Sun Java logo     ÀÌÀü      ¸ñÂ÷      »öÀÎ      ´ÙÀ½     

Sun logo
Sun Java System Identity Server 2004Q2 °ü¸® ¼³¸í¼­ 

3Àå
SSL ¸ðµå¿¡¼­ Identity Server ±¸¼º

´Ü¼ø ÀÎÁõ¿¡¼­ SSL (Secure Socket Layer)À» »ç¿ëÇÏ¸é ±â¹Ð¼º°ú µ¥ÀÌÅÍ ¹«°á¼ºÀÌ º¸ÀåµË´Ï´Ù. Identity Server¸¦ SSL¿¡¼­ »ç¿ëÇÏ·Á¸é ÀϹÝÀûÀ¸·Î ´ÙÀ½°ú °°ÀÌ ÇÕ´Ï´Ù.

  1. Identity Server¸¦ º¸¾È À¥ ÄÁÅ×À̳ʸ¦ »ç¿ëÇÏ¿© ±¸¼º
  2. Identity Server¸¦ º¸¾È Directory Server·Î ±¸¼º

´ÙÀ½ Àý¿¡¼­ ¼³¸íÇÒ ´Ü°è´Â ¾Æ·¡¿Í °°½À´Ï´Ù.


º¸¾È Sun Java System Web Server¸¦ »ç¿ëÇÏ¿© Identity Server ±¸¼º

Sun Java System Web Server¸¦ »ç¿ëÇÏ¿© SSL ¸ðµå¿¡¼­ Identity Server¸¦ ±¸¼ºÇÏ·Á¸é ´ÙÀ½ ´Ü°è¸¦ ÂüÁ¶ÇϽʽÿÀ.

  1. Identity Server Äֿܼ¡¼­ ¼­ºñ½º ±¸¼º ¸ðµâ·Î À̵¿ÇÏ¿© [Ç÷§Æû ¼­ºñ½º]¸¦ ¼±ÅÃÇÕ´Ï´Ù. ¼­¹ö ¸ñ·Ï ¼Ó¼º¿¡¼­ http:// ÇÁ·ÎÅäÄÝÀ» Á¦°ÅÇϰí https:// ÇÁ·ÎÅäÄÝÀ» Ãß°¡ÇÕ´Ï´Ù. ÀúÀåÀ» ´©¸¨´Ï´Ù.

  2. ÁÖ

    [ÀúÀå]À» ´­·¯¾ß ÇÕ´Ï´Ù. ÀúÀåÀ» ´©¸£Áö ¾Ê´õ¶óµµ ´ÙÀ½ ´Ü°è¸¦ °è¼ÓÇÒ ¼ö ÀÖÁö¸¸ ¸ðµç ±¸¼º º¯°æ ³»¿ëÀÌ ¼Õ½ÇµÇ°í °ü¸®ÀÚ·Î ·Î±×ÀÎÇÏ¿© ÇØ´ç ¹®Á¦¸¦ ÇØ°áÇÒ ¼ö ¾ø½À´Ï´Ù.


    ´Ü°è 2ºÎÅÍ ´Ü°è 25±îÁö´Â Sun Java System Web Server¿¡ ´ëÇÑ ¼³¸íÀÔ´Ï´Ù.

  3. WebServer Äֿܼ¡ ·Î±×¿ÂÇÕ´Ï´Ù. ±âº» Æ÷Æ®´Â 58888ÀÔ´Ï´Ù.
  4. Identity Server°¡ ½ÇÇà ÁßÀÎ Web Server ÀνºÅϽº¸¦ ¼±ÅÃÇϰí [°ü¸®]¸¦ ´©¸¨´Ï´Ù.
  5. ±¸¼ºÀÌ º¯°æµÇ¾ú´Ù´Â ¸Þ½ÃÁö°¡ ÀÖ´Â ÆË¾÷ âÀÌ Ç¥½ÃµË´Ï´Ù. [È®ÀÎ]À» ´©¸¨´Ï´Ù.

  6. È­¸éÀÇ ¿À¸¥ÂÊ À§ ¸ð¼­¸®¿¡ ÀÖ´Â [Àû¿ë] ¹öưÀ» ´©¸¨´Ï´Ù.
  7. [¼³Á¤ Àû¿ë]À» ´©¸¨´Ï´Ù.
  8. Web Server°¡ ÀÚµ¿À¸·Î ´Ù½Ã ½ÃÀ۵Ǿî¾ß ÇÕ´Ï´Ù. [È®ÀÎ]À» ´­·¯ °è¼ÓÇÕ´Ï´Ù.

  9. Web Server ÀνºÅϽº ¼±ÅÃÀ» ÁßÁöÇÕ´Ï´Ù.
  10. [º¸¾È ÅÇ]À» ´©¸¨´Ï´Ù.
  11. [µ¥ÀÌÅͺ£À̽º ¸¸µé±â]¸¦ ´©¸¨´Ï´Ù.
  12. »õ µ¥ÀÌÅͺ£À̽º ºñ¹Ð¹øÈ£¸¦ ÀÔ·ÂÇϰí [È®ÀÎ]À» ´©¸¨´Ï´Ù.
  13. ³ªÁß¿¡ »ç¿ëÇÒ ¼ö ÀÖµµ·Ï µ¥ÀÌÅͺ£À̽º ºñ¹Ð¹øÈ£¸¦ ±â·ÏÇØ µÎ½Ê½Ã¿À.

  14. ÀÎÁõ¼­ µ¥ÀÌÅͺ£À̽º¸¦ ÀÛ¼ºÇÑ ÈÄ [ÀÎÁõ¼­ ¿äû]À» ´©¸¨´Ï´Ù.
  15. È­¸é¿¡ Á¦°øµÈ Çʵ忡 µ¥ÀÌÅ͸¦ ÀÔ·ÂÇÕ´Ï´Ù.
  16. Ű ½Ö ÇÊµå ºñ¹Ð¹øÈ£ Çʵå´Â ´Ü°è 9¿¡ ÀÔ·ÂÇÑ °Í°ú µ¿ÀÏÇÕ´Ï´Ù. À§Ä¡ Çʵ忡 À§Ä¡¸¦ Á¤È®ÇÏ°Ô ÀÔ·ÂÇØ¾ß ÇÕ´Ï´Ù. CA¿Í °°Àº ¾à¾î´Â »ç¿ëÇÒ ¼ö ¾ø½À´Ï´Ù. ¸ðµç Çʵ带 Á¤ÀÇÇØ¾ß ÇÕ´Ï´Ù. °øÅë À̸§ Çʵ忡 Web ServerÀÇ È£½ºÆ® À̸§À» ÀÔ·ÂÇÕ´Ï´Ù.

  17. ¾ç½ÄÀÌ Á¦ÃâµÇ¸é ´ÙÀ½°ú °°Àº ¸Þ½ÃÁö°¡ Ç¥½ÃµË´Ï´Ù.
  18.  

    --BEGIN CERTIFICATE REQUEST---

     

    afajsdllwqeroisdaoi234rlkqwelkasjlasnvdknbslajowijalsdkjfalsdflasdf

     

    alsfjawoeirjoi2ejowdnlkswnvnwofijwoeijfwiepwerfoiqeroijeprwpfrwl

     

    --END CERTIFICATE REQUEST--

  19. ÀÌ ÅØ½ºÆ®¸¦ º¹»çÇÏ¿© ÀÎÁõ¼­¸¦ ¿äûÇÒ ¶§ Á¦ÃâÇÕ´Ï´Ù.
  20. ·çÆ® CA ÀÎÁõ¼­¸¦ °¡Á®¿Í¾ß ÇÕ´Ï´Ù.

  21. ÀÎÁõ¼­°¡ Æ÷ÇÔµÈ ´ÙÀ½°ú °°Àº ÀÎÁõ¼­ ÀÀ´äÀ» ¹Þ°Ô µË´Ï´Ù.
  22. --BEGIN CERTIFICATE---

     

    afajsdllwqeroisdaoi234rlkqwelkasjlasnvdknbslajowijalsdkjfalsdflasdf

     

    alsfjawoeirjoi2ejowdnlkswnvnwofijwoeijfwiepwerfoiqeroijeprwpfrwl

     

    --END CERTIFICATE---

  23. ÀÌ ÅØ½ºÆ®¸¦ Ŭ¸³º¸µå¿¡ º¹»çÇϰųª ÅØ½ºÆ®¸¦ ÆÄÀÏ·Î ÀúÀåÇÕ´Ï´Ù.
  24. Web Server ÄַܼΠÀ̵¿ÇÏ¿© [ÀÎÁõ¼­ ¼³Ä¡]¸¦ ´©¸¨´Ï´Ù.
  25. [ÀÌ ¼­¹öÀÇ ÀÎÁõ¼­]¸¦ Ŭ¸¯ÇÕ´Ï´Ù.
  26. [Ű ½Ö ÆÄÀÏ ºñ¹Ð¹øÈ£] Çʵ忡 ÀÎÁõ¼­ µ¥ÀÌÅͺ£À̽º ºñ¹Ð¹øÈ£¸¦ ÀÔ·ÂÇÕ´Ï´Ù.
  27. ÀÎÁõ¼­¸¦ Á¦°øµÈ ÅØ½ºÆ® Çʵ忡 ºÙ¿© ³Ö°Å³ª ¶óµð¿À ¹öưÀ» ´©¸£°í ÅØ½ºÆ® »óÀÚ¿¡ ÆÄÀÏ À̸§À» ÀÔ·ÂÇÕ´Ï´Ù. [Á¦Ãâ]À» Ŭ¸¯ÇÕ´Ï´Ù.
  28. ºê¶ó¿ìÀú¿¡ ÀÎÁõ¼­°¡ Ç¥½ÃµÇ°í ÀÎÁõ¼­¸¦ Ãß°¡Çϱâ À§ÇÑ ¹öưÀÌ Á¦°øµË´Ï´Ù.

  29. [ÀÎÁõ¼­ ¼³Ä¡]¸¦ Ŭ¸¯ÇÕ´Ï´Ù.
  30. [½Å·ÚÇÒ ¼ö ÀÖ´Â ÀÎÁõ ±â°ü¿¡ ´ëÇÑ ÀÎÁõ¼­]¸¦ ´©¸¨´Ï´Ù.
  31. ´Ü°è 16ºÎÅÍ ´Ü°è 21±îÁö ¼³¸íµÈ °Í°ú µ¿ÀÏÇÑ ¹æ¹ýÀ¸·Î ·çÆ® CA ÀÎÁõ¼­¸¦ ¼³Ä¡ÇÕ´Ï´Ù.
  32. µÎ ÀÎÁõ¼­°¡ ¸ðµÎ ¼³Ä¡µÇ¸é Web Server ÄܼÖÀÇ [±âº» ¼³Á¤ ÅÇ]À» ´©¸¨´Ï´Ù.
  33. SSLÀ» ´Ù¸¥ Æ÷Æ®¿¡¼­ »ç¿ë °¡´ÉÇÏ°Ô ÇÏ·Á¸é [¼ö½Å ¼ÒÄÏ Ãß°¡]¸¦ ¼±ÅÃÇÕ´Ï´Ù. ±×·± ´ÙÀ½ [¼ö½Å ¼ÒÄÏ ÆíÁý]À» ¼±ÅÃÇÕ´Ï´Ù.
  34. º¸¾È »óŸ¦ »ç¿ë ºÒ°¡´É¿¡¼­ »ç¿ë °¡´ÉÀ¸·Î º¯°æÇϰí [È®ÀÎ]À» ´­·¯ º¯°æ ³»¿ëÀ» Á¦ÃâÇÕ´Ï´Ù.
  35. ´Ü°è 26ºÎÅÍ ´Ü°è 28±îÁö´Â Identity Server¿¡ ´ëÇÑ ¼³¸íÀÔ´Ï´Ù.

  36. AMConfig.properties ÆÄÀÏÀ» ¿±´Ï´Ù. ±âº»ÀûÀ¸·Î ÀÌ ÆÄÀÏÀÇ À§Ä¡´Â etc/opt/SUNWam/configÀÔ´Ï´Ù.
  37. Web Server ÀνºÅϽº µð·ºÅ丮¸¦ Á¦¿ÜÇϰí http://ÀÇ ¸ðµç ÇÁ·ÎÅäÄÝ Ç׸ñÀ» https://·Î ±³Ã¼ÇÕ´Ï´Ù. Web Server ÀνºÅϽº µð·ºÅ丮µµ AMConfig.properties¿¡ ÁöÁ¤µÇ¾î ÀÖÁö¸¸ ±×´ë·Î À¯ÁöµÇ¾î¾ß ÇÕ´Ï´Ù.
  38. AMConfig.properties ÆÄÀÏÀ» ÀúÀåÇÕ´Ï´Ù.
  39. Web Server Äֿܼ¡¼­ Web Server ÀνºÅϽº¸¦ È£½ºÆ®ÇÏ´Â Identity Server¿¡ ´ëÇÑ ¼³Á¤/ÇØÁ¦ ¹öưÀ» ´©¸¨´Ï´Ù.
  40. Web ServerÀÇ ½ÃÀÛ/ÁßÁö ÆäÀÌÁö¿¡ ÀԷ¶õÀÌ Ç¥½ÃµË´Ï´Ù.

  41. ÅØ½ºÆ® Çʵ忡 ÀÎÁõ¼­ µ¥ÀÌÅͺ£À̽º ºñ¹Ð¹øÈ£¸¦ ÀÔ·ÂÇÏ°í ½ÃÀÛÀ» ¼±ÅÃÇÕ´Ï´Ù.


º¸¾È Sun Java System Application Server¸¦ »ç¿ëÇÏ¿© Identity Server ±¸¼º

SSL »ç¿ë °¡´É Sun Java System Application Server¿¡¼­ ½ÇÇàÇϵµ·Ï Identity Server¸¦ ¼³Á¤ÇÏ´Â ´Ü°è´Â 2´Ü°è ÇÁ·Î¼¼½ºÀÔ´Ï´Ù. ¸ÕÀú ¼³Ä¡µÈ Identity Server¿¡ ´ëÇÑ Application Server ÀνºÅϽº¿¡ º¸¾ÈÀ» ¼³Á¤ÇÑ ´ÙÀ½ Identity Server¸¦ ±¸¼ºÇÕ´Ï´Ù.

SSLÀ» »ç¿ëÇÏ¿© Application Server ¼³Á¤

Application Server ÀνºÅϽº¿¡ º¸¾ÈÀ» ¼³Á¤ÇÏ·Á¸é ´ÙÀ½À» ¼öÇàÇÕ´Ï´Ù.

  1. ºê¶ó¿ìÀú¿¡ ´ÙÀ½ ÁÖ¼Ò¸¦ ÀÔ·ÂÇÏ¿© Sun Java System Application Server Äֿܼ¡ °ü¸®ÀÚ·Î ·Î±×ÀÎÇÕ´Ï´Ù.
  2. http://fullservername:port

    ±âº» Æ÷Æ®´Â 4848ÀÔ´Ï´Ù.

  3. ¼³Ä¡ÇÏ´Â µ¿¾È ÀÔ·ÂÇÑ ¾ÆÀ̵ð¿Í ºñ¹Ð¹øÈ£¸¦ ÀÔ·ÂÇÕ´Ï´Ù.
  4. Identity Server¸¦ ¼³Ä¡Ç߰ųª ¼³Ä¡ÇÒ Application Server ÀνºÅϽº¸¦ ¼±ÅÃÇÕ´Ï´Ù. ¿À¸¥ÂÊ ÇÁ·¹ÀÓ¿¡ ±¸¼ºÀÌ º¯°æµÇ¾ú´Ù´Â ¸Þ½ÃÁö°¡ Ç¥½ÃµË´Ï´Ù.
  5. [º¯°æ ³»¿ë Àû¿ë]À» ´©¸¨´Ï´Ù.
  6. [Àç½ÃÀÛ]À» ´©¸¨´Ï´Ù. Application Server°¡ ÀÚµ¿À¸·Î ´Ù½Ã ½ÃÀ۵Ǿî¾ß ÇÕ´Ï´Ù.
  7. ¿ÞÂÊ ÇÁ·¹ÀÓ¿¡¼­ [º¸¾È]À» ´©¸¨´Ï´Ù.
  8. [µ¥ÀÌÅͺ£À̽º °ü¸® ÅÇ]À» ´©¸¨´Ï´Ù.
  9. [µ¥ÀÌÅͺ£À̽º ¸¸µé±â]¸¦ ´©¸¨´Ï´Ù(¼±ÅÃÇÏÁö ¾ÊÀº °æ¿ì).
  10. »õ µ¥ÀÌÅͺ£À̽º ºñ¹Ð¹øÈ£¸¦ ÀÔ·ÂÇϰí È®ÀÎÇÑ ´ÙÀ½ [È®ÀÎ] ¹öưÀ» ´©¸¨´Ï´Ù. ³ªÁß¿¡ »ç¿ëÇÒ ¼ö ÀÖµµ·Ï µ¥ÀÌÅͺ£À̽º ºñ¹Ð¹øÈ£¸¦ ±â·ÏÇØ µÎ½Ê½Ã¿À.
  11. ÀÎÁõ¼­ µ¥ÀÌÅͺ£À̽º¸¦ ÀÛ¼ºÇÑ ÈÄ [ÀÎÁõ¼­ °ü¸® ÅÇ]À» ´©¸¨´Ï´Ù.
  12. [¿äû ¸µÅ©]¸¦ ´©¸¨´Ï´Ù(¼±ÅÃÇÏÁö ¾ÊÀº °æ¿ì).
  13. ÀÎÁõ¼­¿¡ ´ëÇØ ´ÙÀ½ ¿äû µ¥ÀÌÅ͸¦ ÀÔ·ÂÇÕ´Ï´Ù.
    1. »õ ÀÎÁõ¼­ÀÎÁö ÀÎÁõ¼­ °»½ÅÀÎÁö¸¦ ¼±ÅÃÇÕ´Ï´Ù. ƯÁ¤ ±â°£ÀÌ °æ°úÇÏ¸é ¸¹Àº ÀÎÁõ¼­°¡ ¸¸·áµÇ°í ÀϺΠÀÎÁõ ±â°ü(CA)¿¡¼­´Â °»½Å ¾Ë¸²À» ÀÚµ¿À¸·Î º¸³À´Ï´Ù.
    2. ÀÎÁõ¼­¿¡ ´ëÇÑ ¿äûÀ» Á¦ÃâÇÒ ¹æ¹ýÀ» ÁöÁ¤ÇÕ´Ï´Ù.
    3. CA°¡ ÀüÀÚ ¸ÞÀÏ ¸Þ½ÃÁö·Î ¿äûÀ» ¹Þ´Â °æ¿ì CA ÀüÀÚ ¸ÞÀÏÀ» ¼±ÅÃÇϰí CAÀÇ ÀüÀÚ ¸ÞÀÏ ÁÖ¼Ò¸¦ ÀÔ·ÂÇÕ´Ï´Ù. CA ¸ñ·Ï¿¡¼­ [»ç¿ë °¡´ÉÇÑ ÀÎÁõ ±â°ü ¸ñ·Ï]À» ´©¸¨´Ï´Ù.

      Sun Java System Certificate Server¸¦ »ç¿ëÇÏ´Â ³»ºÎ CA·ÎºÎÅÍ ÀÎÁõ¼­¸¦ ¿äûÇÒ °æ¿ì CA URLÀ» ´©¸£°í Certificate Server¿¡ ´ëÇÑ URLÀ» ÀÔ·ÂÇÕ´Ï´Ù. ÀÌ URLÀº ÀÎÁõ¼­ ¿äûÀ» ó¸®ÇÏ´Â ÀÎÁõ¼­ ¼­¹öÀÇ ÇÁ·Î±×·¥À» °¡¸®ÄÑ¾ß ÇÕ´Ï´Ù.

    4. Ű ½Ö ÆÄÀÏ¿¡ ´ëÇÑ ºñ¹Ð¹øÈ£(´Ü°è 9¿¡¼­ ÁöÁ¤ÇÑ ºñ¹Ð¹øÈ£)¸¦ ÀÔ·ÂÇÕ´Ï´Ù.
    5. ´ÙÀ½ ½Äº° Á¤º¸¸¦ ÀÔ·ÂÇÕ´Ï´Ù.
    6. °øÅë À̸§. Æ÷Æ® ¹øÈ£¸¦ Æ÷ÇÔÇÏ¿© ¼­¹öÀÇ Àüü À̸§ÀÔ´Ï´Ù.

      ¿äûÀÚ À̸§. ¿äûÀÚÀÇ À̸§ÀÔ´Ï´Ù.

      ÀüÈ­ ¹øÈ£. ¿äûÀÚÀÇ ÀüÈ­ ¹øÈ£ÀÔ´Ï´Ù.

      °øÅë À̸§. µðÁöÅÐ ÀÎÁõ¼­¸¦ ¼³Ä¡ÇÒ Sun Java System Application ServerÀÇ Á¤±ÔÈ­µÈ À̸§ÀÔ´Ï´Ù.

      ÀüÀÚ ¸ÞÀÏ ÁÖ¼Ò. °ü¸®ÀÚÀÇ ÀüÀÚ ¸ÞÀÏ ÁÖ¼ÒÀÔ´Ï´Ù.

      Á¶Á÷ À̸§. Á¶Á÷ÀÇ À̸§ÀÔ´Ï´Ù. ÀÎÁõ ±â°üÀº ÀÌ Á¶Á÷¿¡ µî·ÏµÈ µµ¸ÞÀο¡ ¼ÓÇÏ´Â ÀÌ ¼Ó¼º¿¡ ÀÔ·ÂµÈ È£½ºÆ® À̸§À» ¿ä±¸ÇÒ ¼ö ÀÖ½À´Ï´Ù.

      Á¶Á÷ ±¸¼º ´ÜÀ§ À̸§. °ú, ºÎ¼­ ¹× ±âŸ Á¶Á÷ ¿î¿µ ´ÜÀ§ÀÇ À̸§ÀÔ´Ï´Ù.

      ±¸/±º/½Ã À̸§. »ç¿ëÀÚÀÇ ±¸/±º/½Ã À̸§ÀÔ´Ï´Ù.

      ½Ã/µµ À̸§. Á¶Á÷ÀÌ ¹Ì±¹ ¶Ç´Â ij³ª´Ù¿¡ ÀÖ´Â °æ¿ì °¢°¢ Á¶Á÷ÀÌ ¿î¿µµÇ´Â ½Ã ¶Ç´Â µµÀÇ À̸§ÀÔ´Ï´Ù. ¾à¾î¸¦ »ç¿ëÇÏÁö ¸¶½Ê½Ã¿À.

      ±¹°¡ ÄÚµå. ±¹°¡¿¡ ´ëÇÑ 2¹®ÀÚ ISO ÄÚµåÀÔ´Ï´Ù. ¿¹¸¦ µé¾î, ¹Ì±¹ÀÇ ±¹°¡ ÄÚµå´Â USÀÔ´Ï´Ù.

  14. [È®ÀÎ] ¹öưÀ» ´©¸¨´Ï´Ù. ¸Þ½ÃÁö°¡ Ç¥½ÃµË´Ï´Ù. ¿¹¸¦ µé¸é ´ÙÀ½°ú °°½À´Ï´Ù.
  15. --BEGIN NEW CERTIFICATE REQUEST---

    afajsdllwqeroisdaoi234rlkqwelkasjlasnvdknbslajowijalsdkjfalsdfla

    alsfjawoeirjoi2ejowdnlkswnvnwofijwoeijfwiepwerfoiqeroijeprwpfrwl

    --END NEW CERTIFICATE REQUEST--

  16. ÀÌ ÅØ½ºÆ®¸¦ ¸ðµÎ ÆÄÀÏ¿¡ º¹»çÇϰí [È®ÀÎ]À» ´©¸¨´Ï´Ù. ·çÆ® CA ÀÎÁõ¼­¸¦ °¡Á®¿Í¾ß ÇÕ´Ï´Ù.
  17. CA¸¦ ¼±ÅÃÇϰí ÇØ´ç ±â°üÀÇ À¥ »çÀÌÆ® Áö½Ã¿¡ µû¶ó µðÁöÅÐ ÀÎÁõ¼­¸¦ °¡Á®¿É´Ï´Ù. CMS, Verisign ¶Ç´Â Entrust.net¿¡¼­ ÀÎÁõ¼­¸¦ °¡Á®¿Ã ¼ö ÀÖ½À´Ï´Ù.
  18. ÀÎÁõ ±â°üÀ¸·ÎºÎÅÍ µðÁöÅÐ ÀÎÁõ¼­¸¦ ¹ÞÀº ÈÄ ÅØ½ºÆ®¸¦ Ŭ¸³º¸µå¿¡ º¹»çÇϰųª ÆÄÀÏ·Î ÀúÀåÇÒ ¼ö ÀÖ½À´Ï´Ù.
  19. Sun Java System Application Server ÄַܼΠÀ̵¿ÇÏ¿© [¼³Ä¡ ¸µÅ©]¸¦ ´©¸¨´Ï´Ù.
  20. ÀÌ ¼­¹ö¿¡ ´ëÇÑ ÀÎÁõ¼­¸¦ ¼±ÅÃÇÕ´Ï´Ù.
  21. [Ű ½Ö ÆÄÀÏ ºñ¹Ð¹øÈ£] Çʵ忡 ÀÎÁõ¼­ µ¥ÀÌÅͺ£À̽º ºñ¹Ð¹øÈ£¸¦ ÀÔ·ÂÇÕ´Ï´Ù. (´Ü°è 9¿¡ ÀÔ·ÂÇÑ ºñ¹Ð¹øÈ£).
  22. ÀÎÁõ¼­¸¦ Á¦°øµÈ ÅØ½ºÆ® ÇʵåÀÎ ¸Þ½ÃÁö ÅØ½ºÆ®(Çì´õ ÀÖÀ½)¿¡ ºÙ¿© ³Ö°Å³ª ÀÌ ÆÄÀÏ ÀԷ¶õ¿¡ ÀÖ´Â ¸Þ½ÃÁö¿¡ ÆÄÀÏ À̸§À» ÀÔ·ÂÇÕ´Ï´Ù. ÇØ´ç ¶óµð¿À ¹öưÀ» ¼±ÅÃÇÕ´Ï´Ù.
  23. È®ÀÎ ¹öưÀ» ´©¸¨´Ï´Ù. ºê¶ó¿ìÀú¿¡ ÀÎÁõ¼­°¡ Ç¥½ÃµÇ°í ÀÎÁõ¼­¸¦ Ãß°¡ÇÒ ¼ö ÀÖ´Â ¹öưÀÌ Á¦°øµË´Ï´Ù.
  24. [¼­¹ö ÀÎÁõ¼­ Ãß°¡]¸¦ ´©¸¨´Ï´Ù.
  25. ´Ü°è 10ºÎÅÍ ´Ü°è 22±îÁö ¼³¸íµÈ °Í°ú µ¿ÀÏÇÑ ¹æ¹ýÀ¸·Î ·çÆ® CA ÀÎÁõ¼­¸¦ ¼³Ä¡ÇÕ´Ï´Ù. ±×·¯³ª ´Ü°è 18¿¡¼­´Â ½Å·ÚÇÒ ¼ö ÀÖ´Â ÀÎÁõ ±â°ü¿¡ ´ëÇÑ ÀÎÁõ¼­¸¦ ¼±ÅÃÇÕ´Ï´Ù.
  26. ÀÎÁõ¼­ ¼³Ä¡°¡ ¿Ï·áµÈ °æ¿ì ¿ÞÂÊ ÇÁ·¹ÀÓ¿¡¼­ HTTP Server ³ëµå¸¦ È®ÀåÇÕ´Ï´Ù.
  27. HTTP Server¿¡¼­ HTTP ¼ö½Å±â¸¦ ¼±ÅÃÇÕ´Ï´Ù.
  28. http-listener-1À» ¼±ÅÃÇÕ´Ï´Ù. ºê¶ó¿ìÀú¿¡ ¼ÒÄÏ Á¤º¸°¡ Ç¥½ÃµË´Ï´Ù.
  29. http-listener-1¿¡ »ç¿ëµÇ´Â Æ÷Æ® °ªÀ» ÀÀ¿ë ÇÁ·Î±×·¥ ¼­¹ö¸¦ ¼³Ä¡ÇÏ´Â µ¿¾È ÀÔ·ÂÇÑ °ª¿¡¼­ ÇØ´ç °ª(¿¹: 443)À¸·Î º¯°æÇÕ´Ï´Ù.
  30. [SSL/TLS »ç¿ë °¡´É]À» ¼±ÅÃÇÕ´Ï´Ù.
  31. [ÀÎÁõ¼­ º°¸í]À» ¼±ÅÃÇÕ´Ï´Ù.
  32. ¹Ýȯ ¼­¹ö¸¦ ÁöÁ¤ÇÕ´Ï´Ù. ÀÌ À̸§Àº ´Ü°è 12¿¡ ÁöÁ¤µÈ °øÅë À̸§°ú ÀÏÄ¡ÇØ¾ß ÇÕ´Ï´Ù.
  33. [ÀúÀå]À» ´©¸¨´Ï´Ù.
  34. Sun Java System Identity Server ¼ÒÇÁÆ®¿þ¾î¸¦ ¼³Ä¡ÇÒ Application Server ÀνºÅϽº¸¦ ¼±ÅÃÇÕ´Ï´Ù. ¿À¸¥ÂÊ ÇÁ·¹ÀÓ¿¡ ±¸¼ºÀÌ º¯°æµÇ¾ú´Ù´Â ¸Þ½ÃÁö°¡ Ç¥½ÃµË´Ï´Ù.
  35. [º¯°æ ³»¿ë Àû¿ë]À» Ŭ¸¯ÇÕ´Ï´Ù.
  36. [Àç½ÃÀÛ]À» Ŭ¸¯ÇÕ´Ï´Ù. ÀÀ¿ëÇÁ·Î±×·¥ ¼­¹ö°¡ ÀÚµ¿À¸·Î ´Ù½Ã ½ÃÀ۵˴ϴÙ.

SSL ¸ðµå¿¡¼­ Identity Server ±¸¼º

SSL ¸ðµå¿¡¼­ Identity Server¸¦ ±¸¼ºÇÏ·Á¸é ´ÙÀ½À» ¼öÇàÇÕ´Ï´Ù.

  1. Identity Server Äֿܼ¡¼­ ¼­ºñ½º ±¸¼º ¸ðµâ·Î À̵¿ÇÏ¿© [Ç÷§Æû ¼­ºñ½º]¸¦ ¼±ÅÃÇÕ´Ï´Ù. ¼­¹ö ¸ñ·Ï ¼Ó¼º¿¡¼­ HTTPS ÇÁ·ÎÅäÄݰú µ¿ÀÏÇÑ URL ¹× SSL »ç¿ë °¡´É Æ÷Æ® ¹øÈ£¸¦ Ãß°¡ÇÕ´Ï´Ù. [ÀúÀå]À» ´©¸¨´Ï´Ù.

  2. ÁÖ

    ´ÜÀÏ Identity Server ÀνºÅϽº°¡ Http¿Í Https °¢°¢ Çϳª¾¿ µÎ °³ÀÇ Æ÷Æ®¸¦ ¼ö½ÅÇϰí ÀÖ°í Äí۸¦ »ç¿ëÇÏ¿© Identity Server¿¡ ¾×¼¼½ºÇÏ·Á°í ½ÃµµÇÒ °æ¿ì Identity Server´Â ÀÀ´äÇÏÁö ¾Ê´Â »óŰ¡ µË´Ï´Ù. ÀÌ·¯ÇÑ ±¸¼ºÀº Áö¿øµÇÁö ¾Ê½À´Ï´Ù.


  3. ´ÙÀ½ ±âº» À§Ä¡¿¡¼­ AMConfig.properties ÆÄÀÏÀ» ¿±´Ï´Ù.
  4. /etc/opt/SUNWam/config/

  5. http://ÀÇ ¸ðµç ÇÁ·ÎÅäÄÝ Ç׸ñÀ» https://·Î ±³Ã¼ÇÏ°í Æ÷Æ® ¹øÈ£¸¦ SSL »ç¿ë °¡´É Æ÷Æ® ¹øÈ£·Î º¯°æÇÕ´Ï´Ù.
  6. AMConfig.properties ÆÄÀÏÀ» ÀúÀåÇÕ´Ï´Ù.
  7. Application Server¸¦ ´Ù½Ã ½ÃÀÛÇÕ´Ï´Ù.


SSL ¸ðµå¿¡¼­ Identity Server¸¦ Directory Server·Î ±¸¼º

³×Æ®¿öÅ©¸¦ ÅëÇÑ º¸¾È Åë½ÅÀ» Á¦°øÇϱâ À§ÇØ Identity Server¿¡´Â LDAPS Åë½Å ÇÁ·ÎÅäÄÝÀÌ Æ÷ÇԵǾî ÀÖ½À´Ï´Ù. LDAPS´Â Ç¥ÁØ LDAP ÇÁ·ÎÅäÄÝÀÌÁö¸¸ SSL (Secure Sockets Layer)ÀÇ »óÀ§¿¡¼­ ½ÇÇàµË´Ï´Ù. SSL Åë½ÅÀ» »ç¿ëÇÏ·Á¸é ¸ÕÀú Directory Server¸¦ SSL ¸ðµå¿¡¼­ ±¸¼ºÇÑ ´ÙÀ½ Identity Server¸¦ Directory Server·Î ¿¬°áÇÕ´Ï´Ù. ±âº»ÀûÀÎ ´Ü°Ô´Â ´ÙÀ½°ú °°½À´Ï´Ù.

  1. Directory ServerÀÇ ÀÎÁõ¼­¸¦ ±¸ÇØ ¼³Ä¡Çϰí ÀÎÁõ ±â°ü(CA)ÀÇ ÀÎÁõ¼­¸¦ ½Å·ÚÇϵµ·Ï Directory Server¸¦ ±¸¼ºÇÕ´Ï´Ù.
  2. µð·ºÅ丮¿¡¼­ SSLÀ» Ȱ¼ºÈ­ÇÕ´Ï´Ù.
  3. ÀÎÁõ, Á¤Ã¥ ¹× Ç÷§Æû ¼­ºñ½º¸¦ ±¸¼ºÇÏ¿© SSL »ç¿ë Directory Server·Î ¿¬°áÇÕ´Ï´Ù.
  4. Identity Server¸¦ Directory Server ¹é¿£µå¿¡ ¾ÈÀüÇÏ°Ô ¿¬°áµÇµµ·Ï ±¸¼ºÇÕ´Ï´Ù.

SSL ¸ðµå¿¡¼­ Directory Server ±¸¼º

Directory Server¸¦ SSL ¸ðµå¿¡¼­ ±¸¼ºÇÏ·Á¸é ¼­¹ö ÀÎÁõ¼­¸¦ ±¸ÇÏ¿© ¼³Ä¡Çϰí ÀÎÁõ ±â°üÀÇ ÀÎÁõ¼­¸¦ ½Å·ÚÇϵµ·Ï Directory Server¸¦ ±¸¼ºÇÑ ´ÙÀ½ SSLÀ» Ȱ¼ºÈ­ÇØ¾ß ÇÕ´Ï´Ù. ÀÚ¼¼ÇÑ ³»¿ëÀº Directory Server °ü¸® ¼³¸í¼­ÀÇ 11Àå "ÀÎÁõ ¹× ¾Ïȣȭ °ü¸®"¿¡ ÀÖ½À´Ï´Ù. ÀÌ ¹®¼­´Â ´ÙÀ½ À§Ä¡¿¡ ÀÖ½À´Ï´Ù.

¶ÇÇÑ ´ÙÀ½ À§Ä¡¿¡¼­ PDF ÇüÅÂÀÇ ¼³¸í¼­¸¦ ´Ù¿î·ÎµåÇÒ ¼ö ÀÖ½À´Ï´Ù.

http://docs.sun.com/coll/DirectoryServer_04q2¿Í http://docs.sun.com/coll/DirectoryServer_04q2_ko

Directory Server°¡ ÀÌ¹Ì SSL »ç¿ë °¡´É »óÅÂÀ̸é Identity Server¸¦ Directory Server·Î ¿¬°áÇÏ´Â ¹æ¹ýÀ» ÀÚ¼¼È÷ ¼³¸íÇÑ ´ÙÀ½ Àý·Î ³Ñ¾î°¡½Ê½Ã¿À.

Identity Server¸¦ SSL »ç¿ë Directory Server·Î ¿¬°á

ÀÏ´Ü SSL ¸ðµå·Î Directory Server°¡ ±¸¼ºµÈ ´ÙÀ½¿¡´Â Identity Server¸¦ Directory Server ¹é¿£µå·Î ¿¬°áÇØ¾ß ÇÕ´Ï´Ù. ¼öÇà ¹æ¹ý:

  1. Identity Server Äֿܼ¡¼­ ¼­ºñ½º ±¸¼º ¸ðµâÀÇ LDAP ÀÎÁõ ¼­ºñ½º·Î À̵¿ÇÕ´Ï´Ù.
    1. Directory Server Æ÷Æ®¸¦ SSL Æ÷Æ®·Î º¯°æÇÕ´Ï´Ù.
    2. LDAP ¼­¹ö¿¡ ´ëÇÑ SSL ¾×¼¼½º °¡´É ¼Ó¼ºÀ» ¼±ÅÃÇÕ´Ï´Ù.
  2. ¼­ºñ½º ±¸¼º ¸ðµâÀÇ ±¸¼º¿ø ÀÎÁõ ¼­ºñ½º·Î À̵¿ÇÕ´Ï´Ù.
    1. Directory Server Æ÷Æ®¸¦ SSL Æ÷Æ®·Î º¯°æÇÕ´Ï´Ù.
    2. LDAP ¼­¹ö¿¡ ´ëÇÑ SSL ¾×¼¼½º °¡´É ¼Ó¼ºÀ» ¼±ÅÃÇÕ´Ï´Ù.
  3. ¼­ºñ½º ±¸¼º ¸ðµâÀÇ Á¤Ã¥ ±¸¼º ÀÎÁõ ¼­ºñ½º·Î À̵¿ÇÕ´Ï´Ù.
    1. Directory Server Æ÷Æ®¸¦ SSL Æ÷Æ®·Î º¯°æÇÕ´Ï´Ù.
    2. LDAP ¼­¹ö¿¡ ´ëÇÑ SSL ¾×¼¼½º °¡´É ¼Ó¼ºÀ» ¼±ÅÃÇÕ´Ï´Ù.
  4. ÅØ½ºÆ® ÆíÁý±â¿¡¼­ serverconfig.xml ÆÄÀÏÀ» ¿±´Ï´Ù. ÀÌ ÆÄÀÏÀº ´ÙÀ½ À§Ä¡¿¡ ÀÖ½À´Ï´Ù.
  5. etc/opt/SUNWam/config

    1. <Server> ¿ä¼Ò¿¡¼­ ´ÙÀ½ °ªÀ» º¯°æÇÕ´Ï´Ù.
    2. port - Identity Server°¡ ¼ö½ÅÇÏ´Â º¸¾È Æ÷Æ®ÀÇ Æ÷Æ® ¹øÈ£¸¦ ÀÔ·ÂÇÕ´Ï´Ù listens (±âº»°ª: 636).

      type- SIMPLEÀ» SSL·Î º¯°æÇÕ´Ï´Ù.

    3. serverconfig.xml ÆÄÀÏÀ» ÀúÀåÇÑ ´ÙÀ½ ´Ý½À´Ï´Ù.
  6. ´ÙÀ½ ±âº» À§Ä¡¿¡¼­ AMConfig.properties ÆÄÀÏÀ» ¿±´Ï´Ù.
  7. IdentityServer_base/SUNWam/config

    ´ÙÀ½ µî·Ï Á¤º¸¸¦ º¯°æÇÕ´Ï´Ù.

    1. Directory Port = 636 (±âº»°ªÀ» »ç¿ëÇÒ °æ¿ì)
    2. ssl.enabed = true
    3. AMConfig.properties¸¦ ÀúÀåÇÕ´Ï´Ù.
  8. ¼­¹ö¸¦ ´Ù½Ã ½ÃÀÛÇÕ´Ï´Ù.


ÀÌÀü      ¸ñÂ÷      »öÀÎ      ´ÙÀ½     


Copyright 2004 Sun Microsystems, Inc. ¸ðµç ±Ç¸®´Â ÀúÀÛ±ÇÀÚÀÇ ¼ÒÀ¯ÀÔ´Ï´Ù.