著者
Ryosuke Matsumoto Kenji Rikitake Kentaro Kuribayashi
雑誌
情報処理学会論文誌 (ISSN:18827764)
巻号頁・発行日
vol.60, no.9, 2019-09-15

For large-scale certificate management of multi-tenant web servers, preloading numerous certificates for managing numerous hosts under the single server process results in increasing the required memory usage because of the respective page table entry manipulation, which might be a poor resource efficiency and a reduced capacity. To resolve this issue, we propose a method for dynamic loading of certificates bound to the hostnames found during the SSL/TLS handshake sequences without preloading, provided that the Server Name Indication (SNI) extension is available. We implemented the function of choosing the respective certificates with the ngx_mruby module, which extends web server functions using mruby with a small memory footprint while maintaining the execution speed. The proposed method was evaluated by a web hosting service employing the authors.------------------------------This is a preprint of an article intended for publication Journal ofInformation Processing(JIP). This preprint should not be cited. Thisarticle should be cited as: Journal of Information Processing Vol.27(2019) (online)DOI http://dx.doi.org/10.2197/ipsjjip.27.650------------------------------

言及状況

Twitter (10 users, 13 posts, 38 favorites)

ペパボ研究所でJIPに投稿していた、Webサーバの大規模証明書管理に関する我々のジャーナル論文が採録、公開されました!エディターメッセージ読むと、投稿8本で採録は2本と実はすごく厳しかったことが判明して安堵と喜びがあります。 https://t.co/yTxUO6oW7g 論文はこちら https://t.co/6hl5TlvuzO

収集済み URL リスト