![]() | |
Sun Java System Access Manager 6 2005Q1 °ü¸® ¼³¸í¼ |
2Àå
SSL ¸ðµå¿¡¼ Access Manager ±¸¼º´Ü¼ø ÀÎÁõ¿¡¼ SSL(Secure Socket Layer)À» »ç¿ëÇÏ¸é ±â¹Ð¼º°ú µ¥ÀÌÅÍ ¹«°á¼ºÀÌ º¸ÀåµË´Ï´Ù. Access Manager¸¦ SSL ¸ðµå¿¡¼ »ç¿ëÇÏ·Á¸é ÀϹÝÀûÀ¸·Î ´ÙÀ½À» ¼öÇàÇØ¾ß ÇÕ´Ï´Ù.
´ÙÀ½ Àý¿¡¼ ¼³¸íÇÒ ´Ü°è´Â ¾Æ·¡¿Í °°½À´Ï´Ù.
º¸¾È Sun Java System Web Server¸¦ »ç¿ëÇÏ¿© Access Manager ±¸¼ºSun Java System Web Server¸¦ »ç¿ëÇÏ¿© SSL ¸ðµå¿¡¼ Access Manager¸¦ ±¸¼ºÇÏ·Á¸é ´ÙÀ½ ´Ü°è¸¦ ÂüÁ¶ÇϽʽÿÀ.
´Ü°è 2ºÎÅÍ ´Ü°è 25±îÁö´Â Sun Java System Web Server¿¡ ´ëÇÑ ¼³¸íÀÔ´Ï´Ù.
- WebServer Äֿܼ¡ ·Î±×¿ÂÇÕ´Ï´Ù. ±âº» Æ÷Æ®´Â 58888ÀÔ´Ï´Ù.
- Access Manager°¡ ½ÇÇà ÁßÀÎ Web Server ÀνºÅϽº¸¦ ¼±ÅÃÇϰí Manage(°ü¸®)¸¦ ´©¸¨´Ï´Ù.
±¸¼ºÀÌ º¯°æµÇ¾ú´Ù´Â ¸Þ½ÃÁö°¡ ÀÖ´Â ÆË¾÷ âÀÌ Ç¥½ÃµË´Ï´Ù. OK(È®ÀÎ)¸¦ ´©¸¨´Ï´Ù.
- ȸéÀÇ ¿À¸¥ÂÊ À§ ¸ð¼¸®¿¡ ÀÖ´Â Apply(Àû¿ë) ¹öưÀ» ´©¸¨´Ï´Ù.
- Apply Settings(¼³Á¤ Àû¿ë)¸¦ ´©¸¨´Ï´Ù.
Web Server°¡ ÀÚµ¿À¸·Î ´Ù½Ã ½ÃÀ۵Ǿî¾ß ÇÕ´Ï´Ù. È®ÀÎÀ» ´·¯ °è¼ÓÇÕ´Ï´Ù.
- Web Server ÀνºÅϽº ¼±ÅÃÀ» ÁßÁöÇÕ´Ï´Ù.
- Security Tab(º¸¾ÈÅÇ)À» ´©¸¨´Ï´Ù.
- Create Database(µ¥ÀÌÅͺ£À̽º ¸¸µé±â)¸¦ ´©¸¨´Ï´Ù.
- »õ µ¥ÀÌÅͺ£À̽º ºñ¹Ð¹øÈ£¸¦ ÀÔ·ÂÇϰí È®ÀÎÀ» ´©¸¨´Ï´Ù.
³ªÁß¿¡ »ç¿ëÇÒ ¼ö ÀÖµµ·Ï µ¥ÀÌÅͺ£À̽º ºñ¹Ð¹øÈ£¸¦ ±â·ÏÇØ µÎ½Ê½Ã¿À.
- ÀÎÁõ¼ µ¥ÀÌÅͺ£À̽º¸¦ ÀÛ¼ºÇÑ ÈÄ Request a Certificate(ÀÎÁõ¼ ¿äû)À» ´©¸¨´Ï´Ù.
- ȸ鿡 Á¦°øµÈ Çʵ忡 µ¥ÀÌÅ͸¦ ÀÔ·ÂÇÕ´Ï´Ù.
Ű ½Ö ÇÊµå ºñ¹Ð¹øÈ£ Çʵå´Â ´Ü°è 9¿¡ ÀÔ·ÂÇÑ °Í°ú µ¿ÀÏÇÕ´Ï´Ù. À§Ä¡ Çʵ忡 À§Ä¡¸¦ Á¤È®ÇÏ°Ô ÀÔ·ÂÇØ¾ß ÇÕ´Ï´Ù. CA¿Í °°Àº ¾à¾î´Â »ç¿ëÇÒ ¼ö ¾ø½À´Ï´Ù. ¸ðµç Çʵ带 Á¤ÀÇÇØ¾ß ÇÕ´Ï´Ù. °øÅë À̸§ Çʵ忡 Web ServerÀÇ È£½ºÆ® À̸§À» ÀÔ·ÂÇÕ´Ï´Ù.
- ¾ç½ÄÀÌ Á¦ÃâµÇ¸é ´ÙÀ½°ú °°Àº ¸Þ½ÃÁö°¡ Ç¥½ÃµË´Ï´Ù.
--BEGIN CERTIFICATE REQUEST---
afajsdllwqeroisdaoi234rlkqwelkasjlasnvdknbslajowijalsdkjfalsdflasdf
alsfjawoeirjoi2ejowdnlkswnvnwofijwoeijfwiepwerfoiqeroijeprwpfrwl
--END CERTIFICATE REQUEST--
- ÀÌ ÅØ½ºÆ®¸¦ º¹»çÇÏ¿© ÀÎÁõ¼¸¦ ¿äûÇÒ ¶§ Á¦ÃâÇÕ´Ï´Ù.
·çÆ® CA ÀÎÁõ¼¸¦ °¡Á®¿Í¾ß ÇÕ´Ï´Ù.
- ÀÎÁõ¼°¡ Æ÷ÇÔµÈ ´ÙÀ½°ú °°Àº ÀÎÁõ¼ ÀÀ´äÀ» ¹Þ°Ô µË´Ï´Ù.
--BEGIN CERTIFICATE---
afajsdllwqeroisdaoi234rlkqwelkasjlasnvdknbslajowijalsdkjfalsdflasdf
alsfjawoeirjoi2ejowdnlkswnvnwofijwoeijfwiepwerfoiqeroijeprwpfrwl
--END CERTIFICATE---
- ÀÌ ÅØ½ºÆ®¸¦ Ŭ¸³º¸µå¿¡ º¹»çÇϰųª ÅØ½ºÆ®¸¦ ÆÄÀÏ·Î ÀúÀåÇÕ´Ï´Ù.
- Web Server ÄַܼΠÀ̵¿ÇÏ¿© Install Certificate(ÀÎÁõ¼ ¼³Ä¡)¸¦ ´©¸¨´Ï´Ù.
- ÀÌ ¼¹öÀÇ ÀÎÁõ¼¸¦ Ŭ¸¯ÇÕ´Ï´Ù.
- Ű ½Ö ÆÄÀÏ ºñ¹Ð¹øÈ£ Çʵ忡 ÀÎÁõ¼ µ¥ÀÌÅͺ£À̽º ºñ¹Ð¹øÈ£¸¦ ÀÔ·ÂÇÕ´Ï´Ù.
- ÀÎÁõ¼¸¦ Á¦°øµÈ ÅØ½ºÆ® Çʵ忡 ºÙ¿© ³Ö°Å³ª ¶óµð¿À ¹öưÀ» ´©¸£°í ÅØ½ºÆ® »óÀÚ¿¡ ÆÄÀÏ À̸§À» ÀÔ·ÂÇÕ´Ï´Ù. Á¦ÃâÀ» Ŭ¸¯ÇÕ´Ï´Ù.
ºê¶ó¿ìÀú¿¡ ÀÎÁõ¼°¡ Ç¥½ÃµÇ°í ÀÎÁõ¼¸¦ Ãß°¡Çϱâ À§ÇÑ ¹öưÀÌ Á¦°øµË´Ï´Ù.
- ÀÎÁõ¼ ¼³Ä¡¸¦ Ŭ¸¯ÇÕ´Ï´Ù.
- ½Å·ÚÇÒ ¼ö ÀÖ´Â ÀÎÁõ ±â°ü¿¡ ´ëÇÑ ÀÎÁõ¼¸¦ ´©¸¨´Ï´Ù.
- µÎ ÀÎÁõ¼°¡ ¸ðµÎ ¼³Ä¡µÇ¸é Web Server ÄܼÖÀÇ Preferences tab(±âº» ¼³Á¤ ÅÇ)À» ´©¸¨´Ï´Ù.
- SSLÀ» ´Ù¸¥ Æ÷Æ®¿¡¼ »ç¿ë °¡´ÉÇÏ°Ô ÇÏ·Á¸é ¼ö½Å ¼ÒÄÏ Ãß°¡¸¦ ¼±ÅÃÇÕ´Ï´Ù. ±×·± ´ÙÀ½ Edit Listen Socket(¼ö½Å ¼ÒÄÏ ÆíÁý)À» ¼±ÅÃÇÕ´Ï´Ù.
- º¸¾È »óŸ¦ »ç¿ë ºÒ°¡´É¿¡¼ »ç¿ë °¡´ÉÀ¸·Î º¯°æÇϰí OK(È®ÀÎ)¸¦ ´·¯ º¯°æ ³»¿ëÀ» Á¦ÃâÇÕ´Ï´Ù.
´Ü°è 26ºÎÅÍ ´Ü°è 28±îÁö´Â Access Manager¸¦ ¼³¸íÇÕ´Ï´Ù.
- AMConfig.properties ÆÄÀÏÀ» ¿±´Ï´Ù. ±âº»ÀûÀ¸·Î ÀÌ ÆÄÀÏÀÇ À§Ä¡´Â /etc/opt/SUNWam/configÀÔ´Ï´Ù.
- Web Server ÀνºÅϽº µð·ºÅ丮¸¦ Á¦¿ÜÇϰí http://ÀÇ ¸ðµç ÇÁ·ÎÅäÄÝ Ç׸ñÀ» https://·Î ±³Ã¼ÇÕ´Ï´Ù. Web Server ÀνºÅϽº µð·ºÅ丮µµ AMConfig.properties¿¡ ÁöÁ¤µÇ¾î ÀÖÁö¸¸ ±×´ë·Î À¯ÁöµÇ¾î¾ß ÇÕ´Ï´Ù.
- AMConfig.properties ÆÄÀÏÀ» ÀúÀåÇÕ´Ï´Ù.
- Web Server Äֿܼ¡¼ Web Server ÀνºÅϽº¸¦ È£½ºÆ®ÇÏ´Â Access Manager¿¡ ´ëÇÑ ON/OFF(¼³Á¤/ÇØÁ¦) ¹öưÀ» ´©¸¨´Ï´Ù.
Web ServerÀÇ Start/Stop(½ÃÀÛ/ÁßÁö) ÆäÀÌÁö¿¡ ÀԷ¶õÀÌ Ç¥½ÃµË´Ï´Ù.
- ÅØ½ºÆ® Çʵ忡 ÀÎÁõ¼ µ¥ÀÌÅͺ£À̽º ºñ¹Ð¹øÈ£¸¦ ÀÔ·ÂÇÏ°í ½ÃÀÛÀ» ¼±ÅÃÇÕ´Ï´Ù.
º¸¾È Sun Java System Application Server¸¦ »ç¿ëÇÏ¿© Access Manager ±¸¼ºSSL »ç¿ë °¡´É Sun Java System Application Server¿¡¼ ½ÇÇàÇϵµ·Ï Access Manager¸¦ ¼³Á¤ÇÏ·Á¸é µÎ ´Ü°è¸¦ °ÅĨ´Ï´Ù. ¸ÕÀú ¼³Ä¡µÈ Access Manager¿¡ ´ëÇÑ Application Server ÀνºÅϽº¿¡ º¸¾ÈÀ» ¼³Á¤ÇÑ ´ÙÀ½ Access Manager¸¦ ±¸¼ºÇÕ´Ï´Ù.
SSLÀ» »ç¿ëÇÏ¿© Application Server 6.2 ¼³Á¤
Application Server ÀνºÅϽº¿¡ º¸¾ÈÀ» ¼³Á¤ÇÏ·Á¸é ´ÙÀ½À» ¼öÇàÇÕ´Ï´Ù.
- ºê¶ó¿ìÀú¿¡ ´ÙÀ½ ÁÖ¼Ò¸¦ ÀÔ·ÂÇÏ¿© Sun Java System Application Server Äֿܼ¡ °ü¸®ÀÚ·Î ·Î±×ÀÎÇÕ´Ï´Ù.
http://fullservername:port
±âº» Æ÷Æ®´Â 4848ÀÔ´Ï´Ù.
- ¼³Ä¡ÇÏ´Â µ¿¾È ÀÔ·ÂÇÑ ¾ÆÀ̵ð¿Í ºñ¹Ð¹øÈ£¸¦ ÀÔ·ÂÇÕ´Ï´Ù.
- Access Manager¸¦ ¼³Ä¡Ç߰ųª ¼³Ä¡ÇÒ Application Server ÀνºÅϽº¸¦ ¼±ÅÃÇÕ´Ï´Ù. ¿À¸¥ÂÊ ÇÁ·¹ÀÓ¿¡ ±¸¼ºÀÌ º¯°æµÇ¾ú´Ù´Â ¸Þ½ÃÁö°¡ Ç¥½ÃµË´Ï´Ù.
- º¯°æ ³»¿ë Àû¿ëÀ» Ŭ¸¯ÇÕ´Ï´Ù.
- Àç½ÃÀÛÀ» Ŭ¸¯ÇÕ´Ï´Ù. Application Server°¡ ÀÚµ¿À¸·Î ´Ù½Ã ½ÃÀ۵Ǿî¾ß ÇÕ´Ï´Ù.
- ¿ÞÂÊ ÇÁ·¹ÀÓ¿¡¼ º¸¾ÈÀ» ´©¸¨´Ï´Ù.
- µ¥ÀÌÅͺ£À̽º °ü¸® ÅÇÀ» ´©¸¨´Ï´Ù.
- µ¥ÀÌÅͺ£À̽º ¸¸µé±â¸¦ ´©¸¨´Ï´Ù(¼±ÅÃÇÏÁö ¾ÊÀº °æ¿ì).
- »õ µ¥ÀÌÅͺ£À̽º ºñ¹Ð¹øÈ£¸¦ ÀÔ·ÂÇϰí È®ÀÎÇÑ ´ÙÀ½ È®ÀÎ ¹öưÀ» ´©¸¨´Ï´Ù. ³ªÁß¿¡ »ç¿ëÇÒ ¼ö ÀÖµµ·Ï µ¥ÀÌÅͺ£À̽º ºñ¹Ð¹øÈ£¸¦ ±â·ÏÇØ µÎ½Ê½Ã¿À.
- ÀÎÁõ¼ µ¥ÀÌÅͺ£À̽º¸¦ ÀÛ¼ºÇÑ ÈÄ ÀÎÁõ¼ °ü¸® ÅÇÀ» ´©¸¨´Ï´Ù.
- ¿äû ¸µÅ©¸¦ ´©¸¨´Ï´Ù(¼±ÅÃÇÏÁö ¾ÊÀº °æ¿ì).
- ÀÎÁõ¼¿¡ ´ëÇØ ´ÙÀ½ ¿äû µ¥ÀÌÅ͸¦ ÀÔ·ÂÇÕ´Ï´Ù.
- »õ ÀÎÁõ¼ÀÎÁö ÀÎÁõ¼ ¾÷µ¥ÀÌÆ®ÀÎÁö¸¦ ¼±ÅÃÇÕ´Ï´Ù. ƯÁ¤ ±â°£ÀÌ °æ°úÇÏ¸é ¸¹Àº ÀÎÁõ¼°¡ ¸¸·áµÇ°í ÀϺΠÀÎÁõ ±â°ü(CA)¿¡¼´Â ¾÷µ¥ÀÌÆ® ¾Ë¸²À» ÀÚµ¿À¸·Î º¸³À´Ï´Ù.
- ÀÎÁõ¼¿¡ ´ëÇÑ ¿äûÀ» Á¦ÃâÇÒ ¹æ¹ýÀ» ÁöÁ¤ÇÕ´Ï´Ù.
CA°¡ ÀüÀÚ ¸ÞÀÏ ¸Þ½ÃÁö·Î ¿äûÀ» ¹Þ´Â °æ¿ì CA ÀüÀÚ ¸ÞÀÏÀ» ¼±ÅÃÇϰí CAÀÇ ÀüÀÚ ¸ÞÀÏ ÁÖ¼Ò¸¦ ÀÔ·ÂÇÕ´Ï´Ù. CA ¸ñ·Ï¿¡¼ »ç¿ë °¡´ÉÇÑ ÀÎÁõ ±â°ü ¸ñ·ÏÀ» ´©¸¨´Ï´Ù.
Sun Java System Certificate Server¸¦ »ç¿ëÇÏ´Â ³»ºÎ CA·ÎºÎÅÍ ÀÎÁõ¼¸¦ ¿äûÇÒ °æ¿ì CA URLÀ» ´©¸£°í Certificate Server¿¡ ´ëÇÑ URLÀ» ÀÔ·ÂÇÕ´Ï´Ù. ÀÌ URLÀº ÀÎÁõ¼ ¿äûÀ» ó¸®ÇÏ´Â ÀÎÁõ¼ ¼¹öÀÇ ÇÁ·Î±×·¥À» °¡¸®ÄÑ¾ß ÇÕ´Ï´Ù.
- Ű ½Ö ÆÄÀÏ¿¡ ´ëÇÑ ºñ¹Ð¹øÈ£(´Ü°è 9¿¡¼ ÁöÁ¤ÇÑ ºñ¹Ð¹øÈ£)¸¦ ÀÔ·ÂÇÕ´Ï´Ù.
- ´ÙÀ½ ½Äº° Á¤º¸¸¦ ÀÔ·ÂÇÕ´Ï´Ù.
°øÅë À̸§. Æ÷Æ® ¹øÈ£¸¦ Æ÷ÇÔÇÏ¿© ¼¹öÀÇ ¼º¸íÀÔ´Ï´Ù.
¿äûÀÚ À̸§. ¿äûÀÚÀÇ À̸§ÀÔ´Ï´Ù.
ÀüÈ ¹øÈ£. ¿äûÀÚÀÇ ÀüÈ ¹øÈ£ÀÔ´Ï´Ù.
°øÅë À̸§. µðÁöÅÐ ÀÎÁõ¼¸¦ ¼³Ä¡ÇÒ Sun Java System Application ServerÀÇ Á¤±ÔÈµÈ À̸§ÀÔ´Ï´Ù.
ÀüÀÚ ¸ÞÀÏ ÁÖ¼Ò. °ü¸®ÀÚÀÇ ÀüÀÚ ¸ÞÀÏ ÁÖ¼ÒÀÔ´Ï´Ù.
Á¶Á÷ À̸§. Á¶Á÷ÀÇ À̸§ÀÔ´Ï´Ù. ÀÎÁõ ±â°üÀº ÀÌ Á¶Á÷¿¡ µî·ÏµÈ µµ¸ÞÀο¡ ¼ÓÇÏ´Â ÀÌ ¼Ó¼º¿¡ ÀÔ·ÂµÈ È£½ºÆ® À̸§À» ¿ä±¸ÇÒ ¼ö ÀÖ½À´Ï´Ù.
Á¶Á÷ ±¸¼º ´ÜÀ§ À̸§. °ú, ºÎ¼ ¹× ±âŸ Á¶Á÷ ¿î¿µ ´ÜÀ§ÀÇ À̸§ÀÔ´Ï´Ù.
±¸/±º/½Ã À̸§. »ç¿ëÀÚÀÇ ±¸/±º/½Ã À̸§ÀÔ´Ï´Ù.
½Ã/µµ À̸§. Á¶Á÷ÀÌ ¹Ì±¹ ¶Ç´Â ij³ª´Ù¿¡ ÀÖ´Â °æ¿ì °¢°¢ Á¶Á÷ÀÌ ¿î¿µµÇ´Â ½Ã ¶Ç´Â µµÀÇ À̸§ÀÔ´Ï´Ù. ¾à¾î¸¦ »ç¿ëÇÏÁö ¸¶½Ê½Ã¿À.
±¹°¡ ÄÚµå. ±¹°¡¿¡ ´ëÇÑ 2¹®ÀÚ ISO ÄÚµåÀÔ´Ï´Ù. ¿¹¸¦ µé¾î, ¹Ì±¹ÀÇ ±¹°¡ ÄÚµå´Â USÀÔ´Ï´Ù.
- È®ÀÎ ¹öưÀ» ´©¸¨´Ï´Ù. ¸Þ½ÃÁö°¡ Ç¥½ÃµË´Ï´Ù. ¿¹¸¦ µé¸é ´ÙÀ½°ú °°½À´Ï´Ù.
--BEGIN NEW CERTIFICATE REQUEST---
afajsdllwqeroisdaoi234rlkqwelkasjlasnvdknbslajowijalsdkjfalsdfla
alsfjawoeirjoi2ejowdnlkswnvnwofijwoeijfwiepwerfoiqeroijeprwpfrwl
--END NEW CERTIFICATE REQUEST--
- ÀÌ ÅØ½ºÆ®¸¦ ¸ðµÎ ÆÄÀÏ¿¡ º¹»çÇϰí È®ÀÎÀ» ´©¸¨´Ï´Ù. ·çÆ® CA ÀÎÁõ¼¸¦ °¡Á®¿Í¾ß ÇÕ´Ï´Ù.
- CA¸¦ ¼±ÅÃÇϰí ÇØ´ç ±â°üÀÇ À¥ »çÀÌÆ® Áö½Ã¿¡ µû¶ó µðÁöÅÐ ÀÎÁõ¼¸¦ °¡Á®¿É´Ï´Ù. CMS, Verisign ¶Ç´Â Entrust.net¿¡¼ ÀÎÁõ¼¸¦ °¡Á®¿Ã ¼ö ÀÖ½À´Ï´Ù.
- ÀÎÁõ ±â°üÀ¸·ÎºÎÅÍ µðÁöÅÐ ÀÎÁõ¼¸¦ ¹ÞÀº ÈÄ ÅØ½ºÆ®¸¦ Ŭ¸³º¸µå¿¡ º¹»çÇϰųª ÆÄÀÏ·Î ÀúÀåÇÒ ¼ö ÀÖ½À´Ï´Ù.
- Sun Java System Application Server ÄַܼΠÀ̵¿ÇÏ¿© ¼³Ä¡ ¸µÅ©¸¦ ´©¸¨´Ï´Ù.
- ÀÌ ¼¹ö¿¡ ´ëÇÑ ÀÎÁõ¼¸¦ ¼±ÅÃÇÕ´Ï´Ù.
- Ű ½Ö ÆÄÀÏ ºñ¹Ð¹øÈ£ Çʵ忡 ÀÎÁõ¼ µ¥ÀÌÅͺ£À̽º ºñ¹Ð¹øÈ£¸¦ ÀÔ·ÂÇÕ´Ï´Ù(´Ü°è 9¿¡ ÀÔ·ÂÇÑ ºñ¹Ð¹øÈ£).
- ÀÎÁõ¼¸¦ Á¦°øµÈ ÅØ½ºÆ® ÇʵåÀÎ ¸Þ½ÃÁö ÅØ½ºÆ®(Çì´õ ÀÖÀ½)¿¡ ºÙ¿© ³Ö°Å³ª ÀÌ ÆÄÀÏ ÀԷ¶õ¿¡ ÀÖ´Â ¸Þ½ÃÁö¿¡ ÆÄÀÏ À̸§À» ÀÔ·ÂÇÕ´Ï´Ù. ÇØ´ç ¶óµð¿À ¹öưÀ» ¼±ÅÃÇÕ´Ï´Ù.
- È®ÀÎ ¹öưÀ» ´©¸¨´Ï´Ù. ºê¶ó¿ìÀú¿¡ ÀÎÁõ¼°¡ Ç¥½ÃµÇ°í ÀÎÁõ¼¸¦ Ãß°¡ÇÒ ¼ö ÀÖ´Â ¹öưÀÌ Á¦°øµË´Ï´Ù.
- ¼¹ö ÀÎÁõ¼ Ãß°¡¸¦ ´©¸¨´Ï´Ù.
- ´Ü°è 10ºÎÅÍ ´Ü°è 22±îÁö ¼³¸íµÈ °Í°ú µ¿ÀÏÇÑ ¹æ¹ýÀ¸·Î ·çÆ® CA ÀÎÁõ¼¸¦ ¼³Ä¡ÇÕ´Ï´Ù. ±×·¯³ª ´Ü°è 18¿¡¼´Â ½Å·ÚÇÒ ¼ö ÀÖ´Â ÀÎÁõ ±â°ü¿¡ ´ëÇÑ ÀÎÁõ¼¸¦ ¼±ÅÃÇÕ´Ï´Ù.
- ÀÎÁõ¼ ¼³Ä¡°¡ ¿Ï·áµÈ °æ¿ì ¿ÞÂÊ ÇÁ·¹ÀÓ¿¡¼ HTTP Server ³ëµå¸¦ È®ÀåÇÕ´Ï´Ù.
- HTTP Server¿¡¼ HTTP Listeners¸¦ ¼±ÅÃÇÕ´Ï´Ù.
- http-listener-1À» ¼±ÅÃÇÕ´Ï´Ù. ºê¶ó¿ìÀú¿¡ ¼ÒÄÏ Á¤º¸°¡ Ç¥½ÃµË´Ï´Ù.
- http-listener-1¿¡ »ç¿ëµÇ´Â Æ÷Æ® °ªÀ» ÀÀ¿ë ÇÁ·Î±×·¥ ¼¹ö¸¦ ¼³Ä¡ÇÏ´Â µ¿¾È ÀÔ·ÂÇÑ °ª¿¡¼ ÇØ´ç °ª(¿¹: 443)À¸·Î º¯°æÇÕ´Ï´Ù.
- SSL/TLS »ç¿ë °¡´ÉÀ» ¼±ÅÃÇÕ´Ï´Ù.
- ÀÎÁõ¼ º°¸íÀ» ¼±ÅÃÇÕ´Ï´Ù.
- ¹Ýȯ ¼¹ö¸¦ ÁöÁ¤ÇÕ´Ï´Ù. ÀÌ À̸§Àº ´Ü°è 12¿¡ ÁöÁ¤µÈ °øÅë À̸§°ú ÀÏÄ¡ÇØ¾ß ÇÕ´Ï´Ù.
- ÀúÀåÀ» ´©¸¨´Ï´Ù.
- Sun Java System Access Manager ¼ÒÇÁÆ®¿þ¾î¸¦ ¼³Ä¡ÇÒ Application Server ÀνºÅϽº¸¦ ¼±ÅÃÇÕ´Ï´Ù. ¿À¸¥ÂÊ ÇÁ·¹ÀÓ¿¡ ±¸¼ºÀÌ º¯°æµÇ¾ú´Ù´Â ¸Þ½ÃÁö°¡ Ç¥½ÃµË´Ï´Ù.
- º¯°æ ³»¿ë Àû¿ëÀ» Ŭ¸¯ÇÕ´Ï´Ù.
- Àç½ÃÀÛÀ» Ŭ¸¯ÇÕ´Ï´Ù. ÀÀ¿ëÇÁ·Î±×·¥ ¼¹ö°¡ ÀÚµ¿À¸·Î ´Ù½Ã ½ÃÀ۵˴ϴÙ.
SSLÀ» »ç¿ëÇÏ¿© Application Server 8.1 ¼³Á¤
Application Server ÀνºÅϽº¿¡ º¸¾ÈÀ» ¼³Á¤ÇÏ·Á¸é ´ÙÀ½À» ¼öÇàÇÕ´Ï´Ù.
- Application Server ÀνºÅϽº°¡ ÁßÁöµÇ¾ú´ÂÁö È®ÀÎÇÕ´Ï´Ù.
- asadmin>change-master-password ¸í·ÉÀ» »ç¿ëÇÏ¿© ÅäÅ« ºñ¹Ð¹øÈ£¸¦ º¯°æÇÕ´Ï´Ù.
- Application Server ÄַܼΠÀ̵¿ÇÏ¿© ±¸¼º> HTTP ¼ºñ½º> HTTP Listeners¸¦ ¼±ÅÃÇÕ´Ï´Ù.
- »ç¿ëÇÒ ¼ö½Å±â¸¦ ´©¸£°í ¿À¸¥ÂÊ Ã¢¿¡¼ Security:Enabled¸¦ ¼±ÅÃÇÕ´Ï´Ù.
- certutilÀÌ ¼³Ä¡µÇ¾î ÀÖ´ÂÁö È®ÀÎÇÕ´Ï´Ù.
- certutilÀ» »ç¿ëÇÏ¿© certdb¿¡ ¼³Ä¡µÈ ÀÎÁõ¼¸¦ È®ÀÎÇÕ´Ï´Ù.
- ÀÎÁõ¼ ¿äûÀ» »ý¼ºÇÕ´Ï´Ù. ±¸¹®Àº ´ÙÀ½°ú °°½À´Ï´Ù.
certutil -R -s subj -o cert-request-file [-d certdir] [-P dbprefix] [-p phone] [-a]
¿¹¸¦ µé¸é ´ÙÀ½°ú °°½À´Ï´Ù.
certutil -R -s "CN=test.company1.com, O=company1.com, C=US" -o cert.req -d . -a
- ´ÙÀ½ ¸í·ÉÀ» »ç¿ëÇÏ¿© CA·ÎºÎÅÍ ÀÎÁõ¼¸¦ °Ë»öÇÕ´Ï´Ù.
certutil -A -n cert-name -t trustargs [-d certdir] [-P dbprefix] [-a] [-i input]
- ¼¹ö ÀÎÁõ¼¸¦ ÆÄÀÏ·Î ÀúÀåÇÕ´Ï´Ù.
- ´ÙÀ½ ¸í·É ±¸¹®À» »ç¿ëÇÏ¿© ½Å·ÚÇÒ ¼ö ÀÖ´Â CA ÀÎÁõ¼¸¦ ¼³Ä¡ÇÕ´Ï´Ù.
certutil -A -n cert-name -t trustargs [-d certdir] [-P dbprefix] [-a] [-i input]
½Å·ÚÇÒ ¼ö ÀÖ´Â CA ÀÎÁõ¼¸¦ ÆÄÀÏ(¿¹: cacert.txt)·Î ÀúÀåÇÕ´Ï´Ù.
- certdb¸¦ ³ª¿ÇÏ¿© ¼³Ä¡°¡ ¼º°øÇß´ÂÁö È®ÀÎÇÕ´Ï´Ù. ´ÙÀ½ ¸í·ÉÀ» ÀÔ·ÂÇÕ´Ï´Ù.
/var/opt/SUNWappserver/domains/domain1/config/% certutil -L -d
- Application Server °ü¸® ÄַܼΠÀ̵¿ÇÏ¿© HTTP Listeners¸¦ ¼±ÅÃÇÕ´Ï´Ù.
ÀÏ¹Ý ¼³Á¤¿¡¼ »õ ¼¹ö ÀÎÁõ¼·Î HTTP Listener¸¦ ±¸¼ºÇÕ´Ï´Ù.
- Application Server¸¦ ´Ù½Ã ½ÃÀÛÇÕ´Ï´Ù.
SSL ¸ðµå¿¡¼ Access Manager ±¸¼º
SSL ¸ðµå¿¡¼ Access Manager¸¦ ±¸¼ºÇÏ·Á¸é ´ÙÀ½À» ¼öÇàÇÕ´Ï´Ù.
- Access Manager Äֿܼ¡¼ ¼ºñ½º ±¸¼º ¸ðµâ·Î À̵¿ÇÏ¿© Ç÷§Æû ¼ºñ½º¸¦ ¼±ÅÃÇÕ´Ï´Ù. ¼¹ö ¸ñ·Ï ¼Ó¼º¿¡¼ HTTPS ÇÁ·ÎÅäÄݰú µ¿ÀÏÇÑ URL ¹× SSL »ç¿ë °¡´É Æ÷Æ® ¹øÈ£¸¦ Ãß°¡ÇÕ´Ï´Ù. ÀúÀåÀ» ´©¸¨´Ï´Ù.
- ´ÙÀ½ ±âº» À§Ä¡¿¡¼ AMConfig.properties ÆÄÀÏÀ» ¿±´Ï´Ù.
/etc/opt/SUNWam/config
- http://ÀÇ ¸ðµç ÇÁ·ÎÅäÄÝ Ç׸ñÀ» https://·Î ±³Ã¼ÇÏ°í Æ÷Æ® ¹øÈ£¸¦ SSL »ç¿ë °¡´É Æ÷Æ® ¹øÈ£·Î º¯°æÇÕ´Ï´Ù.
- AMConfig.properties ÆÄÀÏÀ» ÀúÀåÇÕ´Ï´Ù.
- Application Server¸¦ ´Ù½Ã ½ÃÀÛÇÕ´Ï´Ù.
º¸¾È BEA WebLogic Server·Î AMSDK ±¸¼ºSSL¿¡¼ AMSDK·Î BEA WebLogic Server¸¦ ±¸¼ºÇϱâ Àü¿¡ ¸ÕÀú À¥ ÄÁÅ×À̳ʷμ BEA WebLogic Server¸¦ ¼³Ä¡ÇØ¾ß ÇÕ´Ï´Ù. ¼³Ä¡ ÁöħÀ» º¸·Á¸é BEA WebLogic Server ¼³¸í¼¸¦ ÂüÁ¶ÇϽʽÿÀ. Access Manager¿¡ ´ëÇÑ À¥ ÄÁÅ×À̳ʷμ WebLogicÀ» ±¸¼ºÇÏ·Á¸é 1Àå, "Access Manager 2005Q1 ±¸¼º ½ºÅ©¸³Æ®"¸¦ ÂüÁ¶ÇϽʽÿÀ.
º¸¾È WebLogic ÀνºÅϽº¸¦ ±¸¼ºÇÏ·Á¸é ´ÙÀ½À» ¼öÇàÇÕ´Ï´Ù.
- Áï¼® ½Ãµ¿ ¸Þ´º¸¦ »ç¿ëÇÏ¿© µµ¸ÞÀÎÀ» ¸¸µì´Ï´Ù.
- WebLogic ¼³Ä¡ µð·ºÅ丮·Î À̵¿ÇÏ¿© ÀÎÁõ¼ ¿äûÀ» »ý¼ºÇÕ´Ï´Ù.
- vetri_csr.txt CSRÀ» »ç¿ëÇÏ¿© ÀÌ ¼¹ö ÀÎÁõ¼¸¦ CA¿¡ Á¦ÃâÇÕ´Ï´Ù.
- ½ÂÀÎµÈ ÀÎÁõ¼¸¦ ÅØ½ºÆ® ÆÄÀÏ·Î ÀúÀåÇÕ´Ï´Ù. ¿¹¸¦ µé¸é approvedcert.txtÀÔ´Ï´Ù.
- ´ÙÀ½ ¸í·ÉÀ» »ç¿ëÇÏ¿© ·çÆ® CA¸¦ cacerts¿¡ ·ÎµåÇÕ´Ï´Ù.
cd jdk141_03/jre/lib/security/
jdk141_03/jre/bin/keytool -keystore cacerts -keyalg RSA -import -trustcacerts -alias "Greenday CA" -storepass changeit -file /opt/bea81/cacert.txt
- ´ÙÀ½ ¸í·ÉÀ» »ç¿ëÇÏ¿© ¼¹ö ÀÎÁõ¼¸¦ ·ÎµåÇÕ´Ï´Ù.
jdk141_03/jre/bin/keytool -import -keystore keystore -keyalg RSA -import -trustcacerts -file approvedcert.txt -alias "mykey"
- »ç¿ëÀÚ À̸§°ú ºñ¹Ð¹øÈ£¸¦ »ç¿ëÇÏ¿© WebLogic Äֿܼ¡ ·Î±×ÀÎÇÕ´Ï´Ù.
- ´ÙÀ½ À§Ä¡·Î À̵¿ÇÕ´Ï´Ù.
yourdomain> Servers> myserver> Configure Keystores
- »ç¿ëÀÚ Á¤ÀÇ ID¸¦ ¼±ÅÃÇÑ ´ÙÀ½ Java Standard Trust¸¦ ¼±ÅÃÇÕ´Ï´Ù.
- Ű ÀúÀå¼Ò À§Ä¡¸¦ ÀÔ·ÂÇÕ´Ï´Ù. ¿¹¸¦ µé¸é /opt/bea81/keystoreÀÔ´Ï´Ù.
- Ű ÀúÀå¼Ò ºñ¹Ð¹øÈ£¿Í Ű ÀúÀå¼Ò ºñ¹Ð ¹®±¸¸¦ ÀÔ·ÂÇÕ´Ï´Ù. ¿¹¸¦ µé¸é ´ÙÀ½°ú °°½À´Ï´Ù.
Ű ÀúÀå¼Ò ºñ¹Ð¹øÈ£: JKS/Java Standard Trust(WL 8.1ÀÇ °æ¿ì JKS¸¸ »ç¿ë)
Ű ÀúÀå¼Ò ºñ¹Ð ¹®±¸: changeit
- ÀÌ ´Ü°è¿¡¼´Â SSL °³ÀΠŰ ¼³Á¤ °³ÀΠŰ º°Äª: mykey ¹× ºñ¹Ð¹øÈ£: secret12¸¦ °ËÅäÇÕ´Ï´Ù.
- Access ManagerÀÇ °æ¿ì ¼³Ä¡ ½Ã AmConfig.propertiesÀÇ ´ÙÀ½ ¸Å°³ º¯¼ö°¡ ÀÚµ¿À¸·Î ±¸¼ºµË´Ï´Ù. ÀÚµ¿ ±¸¼ºµÇÁö ¾ÊÀ» °æ¿ì¿¡´Â »ç¿ëÀÚ°¡ ÀûÀýÇÏ°Ô ÆíÁýÇÒ ¼ö ÀÖ½À´Ï´Ù.
com.sun.identity.jss.donotInstallAtHighestPriority=true [ this is not required for AM 6.3 and above]
com.iplanet.security.SecureRandomFactoryImpl=com.iplanet.am.util.SecureRandomFactoryImpl
com.iplanet.security.SSLSocketFactoryImpl=netscape.ldap.factory.JSSESocketFactory
com.iplanet.security.encryptor=com.iplanet.services.util.JCEEncryption2
JDK °æ·Î°¡ ´ÙÀ½°ú °°Àº °æ¿ì
com.iplanet.am.jdk.path=/usr/jdk/entsys-j2se
Ű µµ±¸ À¯Æ¿¸®Æ¼¸¦ »ç¿ëÇÏ¿© ·çÆ® CA¸¦ ÀÎÁõ¼ µ¥ÀÌÅͺ£À̽º·Î °¡Á®¿Í¾ß ÇÕ´Ï´Ù. ¿¹¸¦ µé¸é ´ÙÀ½°ú °°½À´Ï´Ù.
/usr/jdk/entsys-j2se/jre/lib/security
/usr/jdk/entsys-j2se/jre/bin/keytool -keystore cacerts -keyalg RSA -import -trustcacerts -alias "machinename" -storepass changeit -file
/opt/bea81/cacert.txt
Ű µµ±¸ À¯Æ¿¸®Æ¼´Â ´ÙÀ½ µð·ºÅ丮¿¡ ÀÖ½À´Ï´Ù.
/usr/jdk/entsys-j2se/jre/bin/keytool
- Access Manager amadmin ¸í·ÉÁÙ À¯Æ¿¸®Æ¼¿¡¼ -D"java.protocol.handler.pkgs=com.iplanet.services.comm"À» Á¦°ÅÇÕ´Ï´Ù.
- SSL ¸ðµå¿¡¼ Access Manager¸¦ ±¸¼ºÇÕ´Ï´Ù. ¼¼ºÎ »çÇ׿¡ ´ëÇØ¼´Â SSL ¸ðµå¿¡¼ Access Manager ±¸¼ºÀ» ÂüÁ¶ÇϽʽÿÀ.
º¸¾È IBM WebSphere Application Server·Î AMSDK ±¸¼ºSSL¿¡¼ AMSDK¸¦ »ç¿ëÇÏ¿© IBM WebShpere Server¸¦ ±¸¼ºÇϱâ Àü¿¡ ¸ÕÀú IBM WebShpere Server¸¦ ¼³Ä¡Çϰí À¥ ÄÁÅ×À̳ʷμ ±¸¼ºÇØ¾ß ÇÕ´Ï´Ù. ÀÚ¼¼ÇÑ ³»¿ëÀº WebSphere Server ¼³¸í¼¸¦ ÂüÁ¶ÇϽʽÿÀ. Access ManagerÀÇ À¥ ÄÁÅ×À̳ʷμ WebLogic¸¦ ±¸¼ºÇÏ·Á¸é 1Àå, "Access Manager 2005Q1 ±¸¼º ½ºÅ©¸³Æ®"¸¦ ÂüÁ¶ÇϽʽÿÀ.
º¸¾È WebSphere ÀνºÅϽº¸¦ ±¸¼ºÇÏ·Á¸é ´ÙÀ½À» ¼öÇàÇÕ´Ï´Ù.
- Websphere /bin µð·ºÅ丮¿¡ ÀÖ´Â ikeyman.sh¸¦ ½ÃÀÛÇÕ´Ï´Ù.
- ¼¸íÀÚ ¸Þ´º¿¡¼ ÀÎÁõ ±â°ü(CA)ÀÇ ÀÎÁõ¼¸¦ °¡Á®¿É´Ï´Ù.
- °³ÀÎ ÀÎÁõ¼ ¸Þ´º¿¡¼ CSRÀ» »ý¼ºÇÕ´Ï´Ù.
- ÀÌÀü ´Ü°è¿¡¼ ¸¸µç ÀÎÁõ¼¸¦ °ËÅäÇÕ´Ï´Ù.
- °³ÀÎ ÀÎÁõ¼¸¦ ¼±ÅÃÇÏ°í ¼¹ö ÀÎÁõ¼¸¦ °¡Á®¿É´Ï´Ù.
- WebSphere Äֿܼ¡¼ ±âº» SSL ¼³Á¤À» ¹Ù²Ù°í ¾Ïȣȸ¦ ¼±ÅÃÇÕ´Ï´Ù.
- ±âº» IBMJSSE SSL °ø±ÞÀÚ¸¦ ¼³Á¤ÇÕ´Ï´Ù.
- ´ÙÀ½ ¸í·ÉÀ» ÀÔ·ÂÇÏ¿© ¹æ±Ý ¸¸µç ÆÄÀÏ¿¡¼ CA ÀÎÁõ¼¸¦ ÀÀ¿ë ÇÁ·Î±×·¥ ¼¹ö JVM Ű ÀúÀå¼Ò·Î °¡Á®¿É´Ï´Ù.
$ appserver_root-dir/java/bin/ keytool -import -trustcacerts -alias cmscacert -keystore ../jre/lib/security/cacerts -file /full_path_cacert_filename.txt
app-server-root-dir ´Â ÀÀ¿ë ÇÁ·Î±×·¥ ¼¹öÀÇ ·çÆ® µð·ºÅ丮À̸ç full_path_cacert_filename.txt ´Â ÀÎÁõ¼°¡ ÀÖ´Â ÆÄÀÏÀÇ Àüü °æ·ÎÀÔ´Ï´Ù.
- Access Manager¿¡¼ JSSE¸¦ »ç¿ëÇϵµ·Ï AmConfig.propertiesÀÇ ´ÙÀ½ ¸Å°³ º¯¼ö¸¦ ¾÷µ¥ÀÌÆ®ÇÕ´Ï´Ù.
com.sun.identity.jss.donotInstallAtHighestPriority=true
com.iplanet.security.SecureRandomFactoryImpl=com.iplanet.am.util.SecureRandomFactoryImpl
com.iplanet.security.SSLSocketFactorImpl=netscape.ldap.factory.JSSESocketFactory
com.iplanet.security.encyptor=com.iplanet.services.unil.JCEEncryption
- SSL ¸ðµå¿¡¼ Access Manager¸¦ ±¸¼ºÇÕ´Ï´Ù. ¼¼ºÎ »çÇ׿¡ ´ëÇØ¼´Â SSL ¸ðµå¿¡¼ Access Manager ±¸¼ºÀ» ÂüÁ¶ÇϽʽÿÀ.
SSL ¸ðµå¿¡¼ Access Manager¸¦ Directory Server·Î ±¸¼º³×Æ®¿öÅ©¸¦ ÅëÇÑ º¸¾È Åë½ÅÀ» Á¦°øÇϱâ À§ÇØ Access Manager¿¡´Â LDAPS Åë½Å ÇÁ·ÎÅäÄÝÀÌ Æ÷ÇԵǾî ÀÖ½À´Ï´Ù. LDAPS´Â Ç¥ÁØ LDAP ÇÁ·ÎÅäÄÝÀÌÁö¸¸ SSL(Secure Sockets Layer)ÀÇ »óÀ§¿¡¼ ½ÇÇàµË´Ï´Ù. SSL Åë½ÅÀ» »ç¿ëÇÏ·Á¸é ¸ÕÀú Directory Server¸¦ SSL ¸ðµå¿¡¼ ±¸¼ºÇÑ ´ÙÀ½ Access Manager¸¦ Directory Server·Î ¿¬°áÇÕ´Ï´Ù. ±âº»ÀûÀÎ ´Ü°Ô´Â ´ÙÀ½°ú °°½À´Ï´Ù.
SSL ¸ðµå¿¡¼ Directory Server ±¸¼º
Directory Server¸¦ SSL ¸ðµå¿¡¼ ±¸¼ºÇÏ·Á¸é ¼¹ö ÀÎÁõ¼¸¦ ±¸ÇÏ¿© ¼³Ä¡Çϰí ÀÎÁõ ±â°üÀÇ ÀÎÁõ¼¸¦ ½Å·ÚÇϵµ·Ï Directory Server¸¦ ±¸¼ºÇÑ ´ÙÀ½ SSLÀ» Ȱ¼ºÈÇØ¾ß ÇÕ´Ï´Ù. ÀÚ¼¼ÇÑ ³»¿ëÀº Directory Server °ü¸® ¼³¸í¼ÀÇ 11Àå "ÀÎÁõ ¹× ¾ÏÈ£È °ü¸®"¿¡ ÀÖ½À´Ï´Ù. ÀÌ ¹®¼´Â ´ÙÀ½ À§Ä¡¿¡ ÀÖ½À´Ï´Ù.
¶ÇÇÑ ´ÙÀ½ À§Ä¡¿¡¼ PDF ÇüÅÂÀÇ ¼³¸í¼¸¦ ´Ù¿î·ÎµåÇÒ ¼ö ÀÖ½À´Ï´Ù.
http://docs.sun.com/coll/DirectoryServer_04q2 ¹×
http://docs.sun.com/coll/DirectoryServer_04q2?l=koDirectory Server°¡ ÀÌ¹Ì SSL »ç¿ë °¡´É »óÅÂÀ̸é Access Manager¸¦ Directory Server·Î ¿¬°áÇÏ´Â ¹æ¹ýÀ» ÀÚ¼¼È÷ ¼³¸íÇÏ´Â ´ÙÀ½ Àý·Î À̵¿ÇÕ´Ï´Ù.
Access Manager¸¦ SSL »ç¿ë Directory Server·Î ¿¬°á
ÀÏ´Ü SSL ¸ðµå·Î Directory Server°¡ ±¸¼ºµÈ ´ÙÀ½¿¡´Â Access Manager¸¦ Directory Server ¹é¿£µå·Î ¿¬°áÇØ¾ß ÇÕ´Ï´Ù. ¼öÇà ¹æ¹ýÀº ´ÙÀ½°ú °°½À´Ï´Ù.
- Access Manager Äֿܼ¡¼ ¼ºñ½º ±¸¼º ¸ðµâÀÇ LDAP ÀÎÁõ ¼ºñ½º·Î À̵¿ÇÕ´Ï´Ù.
- ¼ºñ½º ±¸¼º ¸ðµâÀÇ ±¸¼º¿ø ÀÎÁõ ¼ºñ½º·Î À̵¿ÇÕ´Ï´Ù.
- ¼ºñ½º ±¸¼º¿¡ ÀÖ´Â Á¤Ã¥ ±¸¼º ¼ºñ½º·Î À̵¿ÇÕ´Ï´Ù.
- ÅØ½ºÆ® ÆíÁý±â¿¡¼ serverconfig.xml ÆÄÀÏÀ» ¿±´Ï´Ù. ÀÌ ÆÄÀÏÀº ´ÙÀ½ À§Ä¡¿¡ ÀÖ½À´Ï´Ù.
/etc/opt/SUNWam/config
- ´ÙÀ½ ±âº» À§Ä¡¿¡¼ AMConfig.properties ÆÄÀÏÀ» ¿±´Ï´Ù.
AcessManager-base/SUNWam/config
´ÙÀ½ µî·Ï Á¤º¸¸¦ º¯°æÇÕ´Ï´Ù.
- ¼¹ö¸¦ ´Ù½Ã ½ÃÀÛÇÕ´Ï´Ù.