簡単オレオレ証明書†[edit]
/etc/pki/tls/certs の Makefile†[edit]
- make genkey .... /etc/pki/tls/private に秘密鍵 localhost.key を生成する.
- make server.key .... カレントディレクトリに秘密鍵 server.key を生成する.
- make server.csr .... 秘密鍵が無ければ生成して,証明書請求フォーマット(server.csr) を生成する.
- make server.crt .... server.csr が無ければ生成して,サーバ証明書(server.crt)を生成する.
- 認証局証明書は /etc/pki/tls/cert.pem
1. PC -> Server : Handshake ClientHello†[edit]
TLS Record Layer (5Byte)†[edit]
16 03 03 00 9b
- 0x16 : Type: Handshake
- 0x03 0x03 : Version: TLS v1.2
- 0x00 0x9b : 続くデータの長さ (155Byte)
メッセージタイプ (4Byte)†[edit]
01 00 00 97
- 0x01 : メッセージタイプ(msg タイプ): ClientHello
- 0x00 0x00 0x97 : データ部の長さ (151Byte)
データ部 (151Byte)†[edit]
03 03 5d b5 59 02 f8 ...
2. Server -> PC : Handshake SeverHello†[edit]
TLS Record Layer (5Byte)†[edit]
16 03 03 00 55
- 0x16 : Type: Handshake
- 0x03 0x03 : Version: TLS v1.2
- 0x00 0x55 : 続くデータの長さ (85Byte)
メッセージタイプ (4Byte)†[edit]
02 00 00 51
- 0x02 : メッセージタイプ(msg タイプ): SeverHello
- 0x00 0x00 0x51 : データ部の長さ (81Byte)
データ部 (81Byte)†[edit]
03 03 de b4 cd 12 b2 ...
3. Server -> PC : Handshake Certificate†[edit]
16 03 03 09 73 0b 00 09 6f
メッセージタイプ (4Byte)†[edit]
- 0x0b : メッセージタイプ(msg タイプ): Certificate
- 0x00 0x09 0x6f : データ部の長さ(2415Byte)
データ部 (2415バイト)†[edit]
00 09 6c 00 04 b1 30 82 04 ad 30 82 03 ...
4. Server -> PC : Handshake ServerKeyExchange†[edit]
16 03 03 03 0f 0c 00 03 0b
メッセージタイプ (4Byte)†[edit]
- 0x0c : メッセージタイプ(msg タイプ): ServerKeyExchange
- 0x00 0x03 0x0b : データ部の長さ(779Byte)
データ部 (779バイト)†[edit]
01 00 ff ff ff ff ff ff ff ff c9 0f da a2 21 68 c2 ...
5. Server -> PC : Handshake ServerHelloDone†[edit]
16 03 03 00 04 0e 00 00 00
メッセージタイプ (4Byte)†[edit]
0e 00 00 00
- 0x0e : メッセージタイプ(msg タイプ): ServerHelloDone
- 0x00 0x00 0x00 : データ部の長さ(0Byte)
6. PC -> Server : Handshake ClientKeyExchange†[edit]
16 03 03 01 06 10 00 01 02
メッセージタイプ (4Byte)†[edit]
- 0x10 : メッセージタイプ(msg タイプ): ClientKeyExchange
- 0x00 0x01 0x02 : データ部長さ(258Byte)
データ部 (258バイト)†[edit]
01 00 07 cd 69 f6 91 ...
7. PC -> Server : ChangeCipherSpec†[edit]
14 03 03 00 01 01
TLS Record Layer (5Byte)†[edit]
14 03 03 00 01
- 0x14 : Type: ChangeCipherSpec
- 0x03 0x03 : Version
- 0x00 0x01: 続くデータの長さ (1Byte)
データ部 (1Byte)†[edit]
- 0x01 : ChangeCipherSpec : これ以降は暗号化通信を行う
8. PC -> Server : Handshake finished?†[edit]
TLS Record Layer (5Byte)†[edit]
16 03 03 00 28
- 0x16 : Type: Handshake
- 0x03 0x03 : Version
- 0x00 0x28: 続くデータの長さ (40Byte)
メッセージタイプ (4Byte)†[edit]
00 00 00 00 00 00 00 00 97 74 ...
9. Server -> PC : ChangeCipherSpec†[edit]
14 03 03 00 01 01
TLS Record Layer (5Byte)†[edit]
14 03 03 00 01
- 0x14 : Type: ChangeCipherSpec
- 0x03 0x03 : Version
- 0x00 0x01: 続くデータの長さ (1Byte)
メッセージ部 (1Byte)†[edit]
- 0x01 : ChangeCipherSpec : これ以降は暗号化通信を行う
10. Server -> PC : Handshake finished?†[edit]
TLS Record Layer (5Byte)†[edit]
16 03 03 00 28
- 0x16 : Type: Handshake
- 0x03 0x03 : Version
- 0x00 0x28: 続くデータの長さ (40Byte)
メッセージタイプ (4Byte)†[edit]
42 d2 dc b8 50 ...
TLS Record Layer (5Byte)†[edit]
16 03 03 00 28
- 0x16 : Type: Handshake
- 0x03 0x03 : Version
- 0x00 0xbb: 続くデータの長さ (187Byte)