ãã®æŽæ°å±¥æŽãã¡ã€ã«ã®ææ°çã¯ãhttps://github.com/IPA-CyberLab/IPA-DN-Ultra/ ãåç §ããŠãã ããã
ãã®ã©ã€ãã©ãªã¯æªå®æã§ãããŸã 䜿çšããããšã¯ã§ããŸããã2021/1/20 ç»
- LGWAN çã§ã¯ããµãŒããŒããã°ã©ã ããåæç¶æ ã§äžç¶ã·ã¹ãã ã«ã»ãã·ã§ã³ã確ç«ããªãããã«ããŸããããããã·ãµãŒããŒã®èšå®ç»é¢ãéããŠèšå®ãè¡ãªããŸã§ãã»ãã·ã§ã³ã¯æªç¢ºç«ã®ç¶æ ãšãªããŸãã(ãããã·ãµãŒããŒã䜿çšããªãå ŽåããäžåºŠãããã·ãµãŒããŒã®èšå®ç»é¢ãéãå¿ èŠããããŸãã)
- ãµã€ã¬ã³ãã¢ã³ã€ã³ã¹ããŒã«ã«å¯Ÿå¿ããŸãããã"C:\Program Files\Local Governments Telework System for LGWAN Server\LgwanThinSetup.exe" /auto:1ã (ãã¹ã¯ã€ã³ã¹ããŒã«ãããç°å¢ã«ãã£ãŠç°ãªãå ŽåããããŸã) ãå®è¡ãããšãã¢ã³ã€ã³ã¹ããŒã«ãç¡æäœã§å®äºããŸãã(éåžžã¯ãããŸããããäžäžã¢ã³ã€ã³ã¹ããŒã«äžã«ãšã©ãŒãçºçããå Žåã¯ããšã©ãŒã¡ãã»ãŒãžã§åæ¢ããŸãã)
- LGWAN çã§ã¯ããããŸã§ãå®å šéååãã¡ã€ã¢ãŠã©ãŒã«ãç¡å¹ã«ãããªãã·ã§ã³ãèšå®ãããŠããå Žåã§ããå®å šéååãã¡ã€ã¢ãŠã©ãŒã«ãèµ·åããŠããŸã£ãŠããŸããããã®åºŠãããªã·ãŒèŠå¶ãµãŒããŒã§å®å šéååãã¡ã€ã¢ãŠã©ãŒã«ã匷å¶ã§ããããã«ããŸããã®ã§ãå®å šéååãã¡ã€ã¢ãŠã©ãŒã«ã匷å¶ã®å Žåã¯å¿ ãåæ©èœãèµ·åãããã以å€ã®å Žåã¯ãå®å šéååãã¡ã€ã¢ãŠã©ãŒã«ãç¡å¹ã«ãããªãã·ã§ã³ãèšå®ãããŠããå Žåã¯å®å šéååãã¡ã€ã¢ãŠã©ãŒã«ãèµ·åããªãããã«ããŸããã
- ã€ã³ã¹ããŒã©ã§ãWindows ã®ã°ã«ãŒãããªã·ãŒã§ãªã¢ãŒãæ¥ç¶ãæªæ§æã®å Žåã§ã誀ã£ãŠãWindows ã®ã°ã«ãŒãããªã·ãŒã§ãªã¢ãŒãæ¥ç¶ãçŠæ¢ãããŠããŸããããšããæ³šæã¡ãã»ãŒãžã衚瀺ãããŠããŸãåé¡ã解決ããŸãããããªã·ãŒããæªæ§æãã®å Žåããæå¹ããšããŠèª€ã£ãŠåãæ±ã£ãŠããããšãåå ã§ããããæªæ§æãã®å Žåã¯ãç¡å¹ããšããŠåãæ±ãããã«ä¿®æ£ããŸããã
- beta7preview9 ã§è¿œå ãããããµãŒããŒåŽã¡ã¢ãªå®¹éã 4GB 以äžãŸãã¯ç©ºãã¡ã¢ãªã 512MB æªæºã®å Žåã«è¡šç€ºãããç»é¢ã«ã¯ãäžè¬çãªã¡ã¢ãªå¢èšã®å¹çšãåçºããã¡ãã»ãŒãžãå«ãŸããŠããŸãããã®ã¡ãã»ãŒãžã¯ãIPA ã«ãããŠãã€ããªããã«ããã圢æ ã§é åžãããã·ã³ã»ãã¬ã¯ãŒã¯ã·ã¹ãã ã®ãããªãã¯çã§è¡šç€ºãããããšãç®çãšãããã®ã§ãããã³ã³ãã¥ãŒã¿ã«ã¡ã¢ãªãå¢èšããããšã«ãããçç£æ§ã®åäžãæ®æ¥åæžãäœæã®å¢å ãæ¶è²»é»åã®åæžã幞çŠåºŠã®å¢å ããã³æåŸã®å¢å€§ãçãå®çŸãããããšã IPA ãµã€ããŒæè¡ç 究宀ããåŒã³æããã¡ãã»ãŒãžã§ããããããªããããã©ã€ããŒãçã¯åå©çšäŒæ¥çãèªããœãŒã¹ã³ãŒãããã«ãããŠãã€ããªãçæããå瀟瀟å¡ã«é åžããããšãç®çãšããŠãããã®ã§ãããåå©çšäŒæ¥ã®æ¹éãš IPA ã«ããã¡ã¢ãªå¢èšã®å¹çšã®åŒã³æãã®å 容ãççŸããæ··ä¹±ãçããå ŽåããããŸããåå©çšäŒæ¥çã§ã¯ãã¡ã¢ãªå¢èšã®å¹çšãèªç€Ÿç€Ÿå¡ã«ç¥ãããããªãå ŽåããããŸããããã§ãåèšã®äžè¬çãªã¡ã¢ãªå¢èšã®å¹çšã®ã¡ãã»ãŒãžã¯ãããªãã¯çã§ã®ã¿è¡šç€ºãããããã«ãããã©ã€ããŒãçã§ã¯è¡šç€ºãããªãããã«ããŸããããªãããã©ã€ããŒãçã§ã¡ã¢ãªå¢èšã®å¹çšã®åŒã³æãã¡ãã»ãŒãžã埩掻ãããå Žåã¯ããã©ã€ããŒãçãœãŒã¹ã³ãŒãã®ãIPA-DN-ThinApps-Private\src\bin\hamcore\strtable_ja.patch.stbããã¡ã€ã«ã®ãDS_MEMORY_MSG_1ãããã³ãDS_MEMORY_MSG_2ãã®è¡ãåé€ããŠãã ããã
- beta7preview10 ã§è¿œå ãããããªã·ãŒèŠå¶ãµãŒããŒã®èšå®é ç®ã®ãREQUIRE_MINIMUM_CLIENT_BUILDããã誀ã£ãŠãREQUIRE_MIMIMUM_CLIENT_BUILDããšããã¹ãã«ãšãªã£ãŠãããæ£ããèšå®é ç®ã®èªã¿èŸŒã¿ãã§ããŸããã§ãããã¹ãã«ãã¹ãä¿®æ£ããŸãããæ£ããã¯ããREQUIRE_MINIMUM_CLIENT_BUILDãã§ãã
- beta7preview9 ã§è¿œå ãããã¢ã«ãŠã³ãããã¯ã¢ãŠãæ©èœã«ã€ããŠãåäœãå®äºããŸãããããã¯ã¢ãŠããçºçããŠããªãç¶æ ã§äœåºŠããŠãŒã¶ãŒèªèšŒã«å€±æã (äŸç¶ãšããŠããã¯ã¢ãŠãããã倿ªæºã®å€±æã®ç¶æ ã§)ããã®åŸããŠãŒã¶ãŒèªèšŒã« 1 床æåããå Žåã¯ãããã¯ã¢ãŠãã®ã«ãŠã³ãããŠã³ãã¯ãªã¢ããããã«ããŸããããŸãããŠãŒã¶ãŒèªèšŒã«å€±æããããšã奿©ãšãªã£ãŠã¢ã«ãŠã³ãããã¯ã¢ãŠããçºçããå Žåã¯ãããã¯ã¢ãŠããçºçããæšã®ãšã©ãŒã¡ãã»ãŒãžãè¿ãããã«ããŸããã
- MAC ã¢ãã¬ã¹èªèšŒãæå¹ã«ãããŠããå ŽåãéåžžããµãŒããŒèšå®ããŒã«ãçµäºããéã« MAC ã¢ãã¬ã¹ã 1 ã€ãããŒã«ã«èšå®ã§ç»é²ãããŠããªãå Žåã«ãèšå®ãä¿ãã¡ãã»ãŒãžããã¯ã¹ã衚瀺ãããŸããããããªãããããªã·ãŒèšå®ãã¡ã€ã«ã§ãSERVER_ALLOWED_MAC_LIST_URLãé ç®ãèšå®ãããŠããå ŽåãMAC ã¢ãã¬ã¹äžèЧã¯ããªã·ãŒèŠå¶ãµãŒããŒåŽã§ç®¡çããããšãå¯èœã«ãªããŸããããã§ããSERVER_ALLOWED_MAC_LIST_URLãé ç®ãèšå®ãããŠããå Žåã¯ãäžèšã®èšå®ãä¿ãã¡ãã»ãŒãžããã¯ã¹ã衚瀺ããªãããã«ããŸããããªããããªã·ãŒèšå®ãã¡ã€ã«ã«ãSERVER_ALLOWED_MAC_LIST_URLãé ç®ãèšå®ãããŠãããã®ã®ããã® URL ã誀ã£ãŠããããMAC ã¢ãã¬ã¹ãèšè¿°ããããã¹ããã¡ã€ã«ã®èšèŒã誀ã£ãŠãããããŠããå Žåã§ããã¡ãã»ãŒãžã®è¡šç€ºã¯çç¥ãããããã«ãªããŸããããªã·ãŒãã¡ã€ã«ã®ãSERVER_ALLOWED_MAC_LIST_URLãé ç®ãèšèŒãããéã¯ãååãæ³šæãã ããã
- ãµãŒããŒããã³ã¯ã©ã€ã¢ã³ãã¢ããªã®ãããã·èšå®ç»é¢ã«ããäžç¶ã·ã¹ãã ãžã®æ¥ç¶ãç¡å¹åããããªãã·ã§ã³ã远å ããŸããããã®ãªãã·ã§ã³ãæå¹ã«ãããšãäžç¶ã·ã¹ãã ãžã®éä¿¡ãçºçããªããªããŸãããã§ã«ãµãŒããŒããäžç¶ã·ã¹ãã ãžã®ã»ãã·ã§ã³ã確ç«ãããŠããå Žåã¯ãã»ãã·ã§ã³ã¯åæãããŸãã
- ã€ã³ã¹ããŒã©ã®ãã«ãã«ãããŠãã¯ã©ã€ã¢ã³ãã¢ããªã®ã¿ãå«ãã ã€ã³ã¹ããŒã©ããã«ãããããšãã§ããããã«ãªã£ãããœãŒã¹ã³ãŒãäžã®ãsrc/Vars/VarsActivePatch.hãã®ãThinSetupClientOnlyãé ç®ããtrueãã«å€æŽããããšã«ãããã¯ã©ã€ã¢ã³ãã¢ããªã®ã¿ãå«ãã€ã³ã¹ããŒã©ãäœæãããããã¯ã©ã€ã¢ã³ãã¢ããªãšãµãŒããŒã¢ããªã®äž¡æ¹ãå«ãã€ã³ã¹ããŒã©ããšããã¯ã©ã€ã¢ã³ãã®ã¿ãå«ãã€ã³ã¹ããŒã©ãã® 2 çš®é¡ããã«ããããå Žåã¯ãåããããã¡ã€ã«ãæžæããŠã2 åãã«ãããããšã(ããã¯ãå°ãææãã®å®è£ ã§ããããæ¬æ©èœã®éèŠã¯ããã»ã©å€ããªããããã容赊ããã ãããã) ãªãããThinSetupServerOnlyã ãš ãThinSetupClientOnlyã ã¯ããããäžæ¹ããæå®ã§ããªãŸããããThinSetupClientOnlyããšãThinSetupServerOnlyãã®äž¡æ¹ã true ã«ãããšãå šãæå³ã®ãªãã€ã³ã¹ããŒã©ãäœæãããŸãã®ã§ããæ³šæãã ããã
- ããªã·ãŒèŠå¶ãµãŒããŒã®èšå®é ç®ã«ãENFORCE_LIMITED_FIREWALL_COMPUTERNAME_STARTWITHãã远å ããŸããããã®èšå®ã¯ããENFORCE_LIMITED_FIREWALLãèšå®æ©èœ (ãå®å šéååãã¡ã€ã¢ãŠã©ãŒã«ãæ©èœã匷å¶çã«æå¹ã«ããæ©èœ) ãæå¹ã«ãããããã©ããäžéšã®ç«¯æ«ã«ã€ããŠã¯ç¡å¹ã«ããã (é€å€ããã) ãšãããããªå Žåã«å©çšã§ããŸãããã®é ç®ãšããŠèšå®ãããŠããæååããæ¥ç¶ããããšããŠããã¯ã©ã€ã¢ã³ãåŽã® Windows ã³ã³ãã¥ãŒã¿ã®ãã³ã³ãã¥ãŒã¿åãã®æååã®å é éšåã«äžèŽããå Žåã¯ãåœè©²ã¯ã©ã€ã¢ã³ãããã®æ¥ç¶ã«éããŠã¯ããENFORCE_LIMITED_FIREWALLãã 0 ã§ãããšã¿ãªããŠæ¥ç¶åŠçããããŸãããã®é ç®ã«ã¯ãã¹ããŒã¹ãã«ã³ããŸãã¯ã»ãã³ãã³åºåãã§ãè€æ°ã®æååãæå®ã§ããŸããè€æ°ã®æååãæå®ããå Žåããããã 1 ã€ãšäžèŽããå Žåã¯æå¹ã§ãããšã¿ãªãããŸãã倧æåã»å°æåã¯åºå¥ãããŸããããã®é ç®ã¯ããENFORCE_LIMITED_FIREWALLãèšå®é ç®ã 1 ã«èšå®ãããŠããå Žåã«ã®ã¿æå¹ã§ãããã®æ©èœã¯ãã·ã³ã»ãã¬ã¯ãŒã¯ã·ã¹ãã ã®ãããªãã¯çã§ã¯å©çšã§ããŸããã
- ã·ã³ã»ãã¬ã¯ãŒã¯ã·ã¹ãã ãµãŒããŒã®èªåã€ã³ã¹ããŒã© (ç¡äººã€ã³ã¹ããŒã©) (ã/auto:1ããšããã³ãã³ãã©ã€ã³ãªãã·ã§ã³ãæå®ããããšã§å©çšå¯èœ) ã«ãããŠã远å ã§ã/NOAFTERRUN:1ããšããã³ãã³ãã©ã€ã³ãªãã·ã§ã³ã«ã察å¿ããŸãããã/NOAFTERRUN:1ããèšå®ãããšãã€ã³ã¹ããŒã©å®äºåŸã«ããµãŒããŒèšå®ããŒã«ããèªåçã«èµ·åããªãããã«ãªããŸãã
- (LGWAN çã®ã¿) ãµãŒããŒã®èªåã€ã³ã¹ããŒã© (ç¡äººã€ã³ã¹ããŒã©) ãå©çšäžã«ãLGWAN çã®ãããã¯ãŒã¯èªåæ€åºåŸã«æ¬¡ã®ç»é¢ã«èªåçã«é²ãŸãªãåé¡ã解決ããã
- ããªã·ãŒèŠå¶ãµãŒããŒã®èšå®é ç®ã«ãREQUIRE_MINIMUM_CLIENT_BUILDãã远å ããŸããããã®é ç®ã«ã¯æŽæ°å€ãæå®ã§ããŸãããã®é ç®ãæå®ãããŠããå Žåã¯ããµãŒããŒã«æ¥ç¶ããããšããŠããã¯ã©ã€ã¢ã³ãã®ãã«ãçªå·ããæå®ãããçªå·æªæºã®å Žåã«ãã¯ã©ã€ã¢ã³ãåŽã«å¯ŸããŠããŒãžã§ã³ã¢ãããä¿ããšã©ãŒã¡ãã»ãŒãžã衚瀺ãããæ¥ç¶ãæåŠãããŸãããã®æ©èœã¯ãå€ãããŒãžã§ã³ã®ã¯ã©ã€ã¢ã³ãããã®æ¥ç¶ãæåŠãããå Žåã«å©çšã§ããŸããããšãã°ãå€ãããŒãžã§ã³ã®ã¯ã©ã€ã¢ã³ãã«ã¯ããã»ãã¥ãªãã£æ©èœãååšããªãå Žåããã®ãããªå€ãã¯ã©ã€ã¢ã³ãã®æ¥ç¶ãçŠæ¢ããããšãã§ããŸãããREQUIRE_MINIMUM_CLIENT_BUILDãã®å€ã¯ããµãŒããŒåŽã®ãœãããŠã§ã¢èªèº«ã®ãã«ãçªå·ä»¥äžã§ãªããã°ãªããŸããã(ãµãŒããŒåŽã®ãœãããŠã§ã¢ã®ãã«ãçªå·ãè¶ ããå€ãèšå®ãããŠããå Žåã¯ããµãŒããŒåŽã®ãœãããŠã§ã¢ã®ãã«ãçªå·ãèšå®ãããŠãããšã¿ãªãããŸãã) ãã®æ©èœã¯ãã·ã³ã»ãã¬ã¯ãŒã¯ã·ã¹ãã ã®ãããªãã¯çã§ã¯å©çšã§ããŸããããã®æ©èœã¯ãã¯ã©ã€ã¢ã³ãããã®ãããã³ã«äžã®èªå·±ç³åå€ãä¿¡çšããŠåäœããŸããã¯ã©ã€ã¢ã³ããäžæ£ã«æ¹é ãããŠããå Žåã§ãå®éãšç°ãªããã«ãçªå·ãã¯ã©ã€ã¢ã³ãã䞻匵ããå Žåã¯ããµãŒããŒã¯ãããèŠåããããšãã§ããŸããã®ã§ããæ³šæãã ãããæ¬æ©èœã¯ãããŸã§ãäžè¬çãªãŠãŒã¶ãŒã«ããå€ãããŒãžã§ã³ã«ããæ¥ç¶ãèŠå¶ãããã®ã§ãããé«åºŠãªãŠãŒã¶ãŒã«ããå€ãããŒãžã§ã³ã®ã¯ã©ã€ã¢ã³ãããã®æ¥ç¶ããã¹ãŠé®æã§ãããã®ã§ã¯ãããŸããã
- ã·ã³ã»ãã¬ã¯ãŒã¯ã·ã¹ãã ãµãŒããŒã®èªåã€ã³ã¹ããŒã© (ç¡äººã€ã³ã¹ããŒã©) ã«å¯Ÿå¿ããã倧éã®ã³ã³ãã¥ãŒã¿ãžã®ãµãŒããŒã®ã€ã³ã¹ããŒã«ãå¿«é©ã«ãªããã€ã³ã¹ããŒã©ã® EXE ãã¡ã€ã«ãå®è¡ããéã«ã/auto:1ããšããã³ãã³ãã©ã€ã³ãªãã·ã§ã³ãæå®ããããšã«ãããã€ã³ã¹ããŒã©ã¯ããã©ã«ãã®ãªãã·ã§ã³ã®ãŸãŸãç¡äººã§æåŸãŸã§é²ã¿ããµãŒããŒèšå®ããŒã«ãèªåçã«èµ·åãããšãããŸã§é²ãããã«ãªãããªãããã®ã³ãã³ãã©ã€ã³ãªãã·ã§ã³ãæå®ããŠå®è¡ããéã«ã¯ãAdministrators æš©éãå¿ èŠã§ãããæš©éããªãå Žåã¯ãUAC ãããã¢ããã衚瀺ãããããŸããã€ã³ã¹ããŒã«äžã«ããã©ã«ãã§æ¬¡ã«é²ãããšãã§ããªããããªãšã©ãŒãçºçããå Žåã¯ãåœè©²ãšã©ãŒã®è¡šç€ºéšåã§åæ¢ããã®ã§ããã以éã¯æåã§ã€ã³ã¹ããŒã«ãããå¿ èŠãããã
- ãã©ã€ããŒãçã§å®å šéååãã¡ã€ã¢ãŠã©ãŒã«æ©èœã«å¯Ÿå¿ãããã¢ããªã±ãŒã·ã§ã³ãã«ãæã«ãããŠããœãŒã¹ã³ãŒãäžã®ãsrc/Vars/VarsActivePatch.hãã®ãThinFwModeãé ç®ããtrueãã«å€æŽããããšã«ããããå®å šéååãã¡ã€ã¢ãŠã©ãŒã«ãæ©èœãã¯ã©ã€ã¢ã³ãæ¥ç¶æã«åŒã³åºãããããã«ãªãããå®å šéååãã¡ã€ã¢ãŠã©ãŒã«ãã«ãããŠéä¿¡ãäŸå€çã«èš±å¯ããéä¿¡å IP ã¢ãã¬ã¹ (IP ãµãããã) ã®ãªã¹ãã¯ãã€ã³ã¹ããŒã©ã®ãã«ãæã«äºããsrc/bin/hamcore/WhiteListRules.txtãã«åæããŠããå¿ èŠããããã¯ã©ã€ã¢ã³ãåŽãæ°ããããŒãžã§ã³ãå¿ èŠã§ããã
- ã¢ããªã®ã€ã³ã¹ããŒã©ãã«ãæã®ãœãŒã¹ã³ãŒãäžã®ãsrc/Vars/VarsActivePatch.hãã®ãThinFwModeãé ç®ããfalseãã®å Žåã§ãã£ãŠããããªã·ãŒèŠå¶ãµãŒããŒã§ãENFORCE_LIMITED_FIREWALLãé ç®ãã1ãã«èšå®ããããšã«ããããå®å šéååãã¡ã€ã¢ãŠã©ãŒã«ãæ©èœã匷å¶çã«æå¹ã«ããããšãã§ããããã«ãããã¯ã©ã€ã¢ã³ãåŽãæ°ããããŒãžã§ã³ãå¿ èŠã§ããããã©ã€ããŒãçãš LGWAN çã§ã¯å©çšã§ãããããããªãã¯çã§ã¯å©çšã§ããªãã
- ãµãŒããŒåŽã§ãtunnel_logããã£ã¬ã¯ããªã«ãµãŒããŒãšäžç¶ã·ã¹ãã ãšã®éã®éä¿¡ã®è©³çްãªãã°ãåºåããããã«ããããµãŒããŒãšäžç¶ã·ã¹ãã ãšã®éãé »ç¹ã«åãããããªå Žåã¯ããã®ãã°ã確èªããããšã«ãããåå ãç¹å®ããããšã容æãšãªãã
- ã€ã³ã¹ããŒã©ã®ãã«ãã«ãããŠããµãŒããŒã¢ããªã®ã¿ãå«ãã ã€ã³ã¹ããŒã©ããã«ãããããšãã§ããããã«ãªã£ãããœãŒã¹ã³ãŒãäžã®ãsrc/Vars/VarsActivePatch.hãã®ãThinSetupServerOnlyãé ç®ããtrueãã«å€æŽããããšã«ããããµãŒããŒã¢ããªã®ã¿ãå«ãã€ã³ã¹ããŒã©ãäœæãããããã¯ã©ã€ã¢ã³ãã¢ããªãšãµãŒããŒã¢ããªã®äž¡æ¹ãå«ãã€ã³ã¹ããŒã©ããšãããµãŒããŒã¢ããªã®ã¿ãå«ãã€ã³ã¹ããŒã©ãã® 2 çš®é¡ããã«ããããå Žåã¯ãåããããã¡ã€ã«ãæžæããŠã2 åãã«ãããããšã(ããã¯ãå°ãææãã®å®è£ ã§ããããæ¬æ©èœã®éèŠã¯ããã»ã©å€ããªããããã容赊ããã ãããã)
- ãMAC ã¢ãã¬ã¹èªèšŒã«ããã MAC ã¢ãã¬ã¹ã®ãªã¹ãããããªã·ãŒèŠå¶ãµãŒããŒåŽã§äžå 管çãããŠãŒã¶ãŒã«èªç±ã«ç®¡çãããããªãããšããèŠæã«å¯Ÿå¿ãããããããªã·ãŒèŠå¶ãµãŒããŒã®èšå®ãã¡ã€ã«ã«ãNO_LOCAL_MAC_ADDRESS_LISTãã远å ããããããã1ãã«èšå®ããããšã«ããããŠãŒã¶ãŒã¯ MAC ã¢ãã¬ã¹èªèšŒã«ããã MAC ã¢ãã¬ã¹ã®ãªã¹ããæåã§èšå®ããããšãã§ããªããªãããªãããNO_LOCAL_MAC_ADDRESS_LISTããæå¹ãšãªãããã«ã¯ãããªã·ãŒèšå®ãã¡ã€ã«ã®ãCLIENT_ALLOWED_MAC_LIST_URLãããã³ãENFORCE_MACCHECKããèšå®ãããŠããå¿ èŠãããã
- LGWAN çã«ãããŠãã¯ã©ã€ã¢ã³ãã Administrators ãŸã㯠SYSTEM æš©éã§åäœããŠããå Žåã¯ããŠãŒã¶ãŒãæå®ãã mstsc.exe ãã¡ã€ã«ãå®è¡ããããšãã§ããªãããã«ããã
- OTP ã«ãããŠãSMTP (ã¡ãŒã«) ã®ä»£ããã« AWS SNS (Amazon Simple Notification Service) ãçšãã SMS éä¿¡ã«å¯Ÿå¿ããã(ãã€ããŒã¹ã±ãŒã«çã®ã¿ã) 詳现ã¯ããã€ããŒã¹ã±ãŒã«çã®ããã¥ã¡ã³ãã® 8-19 ç¯ãOTP ãé»åã¡ãŒã«ã®ä»£ããã« SMS ã§éä¿¡ããæ¹æ³ããåç §ããããšã
- ã€ã³ã¹ããŒã©ã® EXE ãã¡ã€ã«ãšåããã£ã¬ã¯ããªã« EntryPoint.dat ãã¡ã€ã« (ããã¹ããã¡ã€ã«) ãèšçœ®ãããŠããå Žåã¯ããã®ãã¡ã€ã«ããã€ã³ã¹ããŒã©ãã«ãæã«åã蟌ãŸãã EntryPoint.dat ãã¡ã€ã«ã«åªå ããŠããµãŒããŒãšå ±ã«ã€ã³ã¹ããŒã«ãããããã«ãããããã¯ãããšãã°ã·ã³ã»ãã¬ã¯ãŒã¯ã·ã¹ãã äžç¶ã·ã¹ãã ãçµã¿èŸŒãã ã¢ãã©ã€ã¢ã³ã¹ãå®è£ ãããšããHTML 管çç»é¢çããããã®äžç¶ã·ã¹ãã ã«æ¥ç¶ã§ããã€ã³ã¹ããŒã©ã® ZIP ãã¡ã€ã«ãããŠã³ããŒãã§ãããããªæ©èœãå®è£ ããéã«ã倧å€äŸ¿å©ã§ãããEXE ãã¡ã€ã«ãã®ãã®ã¯ãã¹ãŠã®ã·ã¹ãã ã§å ±éã«ããŠãããEntryPoint.dat ãã¡ã€ã«ã®ã¿ãã·ã¹ãã æ¯ã«ç°ãªããã¡ã€ã«ãèªåçæã㊠ZIP ã§ããŠã³ããŒãå¯èœãšããã·ã¹ãã ãã容æã«æ§ç¯ã§ããããã«ãªã£ãããã®ããšã«ããããŠãŒã¶ãŒã¯ã€ã³ã¹ããŒã©ãç¬èªã«ãã«ãããå¿ èŠããªããåœè©²ã¢ãã©ã€ã¢ã³ã¹ã®è£œé å ã 1 åã®ã¿ãã«ãããã°ããããããŠããã®ããšã¯ Microsoft Authenticode 眲åãã€ã³ã¹ããŒã©ã«ã¢ãã©ã€ã¢ã³ã¹åºè·å ããããããä»äžããããšãã§ããããšãæå³ããã®ã§ããã
- ã¯ã©ã€ã¢ã³ãèšŒææžèªèšŒã«ããã OCSP (Online Certificate Status Protocol) æ€èšŒã®å®è£ ãããªã·ãŒèŠå¶ãµãŒããŒã®ãENABLE_OCSPãé ç®ãã1ãã«èšå®ããããšã«ããããµãŒããŒã¯ãã¯ã©ã€ã¢ã³ãèšŒææžèªèšŒèŠæ±ããã£ãå Žåã§ããã€èªèšŒããµãŒããŒã«ãããããç»é²ãããŠããä¿¡é ŒãããèšŒææž (CA ç) ã«ãã眲åã®æ€èšŒã«ãã£ãŠå®æœãããå Žåã«ãåœè©²ã¯ã©ã€ã¢ã³ãèšŒææžã®æ¡åŒµãã£ãŒã«ãã« OCSP ãµãŒããŒã® URL ãèšèŒãããŠããå Žåã¯ããã® OCSP ãµãŒããŒã® URL å®ã« OCSP ãããã³ã«ã«ããèšŒææžãæå¹ãã©ããã®æ€èšŒã詊ã¿ãŸããç¡å¹ã§ãããšåçãããå Žåã¯ããã°ãã¡ã€ã«ã«ãã®æšãèšèŒããèšŒææžèªèšŒã¯å€±æããŸããOCSP ãµãŒããŒãšã®éä¿¡ã«å€±æããå Žåã¯ãæ€èšŒã¯æåãããã®ãšã¿ãªãããŸãã
- ã¢ã«ãŠã³ãããã¯ã¢ãŠãæ©èœã®å®è£ ãããªã·ãŒèŠå¶ãµãŒããŒã®ãAUTH_LOCKOUT_COUNTãããã³ãAUTH_LOCKOUT_TIMEOUTãé ç®ã 1 以äžã®æŽæ°ã«èšå®ããããšã«ããããŠãŒã¶ãŒèªèšŒ (ãã¹ã¯ãŒãèªèšŒ) ã«ãããŠãã¹ã¯ãŒãã誀ã£ãå Žåã®ã¢ã«ãŠã³ãããã¯ã¢ãŠããå¯èœãšãªããŸãããAUTH_LOCKOUT_COUNT ã«ã¯ãããã¯ã¢ãŠããçºçãããŸã§ã®èªèšŒå€±æåæ°ãæå®ããŸããAUTH_LOCKOUT_TIMEOUT ã«ã¯ãããã¯ã¢ãŠããèªåè§£é€ããããŸã§ã®ã¿ã€ã ã¢ãŠãå€ãç§åäœã§æå®ããŸãã
- ç¡æäœæã®ã¿ã€ã ã¢ãŠãå®è£ ãããªã·ãŒèŠå¶ãµãŒããŒã®ãIDLE_TIMEOUTãé ç®ã 1 以äžã®æŽæ°ã«èšå®ããããšã«ããããŠãŒã¶ãŒãã¯ã©ã€ã¢ã³ãåŽã§ããŠã¹ããIDLE_TIMEOUTãã§æå®ãããç§æ°ä»¥äžç¡æäœã§ãã£ãå Žåã¯ãã¯ã©ã€ã¢ã³ãåŽã®æ¥ç¶ãåæãããç¡æäœã¿ã€ã ã¢ãŠããçºçããæšã®ã¡ãã»ãŒãžããã¯ã¹ãã¯ã©ã€ã¢ã³ãåŽã®ç»é¢ã«è¡šç€ºãããããã«ãªããŸãããã®æ©èœãæå¹ãšãªãã«ã¯ãã¯ã©ã€ã¢ã³ãåŽã®ããŒãžã§ã³ã beta7preview9 以éã§ããå¿ èŠããããŸãããã以åã®ã¯ã©ã€ã¢ã³ãã®å Žåã¯ãç¡èŠãããŸãã
- ããªã·ãŒèŠå¶ãµãŒããŒã®ãSERVER_ALLOWED_MAC_LIST_URLãã«ãã MAC ã¢ãã¬ã¹äžèЧããã¹ããã¡ã€ã«ã®æå®ã«ãããŠãMAC ã¢ãã¬ã¹äžèЧããã¹ããã¡ã€ã«ã®å é è¡ã« UTF-8 ã® BOM æåãå ¥ã£ãŠããå Žåããã® BOM æåãé€å€ããŠåŠçãè¡ãªãããã«æ¹è¯ããŸããã
- 空ãã¡ã¢ãªå®¹éãååã§ãªãå ŽåãããµãŒããŒèšå®ããŒã«ãã§èŠåã¡ãã»ãŒãžã衚瀺ãããããã«ããŸããã
- ãã©ã€ããŒãç (ãã€ããŒã¹ã±ãŒã«ç) ãå®è£ ããŸããã
- ã³ã³ãããŒã©ã®å®å šåé·ã«å¯Ÿå¿ããŸããã
- ãµãŒããŒçã§è©³çްãããã°ãã°ãä¿åããæ©èœãå®è£ ããŸããã
- (LGWAN çã®ã¿) ã€ã³ã¹ããŒã«æã« RDP ãããªã·ãŒã§ç¡å¹ã«ãªã£ãŠããå Žåã¯ãã¯ãªããããŒãããã³ãã¡ã€ã«å ±æãã€ã³ã¹ããŒã«æã«ç¡å¹åãããã®ä»£ãããæ¯åã®æ¥ç¶æã«ã¯ããªã·ãŒãããããªãããã«ããããŸããã€ã³ã¹ããŒã«æã« RDP ãããªã·ãŒã§ç¡å¹ã«ãªã£ãŠããå Žåã¯ããã®æšã®ã¡ãã»ãŒãžã衚瀺ããããã«ããã
- ãµãŒããŒåŽãœãããŠã§ã¢ã«ãããŠãWindows ã®ããŒã«ã«ã°ã«ãŒãããªã·ãŒãŸãã¯ãã¡ã€ã³ã°ã«ãŒãããªã·ãŒã§ãªã¢ãŒããã¹ã¯ããããç¡å¹ã§ããå Žåã§ãæ¥ç¶å仿ã«åŒ·å¶çã«æå¹ã«ããããã«ããŸããã
- ã¯ã©ã€ã¢ã³ãæ¥ç¶äžã¯ã¯ã©ã€ã¢ã³ãåŽ PC ã®ã·ã¹ãã ãã¹ãªãŒãããªãããã«ããŸããã
- çµ±èšæ©èœãå®è£ ããŸããã
- ãã©ã€ããŒãç (ã¹ã¿ã³ãã¢ãã³ç) ãå®è£ ããŸããã
- Windows ã«ãã㊠Admin æš©éãæããŠãããã©ããã®å€å®ãå³å¯åããŸããã
- (LGWAN çã®ã¿) ã¯ãªããããŒãå±¥æŽã®ä¿åãçŠæ¢ããŸãããWindows æšæºã®ã¹ã¯ãªãŒã³ã·ã§ãããããããŒã«ããã¹ã¯ãªãŒã³ã·ã§ããæ®åœ±ãçŠæ¢ããŸããã
- ãµãŒããŒã§ãªã¢ãŒãã¢ã¯ã»ã¹äžã«ãããããã»ã¹ã®èµ·å / çµäºã®ãã°ãä¿åã§ããããã«ããŸããã
- ã²ãŒããŠã§ã€ã§ DisableDoSProtection ãªãã·ã§ã³ãå®è£ ããŸããã
- LGWAN çãå®è£ ããŸããã
- ããªã·ãŒã§ OTPãMAC ã¢ãã¬ã¹æ€æ»ãã¯ã©ã€ã¢ã³ãæ€ç«æ€æ»ãéãã ã匷å¶çã«ç¡å¹åã§ããããã«ããŸããã
- MAC ã¢ãã¬ã¹ãªã¹ãããã«ãã¹ã¬ããç«¶åã«ãã£ãŠçšã«æ¶ããŠããŸãåé¡ã解決ããŸããã
- å®å šéå FW ããªãã·ã§ã³ã§ OFF ã«ãã§ããããã«ããŸããã
- ç»é²ããŒã«å¯Ÿå¿ããŸããã
- Proxy Protocol ã«å¯Ÿå¿ããŸããã
- Windows 10 2004 ã¯ãªãŒã³ã€ã³ã¹ããŒã«ç°å¢ã§ãWindows Hello èªèšŒãã匷å¶ãããŠããå Žåã¯ãRDP æ¥ç¶ãã§ããªãåé¡ãããããã匷å¶ãè§£é€ããããã«ããŸããã
- ãœãŒã¹ã³ãŒãããµãã¢ãžã¥ãŒã«ã«åé¢ããã¢ã¯ãã£ããããããã©ã³ãã£ã³ã°ãå¯èœã«ããŸããã
- Visual Studio 2019 ã«ãããã«ãã«å¯Ÿå¿ããŸããã
- WhiteList Rules ã§ãã©ã€ããŒã IP ã®ç¯å²ãééã£ãŠããã®ãä¿®æ£ããŸããã
- è¡æ¿ã¢ãŒãã§ãµãŒããŒåŽãæ€ç« ON ã®å Žåã¯ãå¿ ã FW æ©èœã匷å¶ããããã«ããŸããã
- Wake on LAN æ©èœ (æ¥ç¶å 端æ«ã®é»æºãèªå® ãã ON ããæ©èœ)
- ç»é¢æ®åœ±ã»ãã£ããã£é²æ¢ã®ããã®é»åéããæ©èœ
- åºæ ID åæåæ©èœ (VDI ã¯ããŒã³å¯Ÿå¿)
- ã¯ã©ã€ã¢ã³ã MAC ã¢ãã¬ã¹èªèšŒã®ããªã·ãŒãµãŒããŒã«ãããªã¹ãäžå ç®¡çæ©èœ
- å®å šéåå FW æ©èœ (ãªã¢ãŒãå©çšäžã¯ãŠãŒã¶ãŒèªå® PC ãšã€ã³ã¿ãŒããããšã®éãå®å šã«é®æ)
- ããªã·ãŒãµãŒããŒã«ãããµãŒããŒç«¯æ«ã®æç€ºççä¿¡èš±å¯æ©èœ (ãªã¹ãã«ç»é²ãããŠããªããµãŒããŒç«¯æ«ã¯åäœçŠæ¢ãã)
- äºèŠçŽ èªèšŒã»ã¯ã³ã¿ã€ã ãã¹ã¯ãŒã (OTP) æ©èœ
- ãã€ãã³ããŒã«ãŒããçšãããŠãŒã¶ãŒèªèšŒæ©èœ
- ã¯ã©ã€ã¢ã³ãæ€ç«æ©èœã»MAC ã¢ãã¬ã¹èªèšŒæ©èœ
- ãšã³ã¿ãŒãã©ã€ãºç°å¢çšããªã·ãŒèŠå¶ãµãŒããŒæ©èœ
- è¡æ¿æ å ±ã·ã¹ãã é©å¿ã¢ãŒã (äžç¶ã·ã¹ãã ã® IP ç¯å²ã®éå®)
- ãã¯ã³ã¿ã€ã ãã¹ã¯ãŒãèªèšŒ (OTP)ã ã远å ããŸãããäŒæ¥ç°å¢ã§ã®æ¢åã®ã»ãã¥ãªãã£ããªã·ãŒã«æºæ ããããããäºèŠçŽ èªèšŒã«å¯Ÿå¿ããŠã»ãããããOTP ã«å¯Ÿå¿ããŠã»ããããšãããèŠæã«ãå¿ãããŠãæ°èŠéçºãããããŸããã
- ãä»®æ³ãã«ããã£ã¹ãã¬ã€æ©èœãã远å ããŸããããè·å Žã® PCãã«ãã£ã¹ãã¬ã€ã 1 æãããªãå Žåã§ããèªå® ã® PC ã«ãã£ã¹ãã¬ã€ã 2 æä»¥äžããã°ãèªå® ããè·å Žã® PC ããªã¢ãŒãæäœããéã«ãã«ããã£ã¹ãã¬ã€åããŠã倧å€å¿«é©ã«æäœããããšãã§ããŸãã
- ããã¹ã¯ãŒãè€éæ§ãæºãããŠããªããŠããèŠåãç¡èŠããã°ç°¡åãªãã¹ã¯ãŒããèšå®ã§ããã®ã¯è¯ããªãã®ã§ã¯ãªãããããšãããæèŠãããã ããŸããã®ã§ããã¹ã¯ãŒãè€éæ§ãæºãããŠããªããã¹ã¯ãŒããèšå®ããããšãã§ããªãããŸããã(Beta 2 ãŸã§ã¯èŠåã¡ãã»ãŒãžã¯ç¡èŠå¯èœã§ããããBeta 3 ã§ã¯ãç¡èŠå¯èœãªèŠåã¡ãã»ãŒãžã¯å»æ¢ãããç¡èŠããããšãã§ããªããšã©ãŒã¡ãã»ãŒãžãšãªããŸããã)
- ãã¹ã¯ãŒãè€éæ§ã®èŠåãèŠçŽãã(1) 8 æå以äžã§ãå°æåã»å€§æåã»æ°åã»èšå·ã®ãã¡å°ãªããšã 3 çš®é¡ä»¥äžã䜿çšãããŠããã(2) 16 æå以äžã§ãå°æåã»å€§æåã»æ°åã»èšå·ã®ãã¡å°ãªããšã 2 çš®é¡ä»¥äžã䜿çšãããŠããã(3) 24 æå以äžã§ãããã®ãããããæºãããŠããã°å¯ãšããŸããã
- ãã·ã³ã»ãã¬ã¯ãŒã¯ã·ã¹ãã ãµãŒããŒãããã³ãã·ã³ã»ãã¬ã¯ãŒã¯ã·ã¹ãã ã¯ã©ã€ã¢ã³ãããšãäžç¶ã·ã¹ãã ãšã®éã®éä¿¡ã®ã»ãã¥ãªã㣠(å¯çšæ§) ãåäžããŸãããäžç¶ã·ã¹ãã ã«ãããããŒããã©ã³ãµãšã®éã®éä¿¡ããäœããã®éä¿¡é害ã«ãã確ç«ã§ããªãå Žåã¯ãã»ã«ã³ããªããŒããã©ã³ãµã«å¯ŸããŠæ¥ç¶ã詊ã¿ãããã«ãªããŸããããŸããã»ã«ã³ããªããŒããã©ã³ãµããè€æ°ã®ãã¡ã€ã³ããã³ AS ã«åæ£ããŠé 眮ããŸãããããã«ãããéä¿¡çµè·¯ã«é害ããã 1 ã€ã®ããŒããã©ã³ãµãšéä¿¡ãã§ããªãå Žåã§ããä»ã®ããŒããã©ã³ãµã«è¿åããŠéä¿¡ã確ç«ã§ããããã«ãªããŸããã
- ãã·ã³ã»ãã¬ã¯ãŒã¯ã·ã¹ãã ã¯ã©ã€ã¢ã³ããã®èµ·åæã«ãããæ°ããããŒãžã§ã³ãå©çšå¯èœã«ãªã£ãŠããå Žåã¯ç»é¢ã«æ¡å ã衚瀺ããããã«ããŸããããã®æ©èœã¯ããããŒãžã§ã³æ å ±ãç»é¢ããç¡å¹ã«ã§ããŸãã
- ãé«åºŠãªãŠãŒã¶ãŒèªèšŒãæ©èœã®èšŒææžèªèšŒã§ãX.509 èšŒææžã®ãããæ°ã 1024 bit ãã倧ããå Žåã«èªèšŒã«å€±æããåé¡ã解決ããŸããã
- HTTP ãããã·ãµãŒããŒãçµç±ããå Žåã® User Agent ã®æååããŠãŒã¶ãŒãèªç±ã«å€æŽã§ããããã«ããŸããã
- ã°ã«ãŒãããªã·ãŒã§ RDP ãç¡å¹ãšãªã£ãŠããå Žåã§ããRDP ãçšããã·ã¹ãã ã¢ãŒãã§ã®æ¥ç¶ãã§ããããã«ããŸããã
- ãŠãŒã¶ãŒã®ã³ã³ãã¥ãŒã¿ã®ããŒããã£ã¹ã¯ãäºãæ»æè ã«ããå¥ã®ææ®µã«ãã䟵害ããããã«ãŠã§ã¢ã®ãã¡ã€ã«ãä¿åãããŠããå Žåã§ããŠãŒã¶ãŒããåœè©²ãã«ãŠã§ã¢ãšåããã£ã¬ã¯ããªã«æ¬ããã°ã©ã ã®ã€ã³ã¹ããŒã©ã眮ããŠå®è¡ãããšããã«ãŠã§ã¢ãå®è¡ãããŠããŸãå Žåãããã»ãã¥ãªãã£åé¡ã解決ããŸãããããã¯ãããã DLL ããªããŒãåé¡ãšåŒã°ãã Windows ã®èšèšäžã®è匱æ§ãããšã§çºçããåé¡ã§ããã¢ããªã±ãŒã·ã§ã³åŽã§ã®å¯ŸçãæœããŸãããæ¥äžéšåžæ°ããã®å ±åã«ãããã®ã§ããããããšãããããŸããã
- ã¯ã©ã€ã¢ã³ãã«ããªã©ãã¯ã¹ã»ã¢ãŒããã远å ããŸããããã¬ã¯ãŒã¯ã®éå§åã«ããªã©ãã¯ã¹ããããšãã§ããŸããããã©ã«ãã§ç¡å¹ã«ãªã£ãŠããŸãããã¯ã©ã€ã¢ã³ãã®ãªãã·ã§ã³èšå®ããæå¹ã«ã§ããŸãããã²ãæå¹ã«ããŠã¿ãŠãã ããã
æåã®ããŒãžã§ã³ã§ãã