Sun ·Î°í      ÀÌÀü      ¸ñÂ÷      »öÀÎ      ´ÙÀ½     

Sun ONE Calendar Server 6.0 °ü¸®ÀÚ ¼³¸í¼­

9Àå
Calendar Server¿¡¼­ÀÇ SSL »ç¿ë

Sun ONE Calendar Server 6.0Àº ´Þ·Â Ŭ¶óÀÌ¾ðÆ® ÃÖÁ¾ »ç¿ëÀÚ¿Í Calendar Server°£ÀÇ µ¥ÀÌÅÍ ¾Ïȣȭ¸¦ À§ÇØ SSL (Secure Sockets Layer) ÇÁ·ÎÅäÄÝÀ» Áö¿øÇÕ´Ï´Ù. SSLÀ» Áö¿øÇϱâ À§ÇØ Calendar Server´Â Netscape Security Services (NSS)ÀÇ SSL ¶óÀ̺귯¸®¸¦ »ç¿ëÇϸç, Sun ONE Messaging Server¿¡¼­µµ ÀÌ ¶óÀ̺귯¸®¸¦ »ç¿ëÇÕ´Ï´Ù.

Calendar Server ·Î±×ÀÎ ¹× ºñ¹Ð¹øÈ£¸¸ ¾ÏȣȭÇϰųª Àüü ´Þ·Â ¼¼¼ÇÀ» ¾ÏȣȭÇϵµ·Ï ics.conf ÆÄÀÏ¿¡¼­ Calendar Server¸¦ ±¸¼ºÇÒ ¼ö ÀÖ½À´Ï´Ù.

ÀÌ ÀåÀº ´ÙÀ½ ³»¿ëÀ¸·Î ±¸¼ºµÇ¾î ÀÖ½À´Ï´Ù.

 


Calendar Server¿¡ ´ëÇØ SSL ±¸¼º

Calendar Server SSL ±¸¼ºÀº µ¶¸³ÀûÀ̸ç Delegated Administrator°¡ ÇÊ¿äÇÏÁö ¾Ê½À´Ï´Ù.

Calendar ServerÀÇ SSLÀ» ±¸¼ºÇÏ·Á¸é ´ÙÀ½ ´Ü°è¸¦ ¼öÇàÇÕ´Ï´Ù.

 

SSL ÀÎÁõ¼­ µ¥ÀÌÅͺ£À̽º ¸¸µé±â

Calendar Server¸¦ À§ÇØ SSLÀ» ±¸ÇöÇÏ·Á¸é ÀÎÁõ¼­ µ¥ÀÌÅͺ£À̽º°¡ ÇÊ¿äÇÕ´Ï´Ù. ÀÎÁõ¼­ µ¥ÀÌÅͺ£À̽º´Â ÀÎÁõ ±â°ü(CA) ¹× Calendar Server¿ë ÀÎÁõ¼­¸¦ Á¤ÀÇÇØ¾ß ÇÕ´Ï´Ù.

Mozilla µµ±¸

À̹ø ¸±¸®½º¿¡´Â ´ÙÀ½ Mozilla µµ±¸°¡ Æ÷ÇԵǾî ÀÖ½À´Ï´Ù.

ÀÌ À¯Æ¿¸®Æ¼´Â ´ÙÀ½ µð·ºÅ丮¿¡¼­ »ç¿ëÇÒ ¼ö ÀÖ½À´Ï´Ù.

/opt/SUNWics5/cal/bin

 

¶óÀ̺귯¸® °æ·Î º¯¼ö

Mozilla µµ±¸¸¦ »ç¿ëÇϱâ Àü¿¡ LD_LIBRARY_PATH º¯¼ö¸¦ ¿Ã¹Ù¸£°Ô ¼³Á¤ÇÕ´Ï´Ù. ¿¹¸¦ µé¸é ´ÙÀ½°ú °°½À´Ï´Ù.

setenv LD_LIBRARY_PATH /opt/SUNWics5/cal/lib

ÆÄÀÏ ¹× µð·ºÅ丮 ¿¹

À̹ø ÀåÀÇ ¿¹¿¡¼­´Â ´ÙÀ½ ÆÄÀϰú µð·ºÅ丮¸¦ »ç¿ëÇÕ´Ï´Ù.

 

ÀÎÁõ¼­ µ¥ÀÌÅͺ£À̽º¸¦ ¸¸µå´Â ¹æ¹ý

  1. ¼öÆÛÀ¯Àú(root)·Î ·Î±×ÀÎÇÕ´Ï´Ù.
  2. certutilÀÇ ÀÎÁõ¼­ µ¥ÀÌÅͺ£À̽º ºñ¹Ð¹øÈ£¸¦ /etc/opt/SUNWics5/config/sslPasswordFile¿¡ ÁöÁ¤ÇÕ´Ï´Ù. ¿¹¸¦ µé¸é ´ÙÀ½°ú °°½À´Ï´Ù.
  3. # echo "password"
    > /etc/opt/SUNWics5/config/sslPasswordFile

    ¿©±â¼­ password´Â °íÀ¯ ºñ¹Ð¹øÈ£ÀÔ´Ï´Ù.

  4. ÀÎÁõ¼­ µ¥ÀÌÅͺ£À̽º alias µð·ºÅ丮¸¦ ¸¸µì´Ï´Ù. ¿¹¸¦ µé¸é ´ÙÀ½°ú °°½À´Ï´Ù.
  5. # cd /var/opt/SUNWics5
    # mkdir alias   

  6. bin µð·ºÅ丮·Î À̵¿Çϰí ÀÎÁõ¼­ µ¥ÀÌÅͺ£À̽º(cert7.db)¿Í Ű µ¥ÀÌÅͺ£À̽º(key3.db)¸¦ ¸¸µì´Ï´Ù. ¿¹¸¦ µé¸é ´ÙÀ½°ú °°½À´Ï´Ù.
  7. # cd /opt/SUNWics5/cal/bin
    # ./certutil -N -d /var/opt/SUNWics5/alias
    -f /etc/opt/SUNWics5/config/sslPasswordFile

  8. ÀÚü ¼­¸íµÈ ±âº» ·çÆ® ÀÎÁõ ±â°ü ÀÎÁõ¼­¸¦ »ý¼ºÇÕ´Ï´Ù. ¿¹¸¦ µé¸é ´ÙÀ½°ú °°½À´Ï´Ù.
  9. # ./certutil -S -n SampleRootCA -x -t "CTu,CTu,CTu"
    -s "CN=My Sample Root CA, O=sesta.com" -m 25000
    -o /var/opt/SUNWics5/alias/SampleRootCA.crt
    -d /var/opt/SUNWics5/alias
    -f /etc/opt/SUNWics5/config/sslPasswordFile -z
    /etc/passwd

  10. È£½ºÆ®¸¦ À§ÇÑ ÀÎÁõ¼­¸¦ »ý¼ºÇÕ´Ï´Ù. ¿¹¸¦ µé¸é ´ÙÀ½°ú °°½À´Ï´Ù.
  11. # ./certutil -S -n SampleSSLServerCert -c SampleRootCA -t "u,u,u"
    -s "CN=hostname.sesta.com, O=sesta.com" -m 25001
    -o /var/opt/SUNWics5/alias/SampleSSLServer.crt
    -d /var/opt/SUNWics5/alias -f /etc/opt/SUNWics5/config/sslPasswordFile
    -z /etc/passwd

    ¿©±â¼­ hostname.sesta.comÀº ¼­¹ö È£½ºÆ® À̸§ÀÔ´Ï´Ù.

  12. ÀÎÁõ¼­¸¦ °ËÁõÇÕ´Ï´Ù. ¿¹¸¦ µé¸é ´ÙÀ½°ú °°½À´Ï´Ù.
  13. # ./certutil -V -u V -n SampleRootCA -d /var/opt/SUNWics5/alias
    # ./certutil -V -u V -n SampleSSLServerCert -d /var/opt/SUNWics5/alias

  14. ÀÎÁõ¼­¸¦ ³ª¿­ÇÕ´Ï´Ù. ¿¹¸¦ µé¸é ´ÙÀ½°ú °°½À´Ï´Ù.
  15. # ./certutil -L -d /var/opt/SUNWics5/alias
    # ./certutil -L -n SampleSSLServerCert -d /var/opt/SUNWics5/alias

  16. modutilÀ» ÅëÇØ »ç¿ë °¡´ÉÇÑ º¸¾È ¸ðµâÀ» ³ª¿­ÇÕ´Ï´Ù(secmod.db). ¿¹¸¦ µé¸é ´ÙÀ½°ú °°½À´Ï´Ù.
  17. # ./modutil -list -dbdir /var/opt/SUNWics5/alias

  18. alias ÆÄÀÏÀÇ ¼ÒÀ¯ÀÚ¸¦ icsuser ¹× icsgroup(¶Ç´Â Calendar Server¸¦ ½ÇÇàÇÒ »ç¿ëÀÚ ¹× ±×·ì ¾ÆÀ̵ð)À¸·Î º¯°æÇÕ´Ï´Ù. ¿¹¸¦ µé¸é ´ÙÀ½°ú °°½À´Ï´Ù.
  19. # find /var/opt/SUNWics5/alias -exec chown icsuser {} \;
    # find /var/opt/SUNWics5/alias -exec chgrp icsgroup {} \;

 

·çÆ® ÀÎÁõ ±â°ü(CA)¿¡ ÀÎÁõ¼­ ¿äû ¹× °¡Á®¿À±â

´ÙÀ½ ´Ü°è¿¡¼­´Â ÀÎÁõ¼­ ¿äûÀ» »ý¼ºÇϰí À̸¦ PKI (Public Key Infrastructure) À¥ »çÀÌÆ®¿¡ Á¦ÃâÇÏ°í ³ª¼­ ÇØ´ç ÀÎÁõ¼­¸¦ °¡Á®¿É´Ï´Ù.

·çÆ® ÀÎÁõ ±â°ü¿¡ ÀÎÁõ¼­¸¦ ¿äûÇÏ°í °¡Á®¿À´Â ¹æ¹ý

  1. ¼öÆÛÀ¯Àú(root)·Î ·Î±×ÀÎÇÕ´Ï´Ù.
  2. bin µð·ºÅ丮·Î À̵¿ÇÕ´Ï´Ù.
  3. # cd /opt/SUNWics5/cal/bin

  4. certutilÀ» »ç¿ëÇÏ¿© ÀÎÁõ ±â°üÀ̳ª PKI (Public Key Infrastructure) À¥ »çÀÌÆ®¸¦ ±â¹ÝÀ¸·Î ÀÎÁõ¼­ ¿äûÀ» ¸¸µì´Ï´Ù. ¿¹¸¦ µé¸é ´ÙÀ½°ú °°½À´Ï´Ù.
  5. # ./certutil -R -s "CN=hostname.sesta.com, OU=hostname / SSL Web Server, O=Sesta C=US" -p "408-555-1234" -o hostnameCert.req -g 1024
    -d /var/opt/SUNWics5/alias
    -f /etc/opt/SUNWics5/config/sslPasswordFile
    -z /etc/passwd -a

    ¿©±â¼­ hostname.sesta.com Àº È£½ºÆ® À̸§ÀÔ´Ï´Ù.

  6. ÀÎÁõ ±â°üÀ̳ª PKI (Public Key Infrastructure) À¥ »çÀÌÆ®¿¡ SSL À¥ ¼­¹ö¿¡ ´ëÇÑ Å×½ºÆ® ÀÎÁõ¼­¸¦ ¿äûÇÕ´Ï´Ù. hostnameCert.req ÆÄÀÏÀÇ ³»¿ëÀ» º¹»çÇÏ¿© ÀÎÁõ¼­ ¿äû¿¡ ºÙÀÔ´Ï´Ù.
  7. ÀÎÁõ¼­°¡ ¼­¸íµÇ¾î ã¾Æ°¥ ¼ö ÀÖ°Ô µÇ¸é °ü¸®ÀÚ¿¡°Ô ¾Ë¸³´Ï´Ù.

  8. ÀÎÁõ ±â°ü ÀÎÁõ¼­ üÀÎ ¹× SSL ¼­¹ö ÀÎÁõÀ» ÅØ½ºÆ® ÆÄÀÏ·Î º¹»çÇÕ´Ï´Ù.
  9. CA ÀÎÁõ¼­ üÀÎÀ» ÀÎÁõ¼­ µ¥ÀÌÅͺ£À̽º·Î °¡Á®¿Í¼­ ÀÎÁõ üÀÎÀ» ¼³Á¤ÇÕ´Ï´Ù. ¿¹¸¦ µé¸é ´ÙÀ½°ú °°½À´Ï´Ù.
  10. # ./certutil -A -n "GTE CyberTrust Root" -t "TCu,TCu,TCuw"
    -d /var/opt/SUNWics5/alias -a -i /export/wspace/Certificates/CA_Certificate_1.txt
    -f /etc/opt/SUNWics5/config/sslPasswordFile

    # ./certutil -A -n "Sesta TEST Root CA" -t "TCu,TCu,TCuw"
    -d /var/opt/SUNWics5/alias -a -i /export/wspace/Certificates/CA_Certificate_2.txt
    -f /etc/opt/SUNWics5/config/sslPasswordFile

  11. ¼­¸íµÈ SSL ¼­¹ö ÀÎÁõ¼­¸¦ °¡Á®¿É´Ï´Ù.
  12. # ./certutil -A -n "hostname SSL Server Test Cert" -t "u,u,u"
    -d /var/opt/SUNWics5/alias -a -i /export/wspace/Certificates/SSL_Server_Certificate.txt
    -f /etc/opt/SUNWics5/config/sslPasswordFile

  13. ÀÎÁõ¼­ µ¥ÀÌÅͺ£À̽ºÀÇ ÀÎÁõ¼­¸¦ ³ª¿­ÇÕ´Ï´Ù.
  14. # ./certutil -L -d /var/opt/SUNWics5/alias

  15. ics.conf ÆÄÀÏÀÇ SSL Server º°¸íÀÌ ¼­¸íµÈ SSL ¼­¹ö ÀÎÁõ¼­°¡ µÇ°Ô ±¸¼ºÇÕ´Ï´Ù. ¿¹: "hostname SSL Server Test Cert"
  16. ÁÖ ics.conf ÆÄÀÏ¿¡ ÀÖ´Â service.http.calendarhostname ¹× service.http.ssl.sourceurl ¸Å°³ º¯¼öÀÇ È£½ºÆ® À̸§ÀÌ SSL ÀÎÁõ¼­ÀÇ È£½ºÆ® À̸§°ú ÀÏÄ¡ÇØ¾ß ÇÕ´Ï´Ù(½Ã½ºÅÛ¿¡ ¿©·¯ °³ÀÇ º°¸íÀÌ ÀÖ´Â °æ¿ì). ¿¹: calendar.sesta.com

ics.conf ÆÄÀÏÀÇ SSL ¸Å°³ º¯¼ö ±¸¼º

Calendar Server¿¡ SSLÀ» ±¸ÇöÇÏ·Á¸é ics.conf ÆÄÀÏ¿¡ ƯÁ¤ ¸Å°³ º¯¼ö¸¦ ¼³Á¤ÇØ¾ß ÇÕ´Ï´Ù. ÀÌ ÀýÀº ´ÙÀ½ ³»¿ëÀ¸·Î ±¸¼ºµÇ¾î ÀÖ½À´Ï´Ù.

 

SSL ±¸¼º ¸Å°³ º¯¼ö

ÄÚµå ¿¹ 9-1¿¡¼­´Â SSL ±¸¼º ¸Å°³ º¯¼ö¸¦ º¸¿© ÁÝ´Ï´Ù. ±× Áß ics.conf ÆÄÀÏ¿¡ ¾ø´Â ¸Å°³ º¯¼ö°¡ ÀÖ´Ù¸é ÇØ´ç º¯¼ö¸¦ ÆÄÀÏ¿¡ Ãß°¡ÇÕ´Ï´Ù. ÀÌ ¸Å°³ º¯¼ö¸¦ ¼³Á¤ÇÑ ´ÙÀ½ »õ °ªÀ» Àû¿ëÇÏ·Á¸é Calendar Server¸¦ ´Ù½Ã ½ÃÀÛÇÕ´Ï´Ù. ÀÌ SSL ¸Å°³ º¯¼ö¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ ³»¿ëÀº "SSL ±¸¼º"À» ÂüÁ¶ÇϽʽÿÀ.

ÄÚµå ¿¹ 9-1 Calendar ServerÀÇ SSL ±¸¼º ¸Å°³ º¯¼ö

 

service.http.ssl.cachedir = "."
service.http.ssl.cachesize = "10000"
service.http.ssl.certdb.password = "password"
service.http.ssl.certdb.path = "/var/opt/SUNWics5/alias"
service.http.ssl.port.enable = "yes"
service.http.ssl.port = "443"
service.http.ssl.securelogin = "yes"
service.http.ssl.securesession = "yes"

! localhost¸¦ ÇØ´ç ·ÎÄà ȣ½ºÆ® À̸§À¸·Î ¼³Á¤ÇÕ´Ï´Ù.

! Æ÷Æ® ¹øÈ£´Â »ç¿ë ÁßÀÎ SSL Æ÷Æ®·Î ¼³Á¤ÇÕ´Ï´Ù(±âº»°ª: 443).

service.http.ssl.sourceurl = "https://localhost:443"

service.http.ssl.ssl2.ciphers = ""
service.http.ssl.ssl2.sessiontimeout = "0"
service.http.ssl.ssl3.ciphers = "rsa_rc4_40_md5,rsa_rc2_40_md5,rsa_des_sha,rsa_rc4_128_md5,rsa_3des_sha"
service.http.ssl.ssl3.sessiontimeout = "0"
service.http.ssl.usessl = "yes"
encryption.rsa.nssslactivation = "on"
encryption.rsa.nssslpersonalityssl = "SampleSSLServerCert"
encryption.rsa.nsssltoken = "internal"
service.http.tmpdir = "/var/opt/SUNWics5/tmp"
service.http.uidir.path = "html"

 


ÁÖÀÇ  

Calendar Server¿¡¼­´Â ¿ø°Ý °ü¸®¸¦ »ç¿ëÇÒ ¼ö ¾ø½À´Ï´Ù. service.admin.port ¸Å°³ º¯¼ö¸¦ ¹Ù²ÙÁö ¸¶½Ê½Ã¿À. Calendar Server¿¡ ÀÇÇØ ÀÌ¹Ì ÇÊ¿äÇÑ °ªÀ¸·Î ¼³Á¤µÇ¾î ÀÖ½À´Ï´Ù. ±×·¸Áö ¾ÊÀ¸¸é csadmind ÇÁ·Î¼¼½º°¡ ¿Ã¹Ù¸£°Ô ½ÇÇàµÇÁö ¾ÊÀ» ¼ö ÀÖ½À´Ï´Ù.


Calendar Server ·Î±×ÀÎ ¶Ç´Â Àüü ´Þ·Â ¼¼¼Ç ¾Ïȣȭ

´ÙÀ½ ¸Å°³ º¯¼ö¸¦ ¼³Á¤ÇÏ¿© Calendar Server°¡ Calendar Server ·Î±×Àΰú ºñ¹Ð¹øÈ£¸¸ ¾ÏȣȭÇϰųª Àüü ´Þ·Â ¼¼¼ÇÀ» ¾ÏȣȭÇϵµ·Ï ±¸¼ºÇÒ ¼ö ÀÖ½À´Ï´Ù.

 


SSL ¹®Á¦ ÇØ°á

¿ì¼± º¹±¸ ºÒ°¡´ÉÇÑ ¹®Á¦°¡ ¹ß»ýÇÒ °æ¿ì¸¦ ´ëºñÇÏ¿© Á¤±âÀûÀ¸·Î ÀÎÁõ¼­ µ¥ÀÌÅͺ£À̽º¸¦ ¹é¾÷ÇÕ´Ï´Ù. SSL¿¡ ¹®Á¦°¡ ÀÖÀ» °æ¿ì ´ÙÀ½ ³»¿ëÀ» È®ÀÎÇϽʽÿÀ.

 

cshttpd ÇÁ·Î¼¼½º Á¡°Ë

SSLÀ» »ç¿ëÇÏ·Á¸é Calendar Server cshttpd ÇÁ·Î¼¼½º°¡ ½ÇÇà ÁßÀ̾î¾ß ÇÕ´Ï´Ù. cshttpd°¡ ½ÇÇà ÁßÀÎÁö È®ÀÎÇÏ·Á¸é Solaris ½Ã½ºÅÛÀÇ °æ¿ì ´ÙÀ½ ¸í·ÉÀ» »ç¿ëÇÕ´Ï´Ù.

# ps -ef | grep cshttpd

ÀÎÁõ¼­ °ËÁõ

ÀÎÁõ¼­ µ¥ÀÌÅͺ£À̽ºÀÇ ÀÎÁõ¼­¸¦ ³ª¿­Çϰí ÇØ´ç À¯È¿ ÀÏÀÚ¸¦ È®ÀÎÇÏ·Á¸é Solaris ½Ã½ºÅÛÀÇ °æ¿ì ´ÙÀ½ ¸í·ÉÀ» »ç¿ëÇÕ´Ï´Ù.

# ./certutil -L -d /var/opt/SUNWics5/alias

Calendar Server ·Î±× ÆÄÀÏ È®ÀÎ

Calendar Server ·Î±× ÆÄÀÏ¿¡ SSL ¿À·ù°¡ ÀÖ´ÂÁö È®ÀÎÇÕ´Ï´Ù. ÀÚ¼¼ÇÑ ³»¿ëÀº "Calendar Server ·Î±× ÆÄÀÏ ¸ð´ÏÅ͸µ"À» ÂüÁ¶ÇϽʽÿÀ.

SSL Æ÷Æ®¿¡ ¿¬°á

ºê¶ó¿ìÀú¿Í ´ÙÀ½ URLÀ» »ç¿ëÇÏ¿© SSL Æ÷Æ®¿¡ ¿¬°áÇÕ´Ï´Ù.

https://server-name:ssl-port-number

¿©±â¼­,

server-nameÀº Calendar Server°¡ ½ÇÇà ÁßÀÎ ¼­¹ö À̸§ÀÔ´Ï´Ù.

ssl-port-number´Â ics.conf ÆÄÀÏÀÇ service.http.ssl.port ¸Å°³ º¯¼ö°¡ ÁöÁ¤ÇÏ´Â SSL Æ÷Æ® ¹øÈ£ÀÔ´Ï´Ù. ±âº»°ªÀº 443ÀÔ´Ï´Ù.



ÀÌÀü      ¸ñÂ÷      »öÀÎ      ´ÙÀ½     


Copyright 2003 Sun Microsystems, Inc. ¸ðµç ±Ç¸®´Â ÀúÀÛ±ÇÀÚÀÇ ¼ÒÀ¯ÀÔ´Ï´Ù.