Microsoft Edgeã§HSTSãšã©ãŒã«æ©ãŸãããŠããŸãããïŒð© å¿é
ããªãã§ãã ãããHTTP Strict Transport SecurityïŒHSTSïŒã«é¢é£ãããã®ããããåé¡ã¯ãç¹ã«ã»ãã¥ãªãã£æ»æã®å¢å ã«äŒŽãããµã€ãã«ã¢ã¯ã»ã¹ã§ããªããªãå¯èœæ§ããããŸãããããã Microsoft Edgeã®ãã©ãã«ã·ã¥ãŒãã£ã³ã°ã¬ã€ããã¹ããããã€ã¹ãããã§è§£èª¬ããã°ããããæ°åã§ã¹ã ãŒãºã§å®å
šãªãã©ãŠãžã³ã°ãåãæ»ããŸãããããæ©éå§ããŸãããïŒããã®ããã«åé¡ã解決ããŸãããïŒâ
Microsoft Edgeã®HSTS ãšã©ãŒãšã¯äœã§ãã?
HSTSïŒHTTP Strict Transport SecurityïŒã¯ããã©ãŠã¶ã«HTTPSã®ã¿ã®äœ¿çšã匷å¶ããå±éºãªHTTPæ¥ç¶ããããã¯ãããŠã§ãã»ãã¥ãªãã£ããªã·ãŒã§ããMicrosoft Edgeã§ã¯ãç¡å¹ãªèšŒææžããã£ãã·ã¥ãããããªã·ãŒãã»ãã¥ãªãã£æ»æã«ããæªæã®ããå¹²æžãªã©ããã©ãŠã¶ãäžäžèŽãæ€åºãããšãHSTSãšã©ãŒã衚瀺ãããŸãã
äžè¬çãªããªã¬ãŒã¯æ¬¡ã®ãšããã§ã:
- ð ãŠã§ããµã€ãäžã® SSL èšŒææžãæéåããŸãã¯ä¿¡é ŒãããŠããªãã
- ð éå°ãªãŠã€ã«ã¹å¯Ÿçãœããããã¡ã€ã¢ãŠã©ãŒã«ãæ¥ç¶ããããã¯ããã
- ð¡ïžãµã€ãã®å€æŽåŸã«ãã£ãã·ã¥ãããHSTSããŒã¿ãå£ããŠããŸããŸããã
- â ïžäžéè
æ»æ (MITM) ãªã©ã®ã»ãã¥ãªãã£æ»æã¯ãæ£èŠã®ãµã€ããæš¡å£ããŠè¡ãããŸãã
Edgeã®æè¿ã®ã¢ããããŒãïŒææ°ã®2026ãã«ãïŒã§ã¯HSTSã®é©çšã匷åããããããã®ãšã©ãŒã¯ããé »ç¹ã«çºçããããã«ãªããŸãããã解決ã¯å®¹æã«ãªã£ãŠããŸãããã©ãã«ã·ã¥ãŒãã£ã³ã°ã®æºåã¯ã§ããŸãããïŒãããå§ããŸãããïŒð
Microsoft Edge HSTS ãšã©ãŒã®ãã©ãã«ã·ã¥ãŒãã£ã³ã°æé
以äžã®å®èšŒæžã¿ã®ä¿®æ£æ¹æ³ãé çªã«å®è¡ããŠãã ãããã»ãšãã©ã®ãŠãŒã¶ãŒã¯æé 3ã§è§£æ±ºããŠããŸããç²ã匷ãåãçµãããšã§ãå®å
šãªèšå®ãå®çŸããŸãïŒðª
1ïžâ£ ã¯ã€ãã¯ã¯ãªã¢: ãã£ãã·ã¥ãCookieããµã€ãããŒã¿
äžçªã®åå ã¯ïŒå€ããã£ãã·ã¥ã§ãããã®åå ã¯æ¬¡ã®ãšããã§ãã
- Microsoft Edgeãéãã[èšå®] (3 ã€ã®ããã) â [ãã©ã€ãã·ãŒãæ€çŽ¢ããµãŒãã¹] ãéžæããŸãã
- ãé²èЧ履æŽããŒã¿ãæ¶å»ãã®äžã§ããã£ãã·ã¥ãããç»å/ãã¡ã€ã«ãš Cookie ã«å¯ŸããŠãå
šæéããéžæããŸãã
- [ä»ããã¯ãªã¢]ãã¯ãªãã¯ããŸãã
Edgeãåèµ·åããŠãµã€ãããã¹ãããŠãã ããã70%ã®ã±ãŒã¹ã§è§£æ±ºããŸããïŒð
2ïžâ£ ãšããžãã©ã°ãšæ¡åŒµæ©èœããªã»ãããã
æ¡åŒµæ©èœãŸãã¯å®éšçãªãã©ã°ã¯HSTSãšè¡çªããå¯èœæ§ããããŸãã
- ãHSTSãã«ç§»åããŠ
edge://flagsæ€çŽ¢ãã調æŽãããã©ã«ãã«ãªã»ããããŸãã
- çµç±ã§ãã¹ãŠã®æ¡åŒµæ©èœãç¡å¹ã«ããŸã
edge://extensionsã
- åå ãç¹å®ããããã«ã1 ã€ãã€åèµ·åããŠå床æå¹ã«ããŸãã
3ïžâ£ ã·ã¹ãã æéãšãããã¯ãŒã¯ã®åºæ¬ã確èªãã
äžæ£ç¢ºãªæ¥ä»/æå»ã«ããèšŒææžãç¡å¹ã«ãªã:
| åé¡ | ä¿®ç |
| ã·ã¹ãã ã¯ããã¯ãééã£ãŠããŸã | èšå® â æå»ãšèšèª â ä»ããåæ |
| ãããã·/VPNå¹²æž | VPNãç¡å¹ã«ããŸããEdgeèšå®ã§ãããã·ã確èªããŸãã |
| DNSã®åé¡ | ãããã¯ãŒã¯èšå®ã§8.8.8.8ïŒGoogle DNSïŒã«åãæ¿ããŸã |
4ïžâ£ Edge ãæŽæ°ãããã«ãŠã§ã¢ãã¹ãã£ã³ãã
Edgeãå€ããªã£ãŠããŸããïŒã¢ããããŒãã¯ãã¡ããã»ãã¥ãªãã£æ»æedge://settings/helpã«ã€ããŠã¯ïŒ
- Windows Defender ã®å®å
šã¹ãã£ã³ãå®è¡ããŸãã
- ãã詳现ãªãã§ãã¯ãè¡ãã«ã¯ãMalwarebytes (ç¡æ) ãããŠã³ããŒãããŠãã ããã
- ã¿ã¹ã¯ ãããŒãžã£ãŒã§çãããããã»ã¹ããªãã確èªããŸãã
æ»æãç¶ãå Žåã¯ãäžæ£ãªèšŒææžããªãããšã確èªããŸã: certmgr.mscâ ä¿¡é Œãããã«ãŒã â äžæãªèšŒææžãåé€ããŸãã
5ïžâ£ é«åºŠãªä¿®æ£: ã³ãã³ãã©ã€ã³ãšã¬ãžã¹ããª
é åºãªã±ãŒã¹ã®å Žå:
- 管çè
ãšããŠã³ãã³ã ããã³ãããéããŸã:
certutil -urlcache -f https://example.com(圱é¿ãåãããµã€ãã«çœ®ãæããŠãã ãã)ã
- ãšããžã·ã§ãŒãã«ãã
--disable-web-securityïŒäžæçãå±éºïŒã
- ã¬ãžã¹ããª:
regeditâ HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Edgeâ HSTS ããŒãååšããå Žåã¯åé€ããŸã (æåã«ããã¯ã¢ããããŠãã ãã)ã
ããã®ãã³ã:ãšã³ã¿ãŒãã©ã€ãº ãŠãŒã¶ãŒã®å Žåãã°ã«ãŒã ããªã·ãŒã«ãã£ãŠå³æ Œãª HSTS ã匷å¶ãããå¯èœæ§ããããŸããIT éšéã«ãçžè«ãã ãããð§
HSTSãšã©ãŒã®èåŸã«ããã»ãã¥ãªãã£æ»æã黿¢ãã
HSTS ãšã©ãŒã¯å€ãã®å Žåãæ¬¡ã®ãããªã»ãã¥ãªãã£æ»æã瀺ããŸãã
- MITM: æ»æè
ã¯èšŒææžãåœè£
ããŸããå¿
ãå京é ã¢ã€ã³ã³ã確èªããŠãã ããã
- ãã£ãã·ã³ã°: åœã® HSTS ãµã€ããããŒã¿ãçã¿ãŸãã
- ãã«ãŠã§ã¢: äžæ£ãªããªã·ãŒãæ¿å
¥ããŸãã
å®å
šã«ãéãããã ãã:
- â
Edge ã®åŒ·åãããã»ãã¥ãªãã£ãæå¹ã«ããŸã (èšå® â ãã©ã€ãã·ãŒ â ã»ãã¥ãªãã£)ã
- ð¡ïž å
¬åŒã® Microsoft Defender çµ±åã䜿çšããŸãã
- ð Microsoft Edge ã»ãã¥ãªã㣠ã»ã³ã¿ãŒã§ãµã€ãã確èªããŸãã
ããŒãã¹:匷åºãªä¿è·ã®ããã«ã(Edge äºæ)çµç±ã§HSTSããªããŒããã°ããŒãã«ã«æå¹ã«ããŸããchrome://net-internals/#hsts
äºé²ïŒãšããžãæ°žä¹
ã«ããã¯ããŠã³
ä¿®æ£åŸ:
- â Edge ãæ¯é±æŽæ°ããŸãã
- ð ãã¹ã¯ãŒãã¢ãã¿ãŒãšè¿œè·¡é²æ¢ïŒå³å¯ã¢ãŒãïŒã䜿çšããŸãã
- â¡ ãªã»ããããåã«ããã¯ããŒã¯ãããã¯ã¢ããããŠãã ããã
ãŸã åé¡ã解決ããªãå Žåã¯ãã³ã¡ã³ãæ¬ã«ãµã€ãã®URLããèšå
¥ãã ãããäžç·ã«åé¡ã解決ããŸãããïŒçæ§ããã®ãã£ãŒãããã¯ãEdgeã®ã»ãã¥ãªãã£ç¶æã«åœ¹ç«ã£ãŠããŸããð
ãŸãšã: å®å
šãªãã©ãŠãžã³ã°ãåŸ
ã£ãŠããŸã!
ããã§ãšãããããŸãïŒ Microsoft Edgeã®ãHSTSãšã©ãŒããšã»ãã¥ãªãã£æ»æã®ãã©ãã«ã·ã¥ãŒãã£ã³ã°ããã¹ã¿ãŒããŸããïŒãããã®æé ã¯ææ°ãã«ãã§å®èšŒæžã¿ã§ãå®å
šæ§ãæãªãããšãªãã¢ã¯ã»ã¹ãå埩ã§ããŸãã倧èã«ãã©ãŠãžã³ã°ããåžžã«æ³šæãæããæåäœéšã以äžã«å
±æããŠãã ãããå®å
šãªããããµãŒãã£ã³ãïŒðâš