º¸¾È¼¹ö SSL º¸¾È¼¹ö SSL À̶õ Secure Sockets Layer ÀÇ ¸Ó¸®±Û·Î¼ À¥¼¹ö ÀÎÁõ, ¼¹ö ÀÎÁõÀ̶ó°íµµ ÇÕ´Ï´Ù. ºê¶ó¿ìÀú¿Í ¼¹ö°£ÀÇ Åë½Å¿¡¼ Á¤º¸¸¦ ¾ÏÈ£È ÇÔÀ¸·Î½á µµÁß¿¡ ÇØÅ·À» ÅëÇØ Á¤º¸°¡ À¯Ã⠵Ǵõ¶óµµ Á¤º¸ÀÇ ³»¿ëÀ» º¸È£ÇÒ ¼ö ÀÖ°Ô ÇØ ÁÖ´Â º¸¾È ¼Ö·ç¼ÇÀ¸·Î ¹ú½á ¼ö¹é¸¸ÀÇ »çÀÌÆ®¿î¿µÀÚ¿¡ ÀÇÇØ »ç¿ëµÇ¾îÁö°í ÀÖ½À´Ï´Ù. Àü¼¼°èÀûÀΠǥÁØ º¸¾È ±â¼úÀº 1994³â Netscape ¿¡ ÀÇÇØ °³¹ßµÇ¾úÀ¸¸ç À¥¼¹ö°ú À¥ºê¶ó¿ìÀú°£ÀÇ ¸ðµç µ¥ÀÌÅ͸¦ ¾ÏÈ£ÈÇؼ º¸³»°Ô µË´Ï´Ù. Apache_1.x + mod_ssl + Mysql + Php + Zend + OpenSSL ¼³Ä¡
( 1 ) OpenSSL ¶óÀ̺귯¸® È®ÀÎ OpenSSL ¼³Ä¡ À¯/¹«¸¦ È®ÀÎÇϽŠÈÄ ÀÌ¹Ì ¼³Ä¡°¡ µÇ¾îÀÖ´Â °æ¿ì ±â¼ú¹®¼ÀÇ OpenSSL ºÎºÐÀ» Àû¿ëÇÏÁö ¾ÊÀ¸¼Åµµ ¹«¹æÇÕ´Ï´Ù. ¨ç rpm ¹öÀüÈ®ÀÎ [root@nextline ~]# rpm -qa | grep openssl rpm ¹öÀüÀ¸·Î ¼³Ä¡µÈ opensslÀÇ À¯/¹«¸¦ È®ÀÎÇÕ´Ï´Ù. Source ¹öÀü ¼³Ä¡¸¦ À§ÇØ rpm ¹öÀüÀ» »èÁ¦ÇÏ½Ã¸é ¾ÈµÇ¸ç openssl »èÁ¦ ½Ã ÀÇÁ¸¼ºÀ» °¡Áö´Â ¶óÀ̺귯¸® ÆÄÀÏÀÇ ¿À·ù·Î ssh, sendmail µîÀÇ ¼ºñ½º°¡ ½ÇÇàµÇÁö ¾ÊÀ¸´Ï ÁÖÀÇÇϽñ⠹ٶø´Ï´Ù.
¨è Source ¹öÀüÈ®ÀÎ whereis ¸í·É¾î ¸í·ÉÀÇ ½ÇÇà ÆÄÀÏ, ¼Ò½º, ¸Å´º¾ó ÆäÀÌÁö°¡ ¾îµð ÀÖ´ÂÁö º¸¿©ÁÝ´Ï´Ù. [root@nextline ~]# whereis openssl rpm ¹öÀüÀÌ ¼³Ä¡µÇ¾î ÀÖÁö ¾ÊÀ» ½Ã À§ ¸í·É¾î¸¦ ÅëÇØ ¼Ò½º¹öÀü ¼³Ä¡ À¯/¹«¸¦ È®ÀÎÇÕ´Ï´Ù.
( 2 ) Source ÆÄÀÏ ´Ù¿î·Îµå wgetÀº À¥¿¡¼ ÀÚµ¿ÀûÀ¸·Î ÆÄÀÏÀ» ¹Þ¾Æ¿À´Âµ¥ »ç¿ëµÇ´Â À¯Æ¿¸®Æ¼À̸ç HTTP, HTTPS, FTP ÇÁ·ÎÅäÄÝÀ» Áö¿øÇÕ´Ï´Ù. ¨ç apache_1.3.37.tar.gz ´Ù¿î·Îµå »çÀÌÆ® : http://httpd.apache.org/download.cgi [root@nextline ~]# wget http://mirror.apache-kr.org/httpd/apache_1.3.37.tar.gz
¨è mysql-4.1.22.tar.gz ´Ù¿î·Îµå »çÀÌÆ® : ftp://mysql.byungsoo.net/pub/mysql/ [root@nextline ~]# wget ftp://mysql.byungsoo.net/pub/mysql/Downloads/MySQL-4.1/mysql4.1.22.tar.gz
¨é php-5.2.3.tar.gz ´Ù¿î·Îµå »çÀÌÆ® : http://www.php.net/downloads.php [root@nextline ~]# wget http://www.php.net/get/php-5.2.3.tar.gz/from/kr2.php.net/mirror
¨ê gd-2.0.35.tar.gz ´Ù¿î·Îµå »çÀÌÆ® : http://www.libgd.org/releases/ [root@nextline ~]# wget http://www.libgd.org/releases/gd-2.0.35.tar.gz
¨ë ZendOptimzer-3.3.0-linux-glibc21-i386.tar.gz ´Ù¿î·Îµå »çÀÌÆ® : http://www.zend.com/ ´Ù¿î·Îµå ¹ÞÀº ZendOptimzerÀ» ftpÀ» ÀÌ¿ëÇÏ¿© ¾÷·Îµå ÇÕ´Ï´Ù. ¨ì mod_ssl-2.8.28-1.3.37.tar.gz ´Ù¿î·Îµå »çÀÌÆ® : http://www.modssl.org/ [root@nextline ~]# wget http://www.modssl.org/source/mod_ssl-2.8.28-1.3.37.tar.gz
¨í openssl-0.9.8e.tar.gz ´Ù¿î·Îµå »çÀÌÆ® : http://www.openssl.org/source/ [root@nextline ~]# wget http://www.openssl.org/source/openssl-0.9.8e.tar.gz
¨î Source ÆÄÀÏ È®ÀÎ [root@nextline ~]# ls ZendOptimizer-3.3.0-linux-glibc21-i386.tar.gz gd-2.0.35.tar.gz apache_1.3.37.tar.gz mysql-4.1.22.tar.gz php-5.2.3.tar.gz mod_ssl-2.8.28-1.3.37.tar.gz openssl-0.9.8e.tar.gz
( 2 ) Source ÆÄÀÏ ¾ÐÃàÇØÁ¦ [tar ¸í·É¾î ¿É¼Ç] tar ¸í·É¾î´Â ÆÄÀÏÀ» ¹°Å³ª Ç® ¶§ »ç¿ëµÇ´Â ¸®´ª½º ¸í·É¾î ÀÔ´Ï´Ù. c : tar ÆÄÀÏÀ» »ý¼ºÇÒ ¶§(¿©·¯ °³ÀÇ ÆÄÀÏÀ» ÇϳªÀÇ ÆÄÀÏ·Î ¹À» ¶§) v : ¹À» ¶§³ª Ç®¾îÁÙ ¶§ ÆÄÀϵéÀÇ ³»¿ëÀ» ÀÚ¼¼ÇÏ°Ô º¸·Á°í ÇÒ ¶§. z : gzip°ú °ü·ÃÇÏ¿© ¾ÐÃàÀ̳ª ÇØÁ¦¸¦ ÇѲ¨¹ø¿¡ ÇÏ·Á°í ÇÒ ¶§ »ç¿ë. x : ÁÖ¾îÁø À̸§ÀÇ ÆÄÀÏ¿¡ ´ëÇÏ¿© ÃßÃâ »ç¿ë¹ý: tar [¿É¼Ç] ÆÄÀÏ¸í ¨ç apache_1.3.37.tar.gz [root@nextline ~]# tar zxvf apache_1.3.37.tar.gz
¨è mysql-4.1.22.tar.gz [root@nextline ~]# tar zxvf mysql-4.1.22.tar.gz
¨é gd-2.0.35.tar.gz [root@nextline ~]# tar zxvf gd-2.0.35.tar.gz
¨ê php-5.2.3.tar.gz [root@nextline ~]# tar zxvf php-5.2.3.tar.gz
¨ë ZendOptimizer-3.3.0-linux-glibc21-i386.tar.gz [root@nextline ~]# tar zxvf ZendOptimizer-3.3.0-linux-glibc21-i386.tar.gz
¨ì mod_ssl-2.8.28-1.3.37.tar.gz [root@nextline ~]# tar zxvf mod_ssl-2.8.28-1.3.37.tar.gz
¨í openssl-0.9.8e.tar.gz [root@nextline ~]# tar zxvf openssl-0.9.8e.tar.gz
¾ÐÃàÇØÁ¦À» ÇØÁ¦ÇÏ¸é ¾Æ·¡¿Í °°ÀÌ ÆÐÅ°Áöº° ¼Ò½ºµð·ºÅ丮°¡ »ý¼ºµË´Ï´Ù. ZendOptimizer-3.3.0-linux-glibc21-i386 mysql-4.1.22 gd-2.0.35 php-5.2.3 mod_ssl-2.8.28-1.3.37 apache_1.3.37 openssl-0.9.8e
( 3 ) OpenSSL ¼³Ä¡ ¨ç ÄÄÆÄÀÏ È¯°æ¼³Á¤ [root@nextline ~]# cd openssl-0.9.8e [root@nextline openssl-0.9.8e]# ./config --prefix=/usr/local/openssl [ ÄÄÆÄÀÏ ¿É¼Ç] --prefix=/usr/local/openssll opensslÀÌ ¼³Ä¡µÉ °æ·Î¸¦ ÁöÁ¤ÇÏ´Â ¿É¼ÇÀÔ´Ï´Ù.
¨è ÄÄÆÄÀÏ [root@nextline openssl-0.9.8e]# make
¨é ¼³Ä¡ Å×½ºÆ® [root@nextline openssl-0.9.8e]# make test
¨ê ¼³Ä¡ [root@nextline openssl-0.9.8e]# make install
¨ë ¼³Ä¡»óÅ ȮÀÎ ¼³Ä¡°¡ ¿Ï·áµÇ¸é ÄÄÆÄÀÏ ½Ã ÁöÁ¤µÈ °æ·Î¿¡ openssl µð·ºÅ丮°¡ »ý¼ºµË´Ï´Ù. [root@nextline openssl-0.9.8e]# ls /usr/local openssl openssl ¸í·ÉÀÇ ½ÇÇà ÆÄÀÏ, ¼Ò½º, ¸Å´º¾ó ÆäÀÌÁöÀÇ ÀνĿ©ºÎ¸¦ È®ÀÎÇÕ´Ï´Ù. [root@nextline openssl-0.9.8e]# whereis openssl openssl: /usr/local/bin/openssl /usr/local/openssl
( 4 ) Apache1 + mod_ssl ¿¬µ¿¼³Ä¡ ¨ç mod_ssl ÄÄÆÄÀÏ È¯°æ¼³Á¤ [root@nextline ~]# cd mod_ssl-2.8.28-1.3.37 [root@nextline mod_ssl-2.8.28-1.3.37]# ./configure --with-apache=../apache_1.3.37
¨è ¾ÆÆÄÄ¡ ÄÄÆÄÀÏ È¯°æ¼³Á¤ [root@nextline mod_ssl-2.8.28-1.3.37]# cd ../apache_1.3.37 [root@nextline apache_1.3.37]# SSL_BASE=/usr [root@nextline apache_1.3.37]# ./configure --prefix=/usr/local/apache --enable-module=ssl --enable-rule=SHARED_CORE --enable-shared=max --enable-module=so [ÄÄÆÄÀÏ ¿É¼Ç] ¾ÆÆÄÄ¡°¡ ¼³Ä¡µÉ °æ·Î¸¦ ÁöÁ¤ÇÕ´Ï´Ù. --prefix=/usr/local/apache mod_ssl À» ¸ðµâÀ» ¾ÆÆÄÄ¡¿¡ ¿Ã¸®±âÀ§ÇÑ ¿É¼ÇÀÔ´Ï´Ù. --enable-module=ssl DSO ¹æ½ÄÀ¸·Î ¾ÆÆÄÄ¡¸¦ ÄÄÆÄÀÏ ÇϱâÀ§ÇÑ ¿É¼ÇÀÔ´Ï´Ù. --enable-rule=SHARED_CORE --enable-shared=max --enable-module=so
¨é ÄÄÆÄÀÏ [root@nextline apache_1.3.37]# make
¨ê ¼³Ä¡ [root@nextline apache_1.3.37]# make certificate
¨ë Á¤º¸ÀÔ·Â ÀÌ ´Ü°è¿¡¼´Â mod_sslÀÇ Àû¿ë Å×½ºÆ®¸¦ À§ÇÔÀ̹ǷΠCSR Ãʱâ Á¤º¸ÀԷºκÐÀº Encrypt the private key now? Á¦¿ÜÇÑ ºÎºÐÀ» µðÆúÆ®·Î [ Enter ]À» ÀÔ·ÂÇÏ°í ³Ñ¾î°©´Ï´Ù. Signature Algorithm ((R)SA or (D)SA) [R]: [ Enter]
1. Country Name(2 letter code) [XY]: [ Enter] 2. State or Province Name(full name)[Snake >Desert]: [ Enter] 3. Locality Name(eg, city)[Snake >Town]: [ Enter] 4. Organization Name(eg, company)[Snake Oil, Ltd]: [ Enter] 5. Organizational Unit Name (eg, section)[Webserver Team]: [ Enter] 6. Common Name (eg, FQDN)[www.snakeoil.dom]: [ Enter] 7. Email Address(eg, name@FQDN) [www@snakeoil.dom]: [ Enter] 8. Certificate Validity(days) [365]: [ Enter]
Encrypt the private key now? [Y/n]: n [y]À» ÀÔ·ÂÇÒ °æ¿ì /usr/local/apache/bin/apachectl startssl ¸í·É½Ã Æнº¿öµå¸¦ ¹¯°ÔµË´Ï´Ù.
Á¤º¸ÀÔ·ÂÀÌ ¿Ï·áµÇ¸é ¾Æ·¡ ȸé°ú °°ÀÌ SSL KEY °æ·Î ¹× °á°ú°¡ Ãâ·ÂµÇ¸ç ÀÌ °æ·Î·Î SSL VirtualHost ºÎºÐÀ» ¼³Á¤ÇϹǷΠ¸Þ¸ðÇØ Áֽñ⠹ٶø´Ï´Ù.
¨ì ¼³Ä¡ [root@nextline apache_1.3.37]# make install
¨í httpd.conf ÆÄÀÏÆíÁý [vi ¿¡µðÅÍ »ç¿ë¹ý] »ç¿ëÇü½Ä: vi [¿É¼Ç] [»ý¼ºÇÒ ÆÄÀϸí/ÆíÁýÇÒ ÆÄÀϸí] vi ¿¡µðÅÍ´Â ÀԷ¸ðµå, ¸í·É¸ðµå, ½ÇÇà¸ðµå·Î ±¸ºÐµË´Ï´Ù. ÀԷ¸ðµå: vi ÆíÁýȸ鿡¼ ¹®ÀÚ¸¦ ÀÔ·ÂÇÒ ¼ö ÀÖ´Â ¸ðµå·Î¼ ÀԷ¸ðµå·Î ÁøÀÔÇϱâ À§Çؼ´Â i, a, o, I, A, O, RµîÀÌ ÀÖ½À´Ï´Ù. Áï Ãʱâ vi ÆíÁý±â ¸ðµå´Â ¸í·É¾î ¸ðµå·Î ÁøÀÔÀ» Çϱ⶧¹®¿¡ ¹®ÀÚ¸¦ ÀÔ·ÂÇϱâ Àü¿¡ ¾ÕÀÇ ´ÜÃàÅ°Áß Çϳª¸¦ ¸ÕÀú ÀÔ·ÂÇØ¾ß ¿øÇÏ´Â ¹®ÀÚ¸¦ ÀÔ·ÂÇÒ ¼ö ÀÖ½À´Ï´Ù. ¸í·É¸ðµå: Ä¿¼À̵¿/¹®ÀÚ»èÁ¦/¹®ÀÚ(¿)±³Ã¼/¹®ÀÚ¿°Ë»ö µîÀ» ÇÒ¼ö ÀÖ´Â ¸ðµå·Î¼ ÀԷ¸ðµå¿¡¼ ÆíÁýÀÌ ¿Ï·áµÇ¸é EscÅ°¸¦ ´·¯ ¸í·É¸ðµå·Î ÁøÀÔÇÏ¸é µË´Ï´Ù. ½ÇÇà¸ðµå: Ưº°ÇÑ ¸í·É¾î¸¦ ½ÇÇàÇÏ´Â ¸ðµå·Î¼ ¸í·É¾î¸ðµå¿¡¼ ":"(ÄÝ·Ð)¸¦ ´©¸£¸é vi ȸé ÇÏ´Ü ÁÂÃø¿¡ vi Ư¼ö¸í·É¾î¸¦ ÀÔ·ÂÇÒ ¼ö ÀÖ½À´Ï´Ù. [½ÇÇà¸ðµåÀÇ ÀϹÝÀûÀ¸·Î ¾²À̴ Ư¼ö ¸í·É¾î] q : ¼öÁ¤ ÀÛ¾÷ÀÌ ÀÌ·ç¾îÁöÁö ¾ÊÀº »óÅ¿¡¼ vi ÆíÁý±â¿¡¼ ºüÁ®³ª¿É´Ï´Ù. q! : ¼öÁ¤ ÀÛ¾÷ÀÌ ÀÌ·ç¾îÁø ºÎºÐÀ» Àû¿ë½ÃÅ°Áö ¾Ê°í vi ÆíÁý±â¸¦ °Á¦·Î ºüÁ®³ª¿É´Ï´Ù. w : ¼öÁ¤µÈ ÀÛ¾÷À» ÀúÀåÇÕ´Ï´Ù. wq : ¼öÁ¤µÈ ÀÛ¾÷À» ÀúÀåÇÏ°í vi ÆíÁý±â¿¡¼ ºüÁ®³ª¿É´Ï´Ù. Ãʱ⠸í·É¾î¸ðµå-> ÀԷ¸ðµåÁøÀÔ -> ÆíÁý -> ¸í·É¾î¸ðµå -> ½ÇÇà¸ðµå -> Á¾·á [root@nextline apache_1.3.37]# vi /usr/local/apache/conf/httpd.conf ¨ë ServerName ¼³Á¤ ServerName ºÎºÐ¿¡ ¾ÆÀÌÇÇ È¤Àº µµ¸ÞÀÎÀ» ±âÀÔÇÕ´Ï´Ù. ServerName xxx.xxx.xxx.xxx
¨ì SSL Virtual Host ¼³Á¤ ´Ù¸¥ SSL ¼³Á¤Àº µðÆúÆ®·Î ÇÏ°í ¡¦ Áö½ÃÀÚ³»ÀÇ ¾Æ·¡Ç׸ñ¸¸ ¾ÆÀÌÇÇ ¹× µµ¸ÞÀο¡ ¸Â°Ô ÆíÁýÇÕ´Ï´Ù. [¾ÆÀÌÇÇ:Æ÷Æ®] DocumentRoot "/home/nextline/public_html" [Ȩµð·ºÅ丮°æ·Î] ServerName nextline.co.kr [µµ¸ÞÀθí] SSL µµ¸ÞÀÎÀº È£½ºÆ®º°·Î ÀÎÁõÀ» ¹Þ¾Æ¾ß ÇϹǷΠÀÎÁõ ¹ÞÀ» µµ¸ÞÀÎÀ» ÀÔ·ÂÇÕ´Ï´Ù.
¨í SSL ¼³Á¤Àû¿ë [root@nextline apache_1.3.37]# /usr/local/apache/bin/apachectl startssl
¨î ssl 443 Æ÷ƮȮÀÎ [root@nextline src]# netstat -anp | grep httpd tcp 0 0 :::80 :::* LISTEN 2215/httpd tcp 0 0 :::443 :::* LISTEN 2215/httpd
¨ï https Á¢¼ÓÅ×½ºÆ® https://nextline.co.kr Á¢¼ÓÀ» ÇÏ½Ã¸é ¾Æ·¡¿Í°°ÀÌ º¸¾È°æ°í âÀÌ º¸¿©Áý´Ï´Ù. [¿¹] – [Enter]
¨ð SSL º¸¾ÈÀû¿ë ȸé mod_sslÀÌ Á¤»óÀûÀ¸·Î Àû¿ëµÇ¾ú½À´Ï´Ù. °³ÀÎÅ°/CSR »ý¼º ¹× CRT(ÀÎÁõ¼) Àû¿ëÀº ÀÌ ¹®¼ÀÇ [OpenSSLÀ» ÀÌ¿ëÇÑ °³ÀÎÅ°/CSR/CRT »ý¼º/ÀÎÁõ¼Á¢¼ö/ÀÎÁõ¼¼³Ä¡] ºÎºÐÀ» Àû¿ëÇÕ´Ï´Ù. ( 5 ) Mysql ¼³Ä¡ ¨ç ÄÄÆÄÀÏ È¯°æ¼³Á¤ [root@nextline ~]# cd mysql-4.1.22 [root@nextline mysql-4.1.22]# ./configure --prefix=/usr/local/mysql --with-charset=euckr [ÄÄÆÄÀÏ ¿É¼Ç] Mysql ÀÌ ¼³Ä¡µÉ °æ·Î¸¦ ÁöÁ¤ÇÏ´Â ¿É¼ÇÀÔ´Ï´Ù. --prefix=/usr/local/mysql ¹®ÀÚ¼ÂÀ» Çѱ¹¾î·Î ¼³Á¤ÇÏ´Â ¿É¼ÇÀÔ´Ï´Ù. --with-charset=euckr
¨è ÄÄÆÄÀÏ [root@nextline mysql-4.1.22]# make
¨é ¼³Ä¡ [root@nextline mysql-4.1.22]# make install
¨ê mysql µ¥ÀÌÅÍ µð·ºÅ丮»ý¼º [root@nextline mysql-4.1.22]# /usr/local/mysql/bin/mysql_install_db
¨ë µ¥ÀÌÅÍ µð·ºÅ丮ȮÀÎ [root@nextline mysql-4.1.22]# ls /usr/local/mysql µ¥ÀÌÅÍ µð·ºÅ丮 [var]
¨ì mysql °èÁ¤»ý¼º [root@nextline mysql-4.1.22]#usradd –M –s /sbin/nologin mysql; passwd mysql New UNIX password : [mysql Æнº¿öµå¸¦ ÁöÁ¤ÇÕ´Ï´Ù] Retype new UNIX password : [mysql Æнº¿öµå¸¦ Àç ÀÔ·ÂÇÕ´Ï´Ù]
¨í mysql µð·ºÅ丮 ¼ÒÀ¯±Çº¯°æ chown - ¸®´ª½ºÀÇ ¼ÒÀ¯±Ç º¯°æ ¸í·É¾î ÀÔ´Ï´Ù. -R ¿É¼Ç - ÇÏÀ§ µð·ºÅ丮±îÁö ¸ðµÎ Àû¿ëÇÕ´Ï´Ù. [root@nextline mysql-4.1.22]#chown –R mysql.mysql /usr/local/mysql
¨î mysql µ¥¸ó±¸µ¿ mysql¸¦ ¹é±×¶ó¿îµå·Î ±¸µ¿ÇÕ´Ï´Ù. [root@nextline mysql-4.1.22]#/usr/local/mysql/bin/mysqld_safe &
¨ï mysql µ¥¸ó ±¸µ¿È®ÀÎ [root@nextline mysql-4.1.22]# netstat -anp | grep mysqld tcp 0 0 0.0.0.0:3306 0.0.0.0:* LISTEN 2433/mysqld
¨ð mysql root Æнº¿öµå¼³Á¤ [root@nextline mysql-4.1.22]#/usr/local/mysql/bin/mysqladmin –u root password ¡®xxxxxx¡¯
¨ñ mysql Á¢¼ÓÈ®ÀÎ [root@nextline mysql-4.1.22]#mysql –u root –p Á¢¼ÓÀÌ Á¤»óÀûÀ¸·Î ÀÌ·ç¾îÁö¸ç mysql ¼³Ä¡°¡ ¿Ï·áµÈ ȸéÀÔ´Ï´Ù.
( 6 ) GD ¼³Ä¡
¨ç ÄÄÆÄÀÏ È¯°æ¼³Á¤ [root@nextline ~]# cd gd-2.0.35 [root@nextline gd-2.0.35]# ./configure --prefix=/usr/local/gd2 [ÄÄÆÄÀÏ ¿É¼Ç] GD°¡ ¼³Ä¡µÉ °æ·Î¸¦ ÁöÁ¤ÇÏ´Â ¿É¼ÇÀÔ´Ï´Ù. --prefix=/usr/local/gd2
¨è ÄÄÆÄÀÏ [root@nextline gd-2.0.35]# make
¨é ¼³Ä¡ [root@nextline gd-2.0.35]# make install
¨ê ¼³Ä¡È®ÀÎ [root@nextline gd-2.0.35]# ls /usr/local/
( 7 ) PHP ¼³Ä¡
¨ç ÄÄÆÄÀÏ È¯°æ¼³Á¤ [root@nextline ~]# cd php-5.2.3 [root@nextline php-5.2.3]# ./configure --prefix=/usr/local/php \ > --with-apxs=/usr/local/apache/bin/apxs \ > --with-config-file-path=/usr/local/lib \ > --with-mysql=/usr/local/mysql \ > --with-gd=/usr/local/gd2 \ > --enable-gd-native-ttf \ > --with-freetype-dir=/usr \ > --with-zlib \ > --with-iconv \ > --with-imap \ > --with-imap-ssl \ > --with-kerberos \ > --enable-mbstring \ > --enable-track-vars \ > --enable-ftp \ > --disable-debug [ÄÄÆÄÀÏ ¿É¼Ç] --prefix=/usr/local/php php ¼³Ä¡°æ·Î¸¦ ÁöÁ¤ÇÕ´Ï´Ù. --with-apxs=/usr/local/apache/bin/apxs °øÀ¯µÈ apache ¸ðµâÀ» ¿¬µ¿Çϱâ À§ÇÑ ¿É¼ÇÀÔ´Ï´Ù. --with-config-file-path=/usr/local/lib php¼³Á¤ÆÄÀÏ php.iniÆÄÀÏÀÌ Á¸ÀçÇÒ À§Ä¡¸¦ ÁöÁ¤ÇÕ´Ï´Ù. --with-mysql=/usr/local/mysql Mysql°ú ¿¬µ¿Çϱâ À§ÇÑ ¿É¼ÇÀÔ´Ï´Ù. --with-gd=/usr/local/gd2 php¿¡¼ gd¶óÀ̺귯¸®°ü·Ã ÇÔ¼ö¸¦ »ç¿ëÇÏ¿© gd¸¦ Áö¿øÇϱâ À§ÇÑ ¿É¼ÇÀÔ´Ï´Ù. --enable-gd-native-ttf GD ¶óÀ̺귯¸®¿¡¼ FreeType¸¦ ÇÔÇÏ´Â ¿É¼ÇÀÔ´Ï´Ù. –-with-freetype-dir=/usr freetype2¸¦ Áö¿øÇϱâ À§ÇÑ ¿É¼ÇÀÔ´Ï´Ù. --with-zlib µ¥ÀÌÅ;ÐÃà ¶óÀ̺귯¸®·Î¼ php¿¡¼ zlibÀ» Áö¿øÇϱâ À§ÇÑ ¿É¼ÇÀÔ´Ï´Ù. --with-iconv ÀÎÄÚµù º¯È¯ÇÁ·Î±×·¥À¸·Î iconv¸¦ Áö¿øÇϱâ À§ÇÑ ¿É¼ÇÀÔ´Ï´Ù. --with-imap pop °ú ÇÔ²² ¸ÞÀϼö½Åµ¥¸óÀ¸·Î »ç¿ëµÇ´Â ¼ºñ½º·Î¼ imap¸¦ Áö¿øÇϱâ À§ÇÑ ¿É¼ÇÀÔ´Ï´Ù. --with-kerberos Kerberos´Â Ŭ¶óÀ̾ðÆ® ¼¹ö ¾ÖÇø®ÄÉÀ̼ÇÀÇ ÀÔÁõÀ» Á¦°øÇϱâ À§ÇÏ¿© »óĪÀûÀÎ ¾ÏÈ£¹ýÀ» ÀÌ¿ëÇÏ´Â ³×Æ®¿öÅ© ÀÎÁõ ÇÁ·ÎÅäÄݷμ kerberos¸¦ Áö¿øÇϱâ À§ÇÑ ¿É¼ÇÀÔ´Ï´Ù. --enable-mbstring multi-byte¹®ÀÚ¸¦ Áö¿øÇϱâ À§ÇÑ ¿É¼ÇÀ¸·Î ¸¹Àº ¾ð¾î¸¦ Ç¥ÇöÇϱâ À§ÇÏ¿© ÀÌ¿ëµÇ¸ç, php¿¡¼ mbstring¸¦ Áö¿øÇϱâ À§ÇÑ ¿É¼ÇÀÔ´Ï´Ù. --enable-track-vars HTTP_GET_VARS, HTTP_POST_VARS, HTTP_COOKIE_VARS ¹è¿¿¡ µé¾îÀÖ´Â GET / POST / cookie º¯¼öµéÀÌ ¾îµð·ÎºÎÅÍ ¿Ô´ÂÁö ±â¾ïÇÏ°Ô ¸¸µì´Ï´Ù. ÀÌ ¿É¼ÇÀº ´ÜÁö Default °ª À» Á¤ÇÏ´Â °Í»ÓÀ̸ç, ÈÄ¿¡ configuration fileÀÇ track_vars Áö½ÃÀÚ¿¡ ÀÇÇØ Enable/Disable ÇÒ ¼ö ÀÖ½À´Ï´Ù. --enable-ftp php¿¡¼ ftp°ü·Ã ÇÔ¼ö¸¦ Áö¿øÇϱâ À§ÇÑ ¿É¼ÇÀÔ´Ï´Ù. --enable-debug Zend Optimizer¸¦ »ç¿ëÇϱâ À§Çؼ´Â debuggingÀ» »ç¿ëÇÏÁö ¾Ê½À´Ï´Ù. [±×¿Ü ¿É¼Ç] --enable-sockets ¼ÒÄÏ(socket) ÆÄÀÏÀ» »ç¿ëÇϱâ À§ÇÑ ¿É¼ÇÀÔ´Ï´Ù. --with-language-korean Çѱ¹¾î¸¦ »ç¿ëÇϱâ À§ÇÑ ¿É¼ÇÀÔ´Ï´Ù. --enable-dba=shared DBA¸¦ µ¿ÀûÀ¸·Î ÀûÀçÇÒ ¼ö ÀÖ´Â °øÀ¯ ¸ðµâ ÇüÅ·Π¸¸µå´Â ¿É¼ÇÀÔ´Ï´Ù. --enable-gdbm[=DIR] GDBM Áö¿øÀ» Æ÷ÇÔÇÏ´Â ¿É¼ÇÀÔ´Ï´Ù. --enable-memory-limit php¿¡¼ ¸Þ¸ð¸® Á¦ÇÑ ±â´ÉÀ» Áö¿øÇÏ´Â ¿É¼ÇÀÔ´Ï´Ù.
¨è ÄÄÆÄÀÏ [root@nextline php-5.2.3]#make
¨ë ¼³Ä¡ [root@nextline php-5.2.3]#make install
¨ì php ¼³Á¤ÆÄÀÏ º¹»ç [root@nextline php-5.2.3]#cp php.ini-dist /usr/local/lib/php.ini
¨í ¾ÆÆÄÄ¡ ¼³Á¤ÆÄÀÏ ÆíÁý [root@nextline php-5.2.3]#vi /usr/local/apache/conf/httpd.conf
¨î PHP À妽ºÆÄÀÏ ¼³Á¤
DirectoryIndex index.html index.htm index.php index.jsp
¨ï AddType ¼³Á¤ AddType application/x-httpd-php .php .php4 .php3
¨ð ¼³Á¤ÆÄÀÏ Àû¿ë [root@nextline php-5.2.3]#/usr/local/apache/bin/apachectl stop [root@nextline php-5.2.3]#/usr/local/apache/bin/apachectl startssl
( 8 ) ZendOptimizer ¼³Ä¡ ¨ç install.sh ½ÇÇà [root@nextline ~]# cd ZendOptimizer-3.3.0-linux-glibc21-i386 [root@nextline ZendOptimizer-3.3.0-linux-glibc21-i386]# ./install.sh
¨è OK
¨é Zend Optimizer ¶óÀ̼¾½º ȸéÀÔ´Ï´Ù. [EXIT]
¨ê ¶óÀ̼¾½º µ¿ÀÇ È¸éÀÔ´Ï´Ù. [Yes]
¨ë Zend ¼³Ä¡°æ·Î¸¦ ÁöÁ¤Çϴ ȸéÀÔ´Ï´Ù. /usr/local/Zend(Àý´ë°æ·Î) È®ÀÎ ÈÄ ¸¦ ¼±ÅÃÇÕ´Ï´Ù. Zend Optimizer ¼³Ä¡ °æ·Î°¡ ÀÚµ¿ ÁöÁ¤µÇÁö ¾ÊÀ» ½Ã ¼öµ¿À¸·Î /usr/local/Zend °æ·Î¸¦ ÁöÁ¤ÇØ ÁÖ½Ã¸é µË´Ï´Ù. (Linux OSÀÇ ÀÀ¿ëÇÁ·Î±×·¥Àº ±âº» /usr/local¿¡ ¼³Ä¡µÇ±â ¶§¹®¿¡ /usr/local/Zend·Î ÁöÁ¤ÇÕ´Ï´Ù.) [OK]
¨ì php.iniÀÇ °æ·Î¸¦ ÁöÁ¤Çϴ ȸéÀÔ´Ï´Ù. php¼³Ä¡ ½Ã php.ini ÆÄÀÏÀÌ /usr/local/lib¿¡ »ý¼ºµÇ±â ¶§¹®¿¡ /usr/local/lib(Àý´ë°æ·Î) ÁöÁ¤ÇÕ´Ï´Ù. [OK]
¨í Zend Optimizer + Apache ¿¬µ¿ÇÒ °ÍÀÎÁö¸¦ ¹¯´Â ȸéÀÔ´Ï´Ù [Yes]
¨î apaachectlÀÇ °æ·Î¸¦ ÁöÁ¤Çϴ ȸéÀÔ´Ï´Ù. [OK]
¨ï php.ini ÆÄÀÏÀÇ php.ini-zend_optimizer.bak ¹é¾÷ÆÄÀÏÀ» »ý¼ºÇϴ ȸéÀ̸ç, »ý¼ºÀ§Ä¡´Â php.ini ÆÄÀÏÀÌ Á¸ÀçÇÏ´Â /usr/local/lib °æ·Î¿¡ »ý¼ºµË´Ï´Ù. [OK]
¨ð Zend Optimizer ¼³Ä¡¿Ï·á ȸéÀÔ´Ï´Ù [OK]
¨ñ apache Àç ½ÃÀÛÀ» ¹¯´Â ȸéÀÔ´Ï´Ù [Yes]
¨ò Apache Àç ½ÃÀÛ ¼º°ø [OK]
¨ó phpinfo ÆÄÀÏ»ý¼º [root@nextline ~]#vi /usr/local/apache/htdocs/php_test.php
¨ô phpinfo Äڵ弳Á¤
phpinfo(); ?>
¨õ APM ¿¬µ¿È®ÀÎ http://xxx.xxx.xxx.xxx/php_test.php
( 9 ) CSR »ý¼º CSR ( Certificate Signing Request ) À̶õ? SSL ¼¹ö¸¦ ¿î¿µÇϴ ȸ»çÀÇ Á¤º¸¸¦ ¾ÏÈ£ÈÇÏ¿© ÀÎÁõ±â°üÀ¸·Î º¸³» ÀÎÁõ¼¸¦ ¹ß±Þ¹Þ°Ô ÇÏ´Â ÀÏÁ¾ÀÇ ½Åû¼À̸ç CSRÀº ASCII ÅؽºÆ® ÈÀÏ·Î »ý¼ºµË´Ï´Ù. ¨ç °³ÀÎÅ° »ý¼º Openssl ¸í·É¾î¸¦ ÀÌ¿ëÇÏ¿© À¥¼¹öÀÇ RSAÅ°(1024ºñÆ® ¾ÏÈ£È)¸¦ »ý¼ºÇÕ´Ï´Ù. °³ÀÎÅ° »ý¼º½Ã DES/RSA ¾ÏÈ£È ¹æ½ÄÀ» ¼±ÅÃÇÒ ¼ö ÀÖÀ¸³ª DES ¹æ½ÄÀ¸·Î °³ÀÎÅ°¸¦ »ý¼ºÇÏ½Ç °æ¿ì ¾ÆÆÄÄ¡¸¦ ±¸µ¿ÇÏ¸é °³ÀÎÅ° »ý¼º½Ã ÀÔ·ÂÇÑ Æнº¿öµå¸¦ ¹¯°Ô µÇ¸ç ºÎÆà ½Ã ¾ÆÆÄÄ¡ µ¥¸óÀÌ ÀÚµ¿À¸·Î ±¸µ¿µÇµµ·Ï ¼³Á¤ÇϽŠ°æ¿ì ºÎÆà Áß Æнº¿öµå¸¦ ¹¯°Ô µÇ¹Ç·Î °ü¸®ÀÇ ¿øÈ°ÇÔÀ» À§ÇØ RSA ¹æ½ÄÀ¸·Î °³ÀÎÅ°¸¦ »ý¼ºÇÕ´Ï´Ù. /usr/local/src µð·ºÅ丮·Î À̵¿ÇÏ¿© Å°»ý¼º ÇÕ´Ï´Ù. [root@nextline ~]# cd /usr/local/src openssl genrsa 1024 > µµ¸ÞÀÎ.key [root@nextline src]# openssl genrsa 1024 > nextline.co.kr.key
¨è µµ¸ÞÀÎ Á¶È¸ CSR Á¤º¸ÀÔ·Â ¹× ÀÎÁõ½Åû¼ ÀÛ¼º½Ã µµ¸ÞÀÎ µî·Ï¾÷ü ¹× µµ¸ÞÀÎ Á¶È¸»çÀÌÆ®¿¡¼ µµ¸ÞÀÎÀ» Á¶È¸ÇÏ¿© Á¶È¸°á°ú¿Í ÀÏÄ¡ÇÏ°Ô Á¤º¸¸¦ ÀÔ·ÂÇÏ¿©¾ß ÇÕ´Ï´Ù. http://whois.nic.or.kr
[CSR Ç׸ñ¿¡ ´ëÇÑ ¼³¸í] CSR Á¤º¸ ÀÔ·Â ½Ã µµ¸ÞÀÎ µî·Ï¾÷ü¿¡ µî·ÏÇϽŠÁ¤º¸¿Í µ¿ÀÏÇÑ Á¤º¸¸¦ ÀÔ·ÂÇÕ´Ï´Ù. Country Name ÀÌ°ÍÀº µÎ ÀÚ·Î µÈ ISO Çü½ÄÀÇ ±¹°¡ ÄÚµåÀÔ´Ï´Ù. State or Province Name ½Ã À̸§À» ÀÔ·ÂÇØ¾ß ÇÏ¸ç ¾à¾î¸¦ »ç¿ëÇÒ ¼ö ¾ø½À´Ï´Ù. Locality Name ÀÌ Çʵå´Â ´ëºÎºÐÀÇ °æ¿ì »ý·«ÀÌ °¡´ÉÇÏ¸ç ¾÷ü°¡ À§Ä¡ÇÑ °÷¸¦ ³ªÅ¸³À´Ï´Ù. Organization »ç¾÷ÀÚ µî·ÏÁõ¿¡ Àִ ȸ»ç¸í°ú ÀÏÄ¡µÇ´Â ¿µ¹®È¸»ç¸íÀ» ÀÔ·ÂÇÏ½Ã¸é µË´Ï´Ù. Organization Unit "¸®´ª½º °ü¸®ÆÀ", "À©µµ¿ì °ü¸®ÆÀ" µî°ú °°ÀÌ ¾÷üÀÇ ºÎ¼¸¦ ÀÔ·ÂÇÒ ¼ö ÀÖ½À´Ï´Ù. Common Name ÀÎÁõ¹ÞÀ» µµ¸ÞÀÎÁÖ¼Ò¸¦ ÀÔ·ÂÇÏ½Ã¸é µË´Ï´Ù. ÀÌ Á¤º¸·Î À¥ »çÀÌÆ®¸¦ ½Äº°ÇϹǷΠȣ½ºÆ® À̸§À» º¯°æÇÒ °æ¿ì ´Ù¸¥ µðÁöÅÐ ID¸¦ ¿äûÇØ¾ß ÇÕ´Ï´Ù. È£½ºÆ®¿¡ ¿¬°áÇϴ Ŭ¶óÀ̾ðÆ® ºê¶ó¿ìÀú°¡ µðÁöÅÐ IDÀÇ À̸§°ú URLÀÌ ÀÏÄ¡ÇÏ´ÂÁö¸¦ È®ÀÎÇÕ´Ï´Ù. [CSR Ç׸ñ ÀԷ½à ÁÖÀÇ»çÇ×] Common Name ¿¡´Â ÀÎÁõ¼¸¦ ¼³Ä¡ÇÒ »çÀÌÆ®ÀÇ µµ¸ÞÀÎÀÇ À̸§À» Á¤È®ÇÏ°Ô ÀÔ·ÂÇÏ¼Å¾ß Çϸç IP ÁÖ¼Ò, Æ÷Æ®¹øÈ£, °æ·Î¸í, http:// ³ª https:// µîÀº Æ÷ÇÔÇÒ ¼ö ¾ø½À´Ï´Ù. CSR Ç׸ñ¿¡´Â < > ~ ! @ # $ % ^ * / \ ( ) ? µîÀÇ Æ¯¼ö 68 ¹®ÀÚ¸¦ ³ÖÀ» ¼ö ¾ø½À´Ï´Ù. CSR »ý¼ºÈÄ ¼¹ö¿¡ °³ÀÎÅ° (Private Key) °¡ »ý¼ºµË´Ï´Ù. °³ÀÎÅ°¸¦ »èÁ¦Çϰųª ºÐ½ÇÇÒ °æ¿ì ÀÎÁõ¼¸¦ ¹ß±Þ¹Þ¾Æµµ ¼³Ä¡°¡ ºÒ°¡ÇÕ´Ï´Ù. µû¶ó¼ ²À °³ÀÎÅ°¸¦ ¹é¾÷¹Þ¾Æ µÎ¼Å¾ß ÇÕ´Ï´Ù. Á¤º¸ÀԷ°úÁ¤ ¸¶Áö¸·¿¡ ³ª¿À´Â A challenge password ¿Í An optional company name µÎ Ç׸ñÀº ÀÔ·ÂÇÏÁö ¸¶½Ã°í Enter ¸¸ ´©¸£°í ³Ñ¾î°¡¾ß ÇÕ´Ï´Ù. µÎ Á¤º¸°¡ ÀÔ·ÂµÉ °æ¿ì À߸øµÈ CSR »ý¼ºµÉ ¼ö ÀÖ½À´Ï´Ù. ¨é CSR(ÀÎÁõ¿äû¼) »ý¼º [root@nextline src]# openssl req -new -key nextline.co.kr.key > nextline.co.kr.csr
[CSR Á¤º¸ÀÔ·Â Ç׸ñ] Country Name (2 letter code) [AU]:KR State or Province Name (full name) [Some-State]:Seongnam Gyeonggi-do Locality Name (eg, city) []:Yatap-dong Bundang-gu Organization Name (eg, company) [Internet Widgits Pty Ltd]:nextline Organizational Unit Name (eg, section) []:Technological Support Department Common Name (eg, YOUR name) []:nextline.co.kr Email Address []:nextline@nextline.co.kr A challenge password/An optional company name Ç׸ñÀº ÀÔ·ÂÇÏÁö ¾Ê°í Enter¸¸ ´©¸£°í ³Ñ¾î°©´Ï´Ù. Please enter the following 'extra' attributes to be sent with your certificate request A challenge password []: An optional company name []:
¨é CSR È®ÀÎ [root@nextline src]# openssl req -noout -text -in nextline.co.kr.csr
( 10 ) ÀÎÁõ¼ Á¢¼ö
³Ø½ºÆ®¶óÀο¡ ÀÎÁõ¼¹ß±Þ ¿äû ½Ã Á¢¼ö¾ç½Ä¿¡ µû¶ó Á¤º¸ ±âÀÔÈÄ ÀÎÁõ¼¹ß±ÞÀ» ½ÅûÇÕ´Ï´Ù. ¨ç ÀÎÁõ¼ ½Åû Á¤º¸ÀÔ·Â µµ¸ÞÀÎ : (www.nextline.co.kr°ú nextline.co.krÀº ´Ù¸¥ µµ¸ÞÀÎÀ¸·Î ÀÎ½ÄµÇ¸ç °¢°¢ ÀÎÁõ¼¸¦ ½ÅûÇÏ¼Å¾ß ÇÕ´Ï´Ù.) »óÇ°Á¾·ù : °æÁ¦Çü/±âº»Çü/°ñµåÇü/ÇÁ¸®¹Ì¾öÇü/¸ÖƼµµ¸ÞÀÎ(µµ¸ÞÀÎÀÌ ¿©·¯°³ÀÏ °æ¿ì ¼±ÅÃ) µµ¸ÞÀÎ Ãß°¡ µî·Ï : ¸ÖƼµµ¸ÞÀÎÀÇ °æ¿ì ÇØ´çµÇ¸ç Ãß°¡ÇÏ½Ç µµ¸ÞÀÎ ¸íÀ» ±âÀÔÇÕ´Ï´Ù. ÀÎÁõ¼ ±â°£ : 1/2/3 ³â ¿î¿µÈ¯°æ : Apache + Mod SSL CSR ÄÚµåÀÔ·Â : CSR ÃßÃâ°ª ÀÔ·Â »óÈ£¸í(¿µ¹®ÀÔ·Â) : nextline ºÎ¼¸í(¿µ¹®ÀÔ·Â) : Technological Support Department ÁÖ¼Ò »ó¼¼ÁÖ¼Ò(¿µ¹®ÀÔ·Â) : Hostway IDC 343-1 ½Ã/±º(¿µ¹®ÀÔ·Â) : Yatap-dong Bundang-gu ½Ã/µµ(¿µ¹®ÀÔ·Â) : Seongnam Gyeonggi-do ¿ìÆí¹øÈ£ : 463-828 ±¹°¡ : KR µî·Ï¹øÈ£(»ç¾÷ÀÚµî·Ï¹øÈ£/Áֹεî·Ï¹øÈ£ µµ¸ÞÀÎ ¼ÒÀ¯ÁÖ) : µµ¸ÞÀÎ Á¶È¸ ½Ã ³ªÅ¸³ª´Â Ã¥ÀÓÀÚ ¹× »ç¾÷ÀÚ Á¤º¸¸¦ ÀÔ·ÂÇÕ´Ï´Ù. ¸ÞÀÏÁÖ¼Ò(ÀÎÁõ¼ ¼ö·É À̸ÞÀϱâÀÔ) : µµ¸ÞÀÎ Á¶È¸ ½Ã ³ªÅ¸³ªÀִ åÀÓÀÚ ÀüÀÚ¿ìÆíÀ» ÀÔ·ÂÇÕ´Ï´Ù. ´ã´çÀÚ À̸§ : µµ¸ÞÀÎ Á¶È¸ ½Ã ³ªÅ¸³ª´Â Ã¥ÀÓÀÚ ¸íÀ» ÀÔ·ÂÇÕ´Ï´Ù. ÀüÈ ¹øÈ£ : µµ¸ÞÀÎ Á¶È¸ ½Ã ³ªÅ¸³ª´Â Ã¥ÀÓÀÚ ÀüȹøÈ£¸¦ ÀÔ·ÂÇÕ´Ï´Ù. ¨è CSR ÃßÃâ [root@nextline src]# cat nextline.co.kr.csr
»ý¼ºµÈ CSR À» Ãâ·ÂÇÏ¸é ¾Æ·¡¿Í °°Àº base64 Çü½ÄÀÇ ¹®¼¸¦ º¼ ¼ö ÀÖÀ¸¸ç ÀÌ ¹®¼ÀÇ Ã¹ ÁÙ -----BEGIN ¡¦ ºÎÅÍ ¸¶Áö¸· ÁÙ -----END ¡¦ ±îÁö º¹»çÇÏ¿© ÀÎÁõ¼ ½Åû½Ã CSR ÄÚµåÀԷ¶õ¿¡ º¹»çÇÏ¿© ºÙ¿© ³ÖÀº µÚ ÀÔ·ÂÁ¤º¸¿Í ÇÔ²² Àü¼Û ÈÄ Áֹεî·ÏÁõ »çº»(°³ÀÎ)/»ç¾÷ÀÚµî·ÏÁõ »çº»(»ç¾÷ÀÚ)¸¦ Æѽº·Î º¸³»Áֽøé Á¢¼ö°¡ ¿Ï·áµË´Ï´Ù.
( 11 ) ÀÎÁõ¼ ¼³Ä¡
Á¢¼öÇÑ CSR ÆÄÀÏÀÌ Á¤»óÀûÀ¸·Î »ý¼ºµÇ¾ú´Ù¸é º°´Ù¸¥ ¹®Á¦¾øÀÌ ÀÎÁõ¼¸¦ ¹ß±Þ ¹ÞÀ» ¼ö ÀÖ½À´Ï´Ù. ÀÎÁõ¼ ÆÄÀÏÀº ½Åû½Ã ±â·ÏÇÑ Email ÁÖ¼Ò¸¦ ÅëÇØ ÀÎÁõ¼¸¦ ÷ºÎÆÄÀÏ·Î ¼ö½ÅÇÏ°Ô µË´Ï´Ù. ¨ç ¹ß±ÞÀÎÁõ¼ ÷ºÎÈÀÏ È®ÀÎ ¸ÞÀÏ·Î ¹ÞÀº ÀÎÁõ¼ ÆÄÀÏÀÇ ¾ÐÃàÀ» ÇØÁ¦ÇϽøé ÀÎÁõ¼ ¹× CA µÎ°³ÀÇ ÆÄÀÏÀÌ È®ÀÎ ÇÏ½Ç ¼ö ÀÖ½À´Ï´Ù.
¨è ftp °èÁ¤»ý¼º ÀÎÁõ¼¸¦ ¼¹ö·Î ¾÷·ÎµåÇϱâÀ§ÇØ FTP °èÁ¤À» »ý¼ºÇÕ´Ï´Ù. ±âÁ¸ FTP °èÁ¤À» ÀÌ¿ëÇÏ¿©µµ ¹«¹æÇÕ´Ï´Ù. °èÁ¤»ý¼º [root@nextline ~]# useradd nextline °èÁ¤ Æнº¿öµå¼³Á¤ [root@nextline ~]# passwd nextline Changing password for user nextline. Æнº¿öµå ÀÔ·Â New UNIX password: Æнº¿öµå ÀçÀÔ·Â Retype new UNIX password: passwd: all authentication tokens updated successfully. ¨é ÀÎÁõ¼ ¾÷·Îµå FTP ÇÁ·Î±×·¥À» ÀÌ¿ëÇÏ¿© 4393142.crt, 4393142.ca-bundle ÆÄÀÏÀ» ¾÷·Îµå ÇÕ´Ï´Ù.
¨ê ÀÎÁõ¼ °æ·Î·Î ÀÎÁõÆÄÀÏ À̵¿ À§ ÆÄÀÏ Áß 4393142.crt ÆÄÀÏÀ» SSLCertificateFile °æ·Î·Î À̵¿ÇÕ´Ï´Ù. SSLCertificateFile /usr/local/apache/conf/ssl.crt/4393142.crt
4393142.ca-bundle ÆÄÀÏÀ» SSLCACertificateFile °æ·Î·Î À̵¿ÇÕ´Ï´Ù. SSLCACertificateFile /usr/local/apache/conf/ssl.crt/4393142.ca-bundle
À§¿¡¼ »ý¼ºÇÑ °³ÀÎÅ°(nextline.co.kr.key)¸¦ SSLCertificateKeyFile °æ·Î·Î À̵¿ÇÕ´Ï´Ù. SSLCertificateKeyFile /usr/local/apache/conf/ssl.key/nextline.co.kr.key
¨ë À¥¼¹ö ȯ°æ¼³Á¤ [root@nextline src]# vi /usr/local/apache/conf/httpd.conf
Apache 1.x + mod_ssl ¿¬µ¿ ¼³Ä¡½Ã ±âº»ÀûÀ¸·Î 80, 443Æ÷Æ®ÀÇ ¼³Á¤ºÎºÐÀÌ Ãß°¡µÇ¹Ç·Î Port 80 ºÎºÐÀ» ÁÖ¼®Ã³¸®ÇÏ¿© Àû¿ëµÇÁö ¾Êµµ·Ï ÇÕ´Ï´Ù. #Port 80 ÁÖ¼®Ã³¸® ÇÕ´Ï´Ù.
ÀÏ¹Ý http 80 Æ÷Æ® Á¢¼Ó VirtualHost ¼³Á¤ NameVirtualHost xxx.xxx.xxx.xxx:80
DocumentRoot /home/nextline/public_html ServerName nextline.co.kr
SSL VirtualHost ¼³Á¤ ¸ðµç º¸¾È °¡»ó È£½ºÆ®µéÀÇ ¼³Á¤Àº ¿Í Áö½ÃÀÚ »çÀÌ¿¡ Æ÷ÇԵǾî¾ß ÇÕ´Ï´Ù. NameVirtualHost xxx.xxx.xxx.xxx:443
DocumentRoot "/home/nextline/public_html" ServerName nextline.co.kr SSLCertificateFile /usr/local/apache/conf/ssl.crt/4393142.crt SSLCertificateKeyFile /usr/local/apache/conf/ssl.key/nextline.co.kr.key SSLCACertificateFile /usr/local/apache/conf/ssl.crt/4393142.ca-bundle
SSL Virtual Host Context ±âº»¼³Á¤
¾ÆÀÌÇÇ ¹× https ÇÁ·ÎÅäÄÝ Æ÷Æ®443 Æ÷Æ®ÀԷ¸¦ ÀÔ·ÂÇÕ´Ï´Ù.
º¸¾È¼¹ö µµ¸ÞÀÎÀÇ È¨µð·ºÅ丮¸¦ ÀÔ·ÂÇÕ´Ï´Ù. DocumentRoot "/home/nextline/public_html" µµ¸ÞÀÎÀ» ÀÔ·ÂÇÕ´Ï´Ù. ServerName nextline.co.kr SSL ¿£ÁøÀ» È°¼ºÈ ÇÕ´Ï´Ù SSLEngine on SSLCipherSuite ALL:!ADH:!EXPORT56:RC4+RSA:+HIGH:+MEDIUM:+LOW:+SSLv2:+EXP:+eNULL ÀÎÁõ¼ÀÇ °æ·Î¿Í ÆÄÀϸíÀ» ¸í½ÃÇÕ´Ï´Ù. SSLCertificateFile /usr/local/apache/conf/ssl.crt/4393142.crt °³ÀÎÅ° °æ·Î¿Í ÆÄÀϸíÀ» ¸í½ÃÇÕ´Ï´Ù. SSLCertificateKeyFile /usr/local/apache/conf/ssl.key/nextline.co.kr.key CA rootÀÎÁõ¼ °æ·Î¿Í ÆÄÀϸíÀ» ¸í½ÃÇÕ´Ï´Ù. SSLCACertificateFile /usr/local/apache/conf/ssl.crt/4393142.ca-bundle
SSLOptions +StdEnvVars
SSLOptions +StdEnvVars
BrowserMatch ".*MSIE.*" \ nokeepalive ssl-unclean-shutdown \ downgrade-1.0 force-response-1.0 CustomLog /usr/local/apache/logs/ssl_request_log \ "%t %h %{SSL_PROTOCOL}x %{SSL_CIPHER}x \"%r\" %b"
¨ì À¥¼¹ö Àç½ÇÇà À¥¼³Á¤ ÆÄÀÏÀÇ ¿À·ù°¡ ¾ø´ÂÁö üũ¸¦ ÇÕ´Ï´Ù. [root@nextline ~]# /usr/local/apache/bin/apachectl configtest Syntax OK [Á¤»ó] À¥¼³Á¤ ÆÄÀÏÀ» Àû¿ëÇϱâ À§ÇØ ¾ÆÆÄÄ¡¸¦ Àç°¡µ¿ÇÕ´Ï´Ù. [root@nextline ~]# /usr/local/apache/bin/apachectl startssl
¨ë À¥¼¹ö Æ÷Æ®Á¡°Ë [root@nextline ~]# netstat -anp | grep httpd httpd µ¥¸óÀÌ 80 / 443 Æ÷Æ®·Î ½ÇÇàµË´Ï´Ù.
¨ì À¥¼ºñ½º µ¿ÀÛ»óÅ Á¡°Ë https://nextline.co.kr ÆäÀÌÁö ÇÏ´ÜÀ» º¸½Ã¸é ¿¼è ¾ÆÀÌÄÜÀÌ º¸ÀÌ°Ô µË´Ï´Ù. ¾ÆÀÌÄÜÀ» Ŭ¸¯ÇÏ°Ô µÇ¸é À§¿Í °°ÀÌ ÀÎÁõ¼ Á¤º¸¸¦ È®ÀÎÇÏ½Ç ¼ö ÀÖ½À´Ï´Ù. ¨í ÀÎÁõ °æ·ÎÈ®ÀÎ
|
|