Home | Data Center | Contact US | Login

Á¦¸ñ Apache SSL ¼³Ä¡¹æ¹ý
÷ºÎÆÄÀÏ (3) Linux Apache SSL.pdf ÀÛ¼ºÀÏ 2007-09-03 12:05:35

 
Apache SSL
 
Apache_1.x + apache_ssl + Mysql + Php + Zend + OpenSSL ¼³Ä¡

( 1 ) Source ÆÄÀÏ ´Ù¿î·Îµå
( 2 ) Source ÆÄÀÏ ¾ÐÃàÇØÁ¦
( 3 ) OpenSSL ¼³Ä¡
( 4 ) apache1 + apache_1.3.37+ssl_1.57 ¿¬µ¿¼³Ä¡
( 5 ) SSL Å° »ý¼º
( 6 ) Mysql ¼³Ä¡
( 7 ) GD ¼³Ä¡
( 8 ) PHP ¼³Ä¡
( 9 ) ZendOptimizer ¼³Ä¡
( 10 ) CSR »ý¼º
( 11 ) ÀÎÁõ¼­ Á¢¼ö
( 12 ) ÀÎÁõ¼­ ¼³Ä¡

 -------------------------------------------------------------------------------------

( 1 ) Source ÆÄÀÏ ´Ù¿î·Îµå
 
¨ç apache_1.3.37.tar.gz
´Ù¿î·Îµå »çÀÌÆ® : http://httpd.apache.org/download.cgi
[root@nextline ~]# wget http://mirror.apache-kr.org/httpd/apache_1.3.37.tar.gz

 
¨è mysql-4.1.22.tar.gz
´Ù¿î·Îµå »çÀÌÆ® : ftp://mysql.byungsoo.net/pub/mysql/
[root@nextline ~]#
wget ftp://mysql.byungsoo.net/pub/mysql/Downloads/MySQL-4.1/mysql4.1.22.tar.gz


¨é php-5.2.3.tar.gz
´Ù¿î·Îµå »çÀÌÆ® : http://www.php.net/downloads.php
[root@nextline ~]#
 wget http://www.php.net/get/php-5.2.3.tar.gz/from/kr2.php.net/mirror


¨ê gd-2.0.35.tar.gz
´Ù¿î·Îµå »çÀÌÆ® : http://www.libgd.org/releases/
[root@nextline ~]# wget http://www.libgd.org/releases/gd-2.0.35.tar.gz


¨ë ZendOptimzer-3.3.0-linux-glibc21-i386.tar.gz
´Ù¿î·Îµå »çÀÌÆ® : http://www.zend.com/
´Ù¿î·Îµå ¹ÞÀº ZendOptimzerÀ» ftpÀ» ÀÌ¿ëÇÏ¿© ¾÷·Îµå ÇÕ´Ï´Ù.
 
¨ì apache_1.3.37+ssl_1.57.tar.gz
´Ù¿î·Îµå »çÀÌÆ® : http://www.apache-ssl.org/
[root@nextline ~]# wget ftp://ftp.zedz.net/pub/mirrors/ftp.apache-ssl.org/apache_1.3.37+ssl_1.57.tar.gz

 
¨í openssl-0.9.8e.tar.gz
´Ù¿î·Îµå »çÀÌÆ® : http://www.openssl.org

 
¨î Source ÆÄÀÏ È®ÀÎ
[root@nextline ~]# ls
ZendOptimizer-3.3.0-linux-glibc21-i386.tar.gz 
gd-2.0.35.tar.gz
apache_1.3.37.tar.gz
mysql-4.1.22.tar.gz
php-5.2.3.tar.gz
apache_1.3.37+ssl_1.57.tar.gz
openssl-0.9.8e.tar.gz

-------------------------------------------------------------------------------------------  

( 2 ) Source ÆÄÀÏ ¾ÐÃàÇØÁ¦
¨ç> apache
[root@nextline ~]# tar zxvf apache_1.3.37.tar.gz

  
¨è> mysql
[root@nextline ~]# tar zxvf mysql-4.1.22.tar.gz

  
¨é> gd
[root@nextline ~]# tar zxvf gd-2.0.35.tar.gz

 
¨ê> php
[root@nextline ~]# tar zxvf php-5.2.3.tar.gz

  
¨ë> ZendOptimizer
[root@nextline ~]# tar zxvf ZendOptimizer-3.3.0-linux-glibc21-i386.tar.gz

 
¨ì> openssl-0.9.8e.tar.gz
[root@nextline ~]# tar zxvf openssl-0.9.8e.tar.gz

 
¾ÐÃàÇØÁ¦À» ÇØÁ¦ÇÏ¸é ¾Æ·¡¿Í °°ÀÌ ÆÐÅ°Áöº° ¼Ò½ºµð·ºÅ丮°¡ »ý¼ºµË´Ï´Ù.
ZendOptimizer-3.3.0-linux-glibc21-i386
mysql-4.1.22
gd-2.0.35
php-5.2.3
openssl-0.9.8e
apache_1.3.37
apache_1.3.37+ssl_1.57.tar.gz

-------------------------------------------------------------------------------------------  
 
( 3 ) OpenSSL ¼³Ä¡
 
¨ç ÄÄÆÄÀÏ È¯°æ¼³Á¤
[root@nextline ~]# cd openssl-0.9.8e
[root@nextline openssl-0.9.8e]# ./config --prefix=/usr/local/openssl
 
[ ÄÄÆÄÀÏ ¿É¼Ç]
--prefix=/usr/local/openssll
opensslÀÌ ¼³Ä¡µÉ °æ·Î¸¦ ÁöÁ¤ÇÏ´Â ¿É¼ÇÀÔ´Ï´Ù.

 
¨è ÄÄÆÄÀÏ
[root@nextline openssl-0.9.8e]# make

 
¨é ¼³Ä¡ Å×½ºÆ®
[root@nextline openssl-0.9.8e]# make test

 
¨ê ¼³Ä¡
[root@nextline openssl-0.9.8e]# make install

 
¨ë ¼³Ä¡»óÅ ȮÀÎ
¼³Ä¡°¡ ¿Ï·áµÇ¸é ÄÄÆÄÀÏ ½Ã ÁöÁ¤µÈ °æ·Î¿¡ openssl µð·ºÅ丮°¡ »ý¼ºµË´Ï´Ù.
[root@nextline openssl-0.9.8e]# ls /usr/local
openssl
openssl ¸í·ÉÀÇ ½ÇÇà ÆÄÀÏ, ¼Ò½º, ¸Å´º¾ó ÆäÀÌÁöÀÇ ÀνĿ©ºÎ¸¦ È®ÀÎÇÕ´Ï´Ù.
[root@nextline openssl-0.9.8e]# whereis openssl
openssl: /usr/local/bin/openssl /usr/local/openssl

 
------------------------------------------------------------------------------------------- 
 
( 4 ) apache1 + apache_1.3.37+ssl_1.57 ¿¬µ¿¼³Ä¡
 
¨ç apache_1.3.37+ssl_1.57 ¾ÐÃàÇØÁ¦
apache_1.3.37 µð·ºÅ丮¿¡ apache_1.3.37+ssl_1.57 ¾ÐÃàÀ» ÇØÁ¦ÇÕ´Ï´Ù.
[root@nextline ~]# tar zxvf apache_1.3.37+ssl_1.57.tar.gz -C apache_1.3.37

 
¨è >SSL ÆÐÄ¡
[root@nextline ~]# cd apache_1.3.37
[root@nextline apache_1.3.37]# patch -p1 < SSLpatch


¨é ÄÄÆÄÀÏ È¯°æ¼³Á¤
 
[root@nextline apache_1.3.37]# ./configure --prefix=/usr/local/apache --enable-rule=SHARED_CORE --enable-shared=max --enable-module=so --enable-module=apache_s´Ï
[ÄÄÆÄÀÏ ¿É¼Ç]
¾ÆÆÄÄ¡°¡ ¼³Ä¡µÉ °æ·Î¸¦ ÁöÁ¤ÇÕ´Ï´Ù.
--prefix=/usr/local/apache
mod_ssl À» ¸ðµâÀ» ¾ÆÆÄÄ¡¿¡ ¿Ã¸®±âÀ§ÇÑ ¿É¼ÇÀÔ´Ï´Ù.
--enable-ssl
DSO ¹æ½ÄÀ¸·Î ¾ÆÆÄÄ¡¸¦ ÄÄÆÄÀÏ ÇϱâÀ§ÇÑ ¿É¼ÇÀÔ´Ï´Ù.
--enable-rule=SHARED_CORE --enable-shared=max --enable-module=so

 
¨ê ÄÄÆÄÀÏ
[root@nextline apache_1.3.37]# make

 
¨ë ¼³Ä¡
[root@nextline apache_1.3.37]# make install

 
¨ì libssl.so ÆÄÀϺ¹»ç

 
¨í httpd.conf ÆÄÀÏÆíÁý
 
[vi ¿¡µðÅÍ »ç¿ë¹ý]
»ç¿ëÇü½Ä: vi [¿É¼Ç] [»ý¼ºÇÒ ÆÄÀϸí/ÆíÁýÇÒ ÆÄÀϸí]
vi ¿¡µðÅÍ´Â ÀԷ¸ðµå, ¸í·É¸ðµå, ½ÇÇà¸ðµå·Î ±¸ºÐµË´Ï´Ù.
ÀԷ¸ðµå: vi ÆíÁýÈ­¸é¿¡¼­ ¹®ÀÚ¸¦ ÀÔ·ÂÇÒ ¼ö ÀÖ´Â ¸ðµå·Î¼­ ÀԷ¸ðµå·Î ÁøÀÔÇϱâ À§Çؼ­´Â i, a, o, I, A, O, RµîÀÌ ÀÖ½À´Ï´Ù. Áï Ãʱâ vi ÆíÁý±â ¸ðµå´Â ¸í·É¾î ¸ðµå·Î ÁøÀÔÀ» Çϱ⶧¹®¿¡ ¹®ÀÚ¸¦ ÀÔ·ÂÇϱâ Àü¿¡ ¾ÕÀÇ ´ÜÃàÅ°Áß Çϳª¸¦ ¸ÕÀú ÀÔ·ÂÇØ¾ß ¿øÇÏ´Â ¹®ÀÚ¸¦ ÀÔ·ÂÇÒ ¼ö ÀÖ½À´Ï´Ù.
¸í·É¸ðµå: Ä¿¼­À̵¿/¹®ÀÚ»èÁ¦/¹®ÀÚ(¿­)±³Ã¼/¹®ÀÚ¿­°Ë»ö µîÀ» ÇÒ¼ö ÀÖ´Â ¸ðµå·Î¼­ ÀԷ¸ðµå¿¡¼­ ÆíÁýÀÌ ¿Ï·áµÇ¸é EscÅ°¸¦ ´­·¯ ¸í·É¸ðµå·Î ÁøÀÔÇÏ¸é µË´Ï´Ù.
½ÇÇà¸ðµå: Ưº°ÇÑ ¸í·É¾î¸¦ ½ÇÇàÇÏ´Â ¸ðµå·Î¼­ ¸í·É¾î¸ðµå¿¡¼­ ":"(ÄÝ·Ð)¸¦ ´©¸£¸é vi È­¸é ÇÏ´Ü ÁÂÃø¿¡ vi Ư¼ö¸í·É¾î¸¦ ÀÔ·ÂÇÒ ¼ö ÀÖ½À´Ï´Ù.
 
[½ÇÇà¸ðµåÀÇ ÀϹÝÀûÀ¸·Î ¾²À̴ Ư¼ö ¸í·É¾î]
q : ¼öÁ¤ ÀÛ¾÷ÀÌ ÀÌ·ç¾îÁöÁö ¾ÊÀº »óÅ¿¡¼­ vi ÆíÁý±â¿¡¼­ ºüÁ®³ª¿É´Ï´Ù.
q! : ¼öÁ¤ ÀÛ¾÷ÀÌ ÀÌ·ç¾îÁø ºÎºÐÀ» Àû¿ë½ÃÅ°Áö ¾Ê°í vi ÆíÁý±â¸¦ °­Á¦·Î ºüÁ®³ª¿É´Ï´Ù.
w : ¼öÁ¤µÈ ÀÛ¾÷À» ÀúÀåÇÕ´Ï´Ù.
wq : ¼öÁ¤µÈ ÀÛ¾÷À» ÀúÀåÇÏ°í vi ÆíÁý±â¿¡¼­ ºüÁ®³ª¿É´Ï´Ù.
Ãʱ⠸í·É¾î¸ðµå-> ÀԷ¸ðµåÁøÀÔ -> ÆíÁý -> ¸í·É¾î¸ðµå -> ½ÇÇà¸ðµå -> Á¾·á

[root@nextline apache_1.3.37]# vi /usr/local/apache/conf/httpsd.conf

 
¨î ServerName ¼³Á¤
ServerName ºÎºÐ¿¡ ¾ÆÀÌÇÇ È¤Àº µµ¸ÞÀÎÀ» ±âÀÔÇÕ´Ï´Ù.
ServerName xxx.xxx.xxx.xxx


¨ï apache_ssl.so ¸ðµâ¼³Á¤ È®ÀÎ
LoadModule apache_ssl_module  libexec/apache_ssl.so


AddModule apache_ssl.c

-----------------------------------------------------------------------------------------

( 5 ) SSL Å° »ý¼º

Apache¿Í Apache+ssl ¿¬µ¿ Å×½ºÆ®¸¦ À§ÇØ ÀÓÀÌÀÇ Å°¸¦ »ý¼ºÇÕ´Ï´Ù.
¨ç CSR ¹× privkey.pem »ý¼º
[root@nextline ~]# cd /usr/local/src
[root@nextline src]# openssl req -new > nextline.co.kr.csr
Enter PEM pass phrase: private key ¾ÏÈ£ÀÔ·Â
Verifying - Enter PEM pass phrase: private key ¾ÏÈ£ ÀçÀÔ·Â
CSR Á¤º¸ÀÔ·Â ºÎºÐÀ» [Enter]·Î ÀÔ·ÂÇÏ°í ³Ñ¾î°©´Ï´Ù.
1. Country Name(2 letter code) [XY]: [ Enter]
2. State or Province Name(full name)[Snake Desert]: [ Enter]
3. Locality Name(eg, city)[Snake Town]: [ Enter]
4. Organization Name(eg, company)[Snake Oil, Ltd]: [ Enter]
5. Organizational Unit Name (eg, section)[Webserver Team]: [ Enter]
6. Common Name (eg, FQDN)[www.snakeoil.dom]: [ Enter]
7. Email Address(eg, name@FQDN) [www@snakeoil.dom]: [ Enter]
8. A challenge password [] : [Enter]
9. An optional company name [] : [Enter]

 
¨è °³ÀÎÅ° »ý¼º
CSR »ý¼º½Ã ÀÔ·ÂÇÑ privkey.pem Å°ÀÇ Æнº¹®ÀÌ »èÁ¦µÈ °³ÀÎÅ°¸¦ »ý¼ºÇÕ´Ï´Ù.
[root@nextline src]# openssl rsa -in privkey.pem -out nextline.key
Enter pass phrase for privkey.pem: [CSR »ý¼º½Ã ÀÔ·ÂÇÑ ¾ÏÈ£¸¦ ±âÀÔÇÕ´Ï´Ù.]

 
¨é CERT »ý¼º
Å×½ºÆ®¿ë ÀÎÁõ¼­¸¦ »ý¼ºÇÕ´Ï´Ù.
[root@nextline src]# openssll x509 –in nextline.csr –out nextline.cert –req –signkey nextline.key –day 365

 
¨ê »ý¼ºÅ° È®ÀÎ


¨ë SSL º¸¾ÈÅ°¸¦ ÀúÀåÇÒ µð·ºÅ丮¸¦ »ý¼ºÇÕ´Ï´Ù.
[root@nextline src]# mkdir /usr/local/apache/cert/

 
 ¨ì ÀÎÁõ¼­ °æ·Î·Î ÀÎÁõÆÄÀÏ À̵¿
[root@nextline src]# mv nextline.key /usr/local/apache/cert/


[root@nextline src]# mv nextline.cert /usr/local/apache/cert/

 
¨í VirtualHost ¼³Á¤

 
http, https Æ÷Æ® ¼³Á¤
Listen 80
Listen 443

 
Apache-sslÀº ±âº»±¸µ¿ÀÌ SSL¸ðµå·Î ±¸µ¿µÇ¹Ç·Î ÀÏ¹Ý http 80 Æ÷Æ® »ç¿ëÀ» À§ÇØ
'Main' server configuration Àü¿ª¼³Á¤ ºÎºÐ¿¡ SSLDisableÀ» ¼³Á¤ÇÕ´Ï´Ù.[±âº»ÀûÀ¸·Î ¼³Á¤µÇ¾î ÀÖÀ½]
SSLDisable

 
VirtualHost ¼³Á¤
 
http(80Æ÷Æ®) Á¢¼ÓÀ» À§ÇÑ ÀϹÝÀûÀÎ VirtualHost ¼³Á¤ÀÔ´Ï´Ù.
NameVirtualHost 61.100.191.46:80

DocumentRoot /home/nextline/public_html
ServerName nextline.co.kr
SSLDisable [SSL ¼³Á¤À» »ç¿ëÇÏÁö ¾Êµµ·Ï ¼³Á¤ÇÕ´Ï´Ù.]

 
NameVirtualHost 61.100.191.46:443

DocumentRoot /home/nextline/public_html
ServerName nextline.co.kr
SSLEnable [SSL ¼³Á¤À» Àû¿ëÇÕ´Ï´Ù.]
[SSLCacheServerPath °æ·Î¸¦ ¼³Á¤ÇÕ´Ï´Ù.]
SSLCacheServerPath /usr/local/apache/bin/gcache
[80,443À» Á¦¿ÜÇÑ ´Ù¸¥ µ¥¸óÀÌ »ç¿ëÇÏÁö ¾ÊÀº SSLCacheServerPort ¼³Á¤ÇÕ´Ï´Ù.]
SSLCacheServerPort 1234
[SSLSessionCacheTimeout ¼³Á¤]
SSLSessionCacheTimeout 3600
[SSLCertificateFile ÀÎÁõ¼­ °æ·Î¼³Á¤]
SSLCertificateFile /usr/local/apache/cert/nextline.cert
[SSLCertificateKeyFile °³ÀÎÅ° °æ·Î¼³Á¤]
SSLCertificateKeyFile /usr/local/apache/cert/nextline.key


 
¨î Apache ±¸µ¿
[root@nextline apache_1.3.37]# /usr/local/apache/bin/httpsdctl start


¨ï Æ÷ƮȮÀÎ
[root@nextline src]# netstat -anp | grep http
tcp  0      0 0.0.0.0:80  0.0.0.0:*      LISTEN      32533/httpsd
tcp  0      0 0.0.0.0:443 0.0.0.0:*      LISTEN      32533/httpsd

 
[root@nextline src]# netstat -anp|grep gcache
tcp  0      0 0.0.0.0:1234  0.0.0.0:*  LISTEN      32534/gcache

 
¨ï https Á¢¼ÓÅ×½ºÆ®
https://nextline.co.krÁ¢¼ÓÀ» ÇÏ½Ã¸é ¾Æ·¡¿Í°°ÀÌ º¸¾È°æ°í âÀÌ º¸¿©Áý´Ï´Ù.
[¿¹] – [Enter]

 
¨ð SSL º¸¾ÈÀû¿ë È­¸é
Apache+SSL Àû¿ë È­¸éÀÔ´Ï´Ù.
 
--------------------------------------------------------------------------------------
 
( 6 ) Mysql ¼³Ä¡
 
¨ç ÄÄÆÄÀÏ È¯°æ¼³Á¤
[root@nextline ~]# cd mysql-4.1.22
[root@nextline mysql-4.1.22]# ./configure
--prefix=/usr/local/mysql
--with-charset=euckr


¨è ÄÄÆÄÀÏ
[root@nextline mysql-4.1.22]# make

  
¨é ¼³Ä¡
[root@nextline mysql-4.1.22]# make install

 
¨ê mysql µ¥ÀÌÅÍ µð·ºÅ丮»ý¼º
[root@nextline mysql-4.1.22]# /usr/local/mysql/bin/mysql_install_db

 
¨ë µ¥ÀÌÅÍ µð·ºÅ丮ȮÀÎ
[root@nextline mysql-4.1.22]# ls /usr/local/mysql/
var [DB µ¥ÀÌÅÍ µð·ºÅ丮]

 
¨ì mysql °èÁ¤»ý¼º

 
¨í mysql µð·ºÅ丮 ¼ÒÀ¯±Çº¯°æ

 
¨î mysql µ¥¸ó±¸µ¿
[root@nextline mysql-4.1.22]# /usr/local/mysql/bin/mysqld_safe &

 
¨ï mysql µ¥¸ó ±¸µ¿È®ÀÎ
tcp  0  0 0.0.0.0:3306  0.0.0.0:*  LISTEN  32681/mysqld

 
¨ð mysql root Æнº¿öµå¼³Á¤

 
¨ñ mysql Á¢¼ÓÈ®ÀÎ
[root@nextline mysql-4.1.22]# /usr/local/mysql/bin/mysql -u root –p
Enter password: [Æнº¿öµå ÀÔ·Â]

 
------------------------------------------------------------------------------------------- 
 
( 7 ) GD ¼³Ä¡

¨ç ÄÄÆÄÀÏ È¯°æ¼³Á¤
[root@nextline ~]# cd gd-2.0.35
[root@nextline gd-2.0.35]# ./configure --prefix=/usr/local/gd2


¨è ÄÄÆÄÀÏ
[root@nextline gd-2.0.35]# make

  
¨é ¼³Ä¡
[root@nextline gd-2.0.35]# make install

 
¨ê ¼³Ä¡È®ÀÎ

 
---------------------------------------------------------------------------------------------- 
 
( 8 ) PHP ¼³Ä¡

¨ç ÄÄÆÄÀÏ È¯°æ¼³Á¤
[root@nextline ~]# cd php-5.2.3
[root@nextline php-5.2.3]# ./configure --prefix=/usr/local/php \
> --with-apxs2=/usr/local/apache/bin/apxs \
> --with-config-file-path=/usr/local/lib \
> --with-mysql=/usr/local/mysql \
> --with-gd=/usr/local/gd2 \
> --enable-gd-native-ttf \
> --with-freetype-dir=/usr \
> --with-zlib \
> --with-iconv \
> --with-imap \
> --with-imap-ssl \
> --with-kerberos \
> --enable-mbstring \
> --enable-track-vars \
> --enable-ftp \
> --disable-debug
 
[ÄÄÆÄÀÏ ¿É¼Ç]
 
--prefix=/usr/local/php
php ¼³Ä¡°æ·Î¸¦ ÁöÁ¤ÇÕ´Ï´Ù.
 
--with-apxs=/usr/local/apache/bin/apxs
°øÀ¯µÈ apache ¸ðµâÀ» ¿¬µ¿Çϱâ À§ÇÑ ¿É¼ÇÀÔ´Ï´Ù.
 
--with-config-file-path=/usr/local/lib
php¼³Á¤ÆÄÀÏ php.iniÆÄÀÏÀÌ Á¸ÀçÇÒ À§Ä¡¸¦ ÁöÁ¤ÇÕ´Ï´Ù.
 
--with-mysql=/usr/local/mysql
Mysql°ú ¿¬µ¿Çϱâ À§ÇÑ ¿É¼ÇÀÔ´Ï´Ù.
 
--with-gd=/usr/local/gd2
php¿¡¼­ gd¶óÀ̺귯¸®°ü·Ã ÇÔ¼ö¸¦ »ç¿ëÇÏ¿© gd¸¦ Áö¿øÇϱâ À§ÇÑ ¿É¼ÇÀÔ´Ï´Ù.
 
--enable-gd-native-ttf
GD ¶óÀ̺귯¸®¿¡¼­ FreeType¸¦ ÇÔÇÏ´Â ¿É¼ÇÀÔ´Ï´Ù.
 
–-with-freetype-dir=/usr
freetype2¸¦ Áö¿øÇϱâ À§ÇÑ ¿É¼ÇÀÔ´Ï´Ù.
 
--with-zlib
µ¥ÀÌÅ;ÐÃà ¶óÀ̺귯¸®·Î¼­ php¿¡¼­ zlibÀ» Áö¿øÇϱâ À§ÇÑ ¿É¼ÇÀÔ´Ï´Ù.
 
--with-iconv
ÀÎÄÚµù º¯È¯ÇÁ·Î±×·¥À¸·Î iconv¸¦ Áö¿øÇϱâ À§ÇÑ ¿É¼ÇÀÔ´Ï´Ù.
 
--with-imap
pop °ú ÇÔ²² ¸ÞÀϼö½Åµ¥¸óÀ¸·Î »ç¿ëµÇ´Â ¼­ºñ½º·Î¼­ imap¸¦ Áö¿øÇϱâ À§ÇÑ ¿É¼ÇÀÔ´Ï´Ù.
--with-kerberos
Kerberos´Â Ŭ¶óÀ̾ðÆ® ¼­¹ö ¾ÖÇø®ÄÉÀ̼ÇÀÇ ÀÔÁõÀ» Á¦°øÇϱâ À§ÇÏ¿© »óĪÀûÀÎ ¾ÏÈ£¹ýÀ» ÀÌ¿ëÇÏ´Â ³×Æ®¿öÅ© ÀÎÁõ ÇÁ·ÎÅäÄݷμ­ kerberos¸¦ Áö¿øÇϱâ À§ÇÑ ¿É¼ÇÀÔ´Ï´Ù.
 
--enable-mbstring
multi-byte¹®ÀÚ¸¦ Áö¿øÇϱâ À§ÇÑ ¿É¼ÇÀ¸·Î ¸¹Àº ¾ð¾î¸¦ Ç¥ÇöÇϱâ À§ÇÏ¿© ÀÌ¿ëµÇ¸ç, php¿¡¼­ mbstring¸¦ Áö¿øÇϱâ À§ÇÑ ¿É¼ÇÀÔ´Ï´Ù.
 
--enable-track-vars
HTTP_GET_VARS, HTTP_POST_VARS, HTTP_COOKIE_VARS ¹è¿­¿¡ µé¾îÀÖ´Â GET /
POST / cookie º¯¼öµéÀÌ ¾îµð·ÎºÎÅÍ ¿Ô´ÂÁö ±â¾ïÇÏ°Ô ¸¸µì´Ï´Ù. ÀÌ ¿É¼ÇÀº ´ÜÁö Default °ª À» Á¤ÇÏ´Â °Í»ÓÀ̸ç, ÈÄ¿¡ configuration fileÀÇ track_vars Áö½ÃÀÚ¿¡ ÀÇÇØ
Enable/Disable ÇÒ ¼ö ÀÖ½À´Ï´Ù.
 
--enable-ftp
php¿¡¼­ ftp°ü·Ã ÇÔ¼ö¸¦ Áö¿øÇϱâ À§ÇÑ ¿É¼ÇÀÔ´Ï´Ù.
 
--enable-debug
Zend Optimizer¸¦ »ç¿ëÇϱâ À§Çؼ­´Â debuggingÀ» »ç¿ëÇÏÁö ¾Ê½À´Ï´Ù.
 
[±×¿Ü ¿É¼Ç]
 
--enable-sockets
¼ÒÄÏ(socket) ÆÄÀÏÀ» »ç¿ëÇϱâ À§ÇÑ ¿É¼ÇÀÔ´Ï´Ù.
 
--with-language-korean
Çѱ¹¾î¸¦ »ç¿ëÇϱâ À§ÇÑ ¿É¼ÇÀÔ´Ï´Ù.
 
--enable-dba=shared
DBA¸¦ µ¿ÀûÀ¸·Î ÀûÀçÇÒ ¼ö ÀÖ´Â °øÀ¯ ¸ðµâ ÇüÅ·Π¸¸µå´Â ¿É¼ÇÀÔ´Ï´Ù.
 
--enable-gdbm[=DIR]
GDBM Áö¿øÀ» Æ÷ÇÔÇÏ´Â ¿É¼ÇÀÔ´Ï´Ù.
 
--enable-memory-limit
php¿¡¼­ ¸Þ¸ð¸® Á¦ÇÑ ±â´ÉÀ» Áö¿øÇÏ´Â ¿É¼ÇÀÔ´Ï´Ù.

 
¨è ÄÄÆÄÀÏ
[root@nextline php-5.2.3]#make

 
¨ë ¼³Ä¡
[root@nextline php-5.2.3]#make install

 
¨ì php ¼³Á¤ÆÄÀÏ º¹»ç
[root@nextline php-5.2.3]#cp php.ini-dist /usr/local/lib/php.ini

  
¨í ¾ÆÆÄÄ¡ ¼³Á¤ÆÄÀÏ ÆíÁý
[root@nextline php-5.2.3]#vi /usr/local/apache/conf/httpd.conf


¨î PHP À妽ºÆÄÀÏ ¼³Á¤

    DirectoryIndex index.html index.htm index.php index.jsp


 
¨ï AddType ¼³Á¤
AddType application/x-httpd-php .php .php4 .php3

 
¨ð ¼³Á¤ÆÄÀÏ Àû¿ë
[root@nextline php-5.2.3]#/usr/local/apache/bin/httpsdctl restart

----------------------------------------------------------------------------------------------
 
 
( 9 ) ZendOptimizer ¼³Ä¡
 
¨ç install.sh ½ÇÇà
[root@nextline ~]# cd ZendOptimizer-3.3.0-linux-glibc21-i386
[root@nextline ZendOptimizer-3.3.0-linux-glibc21-i386]# ./install.sh


¨è OK

 
¨é Zend Optimizer ¶óÀ̼¾½º È­¸éÀÔ´Ï´Ù. [EXIT]

 
¨ê ¶óÀ̼¾½º µ¿ÀÇ È­¸éÀÔ´Ï´Ù. [Yes]

 
¨ë Zend ¼³Ä¡°æ·Î¸¦ ÁöÁ¤ÇÏ´Â È­¸éÀÔ´Ï´Ù.
/usr/local/Zend(Àý´ë°æ·Î) È®ÀÎ ÈÄ ¸¦ ¼±ÅÃÇÕ´Ï´Ù. Zend Optimizer ¼³Ä¡ °æ·Î°¡ ÀÚµ¿ ÁöÁ¤µÇÁö ¾ÊÀ» ½Ã ¼öµ¿À¸·Î /usr/local/Zend °æ·Î¸¦ ÁöÁ¤ÇØ ÁÖ½Ã¸é µË´Ï´Ù. (Linux OSÀÇ ÀÀ¿ëÇÁ·Î±×·¥Àº ±âº» /usr/local¿¡ ¼³Ä¡µÇ±â ¶§¹®¿¡ /usr/local/Zend·Î ÁöÁ¤ÇÕ´Ï´Ù.)
[OK]

 
¨ì php.iniÀÇ °æ·Î¸¦ ÁöÁ¤ÇÏ´Â È­¸éÀÔ´Ï´Ù.
php¼³Ä¡ ½Ã php.ini ÆÄÀÏÀÌ /usr/local/lib¿¡ »ý¼ºµÇ±â ¶§¹®¿¡ /usr/local/lib(Àý´ë°æ·Î) ÁöÁ¤ÇÕ´Ï´Ù.
[OK]


¨í Zend Optimizer + Apache ¿¬µ¿ÇÒ °ÍÀÎÁö¸¦ ¹¯´Â È­¸éÀÔ´Ï´Ù
[Yes]


¨î apaachectlÀÇ °æ·Î¸¦ ÁöÁ¤ÇÏ´Â È­¸éÀÔ´Ï´Ù.
[OK]

 
¨ï php.ini ÆÄÀÏÀÇ php.ini-zend_optimizer.bak ¹é¾÷ÆÄÀÏÀ» »ý¼ºÇÏ´Â È­¸éÀ̸ç, »ý¼ºÀ§Ä¡´Â php.ini ÆÄÀÏÀÌ Á¸ÀçÇÏ´Â /usr/local/lib °æ·Î¿¡ »ý¼ºµË´Ï´Ù.
[OK]

 
¨ð Zend Optimizer ¼³Ä¡¿Ï·á È­¸éÀÔ´Ï´Ù
[OK]


¨ñ apache Àç ½ÃÀÛÀ» ¹¯´Â È­¸éÀÔ´Ï´Ù
[Yes]

 
¨ò Apache Àç ½ÃÀÛ ¼º°ø
[OK]

 
¨ó phpinfo ÆÄÀÏ»ý¼º
[root@nextline ~]#vi /usr/local/apache/htdocs/php_test.php

 
¨ô phpinfo Äڵ弳Á¤
phpinfo();
?>

 
¨õ APM ¿¬µ¿È®ÀÎ
http://xxx.xxx.xxx.xxx/php_test.php
Apache+Php+Mysql ¿¬µ¿°ú apache_ssl ¸ðµâÀÌ Á¤»ó·Îµù µÇ´Â È­¸éÀÔ´Ï´Ù.

 
-----------------------------------------------------------------------------------------

( 10 ) CSR »ý¼º
 
CSR ( Certificate Signing Request ) À̶õ?
 
SSL ¼­¹ö¸¦ ¿î¿µÇϴ ȸ»çÀÇ Á¤º¸¸¦ ¾ÏȣȭÇÏ¿© ÀÎÁõ±â°üÀ¸·Î º¸³» ÀÎÁõ¼­¸¦ ¹ß±Þ¹Þ°Ô ÇÏ´Â ÀÏÁ¾ÀÇ ½Åû¼­À̸ç CSRÀº ASCII ÅؽºÆ® È­ÀÏ·Î »ý¼ºµË´Ï´Ù.
 
¨ç µµ¸ÞÀÎ Á¶È¸
CSR Á¤º¸ÀÔ·Â ¹× ÀÎÁõ½Åû¼­ ÀÛ¼º½Ã µµ¸ÞÀÎ µî·Ï¾÷ü ¹× µµ¸ÞÀÎ Á¶È¸»çÀÌÆ®¿¡¼­ µµ¸ÞÀÎÀ» Á¶È¸ÇÏ¿© Á¶È¸°á°ú¿Í ÀÏÄ¡ÇÏ°Ô Á¤º¸¸¦ ÀÔ·ÂÇÏ¿©¾ß ÇÕ´Ï´Ù.
http://whois.nic.or.kr

 
[CSR Ç׸ñ¿¡ ´ëÇÑ ¼³¸í]
CSR Á¤º¸ ÀÔ·Â ½Ã µµ¸ÞÀÎ µî·Ï¾÷ü¿¡ µî·ÏÇϽŠÁ¤º¸¿Í µ¿ÀÏÇÑ Á¤º¸¸¦ ÀÔ·ÂÇÕ´Ï´Ù.
 
Country Name
ÀÌ°ÍÀº µÎ ÀÚ·Î µÈ ISO Çü½ÄÀÇ ±¹°¡ ÄÚµåÀÔ´Ï´Ù.
State or Province Name
½Ã À̸§À» ÀÔ·ÂÇØ¾ß ÇÏ¸ç ¾à¾î¸¦ »ç¿ëÇÒ ¼ö ¾ø½À´Ï´Ù.
Locality Name
ÀÌ Çʵå´Â ´ëºÎºÐÀÇ °æ¿ì »ý·«ÀÌ °¡´ÉÇÏ¸ç ¾÷ü°¡ À§Ä¡ÇÑ °÷¸¦ ³ªÅ¸³À´Ï´Ù.
Organization
»ç¾÷ÀÚ µî·ÏÁõ¿¡ Àִ ȸ»ç¸í°ú ÀÏÄ¡µÇ´Â ¿µ¹®È¸»ç¸íÀ» ÀÔ·ÂÇÏ½Ã¸é µË´Ï´Ù.
Organization Unit
"¸®´ª½º °ü¸®ÆÀ", "À©µµ¿ì °ü¸®ÆÀ" µî°ú °°ÀÌ ¾÷üÀÇ ºÎ¼­¸¦ ÀÔ·ÂÇÒ ¼ö ÀÖ½À´Ï´Ù.
Common Name
ÀÎÁõ¹ÞÀ» µµ¸ÞÀÎÁÖ¼Ò¸¦ ÀÔ·ÂÇÏ½Ã¸é µË´Ï´Ù.
ÀÌ Á¤º¸·Î À¥ »çÀÌÆ®¸¦ ½Äº°ÇϹǷΠȣ½ºÆ® À̸§À» º¯°æÇÒ °æ¿ì ´Ù¸¥ µðÁöÅÐ ID¸¦ ¿äûÇØ¾ß ÇÕ´Ï´Ù. È£½ºÆ®¿¡ ¿¬°áÇϴ Ŭ¶óÀ̾ðÆ® ºê¶ó¿ìÀú°¡ µðÁöÅÐ IDÀÇ À̸§°ú URLÀÌ ÀÏÄ¡ÇÏ´ÂÁö¸¦ È®ÀÎÇÕ´Ï´Ù.
 
[CSR Ç׸ñ ÀԷ½à ÁÖÀÇ»çÇ×]
Common Name ¿¡´Â ÀÎÁõ¼­¸¦ ¼³Ä¡ÇÒ »çÀÌÆ®ÀÇ µµ¸ÞÀÎÀÇ À̸§À» Á¤È®ÇÏ°Ô ÀÔ·ÂÇÏ¼Å¾ß Çϸç IP ÁÖ¼Ò, Æ÷Æ®¹øÈ£, °æ·Î¸í, http:// ³ª https:// µîÀº Æ÷ÇÔÇÒ ¼ö ¾ø½À´Ï´Ù. 
CSR Ç׸ñ¿¡´Â < > ~ ! @ # $ % ^ * / \ ( ) ? µîÀÇ Æ¯¼ö 68 ¹®ÀÚ¸¦ ³ÖÀ» ¼ö ¾ø½À´Ï´Ù. 
CSR »ý¼ºÈÄ ¼­¹ö¿¡ °³ÀÎÅ° (Private Key) °¡ »ý¼ºµË´Ï´Ù. °³ÀÎÅ°¸¦ »èÁ¦Çϰųª ºÐ½ÇÇÒ °æ¿ì ÀÎÁõ¼­¸¦ ¹ß±Þ¹Þ¾Æµµ ¼³Ä¡°¡ ºÒ°¡ÇÕ´Ï´Ù. µû¶ó¼­ ²À °³ÀÎÅ°¸¦ ¹é¾÷¹Þ¾Æ µÎ¼Å¾ß ÇÕ´Ï´Ù.
Á¤º¸ÀԷ°úÁ¤ ¸¶Áö¸·¿¡ ³ª¿À´Â A challenge password ¿Í An optional company name µÎ Ç׸ñÀº ÀÔ·ÂÇÏÁö ¸¶½Ã°í Enter ¸¸ ´©¸£°í ³Ñ¾î°¡¾ß ÇÕ´Ï´Ù. µÎ Á¤º¸°¡ ÀÔ·ÂµÉ °æ¿ì À߸øµÈ CSR »ý¼ºµÉ ¼ö ÀÖ½À´Ï´Ù.
 
¨è CSR(ÀÎÁõ¿äû¼­) »ý¼º
[root@nextline src]# openssl req -new > nextline.co.kr.csr
Enter PEM pass phrase: [private key ¾ÏÈ£ÀÔ·Â]
Verifying - Enter PEM pass phrase: [private key ¾ÏÈ£ ÀçÀÔ·Â]


[CSR Á¤º¸ÀÔ·Â Ç׸ñ]
Country Name (2 letter code) [AU]:KR
State or Province Name (full name) [Some-State]:Seongnam Gyeonggi-do
Locality Name (eg, city) []:Yatap-dong Bundang-gu
Organization Name (eg, company) [Internet Widgits Pty Ltd]:nextline
Organizational Unit Name (eg, section) []:Technological Support Department
Common Name (eg, YOUR name) []:nextline.co.kr
Email Address []:nextline@nextline.co.kr
A challenge password/An optional company name Ç׸ñÀº ÀÔ·ÂÇÏÁö ¾Ê°í Enter¸¸ ´©¸£°í ³Ñ¾î°©´Ï´Ù.
Please enter the following 'extra' attributes
to be sent with your certificate request
A challenge password []:
An optional company name []:

 
¨é CSR È®ÀÎ
[root@nextline src]# openssl req -noout -text -in nextline.co.kr.csr

 
¨ê °³ÀÎÅ°»ý¼º
CSR »ý¼º½Ã ÀÔ·ÂÇÑ privkey.pem Å°ÀÇ Æнº¹®ÀÌ »èÁ¦µÈ °³ÀÎÅ°¸¦ »ý¼ºÇÕ´Ï´Ù.
[root@nextline src]# openssl rsa -in privkey.pem -out nextline.key
Enter pass phrase for privkey.pem: [CSR »ý¼º½Ã ÀÔ·ÂÇÑ ¾ÏÈ£¸¦ ±âÀÔÇÕ´Ï´Ù.]

 
-------------------------------------------------------------------------------------------------
 
 
( 11 ) ÀÎÁõ¼­ Á¢¼ö
³Ø½ºÆ®¶óÀο¡ ÀÎÁõ¼­¹ß±Þ ¿äû ½Ã Á¢¼ö¾ç½Ä¿¡ µû¶ó Á¤º¸ ±âÀÔÈÄ ÀÎÁõ¼­¹ß±ÞÀ» ½ÅûÇÕ´Ï´Ù.

¨ç ÀÎÁõ¼­ ½Åû Á¤º¸ÀÔ·Â
µµ¸ÞÀÎ :
(www.nextline.co.kr°ú nextline.co.krÀº ´Ù¸¥ µµ¸ÞÀÎÀ¸·Î ÀÎ½ÄµÇ¸ç °¢°¢ ÀÎÁõ¼­¸¦ ½ÅûÇÏ¼Å¾ß ÇÕ´Ï´Ù.)
»óÇ°Á¾·ù : °æÁ¦Çü/±âº»Çü/°ñµåÇü/ÇÁ¸®¹Ì¾öÇü/¸ÖƼµµ¸ÞÀÎ(µµ¸ÞÀÎÀÌ ¿©·¯°³ÀÏ °æ¿ì ¼±ÅÃ)
µµ¸ÞÀÎ Ãß°¡ µî·Ï : ¸ÖƼµµ¸ÞÀÎÀÇ °æ¿ì ÇØ´çµÇ¸ç Ãß°¡ÇÏ½Ç µµ¸ÞÀÎ ¸íÀ» ±âÀÔÇÕ´Ï´Ù.
ÀÎÁõ¼­ ±â°£ : 1/2/3 ³â 
¿î¿µÈ¯°æ : Apache + Mod SSL 
CSR ÄÚµåÀÔ·Â : CSR ÃßÃâ°ª ÀÔ·Â
»óÈ£¸í(¿µ¹®ÀÔ·Â) : nextline
ºÎ¼­¸í(¿µ¹®ÀÔ·Â) : Technological Support Department
ÁÖ¼Ò »ó¼¼ÁÖ¼Ò(¿µ¹®ÀÔ·Â) : Hostway IDC 343-1
½Ã/±º(¿µ¹®ÀÔ·Â) : Yatap-dong Bundang-gu
½Ã/µµ(¿µ¹®ÀÔ·Â) : Seongnam Gyeonggi-do
¿ìÆí¹øÈ£ : 463-828
±¹°¡ : KR
µî·Ï¹øÈ£(»ç¾÷ÀÚµî·Ï¹øÈ£/Áֹεî·Ï¹øÈ£ µµ¸ÞÀÎ ¼ÒÀ¯ÁÖ) : µµ¸ÞÀÎ Á¶È¸ ½Ã ³ªÅ¸³ª´Â Ã¥ÀÓÀÚ ¹× »ç¾÷ÀÚ Á¤º¸¸¦ ÀÔ·ÂÇÕ´Ï´Ù.
¸ÞÀÏÁÖ¼Ò(ÀÎÁõ¼­ ¼ö·É À̸ÞÀϱâÀÔ) : µµ¸ÞÀÎ Á¶È¸ ½Ã ³ªÅ¸³ªÀִ åÀÓÀÚ ÀüÀÚ¿ìÆíÀ» ÀÔ·ÂÇÕ´Ï´Ù.
´ã´çÀÚ À̸§ :  µµ¸ÞÀÎ Á¶È¸ ½Ã ³ªÅ¸³ª´Â Ã¥ÀÓÀÚ ¸íÀ» ÀÔ·ÂÇÕ´Ï´Ù.
ÀüÈ­ ¹øÈ£ : µµ¸ÞÀÎ Á¶È¸ ½Ã ³ªÅ¸³ª´Â Ã¥ÀÓÀÚ ÀüÈ­¹øÈ£¸¦ ÀÔ·ÂÇÕ´Ï´Ù.
 
¨è CSR ÃßÃâ
[root@nextline src]# cat nextline.co.kr.csr

 
»ý¼ºµÈ CSR À» Ãâ·ÂÇÏ¸é ¾Æ·¡¿Í °°Àº base64 Çü½ÄÀÇ ¹®¼­¸¦ º¼ ¼ö ÀÖÀ¸¸ç ÀÌ ¹®¼­ÀÇ Ã¹ ÁÙ -----BEGIN ¡¦ ºÎÅÍ ¸¶Áö¸· ÁÙ -----END ¡¦ ±îÁö º¹»çÇÏ¿© ÀÎÁõ¼­ ½Åû½Ã CSR ÄÚµåÀԷ¶õ¿¡ º¹»çÇÏ¿© ºÙ¿© ³ÖÀº µÚ ÀÔ·ÂÁ¤º¸¿Í ÇÔ²² Àü¼Û ÈÄ Áֹεî·ÏÁõ »çº»(°³ÀÎ)/»ç¾÷ÀÚµî·ÏÁõ »çº»(»ç¾÷ÀÚ)¸¦ Æѽº·Î º¸³»Áֽøé Á¢¼ö°¡ ¿Ï·áµË´Ï´Ù.

 
 -----------------------------------------------------------------------------------------
( 12 ) ÀÎÁõ¼­ ¼³Ä¡

Á¢¼öÇÑ CSR ÆÄÀÏÀÌ Á¤»óÀûÀ¸·Î »ý¼ºµÇ¾ú´Ù¸é º°´Ù¸¥ ¹®Á¦¾øÀÌ ÀÎÁõ¼­¸¦ ¹ß±Þ ¹ÞÀ» ¼ö ÀÖ½À´Ï´Ù. ÀÎÁõ¼­ ÆÄÀÏÀº ½Åû½Ã ±â·ÏÇÑ Email ÁÖ¼Ò¸¦ ÅëÇØ ÀÎÁõ¼­¸¦ ÷ºÎÆÄÀÏ·Î ¼ö½ÅÇÏ°Ô µË´Ï´Ù.
 
¨ç ¹ß±ÞÀÎÁõ¼­ ÷ºÎÈ­ÀÏ È®ÀÎ
¸ÞÀÏ·Î ¹ÞÀº ÀÎÁõ¼­ ÆÄÀÏÀÇ ¾ÐÃàÀ» ÇØÁ¦ÇϽøé ÀÎÁõ¼­ ¹× CA µÎ°³ÀÇ ÆÄÀÏÀÌ È®ÀÎ ÇÏ½Ç ¼ö ÀÖ½À´Ï´Ù.
* ¹ß±ÞµÈ ÀÎÁõ¼­ÀÇ ÆÄÀϸíÀº ÀÎÁõ¼­ ¸¶´Ù ¼­·Î »óÀÌÇÏ´Ï ÇØ´ç ÆÄÀÏ¸í¿¡ ¸Â°Ô ¼³Á¤ÇϽñ⠹ٶø´Ï´Ù.


¨è ftp °èÁ¤»ý¼º
ÀÎÁõ¼­¸¦ ¼­¹ö·Î ¾÷·ÎµåÇϱâÀ§ÇØ FTP °èÁ¤À» »ý¼ºÇÕ´Ï´Ù. ±âÁ¸ FTP °èÁ¤À» ÀÌ¿ëÇÏ¿©µµ ¹«¹æÇÕ´Ï´Ù.
°èÁ¤»ý¼º
[root@nextline ~]# useradd nextline
°èÁ¤ Æнº¿öµå¼³Á¤
[root@nextline ~]# passwd nextline
Changing password for user nextline.
Æнº¿öµå ÀÔ·Â
New UNIX password:
Æнº¿öµå ÀçÀÔ·Â
Retype new UNIX password:
passwd: all authentication tokens updated successfully.
 
 
¨é ÀÎÁõ¼­ ¾÷·Îµå
FTP ÇÁ·Î±×·¥À» ÀÌ¿ëÇÏ¿© 4393142.crt, 4393142.ca-bundle ÆÄÀÏÀ» ¾÷·Îµå ÇÕ´Ï´Ù.

 
¨ê ÀÎÁõ¼­ °æ·Î·Î ÀÎÁõÆÄÀÏ À̵¿
À§ ÆÄÀÏ Áß 4393142.crt ÆÄÀÏÀ» SSLCertificateFile °æ·Î·Î À̵¿ÇÕ´Ï´Ù.
SSLCACertificateFile /usr/local/apache/cert/4393142.crt
4393142.ca-bundle ÆÄÀÏÀ» SSLCACertificateFile °æ·Î·Î À̵¿ÇÕ´Ï´Ù.
SSLCACertificateFile /usr/local/apache/cert/4393142.ca-bundle
 
 
À§¿¡¼­ »ý¼ºÇÑ °³ÀÎÅ°(nextline.co.kr.key)¸¦ SSLCertificateKeyFile °æ·Î·Î À̵¿ÇÕ´Ï´Ù.
SSLCertificateKeyFile /usr/local/apache/conf/cert/nextline.co.kr.key
 
 
¨ë À¥¼­¹ö ȯ°æ¼³Á¤
[root@nextline src]# vi /usr/local/apache/conf/httpsd.conf

 
http, https Æ÷Æ® ¼³Á¤
Listen 80
Listen 443


Apache-sslÀº ±âº»±¸µ¿ÀÌ SSL¸ðµå·Î ±¸µ¿µÇ¹Ç·Î ÀÏ¹Ý http 80 Æ÷Æ® »ç¿ëÀ» À§ÇØ
'Main' server configuration Àü¿ª¼³Á¤ ºÎºÐ¿¡ SSLDisableÀ» ¼³Á¤ÇÕ´Ï´Ù.[±âº»ÀûÀ¸·Î ¼³Á¤µÇ¾î ÀÖÀ½]
SSLDisable


VirtualHost ¼³Á¤
 
http(80Æ÷Æ®) ÀϹÝÁ¢¼Ó ¼³Á¤
NameVirtualHost 61.100.191.46:80

DocumentRoot /home/nextline/public_html
ServerName nextline.co.kr
SSLDisable [SSL ¼³Á¤À» »ç¿ëÇÏÁö ¾Êµµ·Ï ¼³Á¤ÇÕ´Ï´Ù.]

 
SSL º¸¾È¼­¹ö ¼³Á¤
NameVirtualHost 61.100.191.46:443

DocumentRoot /home/nextline/public_html
ServerName nextline.co.kr
SSLEnable [SSL ¼³Á¤À» Àû¿ëÇÕ´Ï´Ù.]
[SSLCacheServerPath °æ·Î¸¦ ¼³Á¤ÇÕ´Ï´Ù.]
SSLCacheServerPath /usr/local/apache/bin/gcache
[SSLCacheServerPort ¼³Á¤ÇÕ´Ï´Ù.]
SSLCacheServerPort 12345
[SSLSessionCacheTimeout ¼³Á¤]
SSLSessionCacheTimeout 3600
[SSLCertificateFile ÀÎÁõ¼­ °æ·Î¼³Á¤]
SSLCertificateFile /usr/local/apache/cert/4393142.crt
[SSLCertificateKeyFile °³ÀÎÅ° °æ·Î¼³Á¤]
SSLCertificateKeyFile /usr/local/apache/cert/nextline.co.kr.key
[CA rootÀÎÁõ¼­ °æ·Î¿Í ÆÄÀϸíÀ» ¸í½ÃÇÕ´Ï´Ù.]
SSLCACertificateFile /usr/local/apache/certs/4393142.ca-bundle

 

 
¨ì Apache ±¸µ¿
[root@nextline apache_1.3.37]# /usr/local/apache/bin/httpsdctl start
 

¨í Æ÷ƮȮÀÎ
[root@nextline src]# netstat -anp | grep http
tcp  0      0 0.0.0.0:80  0.0.0.0:*      LISTEN      32533/httpsd
tcp  0      0 0.0.0.0:443 0.0.0.0:*      LISTEN      32533/httpsd

 
[root@nextline src]# netstat -anp|grep gcache
tcp  0      0 0.0.0.0:1234  0.0.0.0:*  LISTEN      32534/gcache


¨î À¥¼­ºñ½º µ¿ÀÛ»óÅ Á¡°Ë
https://nextline.co.kr
ÆäÀÌÁö ÇÏ´ÜÀ» º¸½Ã¸é ¿­¼è ¾ÆÀÌÄÜÀÌ º¸ÀÌ°Ô µË´Ï´Ù. ¾ÆÀÌÄÜÀ» Ŭ¸¯ÇÏ°Ô µÇ¸é À§¿Í °°ÀÌ ÀÎÁõ¼­ Á¤º¸¸¦ È®ÀÎÇÏ½Ç ¼ö ÀÖ½À´Ï´Ù.
 
 
 
¨ï ÀÎÁõ °æ·ÎÈ®ÀÎ
  º¸¾È¼­¹ö SSL Linux Apache 1.X¹öÀü
  MS-SQL º¹¿ø Çϱâ





ȸ»ç¼Ò°³ °³ÀÎÁ¤º¸Ãë±Þ¹æħ ÀÌ¿ë¾à°ü À̸ÞÀÏÁÖ¼Ò ¹«´Ü¼öÁý°ÅºÎ CONTACT US IDC ¾àµµ
ȸ»ç¼Ò°³ °³ÀÎÁ¤º¸Ãë±Þ¹æħ ÀÌ¿ë¾à°ü À̸ÞÀÏÁÖ¼Ò ¹«´Ü¼öÁý°ÅºÎ CONTACT US IDC ¾àµµ ȸ»ç¼Ò°³ °³ÀÎÁ¤º¸Ãë±Þ¹æħ ÀÌ¿ë¾à°ü À̸ÞÀÏÁÖ¼Ò ¹«´Ü¼öÁý°ÅºÎ CONTACT US IDC ¾àµµ