Corda Enterprise Network Manager1.2ã®ãªãªãŒã¹ããŒãã®ç¿»èš³æãæ²èŒããããŸãã
åæã¯ãã¡ãããã確èªãã ããã
Corda Enterprise Network Manager 1.2.6
CENM 1.2.6 ã§ã¯ãApache Log4j 2 ã®äŸåé¢ä¿ã«èµ·å ããç·æ¥ã®ã»ãã¥ãªãã£åé¡ãä¿®æ£ããŸããããã®ä¿®æ£ã§ã¯ãLog4j ã®äŸåé¢ä¿ãããŒãžã§ã³ v2.17.1 ã«æŽæ°ãããŠããŸãã
ä¿®æ£ãããåé¡
Log4j ã®äŸåé¢ä¿ãããŒãžã§ã³ 2.17.1 ã«æŽæ°ãããæ¢åã® Log4j ã®åé¡ãä¿®æ£ãããŸããã
Corda Enterprise Network Manager 1.2.5
CENM 1.2.5 ã§ã¯ãApache Log4j 2 ã®äŸåé¢ä¿ã«èµ·å ããç·æ¥ã®ã»ãã¥ãªãã£åé¡ - CVE-2021-44228 - ãä¿®æ£ããŸããããã®ä¿®æ£ã§ã¯ãLog4j äŸåé¢ä¿ãããŒãžã§ã³ 2.16.0 ã«æŽæ°ããŠããŸãã
ä¿®æ£ãããåé¡
CVE-2021-44228 ãç·©åããããã«ãLog4j ã®äŸåé¢ä¿ãããŒãžã§ã³ 2.16.0 ã«æŽæ°ããŠããŸãã
â»Corda Enterprise Network Manager 1.2.4ã®å ¬åŒãªãªãŒã¹ã¯ãããŸããã
Corda Enterprise Network Manager 1.2.3
ä¿®æ£ãããåé¡
- CENMã§èš±å¯ããã蚌ææžã®ã·ãªã¢ã«çªå·ã®æ倧é·ã28æ¡(ããŒã¿ããŒã¹ã®NUMBER(28)圢åŒ)ã§ãããçŽ93ãããã®ããŒã¿ãå«ãŸããŠããåé¡ãä¿®æ£ãããSwissPKIãªã©ã®ãµãŒãããŒãã£èªèšŒæ©é¢ã®ãµããŒã(CENM 1.2ã§å°å ¥)ãæ¡åŒµããããã«ãIdentity ManagerãµãŒãã¹ã¯ãRFC 5280ã«æºæ ããããã«ãæ倧20ãªã¯ããã/ãã€ã(160ããã)ã®ãµã€ãºã®èšŒææžã®ã·ãªã¢ã«çªå·ãæ±ããããã«ãªã£ããããã«ãPKIããŒã«ã¯ãæ倧16ãªã¯ããã/ãã€ãã®ã·ãªã¢ã«çªå·ãµã€ãºã®èšŒææžãçæããããã«ãªã£ãã
- è€æ°ã®ããŒãã£ã·ã§ã³ã§securosys HSM䜿çšããŠããå ŽåãPKIããŒã«ããšã©ãŒãæããåé¡ãä¿®æ£ããŸããã
Corda Enterprise Network Manager 1.2.2
ä¿®æ£ãããåé¡
- ããŒãç»é²ã®äžéšãšããŠcsr_tokenã䜿çšãããšãIdentity ManagerããµããŒããããããŒãžã§ã³ã®Oracle DBã䜿çšããããã«èšå®ãããŠããå Žåã«ç»é²ã«å€±æãããšããåé¡ããããŸãã
- CENM 0.4ããã®ã¢ããã°ã¬ãŒãã§ãæ¢åã®å€±å¹ãã蚌ææžã«å€±å¹çç±ããªãå ŽåãCRLã®äœæãšçœ²åã«å€±æããŸãã
Corda Enterprise Network Manager 1.2
äž»ãªæ°æ©èœ
DockerãšKubernetesã®ãµããŒãCorda Enterprise Network Managerã«Dockerã®ãµããŒããæ¡å€§ããŸããããã«ãHelmãšKubernetesã䜿ã£ãåã®ãªãã¡ã¬ã³ã¹ãããã€ã¡ã³ãã玹ä»ããŸããããã«ãããã客æ§ã®éçºãµã€ã¯ã«ãè£å®ããããã®äžæçãªä»£è¡šãã¹ããããã¯ãŒã¯ãæ°åã§ãããã€ããããšãå¯èœã«ãªããŸãã詳现ã¯ãã¡ãã®ããŒãžãã芧ãã ããããŸãããªãŒãã³ãœãŒã¹ã®CAå®è£ ã®ãµã³ãã«ã«ã€ããŠã¯ãã¡ãã®ããŒãžãã芧ãã ããã
ãµãŒãããŒãã£CAããµããŒã
Cordaãããã¯ãŒã¯ã«ããã蚌ææžãšãããã¯ãŒã¯ãµãŒãã¹ã®çœ²åã€ãã³ãã®ãµããŒããããã©ã€ããµã€ã¯ã«ãåŠçããããã«ãµãŒãããŒãã£ã®ãœãããŠã§ã¢ãŸãã¯ãµãŒãã¹ãããã€ãã䜿çšããããšãæãã¯ã©ã€ã¢ã³ããæºè¶³ãããããã«ã眲åãµãŒãã¹ã¯ããã©ã°å¯èœãªã€ã³ã¿ãã§ãŒã¹ãæäŸããããã«ã眲åå¯èœææãªããªããµãŒãã¹ïŒSMRïŒãšCENM眲åãµãŒãã¹ã«åé¢ãããŠããŸãã詳现ã¯ãã¡ãã®ããŒãžãã芧ãã ããã
CRLãšã³ããã€ã³ããã§ãã¯ããŒã«
TLS æ¥ç¶ã«åé¡ãããå Žåã®èšºæè£å©ãšããŠãCENM 1.2 ã§ã¯ CRL Endpoint Check ããŒã«ãå°å ¥ããŠããŸãããã®ã¹ã¿ã³ãã¢ããŒã³ããŒã«ã¯ãæäŸãããããŒã¹ãã¢å ã®ãã¹ãŠã®èšŒææžã®CRLãšã³ããã€ã³ãã®å¥å šæ§ããã§ãã¯ãã蚌ææžããåå¥ã«CRLãšã³ããã€ã³ããæåã§æœåºããããããæ€èšŒãããããç°¡åãªä»£æ¿æ段ãšãªããŸãã詳现ã¯ãã¡ãã®ããŒãžãã芧ãã ããã
ãã€ããŒãªæ©èœ
ããŒãç»é²ã®ã¢ã·ã¹ã
CordaãšNetwork Managerã®äž¡æ¹ã§ãããŒãã®Certificate Signing Requestã®åã«å§ãŸããåŸã«ç¶ããããããªãæ§ã ãªãªã³ããŒãã£ã³ã°ã¯ãŒã¯ãããŒãå¯èœã«ããããã«äœ¿çšããããšãã§ããæ°ãããã£ãŒã«ããå°å ¥ããŸãããããã«ããããããã¯ãŒã¯ãªãã¬ãŒã¿ã¯ãããŒãç»é²ããã»ã¹ããã倧ããªãªã³ããŒãã£ã³ã°ã¯ãŒã¯ãããŒã®äžéšãšããŠçµã¿èŸŒãããšãã§ãããŸãåã«CSRãã¬ãã¥ãŒããŠèšŒææžãçºè¡ããããã»ã¹ãé«éå/èªååããããšãã§ããŸãããã®æ©èœã¯CordaãŸãã¯Corda Enterprise 4.4以äžã®ããŒããå¿ èŠã§ãã
ãã³ãã«ãµãŒãã¹
å°èŠæš¡ãªãããã€ã¡ã³ãããã¹ãç®çã«ã¯ã1ã€ã®Jarãã¡ã€ã«ããè€æ°ã®ãµãŒãã¹ã䞊è¡ããŠå®è¡ããå¯èœæ§ãå°å ¥ããŠããŸãããããBundled ServiceãšåŒã³ãŸãããŠãŒã¶ã¯ãå®è¡ãããµãŒãã¹ãšããã«å¯Ÿå¿ããèšå®ãã¡ã€ã«ãæå®ããå¿ èŠããããŸãããã®æ©èœã¯CENM 1.1ãšã®åŸæ¹äºææ§ããããèšå®ãã¡ã€ã«ãããµãŒãã¹ãçãããšãå¯èœã§ãã
Notaryã®ãã¯ã€ããªã¹ã
é«å¯çšæ§ïŒHAïŒå ¬èšŒäººã®ã¿ããããã¯ãŒã¯ããããIDãããŒãžã£ããèªåçã«ããŒãæ å ±ãååŸããããã«ãªãããã¡ã€ã«ãæåã§ã³ããŒããå¿ èŠããªããªããŸãããé HA ããŒã¿ãªãŒã®ãµããŒãã¯äºå®ãããŠããŸããã®ã§ãã客æ§ã¯ãã¹ãŠã®ããŒã¿ãªãŒãé«å¯çšæ§æ§æã§å±éããããšãæšå¥šããŸãã
ãã®ä»ã®æ¹åç¹
- AWS Cloud HSMãå«ããHSMã®ãµããŒããªã¹ããæ¡åŒµããŸããã
- ããã©ã«ãã®ãã°ãã¡ã€ã«ã®ãã¹ã«ããã°ãã¡ã€ã«ãçæãããµãŒãã¹åïŒäŸïŒ"network-map"ïŒãå«ããããã«ããŸãããããã«ãããè€æ°ã®ãµãŒãã¹ãåããã©ã«ãããå®è¡ãããŠãããããã®ãã³ããã°ãã¡ã€ã«åãè¡çªããããšã¯ãããŸããã
- ã·ã§ã«ã€ã³ã¿ãŒãã§ãŒã¹ïŒSignerããã³Identity ManagerãµãŒãã¹ïŒã¯ãJavaã¹ã¯ãªããã®ããŒããã·ã§ã³ãæäŸããªãããã«ãªããŸããã
- ãã©ã€ããŒããããã¯ãŒã¯ãããã®åé€ - ãã®æ©èœã¯å®æããŠããããå€æŽã¯ãŠãŒã¶ãŒã«ã¯èŠããªãã¯ãã§ããããã¯ãŸã ããŒã¿ããŒã¹ã¹ããŒãããããããåé€ããŸããããå°æ¥ã®ãªãªãŒã¹ã§ã¯åé€ãããäºå®ã§ããé¢é£ããéé¢ããŒãæ å ±ããŒãã«ãšã¹ããŒãžã³ã°ããŒãæ å ±ããŒãã«ã¯ãCENM 1.1 ã§ã¯äœ¿çšãããŠããŸããã
- ããŒã¿ããŒã¹ãšã©ãŒã®ãã°ãæ¹åããé害ãçºçããããšã ããå ±åããã®ã§ã¯ãªããæ ¹æ¬çãªåå ãå ±åããããã«ããŸããã
- ãã³ããã°ã¯ãµãŒãã¹å¥ã®ãã©ã«ãã«æžã蟌ãŸããããã«ãªããè€æ°ã®ãµãŒãã¹ãåããã£ã¬ã¯ããªããå®è¡ãããŠãããã°ãã¡ã€ã«ãè¡çªããªãããã«ãªããŸããã
- CRaSH ã·ã§ã«ããå®è¡ããå Žåã® service healthcheck ã³ãã³ããä¿®æ£ããŸããã
- ãããã¯ãŒã¯ãããã·ã§ã«ã«ãäžãããããã©ã¡ãŒã¿ã®æŽæ°ãåãå ¥ããïŒãŸãã¯åãå ¥ããªãã£ãïŒããŒãã®ãªã¹ãã衚瀺ããæ°ããã³ãã³ããè¿œå ããŸãããïŒ"view nodesAcceptedParametersUpdate accepted: <true/false>, parametersHash: ") ãããã¯ãŒã¯ãã©ã¡ãŒã¿ã®æŽæ°æé ãç£èŠããã®ã«åœ¹ç«ã¡ãŸãã
- CENM ãµãŒãã¹ã®äœæ¥ãã£ã¬ã¯ããªåŒæ°ãè¿œå ãèšå®ãã¡ã€ã«ã蚌ææžãã¡ã€ã«ã®ãã¹ãã¬ãã£ãã¯ã¹ãšãªãã
- Network MapãµãŒãã¹ã®ã·ã§ã«ã«run networkParametersRegistrationãrun flagDayãrun cancelUpdateã³ãã³ããè¿œå ãããµãŒãã¹ãåèµ·åããã«ææ¥ãå®è¡ã§ããããã«ããŸãã詳现ã«ã€ããŠã¯ããããã¯ãŒã¯ãã©ã¡ãŒã¿ã®æŽæ°ãåç §ããŠãã ããã
- Network Map ãµãŒãã¹ã·ã§ã«ã« view publicNetworkNodeInfos ã³ãã³ããè¿œå ãããã¹ãŠã®ãããªãã¯ãããã¯ãŒã¯åå è ã®ããŒãæ å ±ïŒãã©ãããã©ãŒã ããŒãžã§ã³ãå«ãïŒã衚瀺ã§ããããã«ããŸããã
- 蚌ææžã®ååã«ãŒã«ã¯Cordaã®ãããã¯ãŒã¯ã«ãŒã«ã«åŸã£ãŠçºè¡æã«åŒ·å¶ãããããã«ãªããŸããã以åã¯ããŒãã䜿çšã§ããªãååã§ããŒããç»é²ããããšãå¯èœã§ããã
- ç»é²WebãµãŒãã¹ïŒCSRãšCRLïŒããç¡å¹ãªã¯ã©ã€ã¢ã³ãããŒãžã§ã³ãŸãã¯ãã©ãããã©ãŒã ããŒãžã§ã³ãæã€ãªã¯ãšã¹ãã«å¯ŸããŠã400ã§ã¯ãªããäžæ£ãªHTTPãšã©ãŒã³ãŒã500ãè¿ããŠããŸããã
- ç»é²WebãµãŒãã¹ã«ãã£ãŠäœæããããã°ã®æ¹å - ãªã¯ãšã¹ãæ€èšŒäŸå€ïŒäŸïŒä»¶åã«ç¡å¹ãªæåãããããã©ãããã©ãŒã ã®ããŒãžã§ã³ãç¡å¹ïŒã¯ãERRORã¬ãã«ã§ã¯ãªãWARNã¬ãã«ã§ãã°ã«èšé²ãããããã«ãªããŸããã
- H2ããŒã¿ããŒã¹ã®ã¿ã«äœ¿çšãããŠããèšå®ãªãã·ã§ã³ 'database.initialiseSchema' ã¯éæšå¥šãšãªãã代ããã« 'database.runMigration' ã䜿çšããããã«ãªããŸããã
ã»ãã¥ãªãã£ã®åäž
ã·ã§ã«ã€ã³ã¿ãŒãã§ãŒã¹ïŒSignerããã³Identity ManagerãµãŒãã¹ïŒã§ã¯ãJavaã®ã¹ã¯ãªãããèš±å¯ããã³ãã³ãã«ã¢ã¯ã»ã¹ã§ããªããªããŸããã
æ¢ç¥ã®åé¡ç¹
Identity Manager ã® WorkflowPlugin ã¯ãèŠæ±ã"REJECTED" ãŸãã¯"APPROVED"ã«ãªããŸã§ãå€éšã·ã¹ãã ã§æ° ããèŠæ±ãäœæããããšãç¶ããŸããããã¯ãå€éšã·ã¹ãã ããçŸåšåŠçãããŠããèŠæ±ãå éšçã«èšé²ããäœå°ã®äœæè©Šè¡ãæåŠããå¿ èŠãããããšãæå³ããŸããIdentity Manager ãµãŒãã¹ã¯ããã®ããšãèŠåãšããŠãã°ã«èšé²ããŸãã Warning: âThere is already a ticket: ââ corresponding to Request ID = , not creating a new one.â
Last edited by Yoshino