SSL PKI EFS STPP

Similar documents
Windows Oracle -Web - Copyright Oracle Corporation Japan, All rights reserved.

IC API

1. PKI (EDB/PKI) (Single Sign On; SSO) (PKI) ( ) Private PKI, Free Software ITRC 20th Meeting (Oct. 5, 2006) T. The University of Tokush

Windowsクライアント管理の重要性と 工数削減のテクニック

82801pdf.pqxp

untitled

/02/ /09/ /05/ /02/ CA /11/09 OCSP SubjectAltName /12/02 SECOM Passport for Web SR

GTSC Security Response Team Microsoft Asia Limited ( ) 2

BIG‑IP Access Policy Manager | F5 Datasheet

Oracle Identity Managementの概要およびアーキテクチャ

/07/ /10/12 I

untitled

Juniper Networks Corporate PowerPoint Template

EMC® RepliStor® for Microsoft Windows バージョン 6.2 SP2インストール・ガイド

Faronics Core User Guide

FileMaker Server Getting Started Guide

FileMaker Server Getting Started Guide

Win XP SP3 Japanese Ed. NCP IPSec client Hub L3 SW SRX100 Policy base VPN fe-0/0/0 vlan.0 Win 2003 SVR /

untitled

Windows PC/ BCP () PC (BYOD: Bring Your Own Device) Windows 8 2 Windows 8 Windows 8 Windows Windows 8 Windows 8 Windows 8 PC/ 2

"CAS を利用した Single Sign On 環境の構築"

"CAS を利用した Single Sign On 環境の構築"

FirePass Edge Client TM Edge Client LAN Edge Client 7.0 Edge Client Edge Client Edge Client Edge Client Edge Client Edge Client LAN Edge Client VPN Wi

Microsoft Intune MDM ソリューション向けDigiCert® 統合ガイド

Windows Server の セキュリティ概要

new_logo.eps

Cisco® ASA シリーズルーター向けDigiCert® 統合ガイド

実施していただく前に

Web Microsoft 2008 R2 Database Database!! Database 04 08

3. RIR 3.1. RIR Regional Internet Registry APNIC Asia Pacific Network Information Centre RIR RIPE NCC Réseaux IP Européens Network Coordination Centre

Mac OS X Server Windows NTからの移行

IW2001-B2 1 Internet Week 2001 ( ) Copyright 2001 All Rights Reserved, by Seiji Kumagai IW2001-B2 2 CodeRed Copyright 2001 All Rights

Part 1 IT CPU IT IT 1998 Windows NT Server 4.0, Terminal Server Edition 1 Windows Based Terminal WBT Windows CE 1 100Mbps 1Gbps LAN OS 1 PC 1 OS 2

untitled

wp_integrating_AD_10.9_16JAN2014

,,, J-SOX ISMS PCIDSS,, IM/VoIP/VoD Copyright 2008 Juniper Networks, Inc. 2

Windows Vista Smartcard summary

Dec , IS p. 1/60

Windows 10 Windows 10 IT Windows 10 MSDN Windows 10 Pro Windows 10 Enterprise Microsoft Store Windows 10 Pro MSDN Windows 10 Pro Windows 10 Enterprise

C02.pdf

ノベルライセンスプログラム価格表

電子メールのセキュリティ

N manual_JP.PDF

P2P? ( )? ( SOX ) ( ) COPYRIGHT 2005 SSH COMMUNICATIONS SECURITY CORP. ALL RIGHTS RESERVED. 2

wp_integrating_active_directory_ml

<Documents Title Here>

FileMaker Server 9 Getting Started Guide

Office BCP () Office Microsoft Exchange Exchange Server Exchange Online Exchange Server Exchange Online Exchange Exchange 1997 Exc

Oracle Change Management Pack, Oracle Diagnostics Pack, Oracle Tuning Packインストレーション・ガイド リリース2.2

Microsoft SharePoint Server 2010SharePoint Server 2010Web SharePointSharePoint Server 2010 SharePoint SharePoint Server 2010 SharePoint SharePoint Sha

<Documents Title Here>

ISE の BYOD に使用する Windows サーバ AD 2012 の SCEP RA 証明書を更新する

2 BIG-IP 800 LTM v HF2 V LTM L L L IP GUI VLAN.

8 PC CoIT (Consumerization of IT) BCP () PC BYOD (Bring Your Own Device) BYOD IT IT IT IT PC/ 2

Oracle Application Server 10g(9

One Core, One Windows Windows Xbox 360 Xbox One Windows 8 Windows 8.1 OS Windows Phone 8.1 Windows Phone 8 OS OS Devices + IoT Adaptive User Interface

Windows7移行ガイド

FileMaker Server 16 インストールおよび構成ガイド

RouteMagic Controller RMC-MP200 / MP Version

Windows SE RAC 10g 構築手順書

"CAS を利用した Single Sign On 環境の構築"

FileMaker Server Getting Started Guide

Systemwalker IT Service Management Systemwalker IT Service Management V11.0L10 IT Service Management - Centric Manager Windows

Systemwalker Desktop Patrol V15 資産管理集計機能 説明書

Insert VERITAS™ White Paper Title Here

Configuration Manager (SCCM) + IT IT PC IT PC PC Windows XP OS 移行は簡単! P.7 SCCM / SCCM PC OS Configuration Manager PC PC 2

RouteMagic Controller( RMC ) 3.6 RMC RouteMagic RouteMagic Controller RouteMagic Controller MP1200 / MP200 Version 3.6 RouteMagic Controller Version 3

untitled

Microsoft Global Briefing Technical Briefing

1 Microsoft Windows Server 2012 Windows Server Windows Azure Hyper-V Windows Server 2012 Datacenter/Standard Hyper-V Windows Server Windo

untitled

IT Office 365 Microsoft Office 365 IT Office 365 IT Microsoft Office 365 IT WiPro WiPro Technologies Microsoft SharePoint 2IT Office 365 TechTarget

iPhone/iPad/Android(TM) とベリサイン アイデンティティプロテクション(VIP)エンタープライズゲートウェイとの組み合わせによるL2TP+IPsecのワンタイムパスワード設定例

GENESYS2005_Instal_Guide.PDF

FileMaker Server 8 Administrator’s Guide

Windowsユーザーの為のOracle Database セキュリティ入門

FileMaker Server 15 入門ガイド

JP1/Integrated Management - Service Support 操作ガイド

Logitec NAS シリーズ ソフトウェアマニュアル

<Documents Title Here>

Epson Print Admin

Microsoft Enterprise Mobility License

HotFixInfo_ xls

Web STEPS Web Web Form Cookie HTTP STEPS Web

rzammpdf.ps

Logitec NAS シリーズ ソフトウェアマニュアル

Oracle8 Workgroup Server for Windows NTインストレーション・ガイド,リリース8.0.6

P3FY-A JP.PDF

Configuring_01

PowerPoint プレゼンテーション

P X-M PowerChute Business Edition v7.0.5 Basic 84 E

Oracle Fail Safe For Windows NT and Windows 2000 リリース・ノート、リリース 3.1.2

Install.PDF

Enhancements In Certificate Service

InterSafe Personal_v2.3 ユーザーズガイド_初版

ITS資料

DS_BIG-IP LTM VE_jp.indd

<Documents Title Here>

VMware View Persona Management

PowerPoint Presentation

Transcription:

.NET

SSL PKI EFS STPP

Windows NTLM (KDC) SSL/TLS, NTLM, SSL/TLS,

Active Active Directory Directory PKI PKI CRL CRL ( NTLM, NTLM,, PKI, PKI, ) DNS DNS Windows Windows ACL ACL

Active Directory (AD)

AD GUI LDAP

OU OU

AD PKI CA ACL CRL CTL

NTLM Kerberos Version 5

COM+ ADSI,,, IIS CIFS/SMB Secure RPC NTLM HTTP LDAP SChannel SSL/TLS POP3, NNTP SSPI MSV1_0/ SAM KDC/DS

SSPI( Security Support Provider Interface ) SSPI SSPI SSP

3. 4. KDC 1. KDC Windows 2000 Active Directory Key Distribution Center (KDC) 2. KDC Windows 2000

Windows 2000 (Authentication) KDC Active Directory Ticket (Authorization) Request Windows 2000 Domain Controller Ticket ACL Files Devices ACL Application ACL 4. Resource Client Machine Windows 2000 Server(s)

Server 1 Server 2 Windows NT Directory Server Key Distribution Center (KDC) Windows NT domain controller

Windows 2000 - company.com est.company.com east.company.com KDC TGT 2 TGT 3 KDC TGT 1 TICKET 4 srv1.east.company.com Windows 2000 Professional Windows 2000 Server

Windows 2000 Unix KDC OMPANY.REALM nt.company.com Unix KDC TGT 2 Windows 2K KDC TGT 1 TICKET 3 Name Mapping to 2K account Unix Workstation With 2K Auth Data Windows 2K Server

CryptoAPI Authenticode CryptoAPI API Reader SSPI (PKCS) Crypto CSP CSP

Applications GetOpenCardName Common UI SCard* COM SCSP CryptoAPI SCCP Service Providers S D K System Services Device Drivers Driver Driver Driver D D K Hardware

Windows 2000 Reader Reader SC 1 Card insertion causes Winlogon to display GINA 4 LSA accesses smart card and retrieves cert from card 2 User inputs PIN 8 Smart card decrypts the TGT using private key allowing LSA to log user on 3 GINA passes PIN to LSA LSA Kerberos 5 Kerberos sends certificate in a PKINIT login request to the KDC 7 KDC returns TGT, encrypted with a session key which is in turn encrypted using user s public key Kerberos 6 KDC verifies certificate then looks up principal in DS KDC

Windows

API Windows

SSL

IIS Windows DS [ ] UPN CA 1 1

DS Web Cert SSL/TLS Active Directory

PKI

PKI

PKI

Windows 2000 PKI PKI PKI

Windows 2000 PKI MMC IE MMC CRL

Windows 2000 PKI CryptoAPI 1.0 CryptoAPI 2.0 SSPI

Cert Reader SC Windows 2000 PKI Root CA Client Certificate Request and Authentication Active Directory Subordinate CA Publish Certificate?

Reader Cert SC Client Windows 2000 PKI SSL Secure Web Server HTTP with SSL/TLS Certificate Enrollment Subject Lookup Certification Authority Active Directory

Windows 2000 PKI (S/MIME) Active Directory Outlook Express Retrieve user s certificate (LDAP) Internet S/MIME Cert Reader SC Outlook Exchange

Windows 2000 PKI E (SSL ) HTTP with SSL/TLS Secure Web Server Client Trust Relationship Certification Authority Certificate Enrollment

Windows 2000 PKI (Authenticode) HTTP Web Server User Code Signing Process Code Signing Cert Reader SC Code Publishing Developer

EFS

NTFS EFS

Launch key for nuclear missile RedHeat is... User s public key (in certificate) Randomly- generated file encryption key (FEK) File encryption (e.g., DES) RNG Data Decryption Field generation (e.g., RSA) Data Recovery Field generation (e.g., RSA) *#$fjda^j u539!3t t389e *& @ 5e%32 ^kd DDF DRF Recovery agent s public key (in certificate) in recovery policy

*#$fjda^j u539!3t t389e *& @ 5e%32 ^kd User s private key DDF contains file encryption key (FEK) encrypted under user s public key File decryption (e.g., DES) DDF extraction (e.g., RSA) DDF File encryption key (FEK) Launch key for nuclear missile RedHeat is... DDF is decrypted using the private key to get to the file encryption key (FEK)

*#$fjda^j u539!3t t389e *& @ 5e%32 ^kd Recovery agent s private key DRF contains file encryption key (FEK) encrypted under recovery agent s public key File decryption (e.g., DES) DRF extraction (e.g., RSA) DRF File encryption key (FEK) Launch key for nuclear missile RedHeat is... DRF is decrypted using the private key of recovery agent to get to the file encryption key (FEK)

CA PKI

JP273856 [ ] [ ] EFS (1.3.6.1.4.1.311.10.3.4)

JP281245 CA [ ] [ ] (1.3.6.1.5.5.7.3.2) (1.3.6.1.4.1.311.20.2.2)

SSL PKI EFS STPP

STPP Strategic Technology Protection Program 1. 2. 3. Get Secure. Stay Secure.

STPP MCS E-mail Rating System Microsoft Security Tool Kit

Secure Windows Initiative SWI

Security Tool Kit Guide Windows Windows 2000, Windows NT 4.0, Windows NT 4.0 TSE, Step by Step Guide Software Updates Service Pack Windows 2000 Service Pack 2, Windows NT 4.0 SRP Deployment and Management Tools Windows HFNetChk,, IIS Lockdown Wizard Online Resources TechNet

Security Tool Kit Software Update IIS Lockdown Tool HFNetChk Tool Rating System Security Rollup Patches

Windows Update- - Service Pack Security Rollup Internet Windows Update Corporate Edition Microsoft Windows Update Site

Windows Update Windows 3 rd

0120-69 69-0196 ( 9:30-12:00,13:00 12:00,13:00-19:00) 19:00) Security Tool Kit

www.microsoft.com/japan japan/security E-mail Microsoft Security Tool Kit SWI MCS

Windows, VS.NET CD 9000 Windows,ISA,.NET Windows, ISA,.NET

初期設定におけるセキュリティ対策 Office.exeの受取 scriptへ のアクセス無効 XP インターネット接続にファ イアウォールを設定 Windows.NET Server 初期設定でIIS6を無効化 ウィザードによる 不要なサービスの無効化

Get Secure. Stay Secure. STPP MSRC Windows 2000 Security Rollup Package Windows 2000 SP3 VS.NET Windows Update

TRUSTe BBBOnline Deloitte Price Waterhouse Foundstone 1997 GLB MSN XP Kids Passport pre-coppa COPPA.NET My Services

IT IT

Get Secure. Stay Secure.