Sun Java logo     ÀÌÀü      ¸ñÂ÷      »öÀÎ      ´ÙÀ½     

Sun logo
Sun Java System Portal Server Secure Remote Access 6 2005Q1 °ü¸® ¼³¸í¼­ 

13Àå
SSL °¡¼Ó±â ±¸¼º

ÀÌ Àå¿¡¼­´Â Sun Java¢â System Portal Server Secure Remote Access¿¡ ´Ù¾çÇÑ °¡¼Ó±â¸¦ ±¸¼ºÇÏ´Â ¹æ¹ýÀ» ¼³¸íÇÕ´Ï´Ù.

ÀÌ Àå¿¡¼­´Â ´ÙÀ½ ÁÖÁ¦¸¦ ´Ù·ì´Ï´Ù.


°³¿ä

¿ÜºÎ °¡¼Ó±â´Â ¼­¹ö CPUÀÇ SSL ±â´ÉÀ» ºÐ´ãÇÔÀ¸·Î½á CPU°¡ ´Ù¸¥ ÀÛ¾÷À» ¼öÇàÇϵµ·Ï ÇÏ¿© SSL Æ®·£Àè¼ÇÀÇ Ã³¸® ¼Óµµ¸¦ ³ôÀÌ´Â Àü¿ë Çϵå¿þ¾î º¸Á¶ ÇÁ·Î¼¼¼­ÀÔ´Ï´Ù.


Sun Crypto Accelerator 1000

Sun¢â Crypto Accelerator 1000 (Sun CA1000) º¸µå´Â ¾Ïȣȭ ÄÚÇÁ·Î¼¼¼­·Î ÀÛµ¿ÇÏ¿© °ø¿ë Å°¿Í ´ëĪ ¾Ïȣȭ¸¦ °¡¼ÓÈ­Çϴ ªÀº ÇüÅÂÀÇ PCI º¸µåÀÔ´Ï´Ù. ÀÌ Á¦Ç°¿¡´Â ¿ÜºÎ ÀÎÅÍÆäÀ̽º°¡ ¾ø½À´Ï´Ù. ÀÌ º¸µå´Â ³»ºÎ PCI ¹ö½º ÀÎÅÍÆäÀ̽º¸¦ ÅëÇØ È£½ºÆ®¿Í Åë½ÅÇÕ´Ï´Ù. ÀÌ º¸µå´Â eCommerce ÀÀ¿ë ÇÁ·Î±×·¥¿¡¼­ º¸¾È ÇÁ·ÎÅäÄÝÀ» À§ÇÑ ´Ù¾çÇÑ °è»ê Áý¾àÀû ¾Ïȣȭ ¾Ë°í¸®ÁòÀ» °¡¼ÓÈ­Çϱâ À§ÇÑ ¸ñÀûÀ¸·Î »ç¿ëµË´Ï´Ù.

RSA [7] ¹× Triple-DES (3DES) [8]¿Í °°Àº ´Ù¼öÀÇ ÇÙ½É ¾Ïȣȭ ±â´ÉÀ» ÀÀ¿ë ÇÁ·Î±×·¥¿¡¼­ Sun CA1000À¸·Î ºÐ´ã½ÃÄÑ º´·Ä·Î ¼öÇàÇÒ ¼ö ÀÖ½À´Ï´Ù. ±×·¯¸é CPU°¡ ÀÚÀ¯·Ó°Ô ´Ù¸¥ ÀÛ¾÷À» ¼öÇàÇÒ ¼ö ÀÖ¾î SSL Æ®·£Àè¼ÇÀÇ Ã³¸® ¼Óµµ°¡ Áõ°¡ÇÕ´Ï´Ù.

Crypto Accelerator 1000 »ç¿ë

Portal Server Secure Remote Access°¡ ¼³Ä¡µÇ¾î ÀÖ°í °ÔÀÌÆ®¿þÀÌ ¼­¹ö ÀÎÁõ¼­ (Á÷Á¢ ¼­¸í ¶Ç´Â CA¿¡¼­ ¹ßÇà) °¡ ¼³Ä¡µÇ¾ú´ÂÁö È®ÀÎÇÕ´Ï´Ù. ÀÚ¼¼ÇÑ ³»¿ëÀº 7Àå, "ÀÎÁõ¼­"¸¦ ÂüÁ¶ÇϽʽÿÀ.

Ç¥ 13-1¿¡¼­´Â SSL °¡¼Ó±â¸¦ ¼³Ä¡Çϱâ Àü¿¡ ÇÊ¿äÇÑ Á¤º¸¸¦ ÃßÀûÇÏ´Â ÀÏÀ» µ½´Â Á¡°Ë ¸ñ·ÏÀ̸ç Crypto Accelerator 1000 ¸Å°³ º¯¼ö¿Í °ªÀ» ³ª¿­ÇÕ´Ï´Ù.

Ç¥ 13-1  Crypto Accelerator 1000 ¼³Ä¡ Á¡°Ë ¸ñ·Ï

¸Å°³ º¯¼ö

°ª

SRA ¼³Ä¡ ±âº» µð·ºÅ丮

/opt

SRA ÀÎÁõ¼­ µ¥ÀÌÅͺ£À̽º °æ·Î

/etc/opt/SUNWps/cert/default

SRA ¼­¹ö ÀÎÁõ¼­ º°¸í

server-cert

¿µ¿ª

sra-keystore

¿µ¿ª »ç¿ëÀÚ

crypta

Crypto Accelerator 1000 ±¸¼º

    Crypto Accelerator 1000À» ±¸¼ºÇÏ·Á¸é
  1. »ç¿ë ¼³¸í¼­ÀÇ Áöħ¿¡ µû¶ó Çϵå¿þ¾î¸¦ ¼³Ä¡ÇÕ´Ï´Ù. ÂüÁ¶:
  2. http://www.sun.com/products-n-solutions/hardware/docs/pdf/816-2450-11.pdf

  3. CD¿¡¼­ ´ÙÀ½ ÆÐÅ°Áö¸¦ ¼³Ä¡ÇÕ´Ï´Ù.
  4. SUNWcrypm, SUNWcrypu, SUNWcrysu, SUNWdcar, SUNWcrypr, SUNWcrysl, SUNWdcamn, SUNWdcav

  5. ´ÙÀ½ ÆÐÄ¡¸¦ ¼³Ä¡ÇÕ´Ï´Ù. (http://sunsolve.sun.com¿¡¼­ ¾òÀ» ¼ö ÀÖ½À´Ï´Ù.)
  6. 110383-01, 108528-05, 112438-01

  7. pk12util ¹× modutil µµ±¸°¡ ÀÖ´ÂÁö È®ÀÎÇϽʽÿÀ.
  8. ÀÌ µµ±¸´Â /usr/sfw/bin ¾Æ·¡¿¡ ¼³Ä¡µË´Ï´Ù. /usf/sfw/bin µð·ºÅ丮¿¡ µµ±¸°¡ ¾ø´Â °æ¿ì¿¡´Â Sun Java System ¹èÆ÷ ¸Åü¿¡¼­ SUNWtlsu ÆÐÅ°Áö¸¦ ¼öµ¿À¸·Î Ãß°¡ÇØ¾ß ÇÕ´Ï´Ù.

    Solaris_[sparc/x86]/Product/shared_components/

  9. ½½·Ô ÆÄÀÏÀ» ¸¸µì´Ï´Ù.
  10. vi /etc/opt/SUNWconn/crypto/slots

    ±×¸®°í ÆÄÀÏÀÇ Ã³À½ÀÌÀÚ À¯ÀÏÇÑ ¶óÀÎÀ¸·Î "crypta@sra" ¸¦ ³Ö½À´Ï´Ù.

  11. ¿µ¿ªÀ» ¸¸µé°í ¼³Á¤ÇÕ´Ï´Ù.
    1. ·çÆ®·Î ·Î±×ÀÎÇÕ´Ï´Ù.
    2. ´ÙÀ½ ¸í·ÉÀ» ÀÔ·ÂÇÕ´Ï´Ù.
    3. cd /opt/SUNWconn/bin/secadm

      secadm> create realm=sra

      ¿µ¿ª sra°¡ ¼º°øÀûÀ¸·Î ¸¸µé¾îÁ³½À´Ï´Ù.

  12. »ç¿ëÀÚ¸¦ ¸¸µì´Ï´Ù.
    1. ´ÙÀ½ ¸í·ÉÀ» ÀÔ·ÂÇÏ°í ÀÀ´äÇÕ´Ï´Ù.
    2. secadm> set realm=sra

      secadm{srap}> su

      secadm{root@sra}>create user=crypta

      Initial password:

      Confirm password:

      User crypta created successfully.

  13. ¸¸µç »ç¿ëÀÚ·Î ·Î±×ÀÎÇÕ´Ï´Ù.
  14. secadm{root@sra}> login user=crypta

    Password:

    secadm{crypta@sra}> show key

    No keys exist for this user.

  15. Sun Crypto ¸ðµâÀ» ·ÎµåÇÕ´Ï´Ù.
  16. ȯ°æ º¯¼ö LD_LIBRARY_PATH´Â /usr/lib/mps/secv1/À» °¡¸®ÄÑ¾ß ÇÕ´Ï´Ù.

    À¯Çü:

    modutil -dbdir /etc/opt/SUNWps/cert/default -add "Sun Crypto Module" -libfile /opt/SUNWconn/crypto/lib/libpkcs11.so

    ´ÙÀ½ ¸í·ÉÀ» »ç¿ëÇÏ¿© ÀÌ ¸ðµâÀÌ ·ÎµåµÇ¾ú´ÂÁö È®ÀÎÇÕ´Ï´Ù.

    modutil -list -dbdir /etc/opt/SUNWps/cert /default

  17. °ÔÀÌÆ®¿þÀÌ ÀÎÁõ¼­¿Í Å°¸¦ "Sun Crypto Module"·Î ³»º¸³À´Ï´Ù.
  18. ȯ°æ º¯¼ö LD_LIBRARY_PATH´Â /usr/lib/mps/secv1/À» °¡¸®ÄÑ¾ß ÇÕ´Ï´Ù.

    À¯Çü:

    pk12util -o servercert.p12 -d /etc/opt/SUNWps/cert/default -n server-cert

    pk12util -i servercert.p12 -d /etc/opt/SUNWps/cert/default -h "crypta@sra"

    ÀÌÁ¦ show key ¸í·ÉÀ» ½ÇÇàÇÕ´Ï´Ù.

    secadm{crypta@sra}> show key

    ÀÌ »ç¿ëÀÚ¿¡°Ô 2°³ÀÇ Å°°¡ ³ªÅ¸³ª¾ß ÇÕ´Ï´Ù.

  19. /etc/opt/SUNWps/cert/default/.nickname ÆÄÀÏ¿¡¼­ º°¸íÀ» º¯°æÇÕ´Ï´Ù.
  20. vi /etc/opt/SUNWps/cert/default/.nickname

    server-cert¸¦ crypta@sra:server-cert·Î ±³Ã¼ÇÕ´Ï´Ù.

  21. °¡¼ÓÈ­¿ë ¾ÏÈ£¸¦ È°¼ºÈ­ÇÕ´Ï´Ù.
  22. SUN CA1000Àº RSA ±â´ÉÀ» °¡¼ÓÈ­ÇÏÁö¸¸ DES¿Í 3DES ¾ÏÈ£¿¡ ´ëÇÑ °¡¼Ó¸¸ Áö¿øÇÕ´Ï´Ù.

  23. °¡¼Ó±â¸¦ »ç¿ëÇϵµ·Ï /etc/opt/SUNWps/platform.conf.gateway-profile-nameÀ» ¼öÁ¤ÇÕ´Ï´Ù.
  24. gateway.enable.accelerator=true

  25. Å͹̳Πâ¿¡¼­ °ÔÀÌÆ®¿þÀ̸¦ ´Ù½Ã ½ÃÀÛÇÕ´Ï´Ù.
  26. portal-server-install-root/SUNWps/bin/gateway -n gateway-profile-name start


    Âü°í   

    °ÔÀÌÆ®¿þÀÌ´Â °ÔÀÌÆ®¿þÀÌ ÇÁ·ÎÇÊ¿¡¼­ https Æ÷Æ®·Î ¾ð±ÞµÈ Æ÷Æ®ÀÇ ÀÏ¹Ý ServerSocket (ºñ SSL) ¿¡ ¹ÙÀεùÇÕ´Ï´Ù.

    µé¾î¿À´Â Ŭ¶óÀ̾ðÆ® Æ®·¡ÇÈ¿¡ ´ëÇØ SSL ¾Ïȣȭ ¶Ç´Â ¾ÏÈ£ Çص¶ÀÌ ¼öÇàµÇÁö ¾Ê½À´Ï´Ù. °¡¼Ó±â¿¡¼­ ÀÌ ÀÛ¾÷À» ¼öÇàÇÕ´Ï´Ù.

    PDC´Â ÀÌ ¸ðµå¿¡¼­ ÀÛµ¿ÇÏÁö ¾Ê½À´Ï´Ù.



Sun Crypto Accelerator 4000

Sun¢â Crypto Accelerator 4000 º¸µå´Â Sun ¼­¹ö¿¡¼­ IPsec ¹× SSL (´ëĪ ¹× ºñ´ëĪ ¸ðµÎ) ¿¡ ´ëÇÑ ¾Ïȣȭ Çϵå¿þ¾î °¡¼ÓÀ» Áö¿øÇÏ´Â ±â°¡ºñÆ® ÀÌ´õ³Ý ±â¹Ý ³×Æ®¿öÅ© ÀÎÅÍÆäÀ̽º Ä«µåÀÔ´Ï´Ù.

¾ÏȣȭµÇÁö ¾ÊÀº ³×Æ®¿öÅ© Æ®·¡ÇÈÀ» À§ÇÑ Ç¥ÁØ ±â°¡ºñÆ® ÀÌ´õ³Ý ³×Æ®¿öÅ© Ä«µå·Î ÀÛµ¿ÇÏ´Â ¿Ü¿¡ ÀÌ º¸µå¿¡´Â ¾Ïȣȭ IPsec Æ®·¡ÇÈ¿¡ ³ôÀº ó¸® ¼Óµµ¸¦ Áö¿øÇÒ ¾ÏÈ£ Çϵå¿þ¾î°¡ Æ÷ÇԵǾî ÀÖ½À´Ï´Ù.

Crypto Accelerator 4000 º¸µå´Â Çϵå¿þ¾î¿Í ¼ÒÇÁÆ®¿þ¾î ¸ðµÎ¿¡¼­ ¾Ïȣȭ ¾Ë°í¸®ÁòÀ» °¡¼ÓÈ­ÇÕ´Ï´Ù. ¾ÏÈ£ DES ¹× 3DES¿¡ ´ëÇÑ ´ë·® ¾Ïȣȭµµ Áö¿øÇÕ´Ï´Ù.

Crypto Accelerator 4000 »ç¿ë

SRA°¡ ¼³Ä¡µÇ¾î ÀÖ°í °ÔÀÌÆ®¿þÀÌ ¼­¹ö ÀÎÁõ¼­ (Á÷Á¢ ¼­¸í ¶Ç´Â CA¿¡¼­ ¹ßÇà) °¡ ¼³Ä¡µÇ¾ú´ÂÁö È®ÀÎÇÕ´Ï´Ù. ´ÙÀ½ Á¡°Ë ¸ñ·ÏÀ¸·Î SSL °¡¼Ó±â¸¦ ¼³Ä¡Çϱâ Àü¿¡ ÇÊ¿äÇÑ Á¤º¸¸¦ ½±°Ô È®ÀÎÇÒ ¼ö ÀÖ½À´Ï´Ù.

Ç¥ 13-2¿¡ Crypto Accelerator 4000 ¸Å°³ º¯¼ö¿Í ±× °ªÀÌ ³ª¿­µÇ¾î ÀÖ½À´Ï´Ù.

Ç¥ 13-2  Crypto Accelerator 4000 ¼³Ä¡ Á¡°Ë ¸ñ·Ï

¸Å°³ º¯¼ö

°ª

Portal Server Secure Remote Access ¼³Ä¡ ±âº» µð·ºÅ丮

/opt

SRA ÀνºÅϽº

±âº»°ª

SRA ÀÎÁõ¼­ µ¥ÀÌÅͺ£À̽º °æ·Î

/etc/opt/SUNWps/cert/default

SRA ¼­¹ö ÀÎÁõ¼­ º°¸í

server-cert

CA4000 Å° ÀúÀå¼Ò

srap

CA4000 Å° ÀúÀå¼Ò »ç¿ëÀÚ

crypta

Crypto Accelerator 4000 ±¸¼º

    Crypto Accelerator 4000À» ±¸¼ºÇÏ·Á¸é
  1. »ç¿ë ¼³¸í¼­ÀÇ Áöħ¿¡ µû¶ó Çϵå¿þ¾î¿Í ¼ÒÇÁÆ®¿þ¾î ÆÐÅ°Áö¸¦ ¼³Ä¡ÇÕ´Ï´Ù. ÂüÁ¶:
  2. http://www.sun.com/products-n-solutions/hardware/docs/pdf/816-2450-11.pdf

  3. ´ÙÀ½ ÆÐÄ¡¸¦ ¼³Ä¡ÇÕ´Ï´Ù. (http://sunsolve.sun.com¿¡¼­ ¾òÀ» ¼ö ÀÖ½À´Ï´Ù.) 114795
  4. certutil, pk12util ¹× modutil µµ±¸°¡ ÀÖ´ÂÁö È®ÀÎÇϽʽÿÀ.
  5. ÀÌ µµ±¸´Â /usr/sfw/bin ¾Æ·¡¿¡ ¼³Ä¡µË´Ï´Ù.

    /usf/sfw/bin µð·ºÅ丮¿¡¼­ µµ±¸¸¦ »ç¿ëÇÒ ¼ö ¾ø´Â °æ¿ì¿¡´Â

    Sun Java System ¹èÆ÷ ¸Åü¿¡¼­ ¼öµ¿À¸·Î SUNWtlsu ÆÐÅ°Áö¸¦ Ãß°¡ÇØ¾ß ÇÕ´Ï´Ù.

    Solaris_[sparc/x86]/Product/shared_components/

  6. º¸µå¸¦ ÃʱâÈ­ÇÕ´Ï´Ù.
  7. /opt/SUNWconn/bin/vcadm µµ±¸¸¦ ½ÇÇàÇÏ¿© ¾Ïȣȭ º¸µå¸¦ ÃʱâÈ­ÇÏ°í ´ÙÀ½ °ªÀ» ¼³Á¤ÇÕ´Ï´Ù.

    Ãʱ⠺¸¾È °ü¸® À̸§: sec_officer

    Å° ÀúÀå¼Ò À̸§: sra-keystore

    FIPS 140-2 ¸ðµå¿¡¼­ ½ÇÇà: No

  8. »ç¿ëÀÚ¸¦ ¸¸µì´Ï´Ù.
  9. vcaadm{vca0@localhost, sec_officer}> create user

    »õ »ç¿ëÀÚ À̸§: crypta

    »õ »ç¿ëÀÚ ºñ¹Ð¹øÈ£ ÀÔ·Â:

    ºñ¹Ð¹øÈ£ È®ÀÎ:

    »ç¿ëÀÚ crypta°¡ ¼º°øÀûÀ¸·Î ¸¸µé¾îÁ³½À´Ï´Ù.

  10. Å° ÀúÀå¼Ò¿¡ ÅäÅ«À» ¸ÅÇÎÇÕ´Ï´Ù.
  11. vi /opt/SUNWconn/cryptov2/tokens

    ±×¸®°í ÆÄÀÏ¿¡ sra-keystore¸¦ Ãß°¡ÇÕ´Ï´Ù.

  12. ´ë·® ¾ÏȣȭÀÇ »ç¿ëÀ» ¼³Á¤ÇÕ´Ï´Ù.
  13. touch /opt/SUNWconn/cryptov2/sslreg

  14. Sun Crypto ¸ðµâÀ» ·ÎµåÇÕ´Ï´Ù.
  15. ȯ°æ º¯¼ö LD_LIBRARY_PATH´Â /usr/lib/mps/secv1/À» °¡¸®ÄÑ¾ß ÇÕ´Ï´Ù.

    À¯Çü:

    modutil -dbdir /etc/opt/SUNWps/cert/default -add "Sun Crypto Module" -libfile /opt/SUNWconn/cryptov2/lib/libvpkcs11.so

    ´ÙÀ½ ¸í·ÉÀ» »ç¿ëÇÏ¿© ÀÌ ¸ðµâÀÌ ·ÎµåµÇ¾ú´ÂÁö È®ÀÎÇÒ ¼ö ÀÖ½À´Ï´Ù.

    modutil -list -dbdir /etc/opt/SUNWps/cert /default

  16. °ÔÀÌÆ®¿þÀÌ ÀÎÁõ¼­¿Í Å°¸¦ "Sun Crypto Module"·Î ³»º¸³À´Ï´Ù.
  17. ȯ°æ º¯¼ö LD_LIBRARY_PATH´Â /usr/lib/mps/secv1/À» °¡¸®ÄÑ¾ß ÇÕ´Ï´Ù.

    pk12util -o servercert.p12 -d /etc/opt/SUNWps/cert/default -n server-cert

    pk12util -i servercert.p12 -d /etc/opt/SUNWps/cert/default -h "sra-keystore"

    ´ÙÀ½ ¸í·ÉÀ» »ç¿ëÇÏ¿© Å°°¡ ³»º¸³»Á³´ÂÁö È®ÀÎÇÒ ¼ö ÀÖ½À´Ï´Ù.

    certutil -K -h "sra-keystore" -d /etc/opt/SUNWps/cert/default

  18. /etc/opt/SUNWps/cert/default/.nickname ÆÄÀÏ¿¡¼­ º°¸íÀ» º¯°æÇÕ´Ï´Ù.
  19. vi /etc/opt/SUNWps/cert/default/.nickname

    server-cert¸¦ sra-keystore:server-cert·Î ±³Ã¼ÇÕ´Ï´Ù.

  20. °¡¼ÓÈ­¿ë ¾ÏÈ£¸¦ È°¼ºÈ­ÇÕ´Ï´Ù.
  21. ÀÚ¼¼ÇÑ ³»¿ëÀº SSL ¾ÏÈ£ ¼±Åà »ç¿ë¸¦ ÂüÁ¶ÇϽʽÿÀ.

  22. Å͹̳Πâ¿¡¼­ °ÔÀÌÆ®¿þÀ̸¦ ´Ù½Ã ½ÃÀÛÇÕ´Ï´Ù.
  23. portal-server-install-root/SUNWps/bin/gateway -n gateway-profile-name start

    Å° ÀúÀå¼Ò ºñ¹Ð¹øÈ£¸¦ ÀÔ·ÂÇ϶ó´Â °ÔÀÌÆ®¿þÀÌ ÇÁ·ÒÇÁÆ®°¡ Ç¥½ÃµË´Ï´Ù.

    "sra-keystore":crypta:crytpa-password¿¡ ´ëÇÑ ºñ¹Ð¹øÈ£ ¶Ç´Â PINÀ» ÀÔ·ÂÇÕ´Ï´Ù.


    Âü°í   

    °ÔÀÌÆ®¿þÀÌ´Â °ÔÀÌÆ®¿þÀÌ ÇÁ·ÎÇÊ¿¡¼­ https Æ÷Æ®·Î ¾ð±ÞµÈ Æ÷Æ®ÀÇ ÀÏ¹Ý ServerSocket (ºñ SSL) ¿¡ ¹ÙÀεùÇÕ´Ï´Ù.

    µé¾î¿À´Â Ŭ¶óÀ̾ðÆ® Æ®·¡ÇÈ¿¡ ´ëÇØ SSL ¾Ïȣȭ ¶Ç´Â ¾ÏÈ£ Çص¶ÀÌ ¼öÇàµÇÁö ¾Ê½À´Ï´Ù. °¡¼Ó±â¿¡¼­ ÀÌ ÀÛ¾÷À» ¼öÇàÇÕ´Ï´Ù.

    PDC´Â ÀÌ ¸ðµå¿¡¼­ ÀÛµ¿ÇÏÁö ¾Ê½À´Ï´Ù.



¿ÜºÎ SSL ÀåÄ¡ ¹× ÇÁ·Ï½Ã °¡¼Ó±â

¿­¸° ¸ðµå¿¡¼­ ¿ÜºÎ SSL ÀåÄ¡¸¦ Secure Remote Access (SRA) Àü¹æ¿¡¼­ ½ÇÇàÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ ÀåÄ¡´Â Ŭ¶óÀ̾ðÆ®¿Í SRA »çÀÌ¿¡ SSL ¸µÅ©¸¦ Á¦°øÇÕ´Ï´Ù.

¿ÜºÎ SSL ÀåÄ¡ °¡¼Ó±â »ç¿ë

    ¿ÜºÎ SSL ÀåÄ¡ °¡¼Ó±â »ç¿ë
  1. SRA°¡ ¼³Ä¡µÇ¾î ÀÖ°í °ÔÀÌÆ®¿þÀÌ°¡ ¿­¸° ¸ðµå (HTTP ¸ðµå) ¿¡¼­ ½ÇÇàµÇ´ÂÁö È®ÀÎÇÕ´Ï´Ù.
  2. HTTP ¿¬°áÀ» »ç¿ëÇÕ´Ï´Ù. HTTP ±âº» ÀÎÁõ »ç¿ë¸¦ ÂüÁ¶ÇϽʽÿÀ.

Ç¥ 13-3Àº ¿ÜºÎ SSL ÀåÄ¡¿Í ÇÁ·Ï½Ã °¡¼Ó±â ¸Å°³ º¯¼ö ¹× °ªÀ» ³ªÅ¸³À´Ï´Ù.

Ç¥ 13-3  ¿ÜºÎ SSL ÀåÄ¡ ¹× ÇÁ·Ï½Ã °¡¼Ó±â Á¡°Ë ¸ñ·Ï

¸Å°³ º¯¼ö

°ª

SRA ÀνºÅϽº

±âº»°ª

°ÔÀÌÆ®¿þÀÌ ¸ðµå

http

°ÔÀÌÆ®¿þÀÌ Æ÷Æ®

880

¿ÜºÎ ÀåÄ¡/ÇÁ·Ï½Ã Æ÷Æ®

443

¿ÜºÎ SSL ÀåÄ¡ °¡¼Ó±â ±¸¼º

    ¿ÜºÎ SSL ÀåÄ¡ °¡¼Ó±â¸¦ ±¸¼ºÇÏ·Á¸é
  1. »ç¿ë ¼³¸í¼­ÀÇ Áöħ¿¡ µû¶ó Çϵå¿þ¾î¿Í ¼ÒÇÁÆ®¿þ¾î ÆÐÅ°Áö¸¦ ¼³Ä¡ÇÕ´Ï´Ù.
  2. ÇØ´çÇÏ´Â °æ¿ì ÇÊ¿äÇÑ ÆÐÄ¡¸¦ ¼³Ä¡ÇÕ´Ï´Ù.
  3. HTTP¸¦ »ç¿ëÇϵµ·Ï °ÔÀÌÆ®¿þÀÌ ÀνºÅϽº¸¦ ±¸¼ºÇÕ´Ï´Ù.
  4. platform.conf ÆÄÀÏ¿¡ ´ÙÀ½ °ªÀ» ÀÔ·ÂÇÕ´Ï´Ù.
  5. gateway.enable.customurl=true

    gateway.enable.accelerator=true

    gateway.httpurl=https://external-device-URL:port-number

  6. µÎ °¡Áö ¹æ¹ýÀ¸·Î °ÔÀÌÆ®¿þÀÌ ¾Ë¸²À» ±¸¼ºÇÒ ¼ö ÀÖ½À´Ï´Ù.
    • Access Manager°¡ Æ÷Æ® 880¿¡¼­ °ÔÀÌÆ®¿þÀÌ ÄÄÇ»ÅÍ¿Í Á¢¼ÓÇÒ ¼ö ÀÖ´Â °æ¿ì (HTTP·Î ¼¼¼Ç ¾Ë¸²) platform.conf ÆÄÀÏ¿¡ °ªÀ» ÀÔ·ÂÇÕ´Ï´Ù.

      vi /etc/opt/SUNWps/platform.conf.default

      gateway.protocol=http

      gateway.port=880

    • Access Manager°¡ Æ÷Æ® 443¿¡¼­ ¿ÜºÎ ÀåÄ¡/ÇÁ·Ï½Ã¿Í Á¢¼ÓÇÒ ¼ö ÀÖ´Â °æ¿ì (HTTPS ¼¼¼Ç ¾Ë¸²) platform.conf ÆÄÀÏ¿¡ °ªÀ» ÀÔ·ÂÇÕ´Ï´Ù.

      vi /etc/opt/SUNWps/platform.conf.default

      gateway.host=External Device/Proxy Host Name

      gateway.protocol=https

      gateway.port=443

  7. SSL ÀåÄ¡/ÇÁ·Ï½Ã°¡ ÀÛµ¿ÇÏ°í ÀÖÀ¸¸ç °ÔÀÌÆ®¿þÀÌ Æ÷Æ®·Î Æ®·¡ÇÈÀ» ³Ñ±âµµ·Ï ±¸¼ºµÇ¾î ÀÖ´ÂÁö È®ÀÎÇÕ´Ï´Ù.
  8. Å͹̳Πâ¿¡¼­ °ÔÀÌÆ®¿þÀ̸¦ ´Ù½Ã ½ÃÀÛÇÕ´Ï´Ù.
  9. gateway-install-root/SUNWps/bin/gateway -n gateway-profile-name start



ÀÌÀü      ¸ñÂ÷      »öÀÎ      ´ÙÀ½     


ºÎÇ° ¹øÈ£: 819-4615.   ÀúÀÛ±Ç 2005 Sun Microsystems, Inc. ¸ðµç ±Ç¸®´Â ÀúÀÛ±ÇÀÚÀÇ ¼ÒÀ¯ÀÔ´Ï´Ù.