죄송합니다
다시 한번 질문올립니다
부디 한수 가르쳐주시면 정말 감사하겠습니다
리눅스의 매력에 빠져 있는 초보입니다
그럭저럭 이 기능 저기능 모두 구현해보고 있거든요
그런데 인증서버(CA라고 하나요?)를 도대체 어떻게 구현해야 하는지
정말 모르겠네요
Verisign같은데 CSR을 보내서 인증ID를 발급받아서 운영하는 방법 말고
[[[ 순전히 자체 테스트용 ]]] 으로 구현하는 방법을 알고싶어서요
도와주세요
$$$$$$$$$$$$
저의 목적은 http://ssl.nameip.net으로 접속하면 ssl기능이 구현되며
클라이언트의 브라우저에서 인증서를 설치하고 인증서ID를 발급받는겁니다
그런데 위주소로 접속하면
보안경고 팝업창이 나오면서
이사이트와 교환하는 정보는 다른사람이 보거나 변경할 수 없습니다
그러나 사이트보안인증서에 문제가 있습니다
- 신뢰여부를 결정한 적이 없는 회사에서 발급한 보안인증서입니다
인증기관의 신뢰여부를 결정하려면 인증서를 확인하십시요
- 보안 인증서가 만료되었거나 아직 유효하지 않습니다
- 보려는 페이지이름과 보안인증서가 일치합니다
계속하시겠습니까?
예(Y) 아니오(N) 인증서보기(V)
그래서 Y를 선택하면 사이트를 찾지 못하거든요
그래서
로그(/etc/httpd/logs/error_log)를 보면
[Tue Apr 24 11:09:01 2001] [notice] caught SIGTERM, shutting down
[Tue Apr 24 11:09:06 2001] [notice] Apache/1.3.14 (Unix) (Red-Hat/Linux) mod_ss
l/2.7.1 OpenSSL/0.9.5a DAV/1.0.1 PHP/4.0.3pl1 mod_perl/1.24 configured -- resuming normal operations
이렇게 기록되어 있구요
그래서 다시 인증서보기를 선택하면 인증서설치 마법사가 나타나고
마법사가 진행하는대로 인증서를 설치하고 다시 예(Y)를 선택하니까
제가 지정한 사이트의 내용이 나오면서 브라우져 하단에 자물쇠가
나타납니다
그런데 제가 원하는건 인터넷뱅킹등에 접속하면 인증서를 설치하겠습니까?
라고 물어오면서 설치를 하기 원하면 자기 패스워드등을 입력받잖습니까?
이런 기능을 원하는거랍니다
뭐가 잘못 설정되었는지 가르쳐 주시면 정말 감사하겠습니다
$$$$$$$$$$$$$
openssl명령을 써서 구현하는거 같던데
조각조각 나오는 정보만 가지고 구현하려니 막히고 마네요
혹시 CA서버를 이미 구축하신분이나 참조사이트를 아시는분 소개좀
해주지 않겠습니까?
체계적인 이해를 하고 싶어서요
너무 막연한 질문올려 죄송합니다
제가 아는게 없어서 요령있게 질문하기가 어렵네여
그럼....
다소 길더라도 제상황을 정확히 표현하려 한거라 양해바랍니다
참고로 저는 와우까치7.0 쓰구 있어요
제가 작업한 내용입니다
호스트는 www.nameip.net이구 버추얼호스트는 ssl.nameip.net이라고 정했다고
가정하고 읽어봐 주세요
1. openssl.cnf파일의 설정내용을 일부 수정해서 다음과 같이 고쳤습니다
======로 되어 있는 부분까지 입니다
====================================================================
HOME = .
RANDFILE = $ENV::HOME/.rnd
oid_section = new_oids
[ new_oids ]
[ ca ]
default_ca = CA_default # The default ca section
[ CA_default ]
dir = /root/ssl/MyCA # Where everything is kept
certs = $dir/certs # Where the issued certs are kept
crl_dir = $dir/crl # Where the issued crl are kept
database = $dir/index.txt # database index file.
new_certs_dir = $dir/newcerts # default place for new certs.
certificate = $dir/cacert.pem # The CA certificate
serial = $dir/serial # The current serial number
crl = $dir/crl.pem # The current CRL
private_key = $dir/private/cakey.pem # The private key
RANDFILE = $dir/private/.rand # private random number file
x509_extensions = usr_cert # The extentions to add to the cert
default_days = 365 # how long to certify for
default_crl_days= 30 # how long before next CRL
default_md = md5 # which md to use.
preserve = no # keep passed DN ordering
policy = policy_match
# For the CA policy
[ policy_match ]
countryName = match
stateOrProvinceName = match
organizationName = match
organizationalUnitName = optional
commonName = supplied
emailAddress = optional
[ policy_anything ]
countryName = optional
stateOrProvinceName = optional
localityName = optional
organizationName = optional
organizationalUnitName = optional
commonName = supplied
emailAddress = optional
[ req ]
default_bits = 1024
default_keyfile = privkey.pem
distinguished_name = req_distinguished_name
attributes = req_attributes
x509_extensions = v3_ca # The extentions to add to the self signed cert
string_mask = nombstr
[ req_distinguished_name ]
countryName = Country Name (2 letter code)
countryName_default = AU
countryName_min = 2
countryName_max = 2
stateOrProvinceName = State or Province Name (full name)
stateOrProvinceName_default = Some-State
localityName = Locality Name (eg, city)
0.organizationName = Organization Name (eg, company)
0.organizationName_default = Internet Widgits Pty Ltd
organizationalUnitName = Organizational Unit Name (eg, section)
commonName = Common Name (eg, your name or your server's h
ostname)
commonName_max = 64
emailAddress = Email Address
emailAddress_max = 40
[ req_attributes ]
challengePassword = A challenge password
challengePassword_min = 4
challengePassword_max = 20
unstructuredName = An optional company name
[ usr_cert ]
basicConstraints=CA:FALSE
nsCertType = server
###nsCertType = objsign
###nsCertType = client, email
### nsCertType = client, email, objsign
keyUsage = nonRepudiation, digitalSignature, keyEncipherment
nsComment = "OpenSSL Generated Certificate"
subjectKeyIdentifier=hash
authorityKeyIdentifier=keyid,issuer:always
[ v3_req ]
basicConstraints = CA:FALSE
keyUsage = nonRepudiation, digitalSignature, keyEncipherment
[ v3_ca ]
subjectKeyIdentifier=hash
authorityKeyIdentifier=keyid:always,issuer:always
basicConstraints = CA:true
keyUsage = cRLSign, keyCertSign
nsCertType = sslCA, emailCA
[ crl_ext ]
authorityKeyIdentifier=keyid:always,issuer:always
======================================================
1. 비밀키생성을 위해 랜덤화일을 생성했습니다
> openssl md5 * > /root/ssl/MyCA/private/.rand
2. 그리고 먼저 rootCA 생성했습니다
> openssl genrsa -des3 -out ca.key 1024
> openssl req -new -x509 -days 365 -key ca.key -out ca.crt
3. 다음에 Web Server의 RSA키를 생성했구요
> openssl genrsa -des3 -out ssl.nameip.net.key 1024
> openssl req -new -days 365 -key ssl.nameip.net.key -out ssl.nameip.net.csr
> openssl ca -in ssl.nameip.net.csr -out ssl.nameip.net.crt
4. 다음은 아파치 설정내용입니다
NameVirtualHost 211.117.24.205 ===> 제가 테스트할 당시 IP
Listen 443
ServerAdmin root at www.nameip.net DocumentRoot /home/aaa/public_html/ssl
ServerName ssl.nameip.net ===> 버추얼호스트 이름
ErrorLog logs/ssl.error_log
CustomLog logs/ssl.access_log common
SSLEngine on
SSLCertificateFile /root/ssl/ssl.nameip.net.crt
SSLCertificateKeyFile /root/ssl/ssl.nameip.net.key
SSLCACertificateFile /root/ssl/ca.crt
SSLOptions +StdEnvVars
SSLOptions +StdEnvVars
SetEnvIf User-Agent ".*MSIE.*" nokeepalive ssl-unclean-shutdown
CustomLog /var/log/httpd/ssl_request_log
"%t %h %{SSL_PROTOCOL}x %{SSL_CIPHER}x "%r" %b"
그리고 /etc/mime.types에 다음을 추가하였습니다
application/x-x509-ca-cert
application/x-x509-user-cert