Home | Data Center | Contact US | Login

Á¦¸ñ ¸ÖƼµµ¸ÞÀÎ CSR(ÀÎÁõ ½Åû¼­) »ý¼º ¹× CRT(ÀÎÁõ¼­) Àû¿ë¹æ¹ý
÷ºÎÆÄÀÏ CSR »ý¼º¹æ¹ý(¸ÖƼµµ¸ÞÀÎ).pdf ÀÛ¼ºÀÏ 2007-08-17 13:32:13
¸ÖƼµµ¸ÞÀÎ CSR(ÀÎÁõ ½Åû¼­) »ý¼º ¹× CRT(ÀÎÁõ¼­) Àû¿ë¹æ¹ý
 
¸ÖƼµµ¸ÞÀÎÀÇ °æ¿ì ´ÜÀϵµ¸ÞÀΰú À¯»çÇÑ ¼³Á¤À¸·Î ÀÌ·ç¾îÁö¸ç ´ëÇ¥ µµ¸ÞÀÎÀÇ °³ÀÎÅ°¿Í ÀÎÁõ¼­, CA rootÀÎÁõ¼­ ÆÄÀÏÀ» ´Ù¸¥ µµ¸ÞÀο¡µµ µ¿ÀÏÇÏ°Ô Àû¿ëÀ» ½ÃÅ°´Â ¹æ½ÄÀ̸ç ÀÎÁõ¼­ ÆÄÀÏ¿¡ ¸ÖƼµµ¸ÞÀÎÀ¸·Î ½ÅûÇÑ µµ¸ÞÀÎ Å° °ªÀÌ ¸ðµÎ Æ÷ÇԵǾî ÀÖ½À´Ï´Ù.
 
nextline.co.kr À» ´ëÇ¥ µµ¸ÞÀÎÀ¸·Î ÇÑ www.nextline.co.kr 2°³ µµ¸ÞÀÎÀÇ CSR»ý¼º °ú CRTÀ» Àû¿ëÇÑ ¿¹ÀÔ´Ï´Ù.
 
Apache À¥¼­¹ö¿¡ SSL¸¦ Àû¿ëÇϱâ À§ÇØ ¾Æ·¡ Ç׸ñÀÌ ¼³Ä¡µÇ¾î ÀÖ¾î¾ß ÇÕ´Ï´Ù.
 
- OpenSSL ¾Ïȣȭ ¶óÀ̺귯¸®
- Mod_ssl ¸ðµâ
 

( 1 ) OpenSSL ¶óÀ̺귯¸® ¼³Ä¡È®ÀÎ
 
OpenSSL ¶óÀ̺귯¸®°¡ ¼³Ä¡µÇÁö ¾ÊÀº °æ¿ì ±â¼ú¹®¼­¸¦ Âü°íÇÏ¿© ¼³Ä¡ÇÏ¿© Áֽñ⠹ٶø´Ï´Ù.
 
¨ç rpm ¹öÀüÈ®ÀÎ
[root@nextline ~]# rpm -qa | grep openssl
rpm ¹öÀüÀ¸·Î ¼³Ä¡µÈ opensslÀÇ À¯/¹«¸¦ È®ÀÎÇÕ´Ï´Ù.

 

¨è Source ¹öÀüÈ®ÀÎ
 
whereis ¸í·É¾î
¸í·ÉÀÇ ½ÇÇà ÆÄÀÏ, ¼Ò½º, ¸Å´º¾ó ÆäÀÌÁö°¡ ¾îµð ÀÖ´ÂÁö º¸¿©ÁÝ´Ï´Ù.
 
[root@nextline ~]# whereis openssl
rpm ¹öÀüÀÌ ¼³Ä¡µÇ¾î ÀÖÁö ¾ÊÀ» ½Ã À§ ¸í·É¾î¸¦ ÅëÇØ ¼Ò½º¹öÀü ¼³Ä¡ À¯/¹«¸¦ È®ÀÎÇÕ´Ï´Ù.

 
 
 
( 2 ) mod_ssl ¸ðµâÈ®ÀÎ
 
[vi ¿¡µðÅÍ »ç¿ë¹ý]
»ç¿ëÇü½Ä: vi [¿É¼Ç] [»ý¼ºÇÒ ÆÄÀϸí/ÆíÁýÇÒ ÆÄÀϸí]
vi ¿¡µðÅÍ´Â ÀԷ¸ðµå, ¸í·É¸ðµå, ½ÇÇà¸ðµå·Î ±¸ºÐµË´Ï´Ù.
ÀԷ¸ðµå: vi ÆíÁýÈ­¸é¿¡¼­ ¹®ÀÚ¸¦ ÀÔ·ÂÇÒ ¼ö ÀÖ´Â ¸ðµå·Î¼­ ÀԷ¸ðµå·Î ÁøÀÔÇϱâ À§Çؼ­´Â i, a, o, I, A, O, RµîÀÌ ÀÖ½À´Ï´Ù. Áï Ãʱâ vi ÆíÁý±â ¸ðµå´Â ¸í·É¾î ¸ðµå·Î ÁøÀÔÀ» Çϱ⠶§¹®¿¡ ¹®ÀÚ¸¦ ÀÔ·ÂÇϱâ Àü¿¡ ¾ÕÀÇ ´ÜÃàÅ° Áß Çϳª¸¦ ¸ÕÀú ÀÔ·ÂÇØ¾ß ¿øÇÏ´Â ¹®ÀÚ¸¦ ÀÔ·ÂÇÒ ¼ö ÀÖ½À´Ï´Ù.
¸í·É¸ðµå: Ä¿¼­À̵¿/¹®ÀÚ»èÁ¦/¹®ÀÚ(¿­)±³Ã¼/¹®ÀÚ¿­°Ë»ö µîÀ» ÇÒ ¼ö ÀÖ´Â ¸ðµå·Î¼­ ÀԷ¸ðµå¿¡¼­ ÆíÁýÀÌ ¿Ï·áµÇ¸é EscÅ°¸¦ ´­·¯ ¸í·É¸ðµå·Î ÁøÀÔÇÏ¸é µË´Ï´Ù.
½ÇÇà¸ðµå: Ưº°ÇÑ ¸í·É¾î¸¦ ½ÇÇàÇÏ´Â ¸ðµå·Î¼­ ¸í·É¾î¸ðµå¿¡¼­ ":"(ÄÝ·Ð)¸¦ ´©¸£¸é vi È­¸é ÇÏ´Ü ÁÂÃø¿¡ vi Ư¼ö¸í·É¾î¸¦ ÀÔ·ÂÇÒ ¼ö ÀÖ½À´Ï´Ù.
 
[½ÇÇà¸ðµåÀÇ ÀϹÝÀûÀ¸·Î ¾²À̴ Ư¼ö ¸í·É¾î]
q : ¼öÁ¤ ÀÛ¾÷ÀÌ ÀÌ·ç¾îÁöÁö ¾ÊÀº »óÅ¿¡¼­ vi ÆíÁý±â¿¡¼­ ºüÁ®³ª¿É´Ï´Ù.
q! : ¼öÁ¤ ÀÛ¾÷ÀÌ ÀÌ·ç¾îÁø ºÎºÐÀ» Àû¿ë½ÃÅ°Áö ¾Ê°í vi ÆíÁý±â¸¦ °­Á¦·Î ºüÁ®³ª¿É´Ï´Ù.
w : ¼öÁ¤µÈ ÀÛ¾÷À» ÀúÀåÇÕ´Ï´Ù.
wq : ¼öÁ¤µÈ ÀÛ¾÷À» ÀúÀåÇÏ°í vi ÆíÁý±â¿¡¼­ ºüÁ®³ª¿É´Ï´Ù.
Ãʱ⠸í·É¾î¸ðµå-> ÀԷ¸ðµåÁøÀÔ -> ÆíÁý -> ¸í·É¾î¸ðµå -> ½ÇÇà¸ðµå -> Á¾·á

 
¨ç phpinfo ÆÄÀÏ»ý¼º
[root@nextline ~]#vi /usr/local/apache/htdocs/php_test.php

 
 
¨è phpinfo Äڵ弳Á¤
phpinfo();
?>



¨é ¸ðµâÈ®ÀÎ
http://xxx.xxx.xxx.xxx/php_test.php
 
 

( 3 ) CSR »ý¼º
 
CSR ( Certificate Signing Request ) À̶õ?
 
SSL ¼­¹ö¸¦ ¿î¿µÇϴ ȸ»çÀÇ Á¤º¸¸¦ ¾ÏȣȭÇÏ¿© ÀÎÁõ±â°üÀ¸·Î º¸³» ÀÎÁõ¼­¸¦ ¹ß±Þ¹Þ°Ô ÇÏ´Â ÀÏÁ¾ÀÇ ½Åû¼­À̸ç CSRÀº ASCII ÅؽºÆ® È­ÀÏ·Î »ý¼ºµË´Ï´Ù.
 
¨ç °³ÀÎÅ° »ý¼º
Openssl ¸í·É¾î¸¦ ÀÌ¿ëÇÏ¿© À¥¼­¹öÀÇ RSAÅ°(1024ºñÆ® ¾Ïȣȭ)¸¦ »ý¼ºÇÕ´Ï´Ù.
°³ÀÎÅ° »ý¼º½Ã DES/RSA ¾Ïȣȭ ¹æ½ÄÀ» ¼±ÅÃÇÒ ¼ö ÀÖÀ¸³ª DES ¹æ½ÄÀ¸·Î °³ÀÎÅ°¸¦ »ý¼ºÇÏ½Ç °æ¿ì ¾ÆÆÄÄ¡¸¦ ±¸µ¿ÇÏ¸é °³ÀÎÅ° »ý¼º½Ã ÀÔ·ÂÇÑ Æнº¿öµå¸¦ ¹¯°Ô µÇ¸ç ºÎÆà ½Ã ¾ÆÆÄÄ¡ µ¥¸óÀÌ ÀÚµ¿À¸·Î ±¸µ¿µÇµµ·Ï ¼³Á¤ÇϽŠ°æ¿ì ºÎÆà Áß Æнº¿öµå¸¦ ¹¯°Ô µÇ¹Ç·Î °ü¸®ÀÇ ¿øÈ°ÇÔÀ» À§ÇØ RSA ¹æ½ÄÀ¸·Î °³ÀÎÅ°¸¦ »ý¼ºÇÕ´Ï´Ù.
/usr/local/src µð·ºÅ丮·Î À̵¿ÇÏ¿© Å°»ý¼º ÇÕ´Ï´Ù.
 
[root@nextline ~]# cd /usr/local/src
openssl genrsa 1024 > µµ¸ÞÀÎ.key
 
[root@nextline src]# openssl genrsa 1024 > nextline.co.kr.key

 
 
¨è µµ¸ÞÀÎ Á¶È¸
CSR Á¤º¸ÀÔ·Â ¹× ÀÎÁõ½Åû¼­ ÀÛ¼º½Ã µµ¸ÞÀÎ µî·Ï¾÷ü ¹× µµ¸ÞÀÎ Á¶È¸»çÀÌÆ®¿¡¼­ µµ¸ÞÀÎÀ» Á¶È¸ÇÏ¿© Á¶È¸°á°ú¿Í ÀÏÄ¡ÇÏ°Ô Á¤º¸¸¦ ÀÔ·ÂÇÏ¿©¾ß ÇÕ´Ï´Ù.
http://whois.nic.or.kr

 
 
[CSR Ç׸ñ¿¡ ´ëÇÑ ¼³¸í]
CSR Á¤º¸ ÀÔ·Â ½Ã µµ¸ÞÀÎ µî·Ï¾÷ü¿¡ µî·ÏÇϽŠÁ¤º¸¿Í µ¿ÀÏÇÑ Á¤º¸¸¦ ÀÔ·ÂÇÕ´Ï´Ù.
 
Country Name
ÀÌ°ÍÀº µÎ ÀÚ·Î µÈ ISO Çü½ÄÀÇ ±¹°¡ ÄÚµåÀÔ´Ï´Ù.
State or Province Name
½Ã À̸§À» ÀÔ·ÂÇØ¾ß ÇÏ¸ç ¾à¾î¸¦ »ç¿ëÇÒ ¼ö ¾ø½À´Ï´Ù.
Locality Name
ÀÌ Çʵå´Â ´ëºÎºÐÀÇ °æ¿ì »ý·«ÀÌ °¡´ÉÇÏ¸ç ¾÷ü°¡ À§Ä¡ÇÑ °÷¸¦ ³ªÅ¸³À´Ï´Ù.
Organization
»ç¾÷ÀÚ µî·ÏÁõ¿¡ Àִ ȸ»ç¸í°ú ÀÏÄ¡µÇ´Â ¿µ¹®È¸»ç¸íÀ» ÀÔ·ÂÇÏ½Ã¸é µË´Ï´Ù.
Organization Unit
"¸®´ª½º °ü¸®ÆÀ", "À©µµ¿ì °ü¸®ÆÀ" µî°ú °°ÀÌ ¾÷üÀÇ ºÎ¼­¸¦ ÀÔ·ÂÇÒ ¼ö ÀÖ½À´Ï´Ù.
Common Name
ÀÎÁõ¹ÞÀ» µµ¸ÞÀÎÁÖ¼Ò¸¦ ÀÔ·ÂÇÏ½Ã¸é µË´Ï´Ù.
 
ÀÌ Á¤º¸·Î À¥ »çÀÌÆ®¸¦ ½Äº°ÇϹǷΠȣ½ºÆ® À̸§À» º¯°æÇÒ °æ¿ì ´Ù¸¥ µðÁöÅÐ ID¸¦ ¿äûÇØ¾ß ÇÕ´Ï´Ù. È£½ºÆ®¿¡ ¿¬°áÇϴ Ŭ¶óÀ̾ðÆ® ºê¶ó¿ìÀú°¡ µðÁöÅÐ IDÀÇ À̸§°ú URLÀÌ ÀÏÄ¡ÇÏ´ÂÁö¸¦ È®ÀÎÇÕ´Ï´Ù.
 
[CSR Ç׸ñ ÀԷ½à ÁÖÀÇ»çÇ×]
Common Name ¿¡´Â ÀÎÁõ¼­¸¦ ¼³Ä¡ÇÒ »çÀÌÆ®ÀÇ µµ¸ÞÀÎÀÇ À̸§À» Á¤È®ÇÏ°Ô ÀÔ·ÂÇÏ¼Å¾ß Çϸç IP ÁÖ¼Ò, Æ÷Æ®¹øÈ£, °æ·Î¸í, http:// ³ª https:// µîÀº Æ÷ÇÔÇÒ ¼ö ¾ø½À´Ï´Ù. 
CSR Ç׸ñ¿¡´Â < > ~ ! @ # $ % ^ * / \ ( ) ? µîÀÇ Æ¯¼ö 68 ¹®ÀÚ¸¦ ³ÖÀ» ¼ö ¾ø½À´Ï´Ù. 
CSR »ý¼ºÈÄ ¼­¹ö¿¡ °³ÀÎÅ° (Private Key) °¡ »ý¼ºµË´Ï´Ù. °³ÀÎÅ°¸¦ »èÁ¦Çϰųª ºÐ½ÇÇÒ °æ¿ì ÀÎÁõ¼­¸¦ ¹ß±Þ¹Þ¾Æµµ ¼³Ä¡°¡ ºÒ°¡ÇÕ´Ï´Ù. µû¶ó¼­ ²À °³ÀÎÅ°¸¦ ¹é¾÷¹Þ¾Æ µÎ¼Å¾ß ÇÕ´Ï´Ù.
Á¤º¸ÀԷ°úÁ¤ ¸¶Áö¸·¿¡ ³ª¿À´Â A challenge password ¿Í An optional company name µÎ Ç׸ñÀº ÀÔ·ÂÇÏÁö ¸¶½Ã°í Enter ¸¸ ´©¸£°í ³Ñ¾î°¡¾ß ÇÕ´Ï´Ù. µÎ Á¤º¸°¡ ÀÔ·ÂµÉ °æ¿ì À߸øµÈ CSR »ý¼ºµÉ ¼ö ÀÖ½À´Ï´Ù.
 
¨é CSR(ÀÎÁõ¿äû¼­) »ý¼º
[root@nextline src]# openssl req -new -key nextline.co.kr.key > nextline.co.kr.csr

 
 
[CSR Á¤º¸ÀÔ·Â Ç׸ñ]
Country Name (2 letter code) [AU]:KR
State or Province Name (full name) [Some-State]:Seongnam Gyeonggi-do
Locality Name (eg, city) []:Yatap-dong Bundang-gu
Organization Name (eg, company) [Internet Widgits Pty Ltd]:nextline
Organizational Unit Name (eg, section) []:Technological Support Department
Common Name (eg, YOUR name) []:nextline.co.kr
Email Address []:nextline@nextline.co.kr
A challenge password/An optional company name Ç׸ñÀº ÀÔ·ÂÇÏÁö ¾Ê°í Enter¸¸ ´©¸£°í ³Ñ¾î°©´Ï´Ù.
Please enter the following 'extra' attributes
to be sent with your certificate request
A challenge password []:
An optional company name []:
 


 
¨é CSR È®ÀÎ
[root@nextline src]# openssl req -noout -text -in nextline.co.kr.csr

 
 
( 4 ) ÀÎÁõ¼­ Á¢¼ö

³Ø½ºÆ®¶óÀο¡ ÀÎÁõ¼­¹ß±Þ ¿äû ½Ã Á¢¼ö¾ç½Ä¿¡ µû¶ó Á¤º¸ ±âÀÔ ÈÄ ÀÎÁõ¼­¹ß±ÞÀ» ½ÅûÇÕ´Ï´Ù.
 
¨ç ÀÎÁõ¼­ ½Åû Á¤º¸ÀÔ·Â
µµ¸ÞÀÎ : nextline.co.kr
»óÇ°Á¾·ù : ¸ÖƼµµ¸ÞÀÎ
µµ¸ÞÀÎ Ãß°¡ µî·Ï : www.nextline.co.kr (¸ÖƼµµ¸ÞÀÎÀÇ °æ¿ì ÇØ´çµÇ¸ç Ãß°¡ÇÏ½Ç µµ¸ÞÀÎÀ» ±âÀÔÇÕ´Ï´Ù)
ÀÎÁõ¼­ ±â°£ : 1/2/3 ³â 
¿î¿µÈ¯°æ : Apache + Mod SSL
CSR ÄÚµåÀÔ·Â : CSR ÃßÃâ°ª ÀÔ·Â
»óÈ£¸í(¿µ¹®ÀÔ·Â) : nextline
ºÎ¼­¸í(¿µ¹®ÀÔ·Â) : Technological Support Department
ÁÖ¼Ò »ó¼¼ÁÖ¼Ò(¿µ¹®ÀÔ·Â) : Hostway IDC 343-1
½Ã/±º(¿µ¹®ÀÔ·Â) : Yatap-dong Bundang-gu
½Ã/µµ(¿µ¹®ÀÔ·Â) : Seongnam Gyeonggi-do
¿ìÆí¹øÈ£ : 463-828
±¹°¡ : KR
µî·Ï¹øÈ£(»ç¾÷ÀÚµî·Ï¹øÈ£/Áֹεî·Ï¹øÈ£ µµ¸ÞÀÎ ¼ÒÀ¯ÁÖ) : µµ¸ÞÀÎ Á¶È¸ ½Ã ³ªÅ¸³ª´Â Ã¥ÀÓÀÚ ¹× »ç¾÷ÀÚ Á¤º¸¸¦ ÀÔ·ÂÇÕ´Ï´Ù.
¸ÞÀÏÁÖ¼Ò(ÀÎÁõ¼­ ¼ö·É À̸ÞÀϱâÀÔ) : µµ¸ÞÀÎ Á¶È¸ ½Ã ³ªÅ¸³ªÀִ åÀÓÀÚ ÀüÀÚ¿ìÆíÀ» ÀÔ·ÂÇÕ´Ï´Ù.
´ã´çÀÚ À̸§ :  µµ¸ÞÀÎ Á¶È¸ ½Ã ³ªÅ¸³ª´Â Ã¥ÀÓÀÚ ¸íÀ» ÀÔ·ÂÇÕ´Ï´Ù.
ÀüÈ­ ¹øÈ£ : µµ¸ÞÀÎ Á¶È¸ ½Ã ³ªÅ¸³ª´Â Ã¥ÀÓÀÚ ÀüÈ­¹øÈ£¸¦ ÀÔ·ÂÇÕ´Ï´Ù.
 
¨è CSR ÃßÃâ
[root@nextline src]# cat nextline.co.kr.csr

 
 
»ý¼ºµÈ CSR À» Ãâ·ÂÇÏ¸é ¾Æ·¡¿Í °°Àº base64 Çü½ÄÀÇ ¹®¼­¸¦ º¼ ¼ö ÀÖÀ¸¸ç ÀÌ ¹®¼­ÀÇ Ã¹ ÁÙ -----BEGIN ¡¦ ºÎÅÍ ¸¶Áö¸· ÁÙ -----END ¡¦ ±îÁö º¹»çÇÏ¿© ÀÎÁõ¼­ ½Åû½Ã CSR ÄÚµåÀԷ¶õ¿¡ º¹»çÇÏ¿© ºÙ¿© ³ÖÀº µÚ ÀÔ·ÂÁ¤º¸¿Í ÇÔ²² Àü¼Û ÈÄ Áֹεî·ÏÁõ »çº»(°³ÀÎ)/»ç¾÷ÀÚµî·ÏÁõ »çº»(»ç¾÷ÀÚ)¸¦ Æѽº·Î º¸³»Áֽøé Á¢¼ö°¡ ¿Ï·áµË´Ï´Ù.

 
 
( 5 ) ÀÎÁõ¼­ ¼³Ä¡

Á¢¼öÇÑ CSR ÆÄÀÏÀÌ Á¤»óÀûÀ¸·Î »ý¼ºµÇ¾ú´Ù¸é º°´Ù¸¥ ¹®Á¦¾øÀÌ ÀÎÁõ¼­¸¦ ¹ß±Þ ¹ÞÀ» ¼ö ÀÖ½À´Ï´Ù. ÀÎÁõ¼­ ÆÄÀÏÀº ½Åû½Ã ±â·ÏÇÑ Email ÁÖ¼Ò¸¦ ÅëÇØ ÀÎÁõ¼­¸¦ ÷ºÎÆÄÀÏ·Î ¼ö½ÅÇÏ°Ô µË´Ï´Ù.
 
¨ç ¹ß±ÞÀÎÁõ¼­ ÷ºÎÈ­ÀÏ È®ÀÎ
¸ÞÀÏ·Î ¹ÞÀº ÀÎÁõ¼­ ÆÄÀÏÀÇ ¾ÐÃàÀ» ÇØÁ¦ÇϽøé ÀÎÁõ¼­ ¹× CA rootÀÎÁõ¼­ µÎ°³ÀÇ ÆÄÀÏÀÌ È®ÀÎ ÇÏ½Ç ¼ö ÀÖ½À´Ï´Ù.

 
 
¨è ftp °èÁ¤»ý¼º
ÀÎÁõ¼­¸¦ ¼­¹ö·Î ¾÷·Îµå Çϱâ À§ÇØ FTP °èÁ¤À» »ý¼ºÇÕ´Ï´Ù. ±âÁ¸ FTP °èÁ¤À» ÀÌ¿ëÇÏ¿©µµ ¹«¹æÇÕ´Ï´Ù.
°èÁ¤»ý¼º
[root@nextline ~]# useradd nextline
°èÁ¤ Æнº¿öµå¼³Á¤
[root@nextline ~]# passwd nextline
Changing password for user nextline.
Æнº¿öµå ÀÔ·Â
New UNIX password:
Æнº¿öµå ÀçÀÔ·Â
Retype new UNIX password:
passwd: all authentication tokens updated successfully.
 
 
 
¨é ÀÎÁõ¼­ ¾÷·Îµå
FTP ÇÁ·Î±×·¥À» ÀÌ¿ëÇÏ¿© 4393142.crt, 4393142.ca-bundle ÆÄÀÏÀ» ¾÷·Îµå ÇÕ´Ï´Ù.

 
 
¨ê ÀÎÁõ¼­ °æ·Î·Î ÀÎÁõÆÄÀÏ À̵¿
À§ ÆÄÀÏ Áß 4393142.crt ÆÄÀÏÀ» SSLCertificateFile °æ·Î·Î À̵¿ÇÕ´Ï´Ù.
SSLCertificateFile /usr/local/apache/conf/ssl.crt/4393142.crt

 
 
4393142.ca-bundle ÆÄÀÏÀ» SSLCACertificateFile °æ·Î·Î À̵¿ÇÕ´Ï´Ù.
SSLCACertificateFile /usr/local/apache/conf/ssl.crt/4393142.ca-bundle

 
 
 
À§¿¡¼­ »ý¼ºÇÑ °³ÀÎÅ°(nextline.co.kr.key)¸¦ SSLCertificateKeyFile °æ·Î·Î À̵¿ÇÕ´Ï´Ù.
SSLCertificateKeyFile /usr/local/apache/conf/ssl.key/nextline.co.kr.key

  
   
¨ë À¥¼­¹ö ȯ°æ¼³Á¤
[root@nextline src]# vi /usr/local/apache/conf/httpd.conf

 
Apache 1.x + mod_ssll ¿¬µ¿ ¼³Ä¡½Ã ±âº»ÀûÀ¸·Î 80, 443Æ÷Æ®ÀÇ ¼³Á¤ºÎºÐÀÌ Ãß°¡µÇ¹Ç·Î Port 80 ºÎºÐÀ» ÁÖ¼®Ã³¸®ÇÏ¿© Àû¿ëµÇÁö ¾Êµµ·Ï ÇÕ´Ï´Ù.
#Port 80 ºÎºÐ ÁÖ¼®Ã³¸®

 
 
ÀÏ¹Ý http 80 Æ÷Æ® Á¢¼Ó VirtualHost ¼³Á¤
 
NameVirtualHost xxx.xxx.xxx.xxx:80
 

DocumentRoot /home/nextline/public_html
ServerName nextline.co.kr

 

DocumentRoot /home/nextline_2/public_html
ServerName www.nextline.co.kr

 

 
 
SSL VirtualHost ¸ÖƼµµ¸ÞÀÎ ¼³Á¤
¸ðµç º¸¾È °¡»ó È£½ºÆ®µéÀÇ ¼³Á¤Àº ¿Í Áö½ÃÀÚ »çÀÌ¿¡ Æ÷ÇԵǾî¾ß Çϸç CSRÀ» »ý¼ºÇÑ netxtline.co.kr µµ¸ÞÀÎÀÇ °³ÀÎÅ° ¹× ÀÎÁõ¼­, CA rootÀÎÁõ¼­¸¦ www.nextline.co.kr¿¡¼­µµ µ¿ÀÏÇÏ°Ô ¼³Á¤ÇÕ´Ï´Ù.
 
NameVirtualHost xxx.xxx.xxx.xxx:443
 

DocumentRoot "/home/nextline/public_html"
ServerName nextline.co.kr
SSLCertificateFile /usr/local/apache/conf/ssl.crt/4393142.crt
SSLCertificateKeyFile /usr/local/apache/conf/ssl.key/nextline.co.kr.key
SSLCACertificateFile /usr/local/apache/conf/ssl.crt/4393142.ca-bundle

 

DocumentRoot "/home/nextline/public_html"
ServerName nextline.co.kr
SSLCertificateFile /usr/local/apache/conf/ssl.crt/4393142.crt
SSLCertificateKeyFile /usr/local/apache/conf/ssl.key/nextline.co.kr.key
SSLCACertificateFile /usr/local/apache/conf/ssl.crt/4393142.ca-bundle


 
 
SSL Virtual Host Context ¸ÖƼµµ¸ÞÀÎ Àüü¼³Á¤

NameVirtualHost xxx.xxx.xxx.xxx:443
¾ÆÀÌÇÇ ¹× https ÇÁ·ÎÅäÄÝ Æ÷Æ®443 Æ÷Æ®¸¦ ÀÔ·ÂÇÕ´Ï´Ù.

º¸¾È¼­¹ö µµ¸ÞÀÎÀÇ È¨µð·ºÅ丮¸¦ ÀÔ·ÂÇÕ´Ï´Ù.
DocumentRoot "/home/nextline/public_html"
µµ¸ÞÀÎÀ» ÀÔ·ÂÇÕ´Ï´Ù.
ServerName nextline.co.kr
SSL ¿£ÁøÀ» È°¼ºÈ­ ÇÕ´Ï´Ù
SSLEngine on
SSLCipherSuite ALL:!ADH:!EXPORT56:RC4+RSA:+HIGH:+MEDIUM:+LOW:+SSLv2:+EXP:+eNULL
ÀÎÁõ¼­ÀÇ °æ·Î¿Í ÆÄÀϸíÀ» ¸í½ÃÇÕ´Ï´Ù.
SSLCertificateFile /usr/local/apache/conf/ssl.crt/4393142.crt
°³ÀÎÅ° °æ·Î¿Í ÆÄÀϸíÀ» ¸í½ÃÇÕ´Ï´Ù.
SSLCertificateKeyFile /usr/local/apache/conf/ssl.key/nextline.co.kr.key
CA rootÀÎÁõ¼­ °æ·Î¿Í ÆÄÀϸíÀ» ¸í½ÃÇÕ´Ï´Ù.
SSLCACertificateFile /usr/local/apache/conf/ssl.crt/4393142.ca-bundle

    SSLOptions +StdEnvVars


    SSLOptions +StdEnvVars

BrowserMatch ".*MSIE.*" \
         nokeepalive ssl-unclean-shutdown \
         downgrade-1.0 force-response-1.0
CustomLog /usr/local/apache/logs/ssl_request_log \
          "%t %h %{SSL_PROTOCOL}x %{SSL_CIPHER}x \"%r\" %b"

 

º¸¾È¼­¹ö µµ¸ÞÀÎÀÇ È¨µð·ºÅ丮¸¦ ÀÔ·ÂÇÕ´Ï´Ù.
DocumentRoot "/home/nextline/public_html"
µµ¸ÞÀÎÀ» ÀÔ·ÂÇÕ´Ï´Ù.
ServerName www.nextline.co.kr
SSL ¿£ÁøÀ» È°¼ºÈ­ ÇÕ´Ï´Ù
SSLEngine on
SSLCipherSuite ALL:!ADH:!EXPORT56:RC4+RSA:+HIGH:+MEDIUM:+LOW:+SSLv2:+EXP:+eNULL
ÀÎÁõ¼­ÀÇ °æ·Î¿Í ÆÄÀϸíÀ» ¸í½ÃÇϸç nextline.co.kr µµ¸ÞÀΰú µ¿ÀÏÇÑ ÀÎÁõ¼­¸¦ »ç¿ëÇÕ´Ï´Ù.
SSLCertificateFile /usr/local/apache/conf/ssl.crt/4393142.crt
°³ÀÎÅ° °æ·Î¿Í ÆÄÀϸíÀ» ¸í½ÃÇϸç nextline.co.kr µµ¸ÞÀΰú µ¿ÀÏÇÑ °³ÀÎÅ°¸¦ »ç¿ëÇÕ´Ï´Ù.
SSLCertificateKeyFile /usr/local/apache/conf/ssl.key/nextline.co.kr.key
CA rootÀÎÁõ¼­ °æ·Î¿Í ÆÄÀϸíÀ» ¸í½ÃÇϸç nextline.co.kr µµ¸ÞÀΰú µ¿ÀÏÇÑ CA rootÀÎÁõ¼­¸¦ »ç¿ëÇÕ´Ï´Ù.
SSLCACertificateFile /usr/local/apache/conf/ssl.crt/4393142.ca-bundle

    SSLOptions +StdEnvVars


    SSLOptions +StdEnvVars

BrowserMatch ".*MSIE.*" \
         nokeepalive ssl-unclean-shutdown \
         downgrade-1.0 force-response-1.0
CustomLog /usr/local/apache/logs/ssl_request_log \
          "%t %h %{SSL_PROTOCOL}x %{SSL_CIPHER}x \"%r\" %b"


 
¨ì À¥¼­¹ö Àç½ÇÇà
À¥¼³Á¤ ÆÄÀÏÀÇ ¿À·ù°¡ ¾ø´ÂÁö üũ¸¦ ÇÕ´Ï´Ù.
[root@nextline ~]# /usr/local/apache/bin/apachectl configtest
Syntax OK [Á¤»ó]
À¥¼³Á¤ ÆÄÀÏÀ» Àû¿ëÇϱâ À§ÇØ ¾ÆÆÄÄ¡¸¦ Àç°¡µ¿ÇÕ´Ï´Ù.
Apache 1.x ¹öÀü¿¡¼­´Â startsslÀ» ÀÌ¿ëÇÏ¿© http, https ¸ðµÎ ±¸µ¿µÇµµ·Ï ÇÕ´Ï´Ù.
[root@nextline ~]# /usr/local/apache/bin/apachectl startssl

 
 
Apache 2.x ¹öÀü¿¡¼­´Â [start | restart]À» ÀÌ¿ëÇÏ¿© http, https ¸ðµÎ ±¸µ¿µÇµµ·Ï ÇÕ´Ï´Ù.

 
 
¨í À¥¼­¹ö Æ÷Æ®Á¡°Ë
[root@nextline ~]# netstat -anp | grep httpd
httpd µ¥¸óÀÌ 80 / 443 Æ÷Æ®·Î ½ÇÇàµË´Ï´Ù.

 

¨î À¥¼­ºñ½º µ¿ÀÛ»óÅ Á¡°Ë
https://nextline.co.kr
ÆäÀÌÁö ÇÏ´ÜÀ» º¸½Ã¸é ¿­¼è ¾ÆÀÌÄÜÀÌ º¸ÀÌ°Ô µË´Ï´Ù. ¾ÆÀÌÄÜÀ» Ŭ¸¯ÇÏ°Ô µÇ¸é À§¿Í °°ÀÌ ÀÎÁõ¼­ Á¤º¸¸¦ È®ÀÎÇÏ½Ç ¼ö ÀÖ½À´Ï´Ù.
 
 

¨ï ÀÎÁõ °æ·ÎÈ®ÀÎ
 

 
 
¨ð À¥¼­ºñ½º µ¿ÀÛ»óÅ Á¡°Ë
https://www.nextline.co.kr
¸ÖƼµµ¸ÞÀÎÀÇ °æ¿ì ´ëÇ¥ µµ¸ÞÀÎÀÇ °³ÀÎÅ°, ÀÎÁõ¼­, CA rootÀÎÁõ¼­¸¦ µ¿ÀÏ Àû¿ëµÇ¹Ç·Î  nextline.co.kr µµ¸ÞÀΰú ¹ß±Þ´ë»ó, ¹ß±ÞÀÚ, À¯È¿ ±â°£ÀÌ µ¿ÀÏÇÏ°Ô Ç¥½ÃµË´Ï´Ù.

 
 
 
¨ñ ÀÎÁõ °æ·ÎÈ®ÀÎ
ÀÎÁõ °æ·Î¿ª½Ã nextline.co.kr µµ¸ÞÀΰú µ¿ÀÏÇÏ°Ô Ç¥½ÃµË´Ï´Ù.

  SSH root Á¢±Ù±ÝÁö
  º¸¾È¼­¹ö SSL ( Linux Apache 2.X ¹öÀü)





ȸ»ç¼Ò°³ °³ÀÎÁ¤º¸Ãë±Þ¹æħ ÀÌ¿ë¾à°ü À̸ÞÀÏÁÖ¼Ò ¹«´Ü¼öÁý°ÅºÎ CONTACT US IDC ¾àµµ
ȸ»ç¼Ò°³ °³ÀÎÁ¤º¸Ãë±Þ¹æħ ÀÌ¿ë¾à°ü À̸ÞÀÏÁÖ¼Ò ¹«´Ü¼öÁý°ÅºÎ CONTACT US IDC ¾àµµ ȸ»ç¼Ò°³ °³ÀÎÁ¤º¸Ãë±Þ¹æħ ÀÌ¿ë¾à°ü À̸ÞÀÏÁÖ¼Ò ¹«´Ü¼öÁý°ÅºÎ CONTACT US IDC ¾àµµ