Building a Secure RedHat Apache Server HOWTO

Sigle Richard

richard.sigle@equifax.com

¼­Á¤·æ

s_ryong@hotmail.com

¿µ¹® ¹öÀü : 0.1 2001-02-6

ÃÖÁ¾¼öÁ¤ÀÏ : 0.1 2001³â 3¿ù 19ÀÏ


차례
1. ÁöħÀÇ ¸ñÀû/¹üÀ§
1.1. Secure Sockets Layer (SSL)¿¡ ´ëÇØ
1.2. Çǵå¹é
1.3. Copyrights and Trademarks
1.4. Acknowledgements and Thanks
2. Secure Sockets Layer/Private Key Infrastructure ¼Ò°³
2.1. SSL/PKIÀÇ Ã¥ÀÓ
2.2. ¾î¶»°Ô SSLÀÌ ÀÛµ¿Çϴ°¡
2.3. ¾î¶»°Ô PKI°¡ ÀÛµ¿Çϴ°¡
2.4. ÀÎÁõ¼­(x509 Standard)
2.5. µðÁöÅÐ ÀÎÁõ¼­ ºñ¹ÐŰ
2.6. µðÁöÅÐ ÀÎÁõ¼­ °ø°³Å°
2.7. ÀÎÁõ¼­ ¼­¸í ¿äû(Certificate Signing Request,CSR)
3. ÀÎÁõ¼­ °ü·Ã ÀÛ¾÷
3.1. ºñ¹ÐŰ »ý¼ºÇϱâ
3.2. CSR »ý¼ºÇϱâ
3.3. ÀÚÇÊ ¼­¸í ÀÎÁõ¼­ »ý¼ºÇϱâ
3.4. À¥¼­¹ö ÀÎÁõ¼­ ¼³Ä¡Çϱâ
4. ¾ÆÆÄÄ¡ ¼­¹ö ¼³Á¤Çϱâ
9
4.1. º¸¾È °¡»ó È£½ºÆ® Á¤ÀÇÇϱâ
4.2. ÀÎÁõ¼­ ¿¹
4.3. À¥ ¼­¹ö À籸µ¿Çϱâ
5. ¹®Á¦Çذá
5.1. ¼­¹ö´Â ±¸µ¿µÈ µí Çѵ¥, º¸¾È »çÀÌÆ®¿¡ ¾×¼¼½º ÇÒ ¼ö ¾ø´Ù(Server Appears to start, but you cannot access the secure site).
5.2. Ŭ¶óÀÌ¾ðÆ® ºê¶ó¿ìÀú¿¡¼­ ÀÎÁõ¼­ À̸§ üũ °æ°í°¡ ³ªÅ¸³­´Ù(Certificate Name Check Warning is issued by the client's browser).
5.3. Ŭ¶óÀÌ¾ðÆ® À¥ºê¶ó¿ìÀú°¡ "ÀÎÁõ¼­°¡ ½Å·ÚµÇÁö ¾Ê´Â CA¿¡ ÀÇÇØ ¼­¸íµÇ¾ú´Ù"¶ó´Â °æ°í¸¦ ³ªÅ¸³½´Ù(Certificate was Signed by an Untrusted Certificate Authority Warning is issued by the client's browser).
5.4. ¾ÆÆÄÄ¡¸¦ ±¸µ¿ÇÒ ¶§ SSLEngine on ÀÌ ÀνĵÇÁö ¾Ê´Â ¸í·É¾îÀÌ´Ù(SSLEngine on is an un-recognized command (when starting Apache)).
5.5. PEM passphrase¸¦ Àؾú´Âµ¥ À̸¦ Àç¼³Á¤ÇÏ´Â ¹æ¹ýÀ» ¾Ë°í ½Í´Ù(You have forgotten your "PEM Passphrase" and you would like to know how to reset it).
6. ¿ë¾î ÇØ¼³
2

ÀÌ ÁöħÀº PKI¿Í SSLÀÌ ÇÔ²² ÀÛµ¿ÇÏ´Â ¹æ¹ýÀ» ¼³¸íÇϱâ À§ÇÑ °ÍÀ¸·Î º¸¾È ¼­¹ö¸¦ ¼º°øÀûÀ¸·Î ¼³Ä¡Çϱâ À§Çؼ­´Â SSL ÇÁ·ÎÅäÄÝÀÇ ÀÛµ¿ ¿ø¸®¸¦ ÀÌÇØÇÏ´Â °ÍÀÌ ÇʼöÀûÀÌ´Ù.

1. ÁöħÀÇ ¸ñÀû/¹üÀ§

ÀÌ ÁöħÀÇ ¸ñÀûÀº ·¹µåÇÞ ¸®´ª½º »ç¿ëÀڵ鿡°Ô ¾ÆÆÄÄ¡ À¥¼­¹ö¸¦ »ç¿ëÇØ ¼­¹ö (SSL) ÀÎÁõ¼­¸¦ ¼³Ä¡Çϴµ¥ ÀÖ¾î µµ¿òÀ» ÁÖ±â À§ÇÑ °ÍÀ¸·Î ½Ã°£»Ó¸¸¾Æ´Ï¶ó ¸¹Àº °æ¿ì ºñ¿ëÀ» Àý¾àÇÒ ¼ö ÀÖ´Â ¸í¹éÇÑ ÀýÂ÷¸¦ Á¦°øÇÏ´Â °ÍÀÌ´Ù.

¿ì¼± SSL ÇÁ·ÎÅäÄݰú µðÁöÅÐ ÀÎÁõ¼­(digital certificate)¿¡ °üÇØ ¾Ë¾Æ¾ß ÇÒ »çÇ×À» ´Ù·ê °ÍÀε¥ ÀúÀÚÀÇ °æÇè¿¡ ºñÃ߸é ModSSL ¹× OpenSSL°ú ÇÔ²² ¾ÆÆÄÄ¡ À¥¼­¹ö¸¦ ±¸ÃàÇÏ´Â °ÍÀÌ °¡Àå À¯ÀÍÇÏ´Ù. OpenSSLÀº SSL v2/v3¿Í TLS v1 ÇÁ·ÎÅäÄÝÀ» Áö¿øÇÏ´Â ¹ü¿ë ¾ÏÈ£¹ý ¶óÀ̺귯¸®À̰í ModSSLÀº ¾ÆÆÄÄ¡¿Í OpenSSL»çÀÌÀÇ ÀÎÅÍÆäÀ̽º·Î ÀÛ¿ëÇϵµ·Ï ¼³°èµÈ ¾ÆÆÄÄ¡ API ¸ðµâÀÌ´Ù. ¹°·Ð °¡Àå Å« ÀåÁ¡Àº ¼¼°¡Áö ¼ÒÇÁÆ®¿þ¾î ÆÐŰÁö ¸ðµÎ 'free"¶ó´Â °ÍÀÌ´Ù.

4.1ÀýºÎÅÍ ½ÃÀÛÇÏ¿© ModSSL°ú OpenSSL°ú ÇÔ²² ÄÄÆÄÀÏµÈ ·¹µåÇÞ ¾ÆÆÄÄ¡ ¼­¹ö¿¡ Ű »ý¼º ¹× ÀÎÁõ¼­ ¼³Ä¡ÀÇ ´Ü°èÀû ÀýÂ÷¸¦ ÀÚ¼¼È÷ °ËÅäÇÒ °ÍÀÌ´Ù. 4ÀýÀÇ ÀýÂ÷´Â ¾ÆÆÄÄ¡¿Í ¹ÐÁ¢ÇÏ°Ô °ü·ÃµÈ Stronghold¿Í Raven°ú °°Àº »ó¿ë SSL-¼­¹ö ÆÐŰÁö¿¡¼­µµ ¶ÇÇÑ ÀÛ¿ëÇÒ °ÍÀÌ´Ù.

Disclaimer: I am a technical support engineer for Equifax Secure Inc., a Certificate Authority. Therefore, I use Equifax Secure certificates and examples geared towards installing Equifax Secure certificates. However, the instructions will also work with certificates issued by other Certificate Authorities. Since this document was written at my own initiative, Equifax Secure Inc. is neither liable nor accountable for any consequences resulting from the use of these procedures.

My comments to the reader is in this style (emphasized).

Example lines are in plain roman style.

Note that extra comments and advice is found in comments within the SGML source.

1.1. Secure Sockets Layer (SSL)¿¡ ´ëÇØ

SSLÀº TCP¿Í ¾ÖÇø®ÄÉÀÌ¼Ç °èÃþ »çÀÌ¿¡ Á¸ÀçÇÏ´Â presentation °èÃþ ¼­ºñ½º (OSI 7 °èÃþ)·Î Ç÷§Æû°ú ¾ÖÇø®ÄÉÀ̼ǿ¡ µ¶¸³ÀûÀÌ´Ù. SSLÀº Ŭ¶óÀÌ¾ðÆ®¿Í ¼­¹ö»çÀÌÀÇ ¾ÈÀüÇÑ Åë½Å ä³Î °ü¸®¸¦ ´ã´çÇϸç ÀÌµé »çÀÌ¿¡ Àü´ÞµÇ´Â µ¥ÀÌÅ͸¦ ¾ÏÈ£Çϴµ¥ ÀÖ¾î °­·ÂÇÑ ±â±¸¸¦ Á¦°øÇÑ´Ù.

1.2. Çǵå¹é

ÀÌ Áöħ¿¡ ´ëÇÑ ÀǰßÀ» ÀúÀÚ¿¡°Ô º¸³»Áֱ⠹ٶõ´Ù (richard.sigle@equifax.com).

1.3. Copyrights and Trademarks

Copyright (c) 2001 by Richard L. Sigle

Please freely copy and distribute this document in any format. It's requested that corrections and/or comments be forwarded to the document maintainer. You may create a derivative work and distribute it provided that you:

  • Send your derivative work (in the most suitable format such as sgml) to the LDP (Linux Documentation Project) or the like for posting on the Internet. If not the LDP, then let the LDP know where it is available.

  • License the derivative work with this same license or use GPL. Include a copyright notice and at least a pointer to the license used.

  • Give due credit to previous authors and major contributors.

If you're considering making a derived work other than a translation, it's requested that you discuss your plans with the current maintainer.

1.4. Acknowledgements and Thanks

I would like to thank Tony Villasenor for tirelessly reading my drafts and offering his input and advice. Without Tony, this document would never have been finished.