Sun Java logo     ÀÌÀü      ¸ñÂ÷      »öÀÎ      ´ÙÀ½     

Sun logo
Sun Java System Portal Server Secure Remote Access 6 2005Q1 °ü¸® ¼³¸í¼­ 

7Àå
ÀÎÁõ¼­

ÀÌ Àå¿¡¼­´Â ÀÎÁõ¼­ °ü¸®¸¦ ¼³¸íÇÏ°í Á÷Á¢ ¼­¸íÇÑ ÀÎÁõ¼­¿Í ÀÎÁõ ±â°ü¿¡¼­ ¹ÞÀº ÀÎÁõ¼­¸¦ ¼³Ä¡ÇÏ´Â ¹æ¹ýÀ» ¾Ë¾Æº¾´Ï´Ù.

ÀÌ Àå¿¡¼­´Â ´ÙÀ½ ÁÖÁ¦¸¦ ´Ù·ì´Ï´Ù.


SSL ÀÎÁõ¼­ÀÇ °³¿ä

Sun Java™ System Portal Server Secure Remote Access ¼ÒÇÁÆ®¿þ¾î´Â ¿ø°Ý »ç¿ëÀÚ¸¦ À§ÇÑ ÀÎÁõ¼­ ±â¹Ý ÀÎÁõÀ» Á¦°øÇÕ´Ï´Ù. SRA´Â SSL (Secure Socket Layer) À» »ç¿ëÇÏ¿© º¸¾È Åë½ÅÀ» °¡´ÉÇÏ°Ô ÇÕ´Ï´Ù. SSL ÇÁ·ÎÅäÄÝÀ» µÎ ÄÄÇ»ÅÍ °£ º¸¾È Åë½ÅÀ» °¡´ÉÇϵµ·Ï ÇØÁÝ´Ï´Ù.

SSL ÀÎÁõ¼­¿¡¼­´Â °ø°³ Å°¿Í °³ÀÎ Å° ½ÖÀ» »ç¿ëÇÏ¿© ¾Ïȣȭ ¹× ºñ¹Ð¹øÈ£ Çص¶ ±â´ÉÀ» Á¦°øÇÕ´Ï´Ù.

ÀÎÁõ¼­ À¯ÇüÀº 2°¡ÁöÀÔ´Ï´Ù.

±âº»ÀûÀ¸·Î °ÔÀÌÆ®¿þÀ̸¦ ¼³Ä¡ÇÒ ¶§¿¡´Â Á÷Á¢ ¼­¸íÇÑ ÀÎÁõ¼­°¡ »ý¼º ¹× ¼³Ä¡µË´Ï´Ù.

¼³Ä¡ ÈÄ ¾ðÁ¦¶óµµ ÀÎÁõ¼­¸¦ ¼³Ä¡, ½Àµæ ¶Ç´Â ±³Ã¼ÇÒ ¼ö ÀÖ½À´Ï´Ù.

¶ÇÇÑ °³ÀÎ µðÁöÅÐ ÀÎÁõ¼­ (PDC) ¸¦ ÅëÇØ Å¬¶óÀ̾ðÆ® ÀÎÁõÀ» Áö¿øÇÕ´Ï´Ù. PDC´Â SSL Ŭ¶óÀ̾ðÆ® ÀÎÁõÀ¸·Î »ç¿ëÀÚ¸¦ ÀÎÁõÇÏ´Â ¸ÞÄ¿´ÏÁòÀÔ´Ï´Ù. SSL Ŭ¶óÀ̾ðÆ® ÀÎÁõÀ» »ç¿ëÇϸé SSL ÇÚµå¼ÎÀÌÅ©°¡ °ÔÀÌÆ®¿þÀÌ¿¡¼­ Á¾·áµË´Ï´Ù. °ÔÀÌÆ®¿þÀÌ´Â »ç¿ëÀÚÀÇ PDC¸¦ ÃßÃâÇÏ¿© ÀÎÁõµÈ ¼­¹ö·Î Àü´ÞÇÕ´Ï´Ù. ±×·¯¸é ÀÌ ¼­¹ö´Â PDC¸¦ »ç¿ëÇÏ¿© »ç¿ëÀÚ¸¦ ÀÎÁõÇÕ´Ï´Ù. ÀÎÁõ üÀΰú ÇÔ²² PDC¸¦ ±¸¼ºÇÏ·Á¸é ÀÎÁõ üÀÌ´× »ç¿ëÀ» ÂüÁ¶ÇϽʽÿÀ.

SRA¿¡´Â SSL ÀÎÁõ¼­¸¦ °ü¸®ÇÏ´Â µ¥ »ç¿ëÇÒ ¼ö ÀÖ´Â certadminÀ̶ó´Â µµ±¸°¡ ÀÖ½À´Ï´Ù. certadmin ½ºÅ©¸³Æ®¸¦ ÂüÁ¶ÇϽʽÿÀ.


Âü°í   

ÀÎÁõ¼­ Æ˾÷ âÀº SSL ÀÀ¿ë ÇÁ·Î±×·¥¿¡¼­ °øÅëÀûÀ¸·Î ³ªÅ¸³³´Ï´Ù. »ç¿ëÀÚ¿¡°Ô °æ°í¸¦ ½ÂÀÎÇÏ°í °è¼Ó ÁøÇàÇϵµ·Ï ¾Ë·ÁÁֽʽÿÀ.



ÀÎÁõ¼­ ÆÄÀÏ

ÀÎÁõ¼­ °ü·Ã ÆÄÀÏÀº /etc/opt/SUNWps/cert/gateway-profile-name¿¡ ÀÖ½À´Ï´Ù. ÀÌ µð·ºÅ丮¿¡´Â ±âº»ÀûÀ¸·Î ÆÄÀÏÀÌ 5°³ µé¾î ÀÖ½À´Ï´Ù.

Ç¥ 7-1¿¡´Â ÆÄÀÏ°ú ÆÄÀÏ¿¡ ´ëÇÑ ¼³¸íÀÌ ³ª¿­µÇ¾î ÀÖ½À´Ï´Ù.

Ç¥ 7-1  ÀÎÁõ¼­ ÆÄÀÏ

ÆÄÀÏ À̸§

À¯Çü

¼³¸í

cert8.db, key3.db, secmod.db

ÀÌÁø

ÀÎÁõ¼­, Å° ¹× ¾Ïȣȭ ¸ðµâÀ» À§ÇÑ µ¥ÀÌÅÍ°¡ µé¾î ÀÖ½À´Ï´Ù.

certadmin ½ºÅ©¸³Æ®·Î Á¶ÀÛÇÒ ¼ö ÀÖ½À´Ï´Ù.

Sun Java System À¥ ¼­¹ö¿¡¼­ »ç¿ëµÇ´Â µ¥ÀÌÅͺ£À̽º ÆÄÀÏ°ú Çü½ÄÀÌ °°À¸¸ç portal-server-install-root/SUNWwbsvr/alias¿¡ ÀÖ½À´Ï´Ù.

ÇÊ¿ä¿¡ µû¶ó ÀÌ ÆÄÀÏÀº Portal Server È£½ºÆ®¿Í °ÔÀÌÆ®¿þÀÌ ±¸¼º ¿ä¼Ò ¶Ç´Â °ÔÀÌÆ®¿þÀÌ »çÀÌ¿¡¼­ °øÀ¯µÉ ¼ö ÀÖ½À´Ï´Ù.

.jsspass

¼ûÀº ÅؽºÆ® ÆÄÀÏ

SRA Å° µ¥ÀÌÅͺ£À̽º¸¦ À§ÇÑ ¾ÏȣȭµÈ ºñ¹Ð¹øÈ£°¡ µé¾î ÀÖ½À´Ï´Ù.

.nickname

¼ûÀº ÅؽºÆ® ÆÄÀÏ

token-name:certificate-name Çü½ÄÀ¸·Î °ÔÀÌÆ®¿þÀÌ¿¡¼­ »ç¿ëÇØ¾ß ÇÏ´Â ÅäÅ«°ú ÀÎÁõ¼­ À̸§À» ÀúÀåÇÕ´Ï´Ù.

±âº» ÅäÅ« (±âº» ³»ºÎ ¼ÒÇÁÆ®¿þ¾î ¾Ïȣȭ ¸ðµâ¿¡ ÀÖ´Â ÅäÅ«) À» »ç¿ëÇÏ´Â °æ¿ì ÅäÅ« À̸§À» »ý·«ÇϽʽÿÀ. ´ëºÎºÐÀÇ °æ¿ì .nickname ÆÄÀÏÀº ÀÎÁõ¼­ À̸§¸¸ ÀúÀåÇÕ´Ï´Ù.

°ü¸®Àڷμ­ ÀÌ ÆÄÀÏÀÇ ÀÎÁõ¼­ À̸§À» ¼öÁ¤ÇÒ ¼ö ÀÖ½À´Ï´Ù. ÁöÁ¤ÇÑ ÀÎÁõ¼­¸¦ ÀÌÁ¦ °ÔÀÌÆ®¿þÀÌ¿¡¼­ »ç¿ëÇÕ´Ï´Ù.


ÀÎÁõ¼­ Æ®·¯½ºÆ® ¼Ó¼º

ÀÎÁõ¼­ÀÇ Æ®·¯½ºÆ® ¼Ó¼ºÀº ´ÙÀ½°ú °°Àº Á¤º¸¸¦ ³ªÅ¸³À´Ï´Ù.

°¢ ÀÎÁõ¼­¿¡´Â "SSL, ÀüÀÚ ¸ÞÀÏ, °´Ã¼ ¼­¸í" ¼ø¼­·Î »ç¿ëÇÒ ¼ö ÀÖ´Â Æ®·¯½ºÆ® ¹üÁÖ°¡ 3°¡Áö ÀÖ½À´Ï´Ù. ù ¹ø° ¹üÁÖ¸¸ °ÔÀÌÆ®¿þÀÌ¿¡ À¯¿ëÇÕ´Ï´Ù. °¢ ¹üÁÖ À§Ä¡¿¡¼­ Æ®·¯½ºÆ® ¼Ó¼º Äڵ尡 »ç¿ëµÇÁö ¾ÊÀ» ¼öµµ ÀÖ°í ¸¹ÀÌ »ç¿ëµÇ±âµµ ÇÕ´Ï´Ù.

¹üÁÖ¿¡ ´ëÇÑ ¼Ó¼º ÄÚµå´Â ½°Ç¥·Î ºÐ¸®µÇ¸ç Àüü ¼Ó¼º ÁýÇÕÀº µû¿ÈÇ¥·Î ¹­ÀÔ´Ï´Ù. ¿¹¸¦ µé¾î, °ÔÀÌÆ®¿þÀÌ ¼³Ä¡ ½Ã »ý¼º ¹× ¼³Ä¡µÈ Á÷Á¢ ¼­¸íÇÑ ÀÎÁõ¼­´Â "u,u,u"·Î Ç¥½ÃµÇ´Âµ¥ ÀÌ´Â ·çÆ® CA ÀÎÁõ¼­¿Í´Â ¹Ý´ë·Î ¼­¹ö ÀÎÁõ¼­ (»ç¿ëÀÚ ÀÎÁõ¼­) ÀÓÀ» ÀǹÌÇÕ´Ï´Ù.

Ç¥ 7-2¿¡´Â °¡´ÉÇÑ ¼Ó¼º °ª°ú °¢ °ªÀÇ Àǹ̰¡ ³ª¿­µÇ¾î ÀÖ½À´Ï´Ù.

Ç¥ 7-2  ÀÎÁõ¼­ Æ®·¯½ºÆ® ¼Ó¼º 

¼Ó¼º

¼³¸í

p

À¯È¿ÇÑ ÇǾî

P

ÀÎÁõµÈ ÇǾî (p ³»Æ÷)

c

À¯È¿ÇÑ CA

T

Ŭ¶óÀ̾ðÆ® ÀÎÁõ¼­¸¦ ¹ß±ÞÇÒ ¼ö ÀÖµµ·Ï ÀÎÁõµÈ CA (c ³»Æ÷)

C

¼­¹ö ÀÎÁõ¼­¸¦ ¹ß±ÞÇÒ ¼ö ÀÖµµ·Ï ÀÎÁõµÈ CA (SSL Àü¿ë) (c ³»Æ÷)

u

ÀÎÁõ¼­¸¦ ÀÎÁõÀ̳ª ¼­¸í¿¡ »ç¿ëÇÒ ¼ö ÀÖÀ½

w

°æ°í Àü¼Û (ÇØ´ç ÄÁÅؽºÆ®¿¡¼­ ÀÎÁõ¼­°¡ »ç¿ëµÉ °æ¿ì ´Ù¸¥ ¼Ó¼º°ú ÇÔ²² »ç¿ëÇÏ¿© °æ°í Æ÷ÇÔ)


CA Æ®·¯½ºÆ® ¼Ó¼º

Àß ¾Ë·ÁÁø °øÀÎ CA´Â ´ëºÎºÐ ÀÎÁõ¼­ µ¥ÀÌÅͺ£À̽º¿¡ µé¾î ÀÖ½À´Ï´Ù. °øÀÎ CAÀÇ Æ®·¯½ºÆ® ¼Ó¼º ¼öÁ¤¿¡ ´ëÇÑ ³»¿ëÀº ÀÎÁõ¼­ÀÇ Æ®·¯½ºÆ® ¼Ó¼º ¼öÁ¤À» ÂüÁ¶ÇϽʽÿÀ.

Ç¥ 7-3¿¡´Â Æ®·¯½ºÆ® ¼Ó¼ºÀÌ ÀÖ´Â °¡Àå ÀϹÝÀûÀÎ ÀÎÁõ ±â°üÀÌ ³ª¿­µÇ¾î ÀÖ½À´Ï´Ù.

Ç¥ 7-3  °øÀÎ ÀÎÁõ ±â°ü 

ÀÎÁõ ±â°ü À̸§

Æ®·¯½ºÆ® ¼Ó¼º

Verisign/RSA Secure Server CA

CPp,CPp,CPp

VeriSign Class 4 Primary CA

CPp,CPp,CPp

GTE CyberTrust Root CA

CPp,CPp,CPp

GTE CyberTrust Global Root

CPp,CPp,CPp

GTE CyberTrust Root 5

CPp,CPp,CPp

GTE CyberTrust Japan Root CA

CPp,CPp,CPp

GTE CyberTrust Japan Secure Server CA

CPp,CPp,CPp

Thawte Personal Basic CA

CPp,CPp,CPp

Thawte Personal Premium CA

CPp,CPp,CPp

Thawte Personal Freemail CA

CPp,CPp,CPp

Thawte Server CA

CPp,CPp,CPp

Thawte Premium Server CA

CPp,CPp,CPp

American Express CA

CPp,CPp,CPp

American Express Global CA

CPp,CPp,CPp

Equifax Premium CA

CPp,CPp,CPp

Equifax Secure CA

CPp,CPp,CPp

BelSign Object Publishing CA

CPp,CPp,CPp

BelSign Secure Server CA

CPp,CPp,CPp

TC TrustCenter, Germany, Class 0 CA

CPp,CPp,CPp

TC TrustCenter, Germany, Class 1 CA

CPp,CPp,CPp

TC TrustCenter, Germany, Class 2 CA

CPp,CPp,CPp

TC TrustCenter, Germany, Class 3 CA

CPp,CPp,CPp

TC TrustCenter, Germany, Class 4 CA

CPp,CPp,CPp

ABAecom (sub., Am. Bankers Assn.) Root CA

CPp,CPp,CPp

Digital Signature Trust Co. Global CA 1

CPp,CPp,CPp

Digital Signature Trust Co. Global CA 3

CPp,CPp,CPp

Digital Signature Trust Co. Global CA 2

CPp,CPp,CPp

Digital Signature Trust Co. Global CA 4

CPp,CPp,CPp

Deutsche Telekom AG Root CA

CPp,CPp,CPp

Verisign Class 1 Public Primary Certification Authority

CPp,CPp,CPp

Verisign Class 2 Public Primary Certification Authority

CPp,CPp,CPp

Verisign Class 3 Public Primary Certification Authority

CPp,CPp,CPp

Verisign Class 1 Public Primary Certification Authority - G2

CPp,CPp,CPp

Verisign Class 2 Public Primary Certification Authority - G2

CPp,CPp,CPp

Verisign Class 3 Public Primary Certification Authority - G2

CPp,CPp,CPp

Verisign Class 4 Public Primary Certification Authority - G2

CPp,CPp,CPp

GlobalSign Root CA

CPp,CPp,CPp

GlobalSign Partners CA

CPp,CPp,CPp

GlobalSign Primary Class 1 CA

CPp,CPp,CPp

GlobalSign Primary Class 2 CA

CPp,CPp,CPp

GlobalSign Primary Class 3 CA

CPp,CPp,CPp

ValiCert Class 1 VA

CPp,CPp,CPp

ValiCert Class 2 VA

CPp,CPp,CPp

ValiCert Class 3 VA

CPp,CPp,CPp

Thawte Universal CA Root

CPp,CPp,CPp

Verisign Class 1 Public Primary Certification Authority - G3

CPp,CPp,CPp

Verisign Class 2 Public Primary Certification Authority - G3

CPp,CPp,CPp

Verisign Class 3 Public Primary Certification Authority - G3

CPp,CPp,CPp

Verisign Class 4 Public Primary Certification Authority - G3

CPp,CPp,CPp

Entrust.net Secure Server CA

CPp,CPp,CPp

Entrust.net Secure Personal CA

CPp,CPp,CPp

Entrust.net Premium 2048 Secure Server CA

CPp,CPp,CPp

ValiCert OCSP Responder

CPp,CPp,CPp

Baltimore CyberTrust Code Signing Root

CPp,CPp,CPp

Baltimore CyberTrust Root

CPp,CPp,CPp

Baltimore CyberTrust Mobile Commerce Root

CPp,CPp,CPp

Equifax Secure Global eBusiness CA

CPp,CPp,CPp

Equifax Secure eBusiness CA 1

CPp,CPp,CPp

Equifax Secure eBusiness CA 2

CPp,CPp,CPp

Visa International Global Root 1

CPp,CPp,CPp

Visa International Global Root 2

CPp,CPp,CPp

Visa International Global Root 3

CPp,CPp,CPp

Visa International Global Root 4

CPp,CPp,CPp

Visa International Global Root 5

CPp,CPp,CPp

beTRUSTed Root CA

CPp,CPp,CPp

Xcert Root CA

CPp,CPp,CPp

Xcert Root CA 1024

CPp,CPp,CPp

Xcert Root CA v1

CPp,CPp,CPp

Xcert Root CA v1 1024

CPp,CPp,CPp

Xcert EZ

CPp,CPp,CPp

CertEngine CA

CPp,CPp,CPp

BankEngine CA

CPp,CPp,CPp

FortEngine CA

CPp,CPp,CPp

MailEngine CA

CPp,CPp,CPp

TraderEngine CA

CPp,CPp,CPp

USPS Root

CPp,CPp,CPp

USPS Production 1

CPp,CPp,CPp

AddTrust Non-Validated Services Root

CPp,CPp,CPp

AddTrust External Root

CPp,CPp,CPp

AddTrust Public Services Root

CPp,CPp,CPp

AddTrust Qualified Certificates Root

CPp,CPp,CPp

Verisign Class 1 Public Primary OCSP Responder

CPp,CPp,CPp

Verisign Class 2 Public Primary OCSP Responder

CPp,CPp,CPp

Verisign Class 3 Public Primary OCSP Responder

CPp,CPp,CPp

Verisign Secure Server OCSP Responder

CPp,CPp,CPp

Verisign Time Stamping Authority CA

CPp,CPp,CPp

Thawte Time Stamping CA

CPp,CPp,CPp

E-Certify CA

CPp,CPp,CPp

E-Certify RA

CPp,CPp,CPp

Entrust.net Global Secure Server CA

CPp,CPp,CPp

Entrust.net Global Secure Personal CA

CPp,CPp,CPp


certadmin ½ºÅ©¸³Æ®

´ÙÀ½°ú °°Àº ÀÎÁõ¼­ °ü¸® ÀÛ¾÷¿¡ certadmin ½ºÅ©¸³Æ®¸¦ »ç¿ëÇÒ ¼ö ÀÖ½À´Ï´Ù.


Á÷Á¢ ¼­¸íÇÑ ÀÎÁõ¼­ »ý¼º

°¢ ¼­¹ö¿Í °ÔÀÌÆ®¿þÀÌ »çÀÌÀÇ SSL Åë½ÅÀ» À§Çؼ­´Â ÀÎÁõ¼­¸¦ »ý¼ºÇØ¾ß ÇÕ´Ï´Ù.

    ¼³Ä¡ ÈÄ Á÷Á¢ ¼­¸íÇÑ ÀÎÁõ¼­¸¦ »ý¼ºÇÏ·Á¸é

  1. ·çÆ®·Î¼­ ÀÎÁõ¼­¸¦ »ý¼ºÇÏ°íÀÚ ÇÏ´Â °ÔÀÌÆ®¿þÀÌ ÄÄÇ»ÅÍ¿¡ certadmin ½ºÅ©¸³Æ®¸¦ ½ÇÇàÇÕ´Ï´Ù.
  2. portal-server-install-root/SUNWps/bin/certadmin -n gateway-profile-name

    ÀÎÁõ¼­ °ü¸® ¸Þ´º°¡ Ç¥½ÃµË´Ï´Ù.

    1) Generate Self-Signed Certificate

    2) Generate Certificate Signing Request (CSR)

    3) Add Root CA Certificate

    4) Install Certificate From Certificate Authority (CA)

    5) Delete Certificate

    6) Modify Trust Attributes of Certificate (e.g., for PDC)

    7) List Root CA Certificates

    8) List All Certificates

    9) Print Certificate Content

    10) Quit

    choice: [10] 1

  3. ÀÎÁõ¼­ °ü¸® ¸Þ´ºÀÇ ¿É¼Ç 1¸¦ ¼±ÅÃÇÕ´Ï´Ù.
  4. ÀÎÁõ¼­ °ü¸® ½ºÅ©¸³Æ®¿¡¼­ ±âÁ¸ µ¥ÀÌÅͺ£À̽º ÆÄÀÏÀ» À¯ÁöÇÒ °ÍÀÎÁö ¹¯½À´Ï´Ù.

  5. Á¶Á÷º° Á¤º¸, ÅäÅ« À̸§ ¹× ÀÎÁõ¼­ À̸§À» ÀÔ·ÂÇÕ´Ï´Ù.

    Âü°í    

    ¿ÍÀϵåÄ«µå ÀÎÁõ¼­¿¡´Â È£½ºÆ®ÀÇ Á¤±Ô DNS À̸§¿¡ *¸¦ ÁöÁ¤ÇÕ´Ï´Ù. ¿¹¸¦ µé¾î, È£½ºÆ®ÀÇ Á¤±Ô DNS À̸§ÀÌ abc.sesta.comÀ̸é *.sesta.comÀ¸·Î ÁöÁ¤ÇÕ´Ï´Ù. ÀÌÁ¦ »ý¼ºµÈ ÀÎÁõ¼­´Â sesta.com µµ¸ÞÀο¡ ÀÖ´Â ¸ðµç È£½ºÆ® À̸§¿¡ À¯È¿ÇÕ´Ï´Ù.


  6. What is the fully-qualified DNS name of this host? [host_name.domain_name]

    What is the name of your organization (ex: Company)? []

    What is the name of your organizational unit (ex: division)? []

    What is the name of your City or Locality? []

    What is the name (no abbreviation please) of your State or Province? []

    What is the two-letter country code for this unit? []

    Token name is needed only if you are not using the default internal (software) cryptographic module, for example, if you want to use a crypto card (Token names could be listed using: modutil -dbdir /etc/opt/SUNWps/cert/gateway-profile-name -list); Otherwise, just hit Return below.

    Please enter the token name. []

    Enter the name you like for this certificate?

    Enter the validity period for the certificate (months) [6]

    A self-signed certificate is generated and the prompt returns.

    ÅäÅ« À̸§ (±âº»ÀûÀ¸·Î ºñ¾î ÀÖÀ½) °ú ÀÎÁõ¼­ À̸§Àº /etc/opt/SUNWps/cert/gateway-profile-nameÀÇ .nickname ÆÄÀÏ¿¡ ÀúÀåµË´Ï´Ù.

  7. ÀÎÁõ¼­°¡ Àû¿ëµÇµµ·Ï °ÔÀÌÆ®¿þÀ̸¦ ´Ù½Ã ½ÃÀÛÇÕ´Ï´Ù.
  8. gateway-install-root/SUNWps/bin/gateway -n new gateway-profile-name start


ÀÎÁõ¼­ ¼­¸í ¿äû (CSR) »ý¼º

CA°¡ ¹ß±ÞÇÏ´Â ÀÎÁõ¼­¸¦ ÁÖ¹®Çϱâ Àü¿¡ CA¿¡¼­ ¿ä±¸ÇÏ´Â Á¤º¸°¡ µé¾î ÀÖ´Â ÀÎÁõ¼­ ¼­¸í ¿äûÀ» ¸¸µé¾î¾ß ÇÕ´Ï´Ù.

    CSR¸¦ »ý¼ºÇÏ·Á¸é
  1. ·çÆ®·Î¼­ certadmin ½ºÅ©¸³Æ®¸¦ ½ÇÇàÇÕ´Ï´Ù.
  2. portal-server-install-root/SUNWps/bin/certadmin -n gateway-profile-name

    ÀÎÁõ¼­ °ü¸® ¸Þ´º°¡ Ç¥½ÃµË´Ï´Ù.

    1) Generate Self-Signed Certificate

    2) Generate Certificate Signing Request (CSR)

    3) Add Root CA Certificate

    4) Install Certificate From Certificate Authority (CA)

    5) Delete Certificate

    6) Modify Trust Attributes of Certificate (e.g., for PDC)

    7) List Root CA Certificates

    8) List All Certificates

    9) Print Certificate Content

    10) Quit

    choice: [10] 2

  3. ÀÎÁõ¼­ °ü¸® ¸Þ´ºÀÇ ¿É¼Ç 2¸¦ ¼±ÅÃÇÕ´Ï´Ù.
  4. ½ºÅ©¸³Æ®¿¡¼­ Á¶Á÷º° Á¤º¸, ÅäÅ« À̸§ ¹× À¥ ¸¶½ºÅÍÀÇ ÀüÀÚ ¿ìÆí°ú ÀüÈ­ ¹øÈ£¸¦ ÀÔ·ÂÇ϶ó´Â ¸Þ½ÃÁö¸¦ Ç¥½ÃÇÕ´Ï´Ù.

    È£½ºÆ®ÀÇ Á¤±Ô DNS À̸§À» ¹Ýµå½Ã ÁöÁ¤ÇØ¾ß ÇÕ´Ï´Ù.

    What is the fully-qualified DNS name of this host? [snape.sesta.com]

    What is the name of your organization (ex: Company)? []

    What is the name of your organizational unit (ex: division)? []

    What is the name of your City or Locality? []

    What is the name (no abbreviation please) of your State or Province? []

    What is the two-letter country code for this unit? []

    Token name is needed only if you are not using the default internal (software) cryptographic module, for example, if you want to use a crypto card (Token names could be listed using: modutil -dbdir /etc/opt/SUNWps/cert -list); Otherwise, just hit Return below.

    Please enter the token name []

    Now input some contact information for the webmaster of the machine that the certificate is to be generated for.

    What is the email address of the admin/webmaster for this server [] ?

    What is the phone number of the admin/webmaster for this server [] ?

  5. ÇÊ¿äÇÑ Á¤º¸¸¦ ¸ðµÎ ÀÔ·ÂÇϽʽÿÀ.

  6. Âü°í   

    À¥ ¸¶½ºÅÍÀÇ ÀüÀÚ ¸ÞÀÏ°ú ÀüÈ­ ¹øÈ£¸¦ °ø¹éÀ¸·Î ³²°ÜµÎÁö ¸¶½Ê½Ã¿À. ÀÌ Á¤º¸´Â À¯È¿ÇÑ CSR¸¦ ¹Þ´Â µ¥ ÇÊ¿äÇÕ´Ï´Ù.


CSRÀÌ »ý¼ºµÇ¾î portal-server-install-root/SUNWps/bin/csr.hostname.datetimestamp ÆÄÀÏ¿¡ ÀúÀåµË´Ï´Ù. CSRÀº È­¸é¿¡µµ ÀμâµË´Ï´Ù. CA°¡ ¹ß±ÞÇÏ´Â ÀÎÁõ¼­¸¦ ÁÖ¹®ÇÒ ¶§ CSR¸¦ Á÷Á¢ º¹»çÇÑ ÈÄ ºÙ¿©³ÖÀ» ¼ö ÀÖ½À´Ï´Ù.


·çÆ® CA ÀÎÁõ¼­ Ãß°¡

Ŭ¶óÀ̾ðÆ® »çÀÌÆ®¿¡¼­ °ÔÀÌÆ®¿þÀÌ ÀÎÁõ¼­ µ¥ÀÌÅͺ£À̽º¿¡ ¾Ë·ÁÁöÁö ¾ÊÀº CA¿¡¼­ ¼­¸íÇÑ ÀÎÁõ¼­¸¦ Á¦½ÃÇϸé SSL ÇÚµå¼ÎÀÌÅ©°¡ ½ÇÆÐÇÕ´Ï´Ù.

À̸¦ ¹æÁöÇÏ·Á¸é ·çÆ® CA ÀÎÁõ¼­¸¦ ÀÎÁõ¼­ µ¥ÀÌÅͺ£À̽º¿¡ Ãß°¡ÇØ¾ß ÇÕ´Ï´Ù. ±×·¯¸é °ÔÀÌÆ®¿þÀÌ¿¡¼­ CA¸¦ ÀνÄÇÒ ¼ö ÀÖ°Ô µË´Ï´Ù.

CAÀÇ À¥ »çÀÌÆ®¸¦ ã¾Æ¼­ ÇØ´ç CAÀÇ ·çÆ® ÀÎÁõ¼­¸¦ ¾òÀ¸½Ê½Ã¿À. certadmin ½ºÅ©¸³Æ®¸¦ »ç¿ëÇÒ ¶§ ÆÄÀÏ À̸§°ú ·çÆ® CA ÀÎÁõ¼­ÀÇ °æ·Î¸¦ ÁöÁ¤ÇÕ´Ï´Ù.

    ·çÆ® CA ÀÎÁõ¼­¸¦ Ãß°¡ÇÏ·Á¸é
  1. ·çÆ®·Î¼­ certadmin ½ºÅ©¸³Æ®¸¦ ½ÇÇàÇÕ´Ï´Ù.
  2. portal-server-install-root/SUNWps/bin/certadmin -n gateway-profile-name

    ÀÎÁõ¼­ °ü¸® ¸Þ´º°¡ Ç¥½ÃµË´Ï´Ù.

    1) Generate Self-Signed Certificate

    2) Generate Certificate Signing Request (CSR)

    3) Add Root CA Certificate

    4) Install Certificate From Certificate Authority (CA)

    5) Delete Certificate

    6) Modify Trust Attributes of Certificate (e.g., for PDC)

    7) List Root CA Certificates

    8) List All Certificates

    9) Print Certificate Content

    10) Quit

    choice: [10] 3

  3. ÀÎÁõ¼­ °ü¸® ¸Þ´ºÀÇ ¿É¼Ç 3À» ¼±ÅÃÇÕ´Ï´Ù.
  4. ·çÆ® ÀÎÁõ¼­°¡ µé¾î ÀÖ´Â ÆÄÀÏ À̸§À» ÀÔ·ÂÇÑ ´ÙÀ½ ÀÎÁõ¼­ À̸§À» ÀÔ·ÂÇÕ´Ï´Ù.
  5. ±×·¯¸é ·çÆ® CA ÀÎÁõ¼­°¡ ÀÎÁõ¼­ µ¥ÀÌÅͺ£À̽º¿¡ Ãß°¡µË´Ï´Ù.


ÀÎÁõ ±â°ü¿¡¼­ ¹ß±ÞÇÑ SSL ÀÎÁõ¼­ ¼³Ä¡

°ÔÀÌÆ®¿þÀ̸¦ ¼³Ä¡ÇÏ´Â µ¿¾È ±âº»ÀûÀ¸·Î Á÷Á¢ ¼­¸íÇÑ ÀÎÁõ¼­°¡ ¸¸µé¾îÁ® ¼³Ä¡µË´Ï´Ù. ¼³Ä¡ ÈÄ ¾ðÁ¦¶óµµ °ø½Ä ÀÎÁõ ±â°ü (CA) ¼­ºñ½º¸¦ Á¦°øÇÏ´Â °ø±ÞÀÚ ¶Ç´Â ±â¾÷ CA¿¡ ÀÇÇØ ¼­¸íµÈ SSL ÀÎÁõ¼­¸¦ ¼³Ä¡ÇÒ ¼ö ÀÖ½À´Ï´Ù.

ÀÌ ÀÛ¾÷Àº ´ÙÀ½°ú °°Àº 3´Ü°è·Î ÀÌ·ç¾îÁý´Ï´Ù.

CA¿¡¼­ ¹ß±ÞÇÏ´Â ÀÎÁõ¼­ ÁÖ¹®

ÀÎÁõ¼­ ¼­¸í ¿äû (CSR)À» ¸¸µé¾úÀ¸¸é CSR¸¦ »ç¿ëÇÏ¿© CA°¡ ¹ß±ÞÇÏ´Â ÀÎÁõ¼­¸¦ ÁÖ¹®ÇØ¾ß ÇÕ´Ï´Ù.

    CA°¡ ¹ß±ÞÇÏ´Â ÀÎÁõ¼­¸¦ ÁÖ¹®ÇÏ·Á¸é
  1. ÀÎÁõ ±â°üÀÇ À¥ »çÀÌÆ®·Î °¡¼­ ÀÎÁõ¼­¸¦ ÁÖ¹®ÇÕ´Ï´Ù.
  2. CAÀÇ ¿äû¿¡ µû¶ó CSR¸¦ Á¦°øÇÕ´Ï´Ù. CAÀÇ ¿äû¿¡ µû¶ó ±âŸ Á¤º¸µµ Á¦°øÇÕ´Ï´Ù.
  3. ±×·¯¸é CA°¡ ¹ß±ÞÇÏ´Â ÀÎÁõ¼­¸¦ ¹Þ°Ô µË´Ï´Ù. ÀÎÁõ¼­¸¦ ÆÄÀÏ¿¡ ÀúÀåÇÕ´Ï´Ù. ÆÄÀÏ¿¡ ÀÎÁõ¼­¿Í ÇÔ²² "BEGIN CERTIFICATE" ¹× "END CERTIFICATE" ÁÙÀ» Æ÷ÇÔ½Ãŵ´Ï´Ù.

    ´ÙÀ½ ¿¹Á¦¿¡¼­´Â ½ÇÁ¦ ÀÎÁõ¼­ µ¥ÀÌÅ͸¦ »ý·«ÇÏ¿´½À´Ï´Ù.

    -----BEGIN CERTIFICATE-----

    The certificate ¸ñÂ÷...

    ----END CERTIFICATE-----

CA¿¡¼­ ¹ÞÀº ÀÎÁõ¼­ ¼³Ä¡

certadmin ½ºÅ©¸³Æ®¸¦ »ç¿ëÇÏ¿© CA¿¡¼­ ¹ÞÀº ÀÎÁõ¼­¸¦ /etc/opt/SUNWps/cert/gateway-profile-nameÀÇ ·ÎÄà µ¥ÀÌÅͺ£À̽º ÆÄÀÏ¿¡ ¼³Ä¡ÇÕ´Ï´Ù.

    CA¿¡¼­ ¹ÞÀº ÀÎÁõ¼­¸¦ ¼³Ä¡ÇÏ·Á¸é
  1. ·çÆ®·Î¼­ certadmin ½ºÅ©¸³Æ®¸¦ ½ÇÇàÇÕ´Ï´Ù.
  2. portal-server-install-root/SUNWps/bin/certadmin -n gateway-profile-name

    ÀÎÁõ¼­ °ü¸® ¸Þ´º°¡ Ç¥½ÃµË´Ï´Ù.

    1) Generate Self-Signed Certificate

    2) Generate Certificate Signing Request (CSR)

    3) Add Root CA Certificate

    4) Install Certificate From Certificate Authority (CA)

    5) Delete Certificate

    6) Modify Trust Attributes of Certificate (e.g., for PDC)

    7) List Root CA Certificates

    8) List All Certificates

    9) Print Certificate Content

    10) Quit

    choice: [10] 4

  3. ÀÎÁõ¼­ °ü¸® ¸Þ´ºÀÇ ¿É¼Ç 4¸¦ ¼±ÅÃÇÕ´Ï´Ù.
  4. ½ºÅ©¸³Æ®¿¡¼­ ÀÎÁõ¼­ ÆÄÀÏ À̸§, ÀÎÁõ¼­ À̸§ ¹× ÅäÅ« À̸§À» ÀÔ·ÂÇ϶ó°í ¿äûÇÕ´Ï´Ù.

    What is the name (including path) of file that contains the certificate?

    Please enter the token name you used when creating CSR for this certificate. []

  5. ÇÊ¿äÇÑ Á¤º¸¸¦ ¸ðµÎ ÀÔ·ÂÇϽʽÿÀ.
  6. ÀÎÁõ¼­°¡ /etc/opt/SUNWps/cert/gateway-profile-name¿¡ ¼³Ä¡µÇ°í È­¸é ¸Þ½ÃÁö°¡ ³ªÅ¸³³´Ï´Ù.

  7. ÀÎÁõ¼­°¡ Àû¿ëµÇµµ·Ï °ÔÀÌÆ®¿þÀ̸¦ ´Ù½Ã ½ÃÀÛÇÕ´Ï´Ù.
  8. gateway-install-root/SUNWps/bin/gateway -n gateway-profile-name start


ÀÎÁõ¼­ »èÁ¦

ÀÎÁõ¼­ °ü¸® ½ºÅ©¸³Æ®¸¦ »ç¿ëÇϸé ÀÎÁõ¼­¸¦ »èÁ¦ÇÒ ¼ö ÀÖ½À´Ï´Ù.

    ÀÎÁõ¼­¸¦ »èÁ¦ÇÏ·Á¸é
  1. ·çÆ®·Î¼­ certadmin ½ºÅ©¸³Æ®¸¦ ½ÇÇàÇÕ´Ï´Ù.
  2. portal-server-install-root/SUNWps/bin/certadmin -n gateway-profile-name

    ¿©±â¼­ gateway-profile-nameÀº °ÔÀÌÆ®¿þÀÌ ÀνºÅϽºÀÇ À̸§ÀÔ´Ï´Ù.

    ÀÎÁõ¼­ °ü¸® ¸Þ´º°¡ Ç¥½ÃµË´Ï´Ù.

    1) Generate Self-Signed Certificate

    2) Generate Certificate Signing Request (CSR)

    3) Add Root CA Certificate

    4) Install Certificate From Certificate Authority (CA)

    5) Delete Certificate

    6) Modify Trust Attributes of Certificate (e.g., for PDC)

    7) List Root CA Certificates

    8) List All Certificates

    9) Print Certificate Content

    10) Quit

    choice: [10] 5

  3. ÀÎÁõ¼­ °ü¸® ¸Þ´ºÀÇ ¿É¼Ç 5¸¦ ¼±ÅÃÇÕ´Ï´Ù.
  4. »èÁ¦ÇÒ ÀÎÁõ¼­ÀÇ À̸§À» ÀÔ·ÂÇϽʽÿÀ.


ÀÎÁõ¼­ÀÇ Æ®·¯½ºÆ® ¼Ó¼º ¼öÁ¤

ÀÎÁõ¼­ÀÇ Æ®·¯½ºÆ® ¼Ó¼ºÀ» ¼öÁ¤ÇØ¾ß ÇÏ´Â ÇÑ °æ¿ì´Â °ÔÀÌÆ®¿þÀÌ¿¡¼­ Ŭ¶óÀ̾ðÆ® ÀÎÁõÀÌ »ç¿ëµÉ ¶§ÀÔ´Ï´Ù. Ŭ¶óÀ̾ðÆ® ÀÎÁõÀÇ ÇÑ ¿¹´Â PDC (Personal Digital Certificate)ÀÔ´Ï´Ù. PDC¸¦ ¹ß±ÞÇÏ´Â CA´Â °ÔÀÌÆ®¿þÀÌ¿¡ ÀÇÇØ ÀÎÁõµÇ¾î¾ß Çϸç CA ÀÎÁõ¼­¿¡´Â SSL¿ëÀ¸·Î "T"¶ó°í Ç¥½ÃµÇ¾î ÀÖ¾î¾ß ÇÕ´Ï´Ù.

°ÔÀÌÆ®¿þÀÌ ±¸¼º ¿ä¼Ò°¡ HTTPS »çÀÌÆ®¿Í Åë½ÅÇϵµ·Ï ¼³Á¤µÈ °æ¿ì HTTPS »çÀÌÆ® ¼­¹ö ÀÎÁõ¼­ÀÇ CA´Â °ÔÀÌÆ®¿þÀÌ¿¡¼­ ÀÎÁõµÇ¾î¾ß Çϸç CA ÀÎÁõ¼­¿¡´Â SSL¿ëÀÇ "C" Ç¥½Ã°¡ ÀÖ¾î¾ß ÇÕ´Ï´Ù.

    ÀÎÁõ¼­ÀÇ Æ®·¯½ºÆ® ¼Ó¼ºÀ» ¼öÁ¤ÇÏ·Á¸é
  1. ·çÆ®·Î¼­ certadmin ½ºÅ©¸³Æ®¸¦ ½ÇÇàÇÕ´Ï´Ù.
  2. gateway-install-root/SUNWps/bin/certadmin -n gateway-profile-name

    ¿©±â¼­ gateway-profile-nameÀº °ÔÀÌÆ®¿þÀÌ ÀνºÅϽºÀÇ À̸§ÀÔ´Ï´Ù.

    ÀÎÁõ¼­ °ü¸® ¸Þ´º°¡ Ç¥½ÃµË´Ï´Ù.

    1) Generate Self-Signed Certificate

    2) Generate Certificate Signing Request (CSR)

    3) Add Root CA Certificate

    4) Install Certificate From Certificate Authority (CA)

    5) Delete Certificate

    6) Modify Trust Attributes of Certificate (e.g., for PDC)

    7) List Root CA Certificates

    8) List All Certificates

    9) Print Certificate Content

    10) Quit

    choice: [10] 6

  3. ÀÎÁõ¼­ °ü¸® ¸Þ´ºÀÇ ¿É¼Ç 6¸¦ ¼±ÅÃÇÕ´Ï´Ù.
  4. ÀÎÁõ¼­ÀÇ À̸§À» ÀÔ·ÂÇÕ´Ï´Ù. ¿¹¸¦ µé¾î, Thawte Personal Freemail C¿Í °°ÀÌ ÀÔ·ÂÇÏ¸é µË´Ï´Ù.
  5. Please enter the name of the certificate?

    Thawte Personal Freemail CA

  6. ÀÎÁõ¼­ÀÇ Æ®·¯½ºÆ® ¼Ó¼ºÀ» ÀÔ·ÂÇÕ´Ï´Ù.
  7. Please enter the trust attribute you want the certificate to have [CT,CT,CT]

ÀÎÁõ¼­ Æ®·¯½ºÆ® ¼Ó¼ºÀÌ º¯°æµË´Ï´Ù.


·çÆ® CA ÀÎÁõ¼­ ³ª¿­

ÀÎÁõ¼­ °ü¸® ½ºÅ©¸³Æ®¸¦ »ç¿ëÇÏ¸é ¸ðµç ·çÆ® CA ÀÎÁõ¼­¸¦ º¼ ¼ö ÀÖ½À´Ï´Ù.

    ·çÆ® CA ¸ñ·ÏÀ» º¸·Á¸é
  1. ·çÆ®·Î¼­ certadmin ½ºÅ©¸³Æ®¸¦ ½ÇÇàÇÕ´Ï´Ù.
  2. portal-server-install-root/SUNWps/bin/certadmin -n gateway-profile-name

    ¿©±â¼­ gateway-profile-nameÀº °ÔÀÌÆ®¿þÀÌ ÀνºÅϽºÀÇ À̸§ÀÔ´Ï´Ù.

    ÀÎÁõ¼­ °ü¸® ¸Þ´º°¡ Ç¥½ÃµË´Ï´Ù.

    1) Generate Self-Signed Certificate

    2) Generate Certificate Signing Request (CSR)

    3) Add Root CA Certificate

    4) Install Certificate From Certificate Authority (CA)

    5) Delete Certificate

    6) Modify Trust Attributes of Certificate (e.g., for PDC)

    7) List Root CA Certificates

    8) List All Certificates

    9) Print Certificate Content

    10) Quit

    choice: [10] 7

  3. ÀÎÁõ¼­ °ü¸® ¸Þ´ºÀÇ ¿É¼Ç 7¸¦ ¼±ÅÃÇÕ´Ï´Ù.
  4. ¸ðµç ·çÆ® CA ÀÎÁõ¼­°¡ Ç¥½ÃµË´Ï´Ù.


¸ðµç ÀÎÁõ¼­ ³ª¿­

ÀÎÁõ¼­ °ü¸® ½ºÅ©¸³Æ®¸¦ »ç¿ëÇÏ¸é ¸ðµç ÀÎÁõ¼­¿¡ ÇØ´çÇÏ´Â Æ®·¯½ºÆ® ¼Ó¼ºÀ» º¼ ¼ö ÀÖ½À´Ï´Ù.

    ¸ðµç ÀÎÁõ¼­¸¦ ³ª¿­ÇÏ·Á¸é
  1. ·çÆ®·Î¼­ certadmin ½ºÅ©¸³Æ®¸¦ ½ÇÇàÇÕ´Ï´Ù.
  2. portal-server-install-root/SUNWps/bin/certadmin -n gateway-profile-name

    ¿©±â¼­ gateway-profile-nameÀº °ÔÀÌÆ®¿þÀÌ ÀνºÅϽºÀÇ À̸§ÀÔ´Ï´Ù.

    ÀÎÁõ¼­ °ü¸® ¸Þ´º°¡ Ç¥½ÃµË´Ï´Ù.

    1) Generate Self-Signed Certificate

    2) Generate Certificate Signing Request (CSR)

    3) Add Root CA Certificate

    4) Install Certificate From Certificate Authority (CA)

    5) Delete Certificate

    6) Modify Trust Attributes of Certificate (e.g., for PDC)

    7) List Root CA Certificates

    8) List All Certificates

    9) Print Certificate Content

    10) Quit

    choice: [10] 8

  3. ÀÎÁõ¼­ °ü¸® ¸Þ´ºÀÇ ¿É¼Ç 8¸¦ ¼±ÅÃÇÕ´Ï´Ù.
  4. ¸ðµç CA ÀÎÁõ¼­°¡ Ç¥½ÃµË´Ï´Ù.


ÀÎÁõ¼­ Àμâ

ÀÎÁõ¼­ °ü¸® ½ºÅ©¸³Æ®¸¦ »ç¿ëÇϸé ÀÎÁõ¼­¸¦ ÀμâÇÒ ¼ö ÀÖ½À´Ï´Ù.

    ÀÎÁõ¼­¸¦ ÀμâÇÏ·Á¸é
  1. ·çÆ®·Î¼­ certadmin ½ºÅ©¸³Æ®¸¦ ½ÇÇàÇÕ´Ï´Ù.
  2. portal-server-install-root/SUNWps/bin/certadmin -n gateway-profile-name

    ¿©±â¼­ gateway-profile-nameÀº °ÔÀÌÆ®¿þÀÌ ÀνºÅϽºÀÇ À̸§ÀÔ´Ï´Ù.

    ÀÎÁõ¼­ °ü¸® ¸Þ´º°¡ Ç¥½ÃµË´Ï´Ù.

    1) Generate Self-Signed Certificate

    2) Generate Certificate Signing Request (CSR)

    3) Add Root CA Certificate

    4) Install Certificate From Certificate Authority (CA)

    5) Delete Certificate

    6) Modify Trust Attributes of Certificate (e.g., for PDC)

    7) List Root CA Certificates

    8) List All Certificates

    9) Print Certificate Content

    10) Quit

    choice: [10] 9

  3. ÀÎÁõ¼­ °ü¸® ¸Þ´ºÀÇ ¿É¼Ç 9¸¦ ¼±ÅÃÇÕ´Ï´Ù.
  4. ÀÎÁõ¼­ÀÇ À̸§À» ÀÔ·ÂÇÕ´Ï´Ù.


ÀÌÀü      ¸ñÂ÷      »öÀÎ      ´ÙÀ½     


ºÎÇ° ¹øÈ£: 819-4615.   ÀúÀÛ±Ç 2005 Sun Microsystems, Inc. ¸ðµç ±Ç¸®´Â ÀúÀÛ±ÇÀÚÀÇ ¼ÒÀ¯ÀÔ´Ï´Ù.