŠããŸããããŠãŒã¶ãŒãéžæçã« ON ã«ããããšãã§ããŸãã
- äžç¶ã²ãŒããŠã§ã€ã® ThinGate.ini ã®èšå®ã§ãSaveLog ãªãã·ã§ã³ãæå¹ã«ããŠããã«ãããããããTCP ãªã¹ããŒé¢ä¿ã®ãã° (äŸ: DoS æ»æå¯Ÿçæ©èœã®åäœç¶æ³ã®ãã°) ãããŒã«ã«ã® gate_log ã«èšé²ãããªãåé¡ãä¿®æ£ããŸããã
- ThinGate.ini ãã¡ã€ã«ã«ãããŠãDoS æ»æå¯Ÿçæ©èœãæå¹ã«ããŠããå Žå (DisableDoSProtection ã 1 ã«èšå®ãããŠããå Žå)ãDoS æ»æé²æ¢æ©èœãæå¹ãªå Žåã®è©³çްèšå®ãå¯èœã«ããŸãããDosProtection_MaxUnestablishedConnections (ã²ãŒããŠã§ã€å šäœã«ãããŠèš±å®¹ãããæªç¢ºç«ã® (ããªãã¡ãäžéå端ãª) TCP ã³ãã¯ã·ã§ã³æ°ã®æå€§æ°) ããã³ DosProtection_MaxConnectionsPerIp (åäžã®æ¥ç¶å IP ã¢ãã¬ã¹ããåæã«ç¢ºç«ã蚱容ãã TCP ã³ãã¯ã·ã§ã³æ°ã®æå€§æ°) ã®å€ãæŽæ°å€ã§æå®ã§ããããã«ãªããŸããã
- ãããã°ãã°ã®ãªã¢ãŒã syslog ãµãŒããŒãžã®è»¢éæ©èœãå®è£ ããŸããããã°ããªã¢ãŒã syslog ãµãŒããŒã«è»¢éããå Žå㯠SysLogHostname ã«è»¢éå syslog ãµãŒããŒã® IP ã¢ãã¬ã¹ãèšèŒããSysLogPort ã«è»¢éå syslog ãµãŒããŒã® UDP ããŒãçªå·ãèšèŒããããšãã§ããããã«ãªããŸããã詳ãã㯠ThinGate.ini èšå®ãã¡ã€ã«ã® SysLogHostname, SysLogPort, SysLogPrefix, SysLogAddHostname, SysLogAddMacAddress ããã³ SysLogAddIpAddress ãªãã·ã§ã³ããåç §ãã ããã
- ã·ã³ã»ãã¡ã€ã¢ãŠã©ãŒã«æ©èœã远å ããŸãããã·ã³ã»ãã¡ã€ã¢ãŠã©ãŒã«æ©èœã¯ãã·ã³ã»ãã¬ã¯ãŒã¯ã·ã¹ãã ãµãŒããŒæ©èœã«ä»å±ããŠããŸããã·ã³ã»ãã¡ã€ã¢ãŠã©ãŒã«æ©èœã«é¢ãã詳现ã¯ãã·ã³ã»ãã¡ã€ã¢ãŠã©ãŒã«æ©èœã®èšå®ãã¡ã€ã« (ãµãŒããŒèšå®ããŒã«ãããã¿ã³ãã¯ãªãã¯ããŠç°¡åã«ã¢ã¯ã»ã¹ã§ããŸãã) ããåç
§ãã ããããªããã·ã³ã»ãã¡ã€ã¢ãŠã©ãŒã«æ©èœã¯ãæšæºç¶æ
ã§éå§ãããŠãããããŠãŒã¶ãŒãæç€ºçãªæäœãè¡ãåäœãéå§ãããŸã§ã¯åäœããªãããã«ãªã£ãŠããŸãããŸãããœãŒã¹ã³ãŒãã®
src/Vars/VarsActivePatch.hã®Vars_ActivePatch_AddBool("DisableThinFirewallSystem", false);ã®èšå®å€ãtrueã«å€æŽããããšã«ãããã·ã³ã»ãã¡ã€ã¢ãŠã©ãŒã«ã·ã¹ãã æ©èœãå®å šã«ç¡å¹åããããšãã§ããŸãã - ã¡ã¢ãªã®ããŒãé åä¿è·ã匷åããŸãããã¡ã¢ãªã®è§£æŸããã³å確ä¿ã宿œãããéã«ãã¡ã¢ãªã®ååŸé åã«ã«ããªã¢ãšåŒã°ããã©ã³ãã ãªã»ãã¥ãªãã£å€ãæžã蟌ã¿ããã®å€ã倿ŽãããŠããå Žåãã¡ã¢ãªé åã®ãããã¡ãªãŒããŒãããŒã§ãããšã¿ãªããŠããã»ã¹ãå®å šã®ããã«çµäº (åèµ·å) ããŸãããã®æ©èœã¯ãå°æ¥æ¬ã·ã¹ãã ã«äœããã®ããŒãé åãªãŒããŒãããŒã®è匱æ§ãçºèŠãããå Žåã§ãããã®è匱æ§ã«ãããæ©å¯æ§ãŸãã¯å®å šæ§ã䟵害ãããããšã广çã«äºé²ããããšãå¯èœã§ãããšèããããŸãã
- SSL éä¿¡äžã«ãŠãŒã¶ãŒãåææäœãè¡ãããšããå Žåã«ãçšã«ããã»ã¹ãã¯ã©ãã·ã¥ããåé¡ã解決ããŸããã
- (ãã€ããŒã¹ã±ãŒã«çã®ã¿) ã³ã³ãããŒã©ã«ãããŠãããŒã¿ããŒã¹ãé害ã«ãã忢ããŠããŸã£ãŠããå Žåãéåžžã¯ããµãŒããŒããã® VPN æ¥ç¶ã®åŠçã¯ç¶ç¶ããããšãã§ããŸããããããªãããã³ã³ãããŒã©ã®ã³ãŒãã«äžå ·åãããããµãŒããŒã WoL æ©èœãæå¹ã«ããŠããå ŽåãMAC ã¢ãã¬ã¹ã®ç¢ºèªã»ç»é²ã»æŽæ°åŠçã®ããã«ããŒã¿ããŒã¹ã®èªã¿æžãã詊è¡ãããDB ã忢ããŠããå Žåã¯ãããã§äŸå€ãçºçããæ¥ç¶ã«å€±æããŠããŸããã°ãååšããŸããããã®ãã°ãè§£æ¶ããããŒã¿ããŒã¹é害æã«ãããŠããWoL æ©èœãæå¹åããŠãããµãŒããŒããã®æ¥ç¶ãåé¡ãªãå¯èœã«ãªãããã«ä¿®æ£ããŸããã
- (ãã€ããŒã¹ã±ãŒã«çã®ã¿) æ°èŠãµãŒããŒãã³ã³ãããŒã©ã«ç»é²ãããéã«ãããŒã¿ããŒã¹ãžã® INSERT åŠçã宿œãããŸããããã®éãINSERT ã«å ç«ã¡ãSELECT ãçšããŠããŠããŒã¯ãªåæã®ã³ã³ãã¥ãŒã¿ ID ãæ±ºå®ããããšããåŠçãäœåããŸãããã®åŠçã«ãããŠã¯ãåœç¶ããã©ã³ã¶ã¯ã·ã§ã³ã«ããããã¯ããããå¿ èŠããããŸãããSELECT ã§ãŸãèªã¿åããã©ã³ã¶ã¯ã·ã§ã³ãããããæ¬¡ã« INSERT ã®æ®µéã§ããããæžã蟌ã¿ãã©ã³ã¶ã¯ã·ã§ã³ã«å€æãããŸããããã§ãåæã«å€§éã®æ°èŠãµãŒããŒãéãªãåã£ãŠã³ã³ãããŒã©ã«èªããç»é²ããããšãããšããããããã¯ãçºçããŸãããããããã¯ã¯èªåçã«æ€åºãããããŒã«ããã¯ãããŸãã®ã§ãããŒã¿ã®äžè²«æ§ã¯ä¿ãããŸãããããããªãã©ã€ã«æéãèŠããäžéšã®æ¥ç¶ã¯ã¢ããŒãããããµãŒããŒåŽãå詊è¡ãããŸã§åŸ ããããŸãããã®ç¶æ ã¯ããŸãäžè¬çã«ã¯çºçããŸããã®ã§ããããŸã§çºèŠãããŸããã§ãããããã®åºŠã倧éã®æ¥ç¶ãã·ãã¥ã¬ãŒã·ã§ã³ããç¹æ®ãªããŒã«ããå¥ééçºããŠããæäžã«çºèŠãããŸãããããã§ããã®åé¡ãäžå¿è§£æ±ºããããã«ãã³ã³ãããŒã©åŽã§ãäžèšã® INSERT ãš SELECT ãšã®éã§ç°¡æçã«èªäž»çãªããã»ã¹å ããã¯ãçšããŠããã® 2 ã€ã®åŠçãæãåŠçã¯ãåäžã®ã³ã³ãããŒã©ããã¯ãåæã« 1 æ¬ããäœåããªãããã«æ¹è¯ããŸããããã®å€æŽã«ããéåžžæã®ããã©ãŒãã³ã¹ã®å£åã¯ãè€æ°ã®ãµãŒããŒãåæã«ç»é²ã詊ã¿ãŠããå Žåãã®ãããŠã¯ååšããŸãããè€æ°ã®ãµãŒããŒãåæã«ç»é²ã詊ã¿ãŠããå Žåã¯ããã®ç»é²åŠçã¯ãåäžã®ã³ã³ãããŒã©ã®èŠç¹ã§ã¿ããšãåæã« 1 æ¬ããèµ°ããªããªããŸãã®ã§ããã®å Žåã«éã£ãŠã¯ãããã©ãŒãã³ã¹ãç ç²ã«ãªããŸãããããããã®ããšãããèããŠã¿ããšãããšããšè€æ°ã®ãµãŒããŒãåæã«ç»é²ã詊ã¿ãŠããå Žåã¯ãåèšã®ãããªãããããã¯ãçºçããããããé«ãããã®ãããããã¯ã®æ€åºãšå埩ã®ããã®ãªãã©ã€åŠçã®æéãã¹ã®ã»ãããããã¯ã«äŒŽãåŠçã®å€éåã®çŠæ¢ã«ããæéãã¹ããã倧ãããšèããããšãã§ããã®ã§ããã®å€æŽã¯åççã§ãããã ããã®å€æŽã«ãã£ãŠããè€æ°å°ã®ã³ã³ãããŒã©ãåäœããŠããŠããã€ãè€æ°ã®ãµãŒããŒãããããç°ãªãã³ã³ãããŒã©ã«å¯ŸããŠèªããç»é²ããããšããå Žåãä»å远å ãããããã¯ã¯ãããã»ã¹å ã§ã®ã¿æ©èœããã³ã³ãããŒã©éã«ãŸããã£ãããã¯ã¯è¡ãªããªãã®ã§ (ãã®ããã¯ã¯ããŸãã«ããŒã¿ããŒã¹ã®ãã©ã³ã¶ã¯ã·ã§ã³æ©èœãæ ã£ãŠããŸã)ããã®ãããªå Žåã«ã¯ããã¯ãããããããã¯ãçºçãããªãã©ã€ãçããå¯èœæ§ã¯æ®ãããŠããŸãããã ããããã§ãã³ã³ãããŒã©ã®å°æ°ã¯äžè¬çã«ã¯ 2 å°çšåºŠãå€ã㊠3 å°ãããã§ãããšæãããŸãããã³ã³ãããŒã©ãšããŒã¿ããŒã¹ãµãŒããŒãšã®éã®é å»¶ã¯ããã»ã©å€§ãããªããšèããããŸãã®ã§ãå®çšäžã¯ãããã§ããŸãåé¡ã¯ãªããšããããšãã§ãããšæããŸãã
- (ãã€ããŒã¹ã±ãŒã«çã®ã¿) ã³ã³ãããŒã©ç»é¢ã«ãããŠã皌åäžã®äžç¶ã²ãŒããŠã§ã€äžèЧããŒãžã«ããStatusMessageããšããåã远å ãããCpuLatency: 0.035 msããšãããããªè¡šç€ºã远å ããŸããããã® CpuLatency ã¯ãäžç¶ã²ãŒããŠã§ã€ã®åŠçããå š VPN ã»ãã·ã§ã³ã®å éšçãªé å»¶ (CPU å ã§çºçããé å»¶) ã®çŸåšã®å¹³åå€ã衚瀺ããŸãããã® CpuLatency ã®å€ã¯ããããã¯ãŒã¯äžã®é å»¶ãšã¯ç¡é¢ä¿ã§ãããããã¯ãŒã¯ã®åž¯åå¹ ãåé¡ç¡ãäŸçµŠãããŠããŠãã倧éã®ã»ãã·ã§ã³ãäžç¶ã²ãŒããŠã§ã€ãåŠçããããšããå Žåã¯ããã®é å»¶ãå¢å€§ããŸãããã® CpuLatency ã 0.1ms 以å ã§ããã°æ¥µããŠåªè¯ã§ãããè² è·ãé«ããªããšãé å»¶ã¯å¢å€§ããŠãããŸãããã®CpuLatency ãæ° ms ãè¶ ããå ŽåããŠãŒã¶ãŒã®ç»é¢æäœã®å¿«é©æ§ã«åœ±é¿ãçããŸãããã®ãããäžç¶ã²ãŒããŠã§ã€ãéå¶ãããã€ã倧éã®ãŠãŒã¶ãŒã»ãã·ã§ã³ãåŠçããããšããå Žåã«ãããŠãCpuLatency ã®å€ãæ¥åžžçã«èŠå®ãããããå¢å€§ããŠããå Žåã¯ãäžç¶ã²ãŒããŠã§ã€ã®å°æ°ãå¢åŒ·ããããšãæ€èšããããšãæšå¥šãããŸããæ³šæ: CpuLatency ã®å€ã¯ãçŽ 10 ç§ããšã«æŽæ°ãããŸãããŸãã1 æ¬ã VPN ã»ãã·ã§ã³ãæ¥ç¶ãããŠããªãã²ãŒããŠã§ã€ã®å Žåããã®éã¯ãCpuLatency ã®å€ã¯ N/A ãšãªããŸãããªããªãã°ãCpuLatency ã¯å éšé å»¶ã®æž¬å®çµæã§ãããæž¬å®å¯Ÿè±¡ã®ã»ãã·ã§ã³ã 1 æ¬ãååšããªããã°ãããããæž¬å®ãã察象ããªãããã§ãã
- OpenSSL ã®ããŒãžã§ã³ã OpenSSL 3.0.9 ã«ããŒãžã§ã³ã¢ããããŸããã
- æ¬ããã°ã©ã ãå©çšããŠãã OpenSSL ã©ã€ãã©ãªå éšã§äœ¿çšãããŠãã RW Lock (ãªãŒãã©ã€ã¿ããã¯) ãšåŒã°ããããã¯ååŸæ©èœã¯ãOS (libc, pthread, ã«ãŒãã«) ã®æäŸããããã¯æ©èœãåŒã³åºããŸãããæè¿ã® Linux ãã£ã¹ããªãã¥ãŒã·ã§ã³ã«å«ãŸãã pthread ã® RW Lock ã«ã¯ãã°ããããåäžã®ãµãŒããŒã§æ°åã»ãã·ã§ã³ãåŠçããéã«ãçªç¶ãã¹ãŠã® CPU ãã¹ãã³ããã¯çžäºåŸ æ©ç¶æ ã«é¥ããCPU æéãæ¥µããŠé·æéæ¶è²»ããŠãVPN éä¿¡ã»ãã·ã§ã³ã®éä¿¡ãå°é£ã«ãªãããŸã VPN ã»ãã·ã§ã³ãã¿ã€ã ã¢ãŠãã§åæãããŠããŸãåé¡ãçããããŠããŸããããã®åé¡ã¯ãOS åŽã®äžå ·åã§ãããå°ãªããšã Ubuntu 20.04 ãŸãã¯ãã以éã® Linux ãã£ã¹ããªãã¥ãŒã·ã§ã³ã§ãã〠x64 çã§ã®ã¿çºçããŸããããã®åé¡ã¯ OS åŽã®åé¡ã§ã解決ããããšãå°é£ã§ããããããã®åé¡ãåé¿ãããããRW Lock ãå©çšããã代ããã«éåžžã® Mutex Lock ã®ã¿ãå©çšããããã«ããŠãŒã¶ãŒã¢ãŒãããã°ã©ã åŽã®åŠçãæžãæããŸãããããã«ãããæ¬åé¡ã¯åé¿ãããŸããã
- OpenSSL ã® 3.0.0 ãã 3.0.2 ãŸã§ã¯ãTLS 1.0 ïœ TLS 1.2 ã§äœ¿çšå¯èœãªæå·ã¢ã«ãŽãªãºã ã®ãã¡ RC4-MD5 ã®äœ¿çšæã«ãã°ããããæ£åžžãªã¯ã©ã€ã¢ã³ããšã®æ¥ç¶ã«å€±æããåé¡ããããŸããããã®ãããåŸæ¥ã®ããŒãžã§ã³ã§ã¯ RC4-MD5 ãéžæçã«ç¡å¹ã«ããŠããŸãããããããOpenSSL ã®ããŒãžã§ã³ã 3.0.9 ã«ã¢ããããŒããããã®åé¡ã解決ãããããšãããRC4-MD5 ã®éžæçç¡å¹åã¯è§£é€ããŸããããšããã§ãRC4-MD5 ã¯çŸåšã§ã¯å®å šãªã¢ã«ãŽãªãºã ãšã¯ã¿ãªãããŠããªãã®ã§ãéåžžã¯ãããéžæãããããšã¯ãããŸããããŸããTLS 1.3 ã䜿çšããå Žåã¯ããããã RC4-MD5 ãéžæãããäœå°ã¯ãããŸãããããã§ã¯ãRC4-MD5 ãäžå¿å©çšå¯èœãšãªã£ãŠããæå³ã¯äœã§ãããããããã¯ãå€ãããŒãžã§ã³ã® Web ãã©ãŠã¶ (å€ã PCãçµã¿èŸŒã¿ç«¯æ«ãã¹ããŒããã©ã³ç) ã®äžã«ã¯ãRC4-MD5 ã§ã®éä¿¡ãåžæããè ãååšããããç¥ããªãããã§ãããããã£ãå€ããã©ãŠã¶ã§ããã€ãHTML5 察å¿ã®ãã©ãŠã¶ãååšãåŸãŸãããã®ãããªãã©ãŠã¶ã HTML5 ç Web ã¯ã©ã€ã¢ã³ãã® WebSocket éä¿¡ãè¡ãªããã·ã³ã»ãã¬ã¯ãŒã¯ã·ã¹ãã ãšéä¿¡ãããå Žåã¯ãäŸç¶ãšããŠãRC4-MD5 ã¯éèŠãªéžæè¢ã§ãããã ããããã¯æ¥µç«¯ãªã±ãŒã¹ã§ãã®ã§ãäžè¬çã«ã¯ããã®åé¡ã«ã€ããŠã¯ããŸãéèŠããå¿ èŠã¯ãªããšãããŸãã
- HTTP ãããã·çµç±æ¥ç¶ã®æç¹ã«ããã User Agent ã®å€ã¯ããŠãŒã¶ãŒãç»é¢ã§èšå®å¯èœã§ããã以åã®ããŒãžã§ã³ã§ã¯ãããã©ã«ãã§
Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0)ãšããæååãèšå®ãããããã«ãªã£ãŠããŸãããããã¯ãå°ãå€ãããŒãžã§ã³ã®ãã©ãŠã¶ã®å€ãããã£ãŠãããã®ã§ããããããªãããäžéšã®å éçäŒæ¥ãéå¶ããŠãã HTTP ãããã·ãµãŒããŒã¯ãæè¿ãUser Agent ã®å€ãåæã«èªã¿åããããã«åºã¥ããå€ããã©ãŠã¶ãæé€ãããããªæåã瀺ãããã«ãªããŸãããããã¯ãå°ã£ãããšã§ããããã§ãUser Agent ã®ããã©ã«ãå€ãMozilla/5.0 (Windows NT 10.0; Win64; x64) like Geckoã«å€æŽããŸãããããã«ãããHTTP ãããã·ãµãŒããŒã«ãã£ãŠãå€ããã©ãŠã¶ãå©çšãããŠãããšèª€èªããŠéä¿¡ãåæãããªã¹ã¯ãæžããŸããã
- 䜿çšããŠãã OpenSSL ã®ããŒãžã§ã³ããããŒãžã§ã³æ å ±ç»é¢ããã°ãã¡ã€ã«çã§è¡šç€ºã»åºåããããã«ããŸããã
- Windows ã«ãããŠãLAN ã«ãŒãã 2 æä»¥äžååšããäžæ¹ã«ããã©ã«ãã²ãŒããŠã§ã€ãèšå®ãããŠãããããäžæ¹ã«äœ¿çšãã DNS ãµãŒããŒãèšå®ãããŠããã±ãŒã¹ã§ãDNS ã®åå解決ã®å€±æã«ãããªãã©ã€ãçºçããæ¥ç¶æã«é·æé (60 ç§çšåºŠ) ç»é¢ãåºãŸã£ãŠããŸãåé¡ã解決ããŸããã
- å éšçã«äœ¿çšããæå·ã©ã€ãã©ãªã OpenSSL 3.0.7 ã«ã¢ããã°ã¬ãŒãããŸããã
- ãã€ã«ã©ã¹ã¿ã³ãã€æ©èœä»ãããŒã PC ãã¹ã¿ã³ãã€ããŠããŸãåé¡ã解決ããŸããã
- ããã«ãã«ããã£ãŠã®éèŠãªå€æŽç¹ã (éçºè
ããã³ã·ã¹ãã é¢ä¿è
ã®æ¹ã
ã¯å¿
ããäžèªãã ãã)
- ã·ã³ã»ãã¬ã¯ãŒã¯ã·ã¹ãã ã® GitHub ãªããžã㪠https://github.com/IPA-CyberLab/IPA-DN-ThinApps-Private/ ã¯ãgit ã®ãµãã¢ãžã¥ãŒã«ãšããŠãäž»èŠãªãœãŒã¹ã³ãŒãããå¥ã® GitHub ãªããžããªã«éçŽãããã®ãµããªããžããªãåç §ãã圢ã§å®è£ ããŠããŸãã
- [1] èæ¯ãšåŸæ¥ã®åé¡ç¹ - ãIPA-DN-Ultraã ãµããªããžããªã®æ¥µç«¯ãªè¥å€§å
- 1 ã€åã®ããŒãžã§ã³ãbeta8preview9 - 2022/08/08ããŸã§ã¯ããµããªããžããªã®ååã¯ããIPA-DN-Ultraã ãšããæååã§ãããIPA-DN-Ultra ã® GitHub äžã§ã® URL ã¯ãhttps://github.com/IPA-CyberLab/IPA-DN-Ultra/ ã§ããããããŠãã·ã³ã»ãã¬ã¯ãŒã¯ã·ã¹ãã ã® GitHub ãªããžã㪠(IPA-DN-ThinApps-Private) ããéçºçšã®ããŒã«ã«ãã·ã³ã§ååž°ç Pull ããå Žåã¯ãããã¯ããIPA-DN-ThinApps-Private/submodules/IPA-DN-Ultra/ã ãšããããŒã«ã«ã®ãµããã£ã¬ã¯ããªã«ãèªåçã«ãã§ãã¯ã¢ãŠããããŠããŸããã
- ãšãããããIPA-DN-Ultraããµãã¢ãžã¥ãŒã«ã¯ã2020 幎ã®ã·ã³ã»ãã¬ã¯ãŒã¯ã·ã¹ãã ã®éçºæããã®åºŠéãªãã¢ããããŒãã«ãããè¥å€§åããŠããŸããŸãããè¥å€§åã®çµæã®ãµã€ãºã¯ã0.6GB (660MB) ã«ãéããŠããŸã£ãŠããŸããããã®äž»èŠãªåå ã¯ã嫿ãã OpenSSL ã©ã€ãã©ãªã®ã³ã³ãã€ã«æžã¿ãã€ããªã®ãµã€ãºã«ã極ããŠè©³çްãªãããã°ã»ã·ã³ãã«ãå«ãŸããŠããããšãããã³ãã»ãšãã©ã®å Žåã«ã¯äžèŠãªãããã°ã»ãã«ããå«ãŸããŠããããšã§ããã
- ãããã®åå ã«ãããéçºè ãäžç¶ãµãŒããŒéå¶è ã®æ¹ã ããã·ã³ã»ãã¬ã¯ãŒã¯ã·ã¹ãã ã®ãœãŒã¹ã³ãŒãã git pull ãããéã«ããIPA-DN-Ultraããµãã¢ãžã¥ãŒã«ã GitHub ããããŠã³ããŒãããéã«é·æé (1 åé ïœ 10 åé) ãèŠããç¶æ ãšãªã£ãŠããŸããããããŠãåèšã®è¥å€§åã®äž»èŠãªåå ã§ãããã¡ã€ã«çŸ€ã®ãããã°ããŒã¿ã¯ãã»ãšãã©æå³ã®ãªãæ å ±ã§å ããããŠããŸãããããã«ãOpenSSL ã®åºŠéãªãã¢ããããŒãã«ãããéå»ãã¡ã€ã«ã git äžã®å±¥æŽãšããŠå¿ ãæ®ããšãã git ã®æ§è³ªäžããã®è¥å€§åã®åŸåã¯ããŸããŸããäžæ¹çã«éããªãã°ããã§ããã
- ããã«ãè¥å€§åã¯ãåã« clone (pull) ã®åŸ ã¡æéãé·ããªããšããå¿«é©æ§ã®é¢ã ãã§ãªããããæ·±å»ãªãããŒã«ã«ãã£ã¹ã¯æ¶è²»éã®å¢å€§ã«ãã空ã容éäžè¶³ãšããåé¡ããæ°ãã«åŒãèµ·ããã€ã€ãããŸãããgit ã§ clone (pull) ãè¡ãªããšãææ°çã®ãã¡ã€ã«ã ãã§ãªããgit ãªããžããªã®å±¥æŽãå«ããå šããŒã¿ããããŒã«ã«ãã£ã¹ã¯ã«ä¿æãããŸããã·ã³ã»ãã¬ã¯ãŒã¯ã·ã¹ãã ã®å€§éã®å°æ°ã®äžç¶ãµãŒããŒããRaspberry Piãã¯ã©ãŠã VMããŸã㯠Docker/LXD ã³ã³ããçã§éçšãããå ŽåãããŒã«ã«ãã£ã¹ã¯ã®å®¹éã¯ããããã®ãµãŒããŒãéçšããããã®ã³ã¹ãã«çŽçµããŸããç¹ã«ããããªãã¯ã»ã¯ã©ãŠãã§ã¯ããªãããã§ãããŸãããIPA-DN-Ultraããµãã¢ãžã¥ãŒã«ã®è¥å€§åã®çµæã®ãµã€ãºã¯ã0.6GB (660MB) ã«éããŠããŸããããããã¯ãããšãã° 200 å°ã®ã€ã³ã¹ã¿ã³ã¹ãéçšãããšãã120GB ãã®ããŒã¿é åãã»ãšãã©ç¡é§ã«æ¶è²»ããããšã«ã€ãªããã®ã§ãã
- å ããŠãè¥å€§åã¯ã皌åãããŠããäžç¶ãµãŒããŒã®ãã£ã¹ã¯ã®ããã¯ã¢ãããè¡ãªãéã«ãããã®ããã¯ã¢ãããµã€ãºã®å¢å€§ãšããã³ã¹ãå¢ãåŒãèµ·ãããŸãããªããªãã°ãããã¯ã¢ããã¯ãã£ã¹ã¯äžã«ãããã¡ã€ã«çŸ€ãå¿ å®ã«ããã¯ã¢ããããŸããããIPA-DN-Ultraããµãã¢ãžã¥ãŒã«ã®è¥å€§åããããã¡ã€ã«çŸ€ãããã®äžã«ãå«ãŸããããã§ãããŸãã
- äžèšã®ãããªèŠå ã«ãããæè¿ãããããè¥å€§åã®åé¡ãè§£æ¶ããå¿ èŠãããç¶æ ã«å·®ãæãã£ãŠããŸããã
- [2] 解決ç - ãIPA-DN-UltraãâãIPA-DN-ThinLibããžã®ãªããžããªåã®å€æŽãšãå€ãå±¥æŽã®åé€ã«ããè¥å€§åã®è§£æ¶
- ããã§ããã®åºŠãåŸæ¥ã®ãµããªããžããªã§ãããIPA-DN-Ultraãã®å 容ãã³ããŒããŠããIPA-DN-ThinLibã (https://github.com/IPA-CyberLab/IPA-DN-ThinLib/) ãšããååã®æ°ãããµããªããžããªãäœæãããã®éã«ãäžèŠãªéå»ã®å·šå€§ãª OpenSSL ã®ãã¡ã€ã«çŸ€ãåé€ããè¥å€§åãè§£æ¶ããŠãã¹ãªã åãå®çŸããŸããã
- ããã§ãä»åŸã¯ããIPA-DN-ThinLibãããåŸæ¥ã®ãIPA-DN-Ultraãã«ä»£ãã£ãŠããIPA-DN-ThinApps-Private/submodules/IPA-DN-ThinLib/ã ãšããããŒã«ã«ã®ãµããã£ã¬ã¯ããªã«ãèªåçã«ãã§ãã¯ã¢ãŠããããããã«ãªããŸããã
- ä»åã®ã¹ãªã åã®å¹æã¯ãé¡èãªãã®ã§ãããŸãããµããªããžããªã®å®¹éã¯ãåŸæ¥ã® 0.6GB (660MB) ããã 0.05GB (52MB) ã«åæžãããŸãããããªãã¡ã90% 以äžãåæžããããšã«æåãããšããããšã«ãªããŸãã
- ã¹ãªã åã«ãããŠã¯ããŸããgit ã®å±¥æŽäžã®å€ãäžèŠãª OpenSSL çã®æ§ããŒãžã§ã³ã®è¥å€§åããããã¡ã€ã«ãå±¥æŽããŒã¿ããåé€ (éå»ã®æ¹ãã) ããŸããã
- 次ã«ãçŸåšã® OpenSSL ã®ã©ã€ãã©ãªãã¡ã€ã«ã«ã€ããŠããããã°ãã«ã (æé©åãããŠããªãããããã°çšã®ã³ãŒããå€éã«å«ãŸãããã«ã) ããã³ãããã°ã·ã³ãã«ã¯ãOpenSSL ã®å éšçåé¡ã«èµ·å ããäžå ·åã解決ããªããã°ãªããªããããªæ¥µããŠçšãªã±ãŒã¹ã«ãããŠã®ã¿å¿ èŠãšãªãæ å ±ã§ããããšããããIPA-DN-ThinLibãã«ã¯ããããã®ãããã°çšãã¡ã€ã«ããä»åŸå«ããªãããšã«ããŸããã
- ããã§çæ§ããæèµ·ãããåœç¶ã®çåã¯ããäžèšã®çž®å°ã®å·¥å€«ãåççã§ããããšã¯çè§£ã§ããããã©ãããªããä»åã®çž®å°ã«ãããŠããµããªããžããªåã倿Žãããå¿
èŠããã£ãã®ã?ããšãããã®ã§ãããšèããããŸãããã®çç±ã¯ã次ã®ãšããã§ãã
- git ã«ãããŠã¯ããã¡ã€ã«ã®å€æŽå±¥æŽã®å 容ãå«ããããŒã¿ã SHA-1 ããã·ã¥ãšããŠãã³ããã ID ãçæãããŸãã芪ã¢ãžã¥ãŒã«ãšãµãã¢ãžã¥ãŒã«ã®éã®çžäºåç §ã¯ããã¹ãŠãã³ããã ID ã«åºã¥ããŠé£çµãããŠããŠããŸããgit ã«ããéå»ã®æ¹ããã«ãããã³ããã ID ãå€åãããšããã以éã®ã³ããã ID ã«å¯Ÿããåç §ãè¡ãªãéã¯è¯ããã®ã®ããã以åã®ã³ããã ID ãåç §ããŠãããã¹ãŠã®èŠªãããžã§ã¯ãã¯ããã¯ãããã«ãã§ããªããªã£ãŠããŸããŸãã
- ã·ã³ã»ãã¬ã¯ãŒã¯ã·ã¹ãã ã®ãœãŒã¹ã³ãŒãã¯ããããŸã§ã®éçºäžã®ããŒãžã§ã³ã«ã€ããŠãããªãåºç¯å²ã§å©çšãããŠããŸããéå»ã®ä»»æã®ããŒãžã§ã³ãéçºãŸãã¯ãã«äžå ·åã®ç©¶æã®ããã«ãã«ãããå¿ èŠæ§ã¯ãä»åŸãåæ°žä¹ çã«åç¶ããŸãã
- ããã§ãäžèšãæºããããã«ã¯ããIPA-DN-Ultraãã嫿ããéå»ã®å±¥æŽæ å ±ã«ãããã³ããã ID ã¯ã決ããŠå€æŽãããŠã¯ãªããªããšããããšã«ãªããŸãã
- ãããã£ãŠããIPA-DN-Ultraãã¯ãã®ãŸãŸå®çœ®ããäžã§ããIPA-DN-ThinLibããªã©ã®ãç°ãªãååã®ãµãã¢ãžã¥ãŒã«åãæ°ãã«äœæããå¿ èŠãããã®ã§ãã
- ãªãã芪ãªããžããªãããŒã«ã«ãã£ã¹ã¯ã«ãã§ãã¯ã¢ãŠãããéããµããªããžããªã¯ãç©ççã«ã¯ããIPA-DN-ThinApps-Private/submodules/ãµããªããžããªå/ã ãšãããã£ã¬ã¯ããªã«æ ŒçŽããããã®ããŒã«ã«ã®ç©ççãªãµããªããžããªã®ãã£ã¬ã¯ããªåã¯ãGitHub äžã®ãªããžããªåãšãå¿ ãããåäžæååã§ããå¿ èŠã¯ãªãããç¥ããŸãããããã§ãè«çäžã¯ãããŒã«ã«ã®ç©ççãªãµããªããžããªã®ãã£ã¬ã¯ããªåã¯ããIPA-DN-Ultraããä¿ã£ããŸãŸãGitHub äžã®æ°ãããµããªããžã㪠(å¥å) ãæã瀺ãããã«ããããšãããããªæ¹çã¯ããã¡ããèãããããšããã§ãã
- ãããããã®æ¹æ³ã«ãããããŒã«ã«ã®ç©ççãªãµããªããžããªã®ãã£ã¬ã¯ããªåãšãGitHub äžã®æ°ãããµããªããžããªåãšãå¥åãšãªããšãããã¯ãããããéçºè ãŸãã¯éå¶è ã®æ¹ã ã®èŠç¹ã«ãããŠãçŽææ§ã«æ¬ ãã倧ããªæ··ä¹±ãåŒãèµ·ããå¯èœæ§ããããšèããããŸãã
- ããã§ã芪ãªããžããªãããŒã«ã«ãã£ã¹ã¯ã«ãã§ãã¯ã¢ãŠãããéã®ãµããªããžããªã®ãã£ã¬ã¯ããªåããä»åãæ°ãã«ããIPA-DN-UltraãâãIPA-DN-ThinLibãã«å€æŽããããšã«ããŸããã
- ããã«ãããä»åŸãéçºè ãŸãã¯ã·ã¹ãã éå¶è ã®çæ§ã¯ãã·ã³ã»ãã¬ã¯ãŒã¯ã·ã¹ãã ã® GitHub ãªããžã㪠https://github.com/IPA-CyberLab/IPA-DN-ThinApps-Private/ ã® clone (pull) ã«èŠããæéããæ¥µããŠçããªããäžèšã®ãåé¡ç¹ãã§è¿°ã¹ãåçš®åé¡ã¯ã解決ãããŸããã
- [3] å¯äœçš - ãIPA-DN-Ultraãã®å
容ã倿ŽãããŠããéçºè
ïŒéçšè
ã®æ¹ã
ãžã®ããŒã«ã«ãã¡ã€ã«ãã¹ã®å€æŽã®ãé¡ã
- ãšããããããŒã«ã«ã®ç©ççãªãµããªããžããªã®ãã£ã¬ã¯ããªåã¯ãä»åããIPA-DN-ThinApps-Private/submodules/IPA-DN-Ultra/ã ãã ãIPA-DN-ThinApps-Private/submodules/IPA-DN-ThinLib/ã ã«å€åããŠããŸããŸãããããã§ã次㮠2 ã€ã®åé¡ãçºçããŸãã
- åŸæ¥ã® beta8 ãŸãã¯ãã以åã®ãã«ããããŒã«ã«ãã£ã¹ã¯ã§ãã§ãã¯ã¢ãŠã (clone, pull) ãããŠããéçºè ãŸãã¯éå¶è ã®ããŒã«ã«ç°å¢ã«ããããŸããŠã¯ããIPA-DN-ThinApps-Private/submodules/ãã«ãå€ããIPA-DN-Ultraããšãæ°ãããIPA-DN-ThinLibãã® 2 ã€ã®ãµããªããžããªã®ãã£ã¬ã¯ããªãååšããŠããŸããŸãããã®çŸè±¡ãçºçããçç±ã¯ãgit ããã§ãã¯ã¢ãŠããã¹ãæ§ãµããªããžããªã¯ãµãã¢ãžã¥ãŒã«äžèЧãªã¹ãããæ¶ããæ°ãã«å¥ã®ãµããªããžããªããµãã¢ãžã¥ãŒã«äžèЧãªã¹ãã«è¿œå ãããã®ã§ãããgit ã¯ãã§ã«ç©ççã«ãã§ãã¯ã¢ãŠããããå€ããµããªããžããªã®ç©çãã¡ã€ã«ããèªåçã«åé€ããããšã¯ããªããšããå®å šçã®ããã®æåã«ãããã®ã§ãããã ããã®åé¡ã¯ãããã»ã©æ·±å»ãªåé¡ã§ã¯ãããŸãããå°ãçŽããããã§ãããrc1 以éã§ã¯ããIPA-DN-ThinApps-Private/submodules/IPA-DN-ThinLib/ãã®ã¿ãæå¹ãªãµãã¢ãžã¥ãŒã«ã®å®äœãšããŠå©çšãããŸããå€ããIPA-DN-Ultraãã®ãã£ã¬ã¯ããªãæ®åããŠããŠããããã¯ãæ¯éã«ã¯ãªããŸããããã ããããŒã«ã«ãã£ã¹ã¯å®¹éãããçšåºŠç¡é§ã«æ¶è²»ããåé¡ãšãçŽææ§ã«æ¬ ãããšããåé¡ããããŸããå¿ èŠãªå Žåã¯ãå€ããIPA-DN-Ultraãã®ãã£ã¬ã¯ããªã¯ãããããã®ãã£ã¬ã¯ããªã®äžèº«ãæžãæããŠããå Žåãå¿ ããããã¯ã¢ãããåããªã©ããåŸãããŒã«ã«ãã£ã¹ã¯ããåé€ããŠããŸã£ãŠåé¡ãããŸããã
- 次ã«ãåŸæ¥ãéçºè
ãŸãã¯ãµãŒããŒéå¶è
ã®æ¹ãããã«ãã«ãããããIPA-DN-ThinApps-Private/submodules/IPA-DN-Ultra/ãã®ãœãŒã¹ã³ãŒããããŒã¿ã倿ŽãããŠããå Žåãããã®ãã«ãæã®å€æŽæé ãæé æžãŸãã¯ã¹ã¯ãªããçã«åã蟌ãŸããŠããå Žåã¯ããããã®å€æŽå
容ã®é©çšå
ãã£ã¬ã¯ããªã¯ãä»åŸãæ°ãã«ãIPA-DN-ThinApps-Private/submodules/IPA-DN-ThinLib/ãã«å€æŽããŠããã ãå¿
èŠãçããŸãã
- ããã¯ãäžèšã®å¶çŽäžããããåŸãªãããšã§ãã®ã§ãå¿ èŠã«å¿ããŠãæ¢åã®æé æžãã¹ã¯ãªããããŸãã¯å€æŽå±¥æŽããŒã¿çã®å€æŽãŸãã¯ç§»åããé¡ãããããŸãã
- ãã ããããã¯ãéçºè ãŸãã¯éå¶è ã®æ¹ã ãäœæãããŠããæ¢åã®æé æžãã¹ã¯ãªããçã®ãã¡ã®ããã¹ãããŒã¿ãæ€çŽ¢ããŠããsubmodules/IPA-DN-Ultraã(ã¹ã©ãã·ã¥ã¯ãããã¯ã¹ã©ãã·ã¥ã§ããå¯èœæ§ããããŸã) ãšããæååãããéšåãããsubmodules/IPA-DN-ThinLibã(åãããã¹ã©ãã·ã¥ã¯ãããã¯ã¹ã©ãã·ã¥ã§ããå¯èœæ§ããããŸã) ã«é©åã«çœ®æããã ãããšã§ (眮æãããéã¯ãããã¯ã¢ããã®ç¢ºå®ãªä¿åãããŠããã ãããšãæšå¥šããŸã)ãã»ãšãã©ã³ã¹ãããããããšãªããèªåçã»æ©æ¢°çã«å®æœããã ãããšãå¯èœã§ãã
- ãŸãã以åã«ãIPA-DN-UltraããçŽæ¥ç·šéãããŠããå Žåã¯ãç·šéããã倿Žå 容ãããã®ãŸãŸããIPA-DN-ThinLibãã«é©çšããŠããã ããã°ã倿Žç¹ã¯ãåé¡ç¡ãé©çšãããŸãã
- ãããŠããã®å€æŽã¯ã(ä»åŸããsubmodules/IPA-DN-ThinLibããããã«å¥ã®ååã«å€æŽã«ãªããªãéã) 1 åã ãã§æžã¿ãŸãã
- ãšããããããŒã«ã«ã®ç©ççãªãµããªããžããªã®ãã£ã¬ã¯ããªåã¯ãä»åããIPA-DN-ThinApps-Private/submodules/IPA-DN-Ultra/ã ãã ãIPA-DN-ThinApps-Private/submodules/IPA-DN-ThinLib/ã ã«å€åããŠããŸããŸãããããã§ã次㮠2 ã€ã®åé¡ãçºçããŸãã
- äžèšã®å€æŽå 容ã¯ãrc1 ã®ããã¥ã¢ã« ã«ãããã§ã«åæ ãããŠããŸãã
- äžéšã®ç°å¢ã§ããªã·ãŒèŠå¶ãµãŒããŒã®èªåæ€åºã«å€±æããåé¡ããããšããå ±åããããŸãããããã§ããµãŒããŒåŽèšå®ã§ã詳现ãããã°ãã°ããæå¹ã«ããŠããå Žåã¯ããserver_logããã£ã¬ã¯ããªã«ä¿åããããã°ã«ããªã·ãŒèŠå¶ãµãŒããŒã®èªåæ€åºã®ç¶æ³ (ãããã°ã¡ãã»ãŒãž) ãèšé²ããããã«ããŸããã
- ã³ã³ãããŒã©ã 2 å°ä»¥äžã®åé·æ§æãšãªã£ãŠããå Žåã§ããã€ãã¢ããªã±ãŒã·ã§ã³åŽããããã·ãµãŒããŒã䜿çšããŠããå Žåã«ãæåã®æ¥ç¶è©Šè¡å ã³ã³ãããŒã©ã® 1 å°ã®ã³ã³ãããŒã©ã« TCP ã¬ã€ã€ã§ã®æ¥ç¶äžå ·åãçãããšãä»ã®æ¥ç¶è©Šè¡å ã³ã³ãããŒã©ãžã®æ¥ç¶ãžã®è©Šè¡ãããã«ãåœè©²æ¥ç¶äžå ·åãååšããŠããåŽã®ã³ã³ãããŒã©ãžã®æ¥ç¶ããç¶ããåé¡ã解決ããŸããããŸããé¢ä¿ããã¡ã¢ãªãªãŒã¯ãè§£æ¶ããŸããã
- å éšçã«äœ¿çšããæå·ã©ã€ãã©ãªã OpenSSL 3.0.3 ã«ã¢ããã°ã¬ãŒãããŸããã
- TLS 1.0 / TLS 1.1 / TLS 1.2 / TLS 1.3 ã®ãããããç¡å¹ã«ãããªãã·ã§ã³ãå¹ããŠããªãäžå ·åã解決ããŸããã
- EntryPoint.dat ãã¡ã€ã«ã§ UTF-8 BOM ãå é ã«èšèŒãããŠãããšãã«ç¡èŠããããã«ããŸããã
- ã·ã³ã»ãã¬ã¯ãŒã¯ã·ã¹ãã äžç¶ã²ãŒããŠã§ã€ ã¹ã¿ã³ãã¢ãã³çã«ããã SMTP ã«ãã OTP ã¡ãŒã«éä¿¡æ©èœã«ãããŠãSSL/TLS éä¿¡ããã³ SMTP èªèšŒã«å¯Ÿå¿ããŸããã
- ã·ã³ã»ãã¬ã¯ãŒã¯ã·ã¹ãã äžç¶ã²ãŒããŠã§ã€ ã¹ã¿ã³ãã¢ãã³çã« Mikaka DDNS Client ã®çµã¿èŸŒã¿ãè¡ãªããŸããã
- ãŠãŒã¶ãŒã¢ãŒãã®å Žåã§ãã〠Windows é«éã¹ã¿ãŒãã¢ãããæå¹ãªå Žåã¯ãèŠåã¡ãã»ãŒãžã衚瀺ããããã«ããŸããã
- ã·ã¹ãã ãã£ã¹ã¯ã®ç©ºã容éã 500MB æªæºãšãªã£ãå Žåãèµ·åæã«èŠåã¡ãã»ãŒãžã衚瀺ããããã«ããŸããã
- Win32 çã®ã³ã³ãã€ã©ã®ããŒãžã§ã³ã Visual Studio 2019 ãã Visual Studio 2022 ã«æŽæ°ããŸããã
- HTML5 ç Web ã¯ã©ã€ã¢ã³ãã«ãããŠãæ¥æ¬èªããŒããŒãã§æ¥æ¬èªããªå ¥åãè¡ãªãéã«ãã²ãªããªããŒã®ãããæåãå ¥åã§ããªãåé¡ã解決ããŸããããªããã²ãããªããŒã®ãããæåãå ¥åããå Žåã¯ãShift + ããããæŒãå¿ èŠããããŸãã
- ããŠãŒã¶ãŒã¢ãŒã ãªã¢ãŒããã¹ã¯ããããã¢ãŒãã«ãããéèŠãªå¶éäºé ã«ã€ããŠ: äžéšã®ããŒå ¥åãç¹æš©ã䌎ãããŒæäœãã§ããªãå ŽåããããŸããæ¥æ¬èªå ¥åã«ãããŠããªå ¥åã§äžéšã®æå (ãããããããç) ãå ¥åã§ããªãå ŽåããããŸããããŠãŒã¶ãŒã¢ãŒã ãªã¢ãŒããã¹ã¯ããããã¢ãŒãã§ã¯ãããŒãåå ¥åãã䜿ããã ããã
- HTML5 ç Web ã¯ã©ã€ã¢ã³ããããã¯ã©ã€ã¢ã³ãã®ãã€ã¯ã®å ±æãå¯èœã«ãªããŸãããããã«ããããµãŒããŒåŽ PC äžã§åäœããŠãã Teams ã Zoom, Skype, WebEx çã®ãã¬ãäŒè°ã·ã¹ãã ã«ãã¯ã©ã€ã¢ã³ã PC ã®ãã€ã¯ãæ¥ç¶ããããšãå¯èœã«ãªããŸãããã®æ©èœãæå¹ã«ããã«ã¯ããµãŒããŒã¢ããªã±ãŒã·ã§ã³ã®ããŒãžã§ã³ã beta8preview5 以éã«ããå¿ èŠããããŸãããŸããWeb ãã©ãŠã¶ã«ããããã€ã¯ã®å ±ææ©èœãæå¹ã«ããå¿ èŠããããŸããWeb ãã©ãŠã¶ã«ãã£ãŠã¯ããã®æ©èœã¯æ£åžžã«äœ¿çšã§ããªãå ŽåããããŸããGoogle Chrome ã®å©çšãæšå¥šããŸãã
- HTML5 ç Web ã¯ã©ã€ã¢ã³ããããã¯ã©ã€ã¢ã³ããšãµãŒããŒãšã®éã§ã¯ãªããããŒãã®å ±æãå¯èœã«ãªããŸãããããã«ããããµãŒããŒåŽã®ã¯ãŒãããœãããããã¹ããšãã£ã¿çãšãã¯ã©ã€ã¢ã³ãåŽã®ã¯ãŒãããœãããããã¹ããšãã£ã¿çãšã®éã§ããã¹ãã®ã³ããŒïŒããŒã¹ããå¯èœã«ãªããŸããããã®æ©èœãæå¹ã«ããã«ã¯ãWeb ãã©ãŠã¶ã«ãããã¯ãªããããŒãã®å ±ææ©èœãæå¹ã«ããå¿ èŠããããŸããWeb ãã©ãŠã¶ã«ãã£ãŠã¯ããã®æ©èœã¯æ£åžžã«äœ¿çšã§ããªãå ŽåããããŸããGoogle Chrome ã®å©çšãæšå¥šããŸãã
- äžç¶ã²ãŒããŠã§ã€ã® SSL æ¥ç¶åŠçããã©ãŒãã³ã¹ãå€§å¹ ã«åäžãããŸãããbeta8preview1 ã§ã¯ãOpenSSL 3.0 ã«ãããæåãã¢ãŒããã¯ãã£ã®å€§èŠæš¡å€æŽãåå ã§ãæ§èœã®å£åãçºçããŠããŸãããbeta8preview4 ã§ã¯ãã³ãŒãå šäœã®å€§å¹ ãªèŠçŽããè¡ãªããSSL_CTX ã®é«éãã£ãã·ã¥æ©æ§ãå®è£ ããããšã«ããããã®åé¡ã解決ããŸããã
- Win32 çã¯ã©ã€ã¢ã³ãã¢ããªã Nuro å ã® ZTE 瀟㮠HGW ã®é äžã® PC ã§å©çšã§ããªããšããåé¡ãå ±åãããŸãããããã¯ãNuro å ã® ZTE 瀟㮠HGW ã® DNS ãã£ãã·ã¥ãµãŒããŒã®ãã°ã§ããããšã倿ããŸããããã®åé¡ãåé¿ããããã®ã³ãŒãã远å ããŸããã
- Let's Encrypt ã®ã«ãŒãèšŒææžã®æå¹æéåãåé¡ (2021/09/30 ã«çºç) ã«å¯Ÿå¿ããããããã¹ãŠã® Let's Encrypt äžéèšŒææžãã§ãŒã³ã«å«ãŸããèšŒææžãã¯ã©ã€ã¢ã³ãã«å¯ŸããŠåŒ·å¶çã« Web ã¯ã©ã€ã¢ã³ãã«å¯ŸããŠéä»ããããã«ããŸããããèæ¯ã HTML5 ç Web ã¯ã©ã€ã¢ã³ãã«ãããŠãSSL (HTTPS) ããŽã·ãšãŒã·ã§ã³æã¯ãWeb ãµãŒããŒã¯ãWeb ã¯ã©ã€ã¢ã³ãã«å¯ŸããŠã以åã®ããŒãžã§ã³ã¯ãWeb ãµãŒããŒãåäœãããŠãã OS ãŸã㯠OpenSSL ãå ±åããèšŒææžãã§ãŒã³ããã®ãŸãŸéä»ããŠããŸãããããããªããã2021/09/30 é ã«äžççã«çºçããŠããçŸè±¡ã§ãã Let's Encrypt ã®ã«ãŒãèšŒææžããã³äžéèšŒææžã®æå¹æéåãã«ãããšã©ãŒçºççã®äºè±¡ã«äŒŽããOS ãŸã㯠OpenSSL ãå ±åããèšŒææžãã§ãŒã³ã« Let's Encrypt ã®æå¹æéãåããå€ãèšŒææžã®ã¿ãå«ãŸããŠãããããŸãã¯/ããã³æ°ãã Let's Encrypt ã®ã«ãŒãèšŒææžã«å¯ŸããäžéèšŒææžãå«ãŸããŠããªãå Žåã«ãæ°ãã Let's Encrypt ã®ã«ãŒãèšŒææžã«å¯ŸããäžéèšŒææžã HTTPS ã¯ã©ã¢ã³ãã«éä»ãããªãããšããã䞻㫠Let's Encrypt èšŒææžãå©çšããå Žåã«ãããŠãäžéšã® HTTPS ã¯ã©ã€ã¢ã³ãã§èšŒææžæ€èšŒãšã©ãŒãçºçããããã«ãªããŸããããè§£æ±ºææ³ã ãã®åé¡ã解決ãããããHTML5 ç Web ã¯ã©ã€ã¢ã³ãçš Web ãµãŒããŒã¯ãOS ãŸã㯠OpenSSL ãå ±åããèšŒææžãã§ãŒã³ã®å 容ã«ãããããã匷å¶çã«ããã¹ãŠã®äžéèšŒææžãã§ãŒã³ã Web ã¯ã©ã€ã¢ã³ãã«éä»ããããã«ããŸããããªãããã®æå㯠Linux äžã§ã·ã³ã»ãã¬ã¯ãŒã¯ã·ã¹ãã HTML5 ç Web ã¯ã©ã€ã¢ã³ãçš Web ãµãŒããŒã皌åãããŠããå Žåã«ã®ã¿é©çšãããŸããWindows äžã§ã·ã³ã»ãã¬ã¯ãŒã¯ã·ã¹ãã HTML5 ç Web ã¯ã©ã€ã¢ã³ãçš Web ãµãŒããŒã皌åãããŠããå Žåã¯ãåäžã® SSL èšŒææžä¿¡é Œãã¹ã®ã¿ãã¯ã©ã€ã¢ã³ãã«éä»ãããŸãã
- Windows 11 宿çã§ã®åäœç¢ºèªãäžéãè¡ãªããŸãããWindows 11 ã«ããããã¹ãŠã®æ©èœãšå ±ã«åäœããããšãæ€èšŒããŠããèš³ã§ã¯ãããŸããããäžè¬ç㪠Windows 11 ç°å¢ã«ãããŠãæ¯éãªãåäœããããšã確èªããŠããŸãã
- HTML5 ç Web ã¯ã©ã€ã¢ã³ãã«ãããŠãèšŒææžèªèšŒãè¡ãªãéã«ãèªèšŒã«å€±æããå Žåã«ãã®è©³çްãªåå ãšãšãã«ãšã©ãŒã¡ãã»ãŒãžã衚瀺ããããã«ããŸããã
- å éšçã«äœ¿çšããæå·ã©ã€ãã©ãªã OpenSSL 3.0.0 ã«ã¢ããã°ã¬ãŒãããŸããã
- IPv6 ã® DNS åå解決ãæå¹ã§ããã IPv6 éä¿¡ãã§ããªãç°å¢ã§ãã¯ã©ã€ã¢ã³ãã¢ããªã§ RDP æ¥ç¶ãšã©ãŒãçºçããåé¡ãä¿®æ£ããŸããã
- HTML5 ç Web ã¯ã©ã€ã¢ã³ãã«å¯Ÿå¿ããŸãããHTML5 ç Web ã¯ã©ã€ã¢ã³ãã䜿çšãããšãWeb ãã©ãŠã¶ããè·å Žã®ãã·ã³ã»ãã¬ã¯ãŒã¯ã·ã¹ãã ãµãŒããŒã端æ«ã«æ¥ç¶ããWindows ãã¹ã¯ãããã«ãªã¢ãŒããã°ã€ã³ã§ããŸããèªå® ã® Mac ã ChromeBook ãªã©ã®ç«¯æ«ãããè·å Žã® Windows ãå®å šã»å¿«é©ã«ãå šç»é¢ã§æäœã§ããŸãã
- ããªã·ãŒèŠå¶ãµãŒããŒã®èšå®ãã¡ã€ã«ã§ãæ°ãã«ãDENY_CLIENTS_APPãããã³ãDENY_CLIENTS_HTML5ãå€ãèšå®ã§ããããã«ãªããŸãããDENY_CLIENTS_APP ã« 1 ãèšå®ãããšãåŸæ¥ã®ãã¹ã¯ãããã¢ããªçã®ã·ã³ã»ãã¬ã¯ãŒã¯ã·ã¹ãã ã¯ã©ã€ã¢ã³ãããã®æ¥ç¶ãçŠæ¢ãããŸããDENY_CLIENTS_HTML5 ã« 1 ãèšå®ãããšãHTML5 ç Web ã¯ã©ã€ã¢ã³ãããã®æ¥ç¶ãçŠæ¢ãããŸããDENY_CLIENTS_APP ãš DENY_CLIENTS_HTML5 ã®äž¡æ¹ã« 1 ãèšå®ããããšã¯ã§ããŸããã
- NTT ãã³ã¢çã® IPv6 ã·ã³ã°ã«ã¹ã¿ã㯠(IPv6 SS) ç°å¢ (NAT64 / DNS64) ã«å¯Ÿå¿ããŸããã
- ã¯ã©ã€ã¢ã³ãåŽã¢ããªã«ãã㊠IPv6 ã·ã³ã°ã«ã¹ã¿ã㯠(IPv6 SS) ç°å¢ã§ã〠NAT64 / DNS64 ãæå¹ãªå Žåã«ãšã©ãŒãçºçããåé¡ãè§£æ¶ããŸããã
- ã€ã³ã¹ããŒã«æã«èšèªãéžæããããšãã§ããããã«ãªããŸããã
- ã¯ã©ã€ã¢ã³ãåŽã¢ããªã®èšå®ç»é¢ã§ããªã¢ãŒãç»é¢èµ·åæã«å éšçã« 127.0.0.1 ã瀺ãç¹æ®ãª FQDN åãæå®ãã 127.0.0.1 ãçŽæ¥æå® (åå解決ãšã©ãŒæã« ON ã«ããŠã¿ãŠãã ãã)ããªãã·ã§ã³ã远å ããŸããã
- Wake on LAN ãã±ããéä¿¡æ©èœã«ãããŠãã¿ãŒã²ããã®ãµãŒããŒåŽã³ã³ãã¥ãŒã¿ãå±ããŠãããã¹ãŠã®ãµããããã®ãããŒããã£ã¹ãã¢ãã¬ã¹å®ã«ã WoL ãã±ãããéä»ããããã«ããŸãããããã¯ãçµç¹ã® LAN ãã«ãŒã¿ãŸãã¯ã¬ã€ã€ 3 ã¹ã€ããã§åå²ãããŠããããã€ãã¬ã€ã€ 3 ã¹ã€ããçã«ãããŠãIP Directed Broadcastãæ©èœãæå¹ãªå Žåã«å¹æçã§ããIP Directed Broadcast æ©èœãæå¹ãªå Žåãç°ãªãã¬ã€ã€ 3 ã»ã°ã¡ã³ãäžã®ãµãŒããŒã WoL ã§èµ·åããããšãå¯èœãªå ŽåããããŸããã¬ã€ã€ 3 ã¹ã€ããã®åŽã®èšå®ãå¿ èŠã§ããäŸãšããŠãCisco 瀟ã®ããã¥ã¡ã³ãã¯ä»¥äžã®ãšããã§ã: https://www.cisco.com/c/ja_jp/support/docs/switches/catalyst-3750-series-switches/91672-catl3-wol-vlans.html äžè¬çã«ãä»ã®ã¹ã€ãã補åã«ãåæ§ã®æ©èœããããŸãããã®æ©èœãå©çšããã«ã¯ããã¿ãŒã²ãã PCãããã³ãããªã¬ PCãã®äž¡æ¹ããå°ãªããšã beta7preview16 以éã«ã¢ããããŒãããå¿ èŠããããŸãã
- LGWAN çã«ãããŠãã¯ã©ã€ã¢ã³ãããã°ã©ã ã®èšå®ç»é¢ã§ "æ¥ç¶å ã®ãµãŒããŒããè¡æ¿æ å ±ã·ã¹ãã é©åã¢ãŒããã®å Žåããå®å šéååãã¡ã€ã¢ãŠã©ãŒã«ããèµ·å" ã OFF ã«ãªã£ãŠããå Žåã§ãããå®å šéååãã¡ã€ã¢ãŠã©ãŒã«ããèµ·åããŠããŸãåé¡ãä¿®æ£ããŸããã
- ãµãŒããŒã®ãµã€ã¬ã³ãã¢ã³ã€ã³ã¹ããŒã«æ©èœã«ãããŠãèšå®ãã¡ã€ã«ã®èªååé€ã«å¯Ÿå¿ããŸãããã"C:\Program Files\Local Governments Telework System for LGWAN Server\LgwanThinSetup.exe" /auto:1 /deleteconfig:1ã (ãã¹ã¯ã€ã³ã¹ããŒã«ãããç°å¢ã«ãã£ãŠç°ãªãå ŽåããããŸã) ãå®è¡ãããšãã¢ã³ã€ã³ã¹ããŒã«ãç¡æäœã§å®äºããèšå®ãã¡ã€ã«ãèªåæ¶å»ãããŸããããã«ããããµãŒããŒã«ãããã€ã³ã¹ããŒã«åŸã®ãŠãŒã¶ãŒã®èšå®æ å ± (OTP ã®ã¡ãŒã«ã¢ãã¬ã¹ãMAC ã¢ãã¬ã¹ç) ã¯æ¶å»ãããŸãããã®åŸå床ãµãŒããŒãã€ã³ã¹ããŒã«ãããšããããã®åèšå®ãå¿ èŠã«ãªããŸãããã ãããµãŒããŒã®åºæ ID ãšãããã«çŽä»ããããŠããã³ã³ãã¥ãŒã¿ ID ã¯å€åããŸãããåºæ ID ããªã»ãããããå Žåã¯ãå¥éãªã»ããæäœãå¿ èŠã§ãã
- ãã€ããŒã¹ã±ãŒã«çã®ã³ã³ãããŒã©ã®ã³ãŒãã .NET SDK 5.0.200 ã§ã³ã³ãã€ã«ã§ããªããªã£ãŠããåé¡ãä¿®æ£ããŸãããããã¯ããããã Microsoft ã®åŽã® C# ã³ã³ãã€ã©ã®ãã°ã§ãã
- LGWAN çã§ã¯ããµãŒããŒããã°ã©ã ããåæç¶æ ã§äžç¶ã·ã¹ãã ã«ã»ãã·ã§ã³ã確ç«ããªãããã«ããŸããããããã·ãµãŒããŒã®èšå®ç»é¢ãéããŠèšå®ãè¡ãªããŸã§ãã»ãã·ã§ã³ã¯æªç¢ºç«ã®ç¶æ ãšãªããŸãã(ãããã·ãµãŒããŒã䜿çšããªãå ŽåããäžåºŠãããã·ãµãŒããŒã®èšå®ç»é¢ãéãå¿ èŠããããŸãã)
- ãµã€ã¬ã³ãã¢ã³ã€ã³ã¹ããŒã«ã«å¯Ÿå¿ããŸãããã"C:\Program Files\Local Governments Telework System for LGWAN Server\LgwanThinSetup.exe" /auto:1ã (ãã¹ã¯ã€ã³ã¹ããŒã«ãããç°å¢ã«ãã£ãŠç°ãªãå ŽåããããŸã) ãå®è¡ãããšãã¢ã³ã€ã³ã¹ããŒã«ãç¡æäœã§å®äºããŸãã(éåžžã¯ãããŸããããäžäžã¢ã³ã€ã³ã¹ããŒã«äžã«ãšã©ãŒãçºçããå Žåã¯ããšã©ãŒã¡ãã»ãŒãžã§åæ¢ããŸãã)
- LGWAN çã§ã¯ããããŸã§ãå®å šéååãã¡ã€ã¢ãŠã©ãŒã«ãç¡å¹ã«ãããªãã·ã§ã³ãèšå®ãããŠããå Žåã§ããå®å šéååãã¡ã€ã¢ãŠã©ãŒã«ãèµ·åããŠããŸã£ãŠããŸããããã®åºŠãããªã·ãŒèŠå¶ãµãŒããŒã§å®å šéååãã¡ã€ã¢ãŠã©ãŒã«ã匷å¶ã§ããããã«ããŸããã®ã§ãå®å šéååãã¡ã€ã¢ãŠã©ãŒã«ã匷å¶ã®å Žåã¯å¿ ãåæ©èœãèµ·åãããã以å€ã®å Žåã¯ãå®å šéååãã¡ã€ã¢ãŠã©ãŒã«ãç¡å¹ã«ãããªãã·ã§ã³ãèšå®ãããŠããå Žåã¯å®å šéååãã¡ã€ã¢ãŠã©ãŒã«ãèµ·åããªãããã«ããŸããã
- ã€ã³ã¹ããŒã©ã§ãWindows ã®ã°ã«ãŒãããªã·ãŒã§ãªã¢ãŒãæ¥ç¶ãæªæ§æã®å Žåã§ã誀ã£ãŠãWindows ã®ã°ã«ãŒãããªã·ãŒã§ãªã¢ãŒãæ¥ç¶ãçŠæ¢ãããŠããŸããããšããæ³šæã¡ãã»ãŒãžã衚瀺ãããŠããŸãåé¡ã解決ããŸãããããªã·ãŒããæªæ§æãã®å Žåããæå¹ããšããŠèª€ã£ãŠåãæ±ã£ãŠããããšãåå ã§ããããæªæ§æãã®å Žåã¯ãç¡å¹ããšããŠåãæ±ãããã«ä¿®æ£ããŸããã
- beta7preview9 ã§è¿œå ãããããµãŒããŒåŽã¡ã¢ãªå®¹éã 4GB 以äžãŸãã¯ç©ºãã¡ã¢ãªã 512MB æªæºã®å Žåã«è¡šç€ºãããç»é¢ã«ã¯ãäžè¬çãªã¡ã¢ãªå¢èšã®å¹çšãåçºããã¡ãã»ãŒãžãå«ãŸããŠããŸãããã®ã¡ãã»ãŒãžã¯ãIPA ã«ãããŠãã€ããªããã«ããã圢æ ã§é åžãããã·ã³ã»ãã¬ã¯ãŒã¯ã·ã¹ãã ã®ãããªãã¯çã§è¡šç€ºãããããšãç®çãšãããã®ã§ãããã³ã³ãã¥ãŒã¿ã«ã¡ã¢ãªãå¢èšããããšã«ãããçç£æ§ã®åäžãæ®æ¥åæžãäœæã®å¢å ãæ¶è²»é»åã®åæžã幞çŠåºŠã®å¢å ããã³æåŸã®å¢å€§ãçãå®çŸãããããšã IPA ãµã€ããŒæè¡ç 究宀ããåŒã³æããã¡ãã»ãŒãžã§ããããããªããããã©ã€ããŒãçã¯åå©çšäŒæ¥çãèªããœãŒã¹ã³ãŒãããã«ãããŠãã€ããªãçæããå瀟瀟å¡ã«é åžããããšãç®çãšããŠãããã®ã§ãããåå©çšäŒæ¥ã®æ¹éãš IPA ã«ããã¡ã¢ãªå¢èšã®å¹çšã®åŒã³æãã®å 容ãççŸããæ··ä¹±ãçããå ŽåããããŸããåå©çšäŒæ¥çã§ã¯ãã¡ã¢ãªå¢èšã®å¹çšãèªç€Ÿç€Ÿå¡ã«ç¥ãããããªãå ŽåããããŸããããã§ãåèšã®äžè¬çãªã¡ã¢ãªå¢èšã®å¹çšã®ã¡ãã»ãŒãžã¯ãããªãã¯çã§ã®ã¿è¡šç€ºãããããã«ãããã©ã€ããŒãçã§ã¯è¡šç€ºãããªãããã«ããŸããããªãããã©ã€ããŒãçã§ã¡ã¢ãªå¢èšã®å¹çšã®åŒã³æãã¡ãã»ãŒãžã埩掻ãããå Žåã¯ããã©ã€ããŒãçãœãŒã¹ã³ãŒãã®ãIPA-DN-ThinApps-Private\src\bin\hamcore\strtable_ja.patch.stbããã¡ã€ã«ã®ãDS_MEMORY_MSG_1ãããã³ãDS_MEMORY_MSG_2ãã®è¡ãåé€ããŠãã ããã
- beta7preview10 ã§è¿œå ãããããªã·ãŒèŠå¶ãµãŒããŒã®èšå®é ç®ã®ãREQUIRE_MINIMUM_CLIENT_BUILDããã誀ã£ãŠãREQUIRE_MIMIMUM_CLIENT_BUILDããšããã¹ãã«ãšãªã£ãŠãããæ£ããèšå®é ç®ã®èªã¿èŸŒã¿ãã§ããŸããã§ãããã¹ãã«ãã¹ãä¿®æ£ããŸãããæ£ããã¯ããREQUIRE_MINIMUM_CLIENT_BUILDãã§ãã
- beta7preview9 ã§è¿œå ãããã¢ã«ãŠã³ãããã¯ã¢ãŠãæ©èœã«ã€ããŠãåäœãæ¹è¯ããŸãããããã¯ã¢ãŠããçºçããŠããªãç¶æ ã§äœåºŠããŠãŒã¶ãŒèªèšŒã«å€±æã (äŸç¶ãšããŠããã¯ã¢ãŠãããã倿ªæºã®å€±æã®ç¶æ ã§)ããã®åŸããŠãŒã¶ãŒèªèšŒã« 1 床æåããå Žåã¯ãããã¯ã¢ãŠãã®ã«ãŠã³ãããŠã³ãã¯ãªã¢ããããã«ããŸããããŸãããŠãŒã¶ãŒèªèšŒã«å€±æããããšã奿©ãšãªã£ãŠã¢ã«ãŠã³ãããã¯ã¢ãŠããçºçããå Žåã¯ãããã¯ã¢ãŠããçºçããæšã®ãšã©ãŒã¡ãã»ãŒãžãè¿ãããã«ããŸããã
- MAC ã¢ãã¬ã¹èªèšŒãæå¹ã«ãããŠããå ŽåãéåžžããµãŒããŒèšå®ããŒã«ãçµäºããéã« MAC ã¢ãã¬ã¹ã 1 ã€ãããŒã«ã«èšå®ã§ç»é²ãããŠããªãå Žåã«ãèšå®ãä¿ãã¡ãã»ãŒãžããã¯ã¹ã衚瀺ãããŸããããããªãããããªã·ãŒèšå®ãã¡ã€ã«ã§ãSERVER_ALLOWED_MAC_LIST_URLãé ç®ãèšå®ãããŠããå ŽåãMAC ã¢ãã¬ã¹äžèЧã¯ããªã·ãŒèŠå¶ãµãŒããŒåŽã§ç®¡çããããšãå¯èœã«ãªããŸããããã§ããSERVER_ALLOWED_MAC_LIST_URLãé ç®ãèšå®ãããŠããå Žåã¯ãäžèšã®èšå®ãä¿ãã¡ãã»ãŒãžããã¯ã¹ã衚瀺ããªãããã«ããŸããããªããããªã·ãŒèšå®ãã¡ã€ã«ã«ãSERVER_ALLOWED_MAC_LIST_URLãé ç®ãèšå®ãããŠãããã®ã®ããã® URL ã誀ã£ãŠããããMAC ã¢ãã¬ã¹ãèšè¿°ããããã¹ããã¡ã€ã«ã®èšèŒã誀ã£ãŠãããããŠããå Žåã§ããã¡ãã»ãŒãžã®è¡šç€ºã¯çç¥ãããããã«ãªããŸããããªã·ãŒãã¡ã€ã«ã®ãSERVER_ALLOWED_MAC_LIST_URLãé ç®ãèšèŒãããéã¯ãååãæ³šæãã ããã
- ãµãŒããŒããã³ã¯ã©ã€ã¢ã³ãã¢ããªã®ãããã·èšå®ç»é¢ã«ããäžç¶ã·ã¹ãã ãžã®æ¥ç¶ãç¡å¹åããããªãã·ã§ã³ã远å ããŸããããã®ãªãã·ã§ã³ãæå¹ã«ãããšãäžç¶ã·ã¹ãã ãžã®éä¿¡ãçºçããªããªããŸãããã§ã«ãµãŒããŒããäžç¶ã·ã¹ãã ãžã®ã»ãã·ã§ã³ã確ç«ãããŠããå Žåã¯ãã»ãã·ã§ã³ã¯åæãããŸãã
- ã€ã³ã¹ããŒã©ã®ãã«ãã«ãããŠãã¯ã©ã€ã¢ã³ãã¢ããªã®ã¿ãå«ãã ã€ã³ã¹ããŒã©ããã«ãããããšãã§ããããã«ãªã£ãããœãŒã¹ã³ãŒãäžã®ãsrc/Vars/VarsActivePatch.hãã®ãThinSetupClientOnlyãé ç®ããtrueãã«å€æŽããããšã«ãããã¯ã©ã€ã¢ã³ãã¢ããªã®ã¿ãå«ãã€ã³ã¹ããŒã©ãäœæãããããã¯ã©ã€ã¢ã³ãã¢ããªãšãµãŒããŒã¢ããªã®äž¡æ¹ãå«ãã€ã³ã¹ããŒã©ããšããã¯ã©ã€ã¢ã³ãã®ã¿ãå«ãã€ã³ã¹ããŒã©ãã® 2 çš®é¡ããã«ããããå Žåã¯ãåããããã¡ã€ã«ãæžæããŠã2 åãã«ãããããšã(ããã¯ãå°ãææãã®å®è£ ã§ããããæ¬æ©èœã®éèŠã¯ããã»ã©å€ããªããããã容赊ããã ãããã) ãªãããThinSetupServerOnlyã ãš ãThinSetupClientOnlyã ã¯ããããäžæ¹ããæå®ã§ããªãŸããããThinSetupClientOnlyããšãThinSetupServerOnlyãã®äž¡æ¹ã true ã«ãããšãå šãæå³ã®ãªãã€ã³ã¹ããŒã©ãäœæãããŸãã®ã§ããæ³šæãã ããã
- ããªã·ãŒèŠå¶ãµãŒããŒã®èšå®é ç®ã«ãENFORCE_LIMITED_FIREWALL_COMPUTERNAME_STARTWITHãã远å ããŸããããã®èšå®ã¯ããENFORCE_LIMITED_FIREWALLãèšå®æ©èœ (ãå®å šéååãã¡ã€ã¢ãŠã©ãŒã«ãæ©èœã匷å¶çã«æå¹ã«ããæ©èœ) ãæå¹ã«ãããããã©ããäžéšã®ç«¯æ«ã«ã€ããŠã¯ç¡å¹ã«ããã (é€å€ããã) ãšãããããªå Žåã«å©çšã§ããŸãããã®é ç®ãšããŠèšå®ãããŠããæååããæ¥ç¶ããããšããŠããã¯ã©ã€ã¢ã³ãåŽã® Windows ã³ã³ãã¥ãŒã¿ã®ãã³ã³ãã¥ãŒã¿åãã®æååã®å é éšåã«äžèŽããå Žåã¯ãåœè©²ã¯ã©ã€ã¢ã³ãããã®æ¥ç¶ã«éããŠã¯ããENFORCE_LIMITED_FIREWALLãã 0 ã§ãããšã¿ãªããŠæ¥ç¶åŠçããããŸãããã®é ç®ã«ã¯ãã¹ããŒã¹ãã«ã³ããŸãã¯ã»ãã³ãã³åºåãã§ãè€æ°ã®æååãæå®ã§ããŸããè€æ°ã®æååãæå®ããå Žåããããã 1 ã€ãšäžèŽããå Žåã¯æå¹ã§ãããšã¿ãªãããŸãã倧æåã»å°æåã¯åºå¥ãããŸããããã®é ç®ã¯ããENFORCE_LIMITED_FIREWALLãèšå®é ç®ã 1 ã«èšå®ãããŠããå Žåã«ã®ã¿æå¹ã§ãããã®æ©èœã¯ãã·ã³ã»ãã¬ã¯ãŒã¯ã·ã¹ãã ã®ãããªãã¯çã§ã¯å©çšã§ããŸããã
- ã·ã³ã»ãã¬ã¯ãŒã¯ã·ã¹ãã ãµãŒããŒã®èªåã€ã³ã¹ããŒã© (ç¡äººã€ã³ã¹ããŒã©) (ã/auto:1ããšããã³ãã³ãã©ã€ã³ãªãã·ã§ã³ãæå®ããããšã§å©çšå¯èœ) ã«ãããŠã远å ã§ã/NOAFTERRUN:1ããšããã³ãã³ãã©ã€ã³ãªãã·ã§ã³ã«ã察å¿ããŸãããã/NOAFTERRUN:1ããèšå®ãããšãã€ã³ã¹ããŒã©å®äºåŸã«ããµãŒããŒèšå®ããŒã«ããèªåçã«èµ·åããªãããã«ãªããŸãã
- (LGWAN çã®ã¿) ãµãŒããŒã®èªåã€ã³ã¹ããŒã© (ç¡äººã€ã³ã¹ããŒã©) ãå©çšäžã«ãLGWAN çã®ãããã¯ãŒã¯èªåæ€åºåŸã«æ¬¡ã®ç»é¢ã«èªåçã«é²ãŸãªãåé¡ã解決ããã
- ããªã·ãŒèŠå¶ãµãŒããŒã®èšå®é ç®ã«ãREQUIRE_MINIMUM_CLIENT_BUILDãã远å ããŸããããã®é ç®ã«ã¯æŽæ°å€ãæå®ã§ããŸãããã®é ç®ãæå®ãããŠããå Žåã¯ããµãŒããŒã«æ¥ç¶ããããšããŠããã¯ã©ã€ã¢ã³ãã®ãã«ãçªå·ããæå®ãããçªå·æªæºã®å Žåã«ãã¯ã©ã€ã¢ã³ãåŽã«å¯ŸããŠããŒãžã§ã³ã¢ãããä¿ããšã©ãŒã¡ãã»ãŒãžã衚瀺ãããæ¥ç¶ãæåŠãããŸãããã®æ©èœã¯ãå€ãããŒãžã§ã³ã®ã¯ã©ã€ã¢ã³ãããã®æ¥ç¶ãæåŠãããå Žåã«å©çšã§ããŸããããšãã°ãå€ãããŒãžã§ã³ã®ã¯ã©ã€ã¢ã³ãã«ã¯ããã»ãã¥ãªãã£æ©èœãååšããªãå Žåããã®ãããªå€ãã¯ã©ã€ã¢ã³ãã®æ¥ç¶ãçŠæ¢ããããšãã§ããŸãããREQUIRE_MINIMUM_CLIENT_BUILDãã®å€ã¯ããµãŒããŒåŽã®ãœãããŠã§ã¢èªèº«ã®ãã«ãçªå·ä»¥äžã§ãªããã°ãªããŸããã(ãµãŒããŒåŽã®ãœãããŠã§ã¢ã®ãã«ãçªå·ãè¶ ããå€ãèšå®ãããŠããå Žåã¯ããµãŒããŒåŽã®ãœãããŠã§ã¢ã®ãã«ãçªå·ãèšå®ãããŠãããšã¿ãªãããŸãã) ãã®æ©èœã¯ãã·ã³ã»ãã¬ã¯ãŒã¯ã·ã¹ãã ã®ãããªãã¯çã§ã¯å©çšã§ããŸããããã®æ©èœã¯ãã¯ã©ã€ã¢ã³ãããã®ãããã³ã«äžã®èªå·±ç³åå€ãä¿¡çšããŠåäœããŸããã¯ã©ã€ã¢ã³ããäžæ£ã«æ¹é ãããŠããå Žåã§ãå®éãšç°ãªããã«ãçªå·ãã¯ã©ã€ã¢ã³ãã䞻匵ããå Žåã¯ããµãŒããŒã¯ãããèŠåããããšãã§ããŸããã®ã§ããæ³šæãã ãããæ¬æ©èœã¯ãããŸã§ãäžè¬çãªãŠãŒã¶ãŒã«ããå€ãããŒãžã§ã³ã«ããæ¥ç¶ãèŠå¶ãããã®ã§ãããé«åºŠãªãŠãŒã¶ãŒã«ããå€ãããŒãžã§ã³ã®ã¯ã©ã€ã¢ã³ãããã®æ¥ç¶ããã¹ãŠé®æã§ãããã®ã§ã¯ãããŸããã
- ã·ã³ã»ãã¬ã¯ãŒã¯ã·ã¹ãã ãµãŒããŒã®èªåã€ã³ã¹ããŒã© (ç¡äººã€ã³ã¹ããŒã©) ã«å¯Ÿå¿ããã倧éã®ã³ã³ãã¥ãŒã¿ãžã®ãµãŒããŒã®ã€ã³ã¹ããŒã«ãå¿«é©ã«ãªããã€ã³ã¹ããŒã©ã® EXE ãã¡ã€ã«ãå®è¡ããéã«ã/auto:1ããšããã³ãã³ãã©ã€ã³ãªãã·ã§ã³ãæå®ããããšã«ãããã€ã³ã¹ããŒã©ã¯ããã©ã«ãã®ãªãã·ã§ã³ã®ãŸãŸãç¡äººã§æåŸãŸã§é²ã¿ããµãŒããŒèšå®ããŒã«ãèªåçã«èµ·åãããšãããŸã§é²ãããã«ãªãããªãããã®ã³ãã³ãã©ã€ã³ãªãã·ã§ã³ãæå®ããŠå®è¡ããéã«ã¯ãAdministrators æš©éãå¿ èŠã§ãããæš©éããªãå Žåã¯ãUAC ãããã¢ããã衚瀺ãããããŸããã€ã³ã¹ããŒã«äžã«ããã©ã«ãã§æ¬¡ã«é²ãããšãã§ããªããããªãšã©ãŒãçºçããå Žåã¯ãåœè©²ãšã©ãŒã®è¡šç€ºéšåã§åæ¢ããã®ã§ããã以éã¯æåã§ã€ã³ã¹ããŒã«ãããå¿ èŠãããã
- ãã©ã€ããŒãçã§å®å šéååãã¡ã€ã¢ãŠã©ãŒã«æ©èœã«å¯Ÿå¿ãããã¢ããªã±ãŒã·ã§ã³ãã«ãæã«ãããŠããœãŒã¹ã³ãŒãäžã®ãsrc/Vars/VarsActivePatch.hãã®ãThinFwModeãé ç®ããtrueãã«å€æŽããããšã«ããããå®å šéååãã¡ã€ã¢ãŠã©ãŒã«ãæ©èœãã¯ã©ã€ã¢ã³ãæ¥ç¶æã«åŒã³åºãããããã«ãªãããå®å šéååãã¡ã€ã¢ãŠã©ãŒã«ãã«ãããŠéä¿¡ãäŸå€çã«èš±å¯ããéä¿¡å IP ã¢ãã¬ã¹ (IP ãµãããã) ã®ãªã¹ãã¯ãã€ã³ã¹ããŒã©ã®ãã«ãæã«äºããsrc/bin/hamcore/WhiteListRules.txtãã«åæããŠããå¿ èŠããããã¯ã©ã€ã¢ã³ãåŽãæ°ããããŒãžã§ã³ãå¿ èŠã§ããã
- ã¢ããªã®ã€ã³ã¹ããŒã©ãã«ãæã®ãœãŒã¹ã³ãŒãäžã®ãsrc/Vars/VarsActivePatch.hãã®ãThinFwModeãé ç®ããfalseãã®å Žåã§ãã£ãŠããããªã·ãŒèŠå¶ãµãŒããŒã§ãENFORCE_LIMITED_FIREWALLãé ç®ãã1ãã«èšå®ããããšã«ããããå®å šéååãã¡ã€ã¢ãŠã©ãŒã«ãæ©èœã匷å¶çã«æå¹ã«ããããšãã§ããããã«ãããã¯ã©ã€ã¢ã³ãåŽãæ°ããããŒãžã§ã³ãå¿ èŠã§ããããã©ã€ããŒãçãš LGWAN çã§ã¯å©çšã§ãããããããªãã¯çã§ã¯å©çšã§ããªãã
- ãµãŒããŒåŽã§ãtunnel_logããã£ã¬ã¯ããªã«ãµãŒããŒãšäžç¶ã·ã¹ãã ãšã®éã®éä¿¡ã®è©³çްãªãã°ãåºåããããã«ããããµãŒããŒãšäžç¶ã·ã¹ãã ãšã®éãé »ç¹ã«åãããããªå Žåã¯ããã®ãã°ã確èªããããšã«ãããåå ãç¹å®ããããšã容æãšãªãã
- ã€ã³ã¹ããŒã©ã®ãã«ãã«ãããŠããµãŒããŒã¢ããªã®ã¿ãå«ãã ã€ã³ã¹ããŒã©ããã«ãããããšãã§ããããã«ãªã£ãããœãŒã¹ã³ãŒãäžã®ãsrc/Vars/VarsActivePatch.hãã®ãThinSetupServerOnlyãé ç®ããtrueãã«å€æŽããããšã«ããããµãŒããŒã¢ããªã®ã¿ãå«ãã€ã³ã¹ããŒã©ãäœæãããããã¯ã©ã€ã¢ã³ãã¢ããªãšãµãŒããŒã¢ããªã®äž¡æ¹ãå«ãã€ã³ã¹ããŒã©ããšãããµãŒããŒã¢ããªã®ã¿ãå«ãã€ã³ã¹ããŒã©ãã® 2 çš®é¡ããã«ããããå Žåã¯ãåããããã¡ã€ã«ãæžæããŠã2 åãã«ãããããšã(ããã¯ãå°ãææãã®å®è£ ã§ããããæ¬æ©èœã®éèŠã¯ããã»ã©å€ããªããããã容赊ããã ãããã)
- ãMAC ã¢ãã¬ã¹èªèšŒã«ããã MAC ã¢ãã¬ã¹ã®ãªã¹ãããããªã·ãŒèŠå¶ãµãŒããŒåŽã§äžå 管çãããŠãŒã¶ãŒã«èªç±ã«ç®¡çãããããªãããšããèŠæã«å¯Ÿå¿ãããããããªã·ãŒèŠå¶ãµãŒããŒã®èšå®ãã¡ã€ã«ã«ãNO_LOCAL_MAC_ADDRESS_LISTãã远å ããããããã1ãã«èšå®ããããšã«ããããŠãŒã¶ãŒã¯ MAC ã¢ãã¬ã¹èªèšŒã«ããã MAC ã¢ãã¬ã¹ã®ãªã¹ããæåã§èšå®ããããšãã§ããªããªãããªãããNO_LOCAL_MAC_ADDRESS_LISTããæå¹ãšãªãããã«ã¯ãããªã·ãŒèšå®ãã¡ã€ã«ã®ãCLIENT_ALLOWED_MAC_LIST_URLãããã³ãENFORCE_MACCHECKããèšå®ãããŠããå¿ èŠãããã
- LGWAN çã«ãããŠãã¯ã©ã€ã¢ã³ãã Administrators ãŸã㯠SYSTEM æš©éã§åäœããŠããå Žåã¯ããŠãŒã¶ãŒãæå®ãã mstsc.exe ãã¡ã€ã«ãå®è¡ããããšãã§ããªãããã«ããã
- OTP ã«ãããŠãSMTP (ã¡ãŒã«) ã®ä»£ããã« AWS SNS (Amazon Simple Notification Service) ãçšãã SMS éä¿¡ã«å¯Ÿå¿ããã(ãã€ããŒã¹ã±ãŒã«çã®ã¿ã) 詳现ã¯ããã€ããŒã¹ã±ãŒã«çã®ããã¥ã¡ã³ãã® 8-19 ç¯ãOTP ãé»åã¡ãŒã«ã®ä»£ããã« SMS ã§éä¿¡ããæ¹æ³ããåç §ããããšã
- ã€ã³ã¹ããŒã©ã® EXE ãã¡ã€ã«ãšåããã£ã¬ã¯ããªã« EntryPoint.dat ãã¡ã€ã« (ããã¹ããã¡ã€ã«) ãèšçœ®ãããŠããå Žåã¯ããã®ãã¡ã€ã«ããã€ã³ã¹ããŒã©ãã«ãæã«åã蟌ãŸãã EntryPoint.dat ãã¡ã€ã«ã«åªå ããŠããµãŒããŒãšå ±ã«ã€ã³ã¹ããŒã«ãããããã«ãããããã¯ãããšãã°ã·ã³ã»ãã¬ã¯ãŒã¯ã·ã¹ãã äžç¶ã·ã¹ãã ãçµã¿èŸŒãã ã¢ãã©ã€ã¢ã³ã¹ãå®è£ ãããšããHTML 管çç»é¢çããããã®äžç¶ã·ã¹ãã ã«æ¥ç¶ã§ããã€ã³ã¹ããŒã©ã® ZIP ãã¡ã€ã«ãããŠã³ããŒãã§ãããããªæ©èœãå®è£ ããéã«ã倧å€äŸ¿å©ã§ãããEXE ãã¡ã€ã«ãã®ãã®ã¯ãã¹ãŠã®ã·ã¹ãã ã§å ±éã«ããŠãããEntryPoint.dat ãã¡ã€ã«ã®ã¿ãã·ã¹ãã æ¯ã«ç°ãªããã¡ã€ã«ãèªåçæã㊠ZIP ã§ããŠã³ããŒãå¯èœãšããã·ã¹ãã ãã容æã«æ§ç¯ã§ããããã«ãªã£ãããã®ããšã«ããããŠãŒã¶ãŒã¯ã€ã³ã¹ããŒã©ãç¬èªã«ãã«ãããå¿ èŠããªããåœè©²ã¢ãã©ã€ã¢ã³ã¹ã®è£œé å ã 1 åã®ã¿ãã«ãããã°ããããããŠããã®ããšã¯ Microsoft Authenticode 眲åãã€ã³ã¹ããŒã©ã«ã¢ãã©ã€ã¢ã³ã¹åºè·å ããããããä»äžããããšãã§ããããšãæå³ããã®ã§ããã
- ã¯ã©ã€ã¢ã³ãèšŒææžèªèšŒã«ããã OCSP (Online Certificate Status Protocol) æ€èšŒã®å®è£ ãããªã·ãŒèŠå¶ãµãŒããŒã®ãENABLE_OCSPãé ç®ãã1ãã«èšå®ããããšã«ããããµãŒããŒã¯ãã¯ã©ã€ã¢ã³ãèšŒææžèªèšŒèŠæ±ããã£ãå Žåã§ããã€èªèšŒããµãŒããŒã«ãããããç»é²ãããŠããä¿¡é ŒãããèšŒææž (CA ç) ã«ãã眲åã®æ€èšŒã«ãã£ãŠå®æœãããå Žåã«ãåœè©²ã¯ã©ã€ã¢ã³ãèšŒææžã®æ¡åŒµãã£ãŒã«ãã« OCSP ãµãŒããŒã® URL ãèšèŒãããŠããå Žåã¯ããã® OCSP ãµãŒããŒã® URL å®ã« OCSP ãããã³ã«ã«ããèšŒææžãæå¹ãã©ããã®æ€èšŒã詊ã¿ãŸããç¡å¹ã§ãããšåçãããå Žåã¯ããã°ãã¡ã€ã«ã«ãã®æšãèšèŒããèšŒææžèªèšŒã¯å€±æããŸããOCSP ãµãŒããŒãšã®éä¿¡ã«å€±æããå Žåã¯ãæ€èšŒã¯æåãããã®ãšã¿ãªãããŸãã
- ã¢ã«ãŠã³ãããã¯ã¢ãŠãæ©èœã®å®è£ ãããªã·ãŒèŠå¶ãµãŒããŒã®ãAUTH_LOCKOUT_COUNTãããã³ãAUTH_LOCKOUT_TIMEOUTãé ç®ã 1 以äžã®æŽæ°ã«èšå®ããããšã«ããããŠãŒã¶ãŒèªèšŒ (ãã¹ã¯ãŒãèªèšŒ) ã«ãããŠãã¹ã¯ãŒãã誀ã£ãå Žåã®ã¢ã«ãŠã³ãããã¯ã¢ãŠããå¯èœãšãªããŸãããAUTH_LOCKOUT_COUNT ã«ã¯ãããã¯ã¢ãŠããçºçãããŸã§ã®èªèšŒå€±æåæ°ãæå®ããŸããAUTH_LOCKOUT_TIMEOUT ã«ã¯ãããã¯ã¢ãŠããèªåè§£é€ããããŸã§ã®ã¿ã€ã ã¢ãŠãå€ãç§åäœã§æå®ããŸãã
- ç¡æäœæã®ã¿ã€ã ã¢ãŠãå®è£ ãããªã·ãŒèŠå¶ãµãŒããŒã®ãIDLE_TIMEOUTãé ç®ã 300 以äžã®æŽæ°ã«èšå®ããããšã«ããããŠãŒã¶ãŒãã¯ã©ã€ã¢ã³ãåŽã§ããŠã¹ããIDLE_TIMEOUTãã§æå®ãããç§æ°ä»¥äžç¡æäœã§ãã£ãå Žåã¯ãã¯ã©ã€ã¢ã³ãåŽã®æ¥ç¶ãåæãããç¡æäœã¿ã€ã ã¢ãŠããçºçããæšã®ã¡ãã»ãŒãžããã¯ã¹ãã¯ã©ã€ã¢ã³ãåŽã®ç»é¢ã«è¡šç€ºãããããã«ãªããŸãããã®æ©èœãæå¹ãšãªãã«ã¯ãã¯ã©ã€ã¢ã³ãåŽã®ããŒãžã§ã³ã beta7preview9 以éã§ããå¿ èŠããããŸãããã以åã®ã¯ã©ã€ã¢ã³ãã®å Žåã¯ãç¡èŠãããŸãã
- ããªã·ãŒèŠå¶ãµãŒããŒã®ãSERVER_ALLOWED_MAC_LIST_URLãã«ãã MAC ã¢ãã¬ã¹äžèЧããã¹ããã¡ã€ã«ã®æå®ã«ãããŠãMAC ã¢ãã¬ã¹äžèЧããã¹ããã¡ã€ã«ã®å é è¡ã« UTF-8 ã® BOM æåãå ¥ã£ãŠããå Žåããã® BOM æåãé€å€ããŠåŠçãè¡ãªãããã«æ¹è¯ããŸããã
- 空ãã¡ã¢ãªå®¹éãååã§ãªãå ŽåãããµãŒããŒèšå®ããŒã«ãã§èŠåã¡ãã»ãŒãžã衚瀺ãããããã«ããŸããã
- ãã©ã€ããŒãç (ãã€ããŒã¹ã±ãŒã«ç) ãå®è£ ããŸããã
- ã³ã³ãããŒã©ã®å®å šåé·ã«å¯Ÿå¿ããŸããã
- ãµãŒããŒçã§è©³çްãããã°ãã°ãä¿åããæ©èœãå®è£ ããŸããã
- (LGWAN çã®ã¿) ã€ã³ã¹ããŒã«æã« RDP ãããªã·ãŒã§ç¡å¹ã«ãªã£ãŠããå Žåã¯ãã¯ãªããããŒãããã³ãã¡ã€ã«å ±æãã€ã³ã¹ããŒã«æã«ç¡å¹åãããã®ä»£ãããæ¯åã®æ¥ç¶æã«ã¯ããªã·ãŒãããããªãããã«ããããŸããã€ã³ã¹ããŒã«æã« RDP ãããªã·ãŒã§ç¡å¹ã«ãªã£ãŠããå Žåã¯ããã®æšã®ã¡ãã»ãŒãžã衚瀺ããããã«ããã
- ãµãŒããŒåŽãœãããŠã§ã¢ã«ãããŠãWindows ã®ããŒã«ã«ã°ã«ãŒãããªã·ãŒãŸãã¯ãã¡ã€ã³ã°ã«ãŒãããªã·ãŒã§ãªã¢ãŒããã¹ã¯ããããç¡å¹ã§ããå Žåã§ãæ¥ç¶å仿ã«åŒ·å¶çã«æå¹ã«ããããã«ããŸããã
- ã¯ã©ã€ã¢ã³ãæ¥ç¶äžã¯ã¯ã©ã€ã¢ã³ãåŽ PC ã®ã·ã¹ãã ãã¹ãªãŒãããªãããã«ããŸããã
- çµ±èšæ©èœãå®è£ ããŸããã
- ãã©ã€ããŒãç (ã¹ã¿ã³ãã¢ãã³ç) ãå®è£ ããŸããã
- Windows ã«ãã㊠Admin æš©éãæããŠãããã©ããã®å€å®ãå³å¯åããŸããã
- (LGWAN çã®ã¿) ã¯ãªããããŒãå±¥æŽã®ä¿åãçŠæ¢ããŸãããWindows æšæºã®ã¹ã¯ãªãŒã³ã·ã§ãããããããŒã«ããã¹ã¯ãªãŒã³ã·ã§ããæ®åœ±ãçŠæ¢ããŸããã
- ãµãŒããŒã§ãªã¢ãŒãã¢ã¯ã»ã¹äžã«ãããããã»ã¹ã®èµ·å / çµäºã®ãã°ãä¿åã§ããããã«ããŸããã
- ã²ãŒããŠã§ã€ã§ DisableDoSProtection ãªãã·ã§ã³ãå®è£ ããŸããã
- LGWAN çãå®è£ ããŸããã
- ããªã·ãŒã§ OTPãMAC ã¢ãã¬ã¹æ€æ»ãã¯ã©ã€ã¢ã³ãæ€ç«æ€æ»ãéãã ã匷å¶çã«ç¡å¹åã§ããããã«ããŸããã
- MAC ã¢ãã¬ã¹ãªã¹ãããã«ãã¹ã¬ããç«¶åã«ãã£ãŠçšã«æ¶ããŠããŸãåé¡ã解決ããŸããã
- å®å šéå FW ããªãã·ã§ã³ã§ OFF ã«ãã§ããããã«ããŸããã
- ç»é²ããŒã«å¯Ÿå¿ããŸããã
- Proxy Protocol ã«å¯Ÿå¿ããŸããã
- Windows 10 2004 ã¯ãªãŒã³ã€ã³ã¹ããŒã«ç°å¢ã§ãWindows Hello èªèšŒãã匷å¶ãããŠããå Žåã¯ãRDP æ¥ç¶ãã§ããªãåé¡ãããããã匷å¶ãè§£é€ããããã«ããŸããã
- ãœãŒã¹ã³ãŒãããµãã¢ãžã¥ãŒã«ã«åé¢ããã¢ã¯ãã£ããããããã©ã³ãã£ã³ã°ãå¯èœã«ããŸããã
- Visual Studio 2019 ã«ãããã«ãã«å¯Ÿå¿ããŸããã
- WhiteList Rules ã§ãã©ã€ããŒã IP ã®ç¯å²ãééã£ãŠããã®ãä¿®æ£ããŸããã
- è¡æ¿ã¢ãŒãã§ãµãŒããŒåŽãæ€ç« ON ã®å Žåã¯ãå¿ ã FW æ©èœã匷å¶ããããã«ããŸããã
- Wake on LAN æ©èœ (æ¥ç¶å 端æ«ã®é»æºãèªå® ãã ON ããæ©èœ)
- ç»é¢æ®åœ±ã»ãã£ããã£é²æ¢ã®ããã®é»åéããæ©èœ
- åºæ ID åæåæ©èœ (VDI ã¯ããŒã³å¯Ÿå¿)
- ã¯ã©ã€ã¢ã³ã MAC ã¢ãã¬ã¹èªèšŒã®ããªã·ãŒãµãŒããŒã«ãããªã¹ãäžå ç®¡çæ©èœ
- å®å šéåå FW æ©èœ (ãªã¢ãŒãå©çšäžã¯ãŠãŒã¶ãŒèªå® PC ãšã€ã³ã¿ãŒããããšã®éãå®å šã«é®æ)
- ããªã·ãŒãµãŒããŒã«ãããµãŒããŒç«¯æ«ã®æç€ºççä¿¡èš±å¯æ©èœ (ãªã¹ãã«ç»é²ãããŠããªããµãŒããŒç«¯æ«ã¯åäœçŠæ¢ãã)
- äºèŠçŽ èªèšŒã»ã¯ã³ã¿ã€ã ãã¹ã¯ãŒã (OTP) æ©èœ
- ãã€ãã³ããŒã«ãŒããçšãããŠãŒã¶ãŒèªèšŒæ©èœ
- ã¯ã©ã€ã¢ã³ãæ€ç«æ©èœã»MAC ã¢ãã¬ã¹èªèšŒæ©èœ
- ãšã³ã¿ãŒãã©ã€ãºç°å¢çšããªã·ãŒèŠå¶ãµãŒããŒæ©èœ
- è¡æ¿æ å ±ã·ã¹ãã é©å¿ã¢ãŒã (äžç¶ã·ã¹ãã ã® IP ç¯å²ã®éå®)
- ãã¯ã³ã¿ã€ã ãã¹ã¯ãŒãèªèšŒ (OTP)ã ã远å ããŸãããäŒæ¥ç°å¢ã§ã®æ¢åã®ã»ãã¥ãªãã£ããªã·ãŒã«æºæ ããããããäºèŠçŽ èªèšŒã«å¯Ÿå¿ããŠã»ãããããOTP ã«å¯Ÿå¿ããŠã»ããããšãããèŠæã«ãå¿ãããŠãæ°èŠéçºãããããŸããã
- ãä»®æ³ãã«ããã£ã¹ãã¬ã€æ©èœãã远å ããŸããããè·å Žã® PCãã«ãã£ã¹ãã¬ã€ã 1 æãããªãå Žåã§ããèªå® ã® PC ã«ãã£ã¹ãã¬ã€ã 2 æä»¥äžããã°ãèªå® ããè·å Žã® PC ããªã¢ãŒãæäœããéã«ãã«ããã£ã¹ãã¬ã€åããŠã倧å€å¿«é©ã«æäœããããšãã§ããŸãã
- ããã¹ã¯ãŒãè€éæ§ãæºãããŠããªããŠããèŠåãç¡èŠããã°ç°¡åãªãã¹ã¯ãŒããèšå®ã§ããã®ã¯è¯ããªãã®ã§ã¯ãªãããããšãããæèŠãããã ããŸããã®ã§ããã¹ã¯ãŒãè€éæ§ãæºãããŠããªããã¹ã¯ãŒããèšå®ããããšãã§ããªãããŸããã(Beta 2 ãŸã§ã¯èŠåã¡ãã»ãŒãžã¯ç¡èŠå¯èœã§ããããBeta 3 ã§ã¯ãç¡èŠå¯èœãªèŠåã¡ãã»ãŒãžã¯å»æ¢ãããç¡èŠããããšãã§ããªããšã©ãŒã¡ãã»ãŒãžãšãªããŸããã)
- ãã¹ã¯ãŒãè€éæ§ã®èŠåãèŠçŽãã(1) 8 æå以äžã§ãå°æåã»å€§æåã»æ°åã»èšå·ã®ãã¡å°ãªããšã 3 çš®é¡ä»¥äžã䜿çšãããŠããã(2) 16 æå以äžã§ãå°æåã»å€§æåã»æ°åã»èšå·ã®ãã¡å°ãªããšã 2 çš®é¡ä»¥äžã䜿çšãããŠããã(3) 24 æå以äžã§ãããã®ãããããæºãããŠããã°å¯ãšããŸããã
- ãã·ã³ã»ãã¬ã¯ãŒã¯ã·ã¹ãã ãµãŒããŒãããã³ãã·ã³ã»ãã¬ã¯ãŒã¯ã·ã¹ãã ã¯ã©ã€ã¢ã³ãããšãäžç¶ã·ã¹ãã ãšã®éã®éä¿¡ã®ã»ãã¥ãªã㣠(å¯çšæ§) ãåäžããŸãããäžç¶ã·ã¹ãã ã«ãããããŒããã©ã³ãµãšã®éã®éä¿¡ããäœããã®éä¿¡é害ã«ãã確ç«ã§ããªãå Žåã¯ãã»ã«ã³ããªããŒããã©ã³ãµã«å¯ŸããŠæ¥ç¶ã詊ã¿ãããã«ãªããŸããããŸããã»ã«ã³ããªããŒããã©ã³ãµããè€æ°ã®ãã¡ã€ã³ããã³ AS ã«åæ£ããŠé 眮ããŸãããããã«ãããéä¿¡çµè·¯ã«é害ããã 1 ã€ã®ããŒããã©ã³ãµãšéä¿¡ãã§ããªãå Žåã§ããä»ã®ããŒããã©ã³ãµã«è¿åããŠéä¿¡ã確ç«ã§ããããã«ãªããŸããã
- ãã·ã³ã»ãã¬ã¯ãŒã¯ã·ã¹ãã ã¯ã©ã€ã¢ã³ããã®èµ·åæã«ãããæ°ããããŒãžã§ã³ãå©çšå¯èœã«ãªã£ãŠããå Žåã¯ç»é¢ã«æ¡å ã衚瀺ããããã«ããŸããããã®æ©èœã¯ããããŒãžã§ã³æ å ±ãç»é¢ããç¡å¹ã«ã§ããŸãã
- ãé«åºŠãªãŠãŒã¶ãŒèªèšŒãæ©èœã®èšŒææžèªèšŒã§ãX.509 èšŒææžã®ãããæ°ã 1024 bit ãã倧ããå Žåã«èªèšŒã«å€±æããåé¡ã解決ããŸããã
- HTTP ãããã·ãµãŒããŒãçµç±ããå Žåã® User Agent ã®æååããŠãŒã¶ãŒãèªç±ã«å€æŽã§ããããã«ããŸããã
- ã°ã«ãŒãããªã·ãŒã§ RDP ãç¡å¹ãšãªã£ãŠããå Žåã§ããRDP ãçšããã·ã¹ãã ã¢ãŒãã§ã®æ¥ç¶ãã§ããããã«ããŸããã
- ãŠãŒã¶ãŒã®ã³ã³ãã¥ãŒã¿ã®ããŒããã£ã¹ã¯ãäºãæ»æè ã«ããå¥ã®ææ®µã«ãã䟵害ããããã«ãŠã§ã¢ã®ãã¡ã€ã«ãä¿åãããŠããå Žåã§ããŠãŒã¶ãŒããåœè©²ãã«ãŠã§ã¢ãšåããã£ã¬ã¯ããªã«æ¬ããã°ã©ã ã®ã€ã³ã¹ããŒã©ã眮ããŠå®è¡ãããšããã«ãŠã§ã¢ãå®è¡ãããŠããŸãå Žåãããã»ãã¥ãªãã£åé¡ã解決ããŸãããããã¯ãããã DLL ããªããŒãåé¡ãšåŒã°ãã Windows ã®èšèšäžã®è匱æ§ãããšã§çºçããåé¡ã§ããã¢ããªã±ãŒã·ã§ã³åŽã§ã®å¯ŸçãæœããŸãããæ¥äžéšåžæ°ããã®å ±åã«ãããã®ã§ããããããšãããããŸããã
- ã¯ã©ã€ã¢ã³ãã«ããªã©ãã¯ã¹ã»ã¢ãŒããã远å ããŸããããã¬ã¯ãŒã¯ã®éå§åã«ããªã©ãã¯ã¹ããããšãã§ããŸããããã©ã«ãã§ç¡å¹ã«ãªã£ãŠããŸãããã¯ã©ã€ã¢ã³ãã®ãªãã·ã§ã³èšå®ããæå¹ã«ã§ããŸãããã²ãæå¹ã«ããŠã¿ãŠãã ããã
æåã®ããŒãžã§ã³ã§ãã