Sun Java logo     ÀÌÀü      ¸ñÂ÷      »öÀÎ      ´ÙÀ½     

Sun logo
Sun Java System Access Manager 6 2005Q1 °ü¸® ¼³¸í¼­ 

2Àå
SSL ¸ðµå¿¡¼­ Access Manager ±¸¼º

´Ü¼ø ÀÎÁõ¿¡¼­ SSL(Secure Socket Layer)À» »ç¿ëÇÏ¸é ±â¹Ð¼º°ú µ¥ÀÌÅÍ ¹«°á¼ºÀÌ º¸ÀåµË´Ï´Ù. Access Manager¸¦ SSL ¸ðµå¿¡¼­ »ç¿ëÇÏ·Á¸é ÀϹÝÀûÀ¸·Î ´ÙÀ½À» ¼öÇàÇØ¾ß ÇÕ´Ï´Ù.

  1. º¸¾È À¥ ÄÁÅ×À̳ʸ¦ »ç¿ëÇÏ¿© Access Manager ±¸¼º
  2. Access Manager¸¦ º¸¾È Directory Server·Î ±¸¼º

´ÙÀ½ Àý¿¡¼­ ¼³¸íÇÒ ´Ü°è´Â ¾Æ·¡¿Í °°½À´Ï´Ù.


º¸¾È Sun Java System Web Server¸¦ »ç¿ëÇÏ¿© Access Manager ±¸¼º

Sun Java System Web Server¸¦ »ç¿ëÇÏ¿© SSL ¸ðµå¿¡¼­ Access Manager¸¦ ±¸¼ºÇÏ·Á¸é ´ÙÀ½ ´Ü°è¸¦ ÂüÁ¶ÇϽʽÿÀ.

  1. Access Manager Äֿܼ¡¼­ ¼­ºñ½º ±¸¼º ¸ðµâ·Î À̵¿ÇÏ¿© Ç÷§Æû ¼­ºñ½º¸¦ ¼±ÅÃÇÕ´Ï´Ù. ¼­¹ö ¸ñ·Ï ¼Ó¼º¿¡¼­ http:// ÇÁ·ÎÅäÄÝÀ» Á¦°ÅÇϰí https:// ÇÁ·ÎÅäÄÝÀ» Ãß°¡ÇÕ´Ï´Ù. ÀúÀåÀ» ´©¸¨´Ï´Ù.

  2. ÁÖ

    ÀúÀåÀ» ´­·¯¾ß ÇÕ´Ï´Ù. ÀúÀåÀ» ´©¸£Áö ¾Ê´õ¶óµµ ´ÙÀ½ ´Ü°è¸¦ °è¼ÓÇÒ ¼ö ÀÖÁö¸¸ ¸ðµç ±¸¼º º¯°æ ³»¿ëÀÌ ¼Õ½ÇµÇ¸ç °ü¸®ÀÚ·Î ·Î±×ÀÎÇÏ¿© ÇØ´ç ¹®Á¦¸¦ ÇØ°áÇÒ ¼ö ¾ø½À´Ï´Ù.


´Ü°è 2ºÎÅÍ ´Ü°è 25±îÁö´Â Sun Java System Web Server¿¡ ´ëÇÑ ¼³¸íÀÔ´Ï´Ù.

  1. WebServer Äֿܼ¡ ·Î±×¿ÂÇÕ´Ï´Ù. ±âº» Æ÷Æ®´Â 58888ÀÔ´Ï´Ù.
  2. Access Manager°¡ ½ÇÇà ÁßÀÎ Web Server ÀνºÅϽº¸¦ ¼±ÅÃÇϰí Manage(°ü¸®)¸¦ ´©¸¨´Ï´Ù.
  3. ±¸¼ºÀÌ º¯°æµÇ¾ú´Ù´Â ¸Þ½ÃÁö°¡ ÀÖ´Â ÆË¾÷ âÀÌ Ç¥½ÃµË´Ï´Ù. OK(È®ÀÎ)¸¦ ´©¸¨´Ï´Ù.

  4. È­¸éÀÇ ¿À¸¥ÂÊ À§ ¸ð¼­¸®¿¡ ÀÖ´Â Apply(Àû¿ë) ¹öưÀ» ´©¸¨´Ï´Ù.
  5. Apply Settings(¼³Á¤ Àû¿ë)¸¦ ´©¸¨´Ï´Ù.
  6. Web Server°¡ ÀÚµ¿À¸·Î ´Ù½Ã ½ÃÀ۵Ǿî¾ß ÇÕ´Ï´Ù. È®ÀÎÀ» ´­·¯ °è¼ÓÇÕ´Ï´Ù.

  7. Web Server ÀνºÅϽº ¼±ÅÃÀ» ÁßÁöÇÕ´Ï´Ù.
  8. Security Tab(º¸¾ÈÅÇ)À» ´©¸¨´Ï´Ù.
  9. Create Database(µ¥ÀÌÅͺ£À̽º ¸¸µé±â)¸¦ ´©¸¨´Ï´Ù.
  10. »õ µ¥ÀÌÅͺ£À̽º ºñ¹Ð¹øÈ£¸¦ ÀÔ·ÂÇϰí È®ÀÎÀ» ´©¸¨´Ï´Ù.
  11. ³ªÁß¿¡ »ç¿ëÇÒ ¼ö ÀÖµµ·Ï µ¥ÀÌÅͺ£À̽º ºñ¹Ð¹øÈ£¸¦ ±â·ÏÇØ µÎ½Ê½Ã¿À.

  12. ÀÎÁõ¼­ µ¥ÀÌÅͺ£À̽º¸¦ ÀÛ¼ºÇÑ ÈÄ Request a Certificate(ÀÎÁõ¼­ ¿äû)À» ´©¸¨´Ï´Ù.
  13. È­¸é¿¡ Á¦°øµÈ Çʵ忡 µ¥ÀÌÅ͸¦ ÀÔ·ÂÇÕ´Ï´Ù.
  14. Ű ½Ö ÇÊµå ºñ¹Ð¹øÈ£ Çʵå´Â ´Ü°è 9¿¡ ÀÔ·ÂÇÑ °Í°ú µ¿ÀÏÇÕ´Ï´Ù. À§Ä¡ Çʵ忡 À§Ä¡¸¦ Á¤È®ÇÏ°Ô ÀÔ·ÂÇØ¾ß ÇÕ´Ï´Ù. CA¿Í °°Àº ¾à¾î´Â »ç¿ëÇÒ ¼ö ¾ø½À´Ï´Ù. ¸ðµç Çʵ带 Á¤ÀÇÇØ¾ß ÇÕ´Ï´Ù. °øÅë À̸§ Çʵ忡 Web ServerÀÇ È£½ºÆ® À̸§À» ÀÔ·ÂÇÕ´Ï´Ù.

  15. ¾ç½ÄÀÌ Á¦ÃâµÇ¸é ´ÙÀ½°ú °°Àº ¸Þ½ÃÁö°¡ Ç¥½ÃµË´Ï´Ù.
  16.  

    --BEGIN CERTIFICATE REQUEST---

     

    afajsdllwqeroisdaoi234rlkqwelkasjlasnvdknbslajowijalsdkjfalsdflasdf

     

    alsfjawoeirjoi2ejowdnlkswnvnwofijwoeijfwiepwerfoiqeroijeprwpfrwl

     

    --END CERTIFICATE REQUEST--

  17. ÀÌ ÅØ½ºÆ®¸¦ º¹»çÇÏ¿© ÀÎÁõ¼­¸¦ ¿äûÇÒ ¶§ Á¦ÃâÇÕ´Ï´Ù.
  18. ·çÆ® CA ÀÎÁõ¼­¸¦ °¡Á®¿Í¾ß ÇÕ´Ï´Ù.

  19. ÀÎÁõ¼­°¡ Æ÷ÇÔµÈ ´ÙÀ½°ú °°Àº ÀÎÁõ¼­ ÀÀ´äÀ» ¹Þ°Ô µË´Ï´Ù.
  20. --BEGIN CERTIFICATE---

     

    afajsdllwqeroisdaoi234rlkqwelkasjlasnvdknbslajowijalsdkjfalsdflasdf

     

    alsfjawoeirjoi2ejowdnlkswnvnwofijwoeijfwiepwerfoiqeroijeprwpfrwl

     

    --END CERTIFICATE---

  21. ÀÌ ÅØ½ºÆ®¸¦ Ŭ¸³º¸µå¿¡ º¹»çÇϰųª ÅØ½ºÆ®¸¦ ÆÄÀÏ·Î ÀúÀåÇÕ´Ï´Ù.
  22. Web Server ÄַܼΠÀ̵¿ÇÏ¿© Install Certificate(ÀÎÁõ¼­ ¼³Ä¡)¸¦ ´©¸¨´Ï´Ù.
  23. ÀÌ ¼­¹öÀÇ ÀÎÁõ¼­¸¦ Ŭ¸¯ÇÕ´Ï´Ù.
  24. Ű ½Ö ÆÄÀÏ ºñ¹Ð¹øÈ£ Çʵ忡 ÀÎÁõ¼­ µ¥ÀÌÅͺ£À̽º ºñ¹Ð¹øÈ£¸¦ ÀÔ·ÂÇÕ´Ï´Ù.
  25. ÀÎÁõ¼­¸¦ Á¦°øµÈ ÅØ½ºÆ® Çʵ忡 ºÙ¿© ³Ö°Å³ª ¶óµð¿À ¹öưÀ» ´©¸£°í ÅØ½ºÆ® »óÀÚ¿¡ ÆÄÀÏ À̸§À» ÀÔ·ÂÇÕ´Ï´Ù. Á¦ÃâÀ» Ŭ¸¯ÇÕ´Ï´Ù.
  26. ºê¶ó¿ìÀú¿¡ ÀÎÁõ¼­°¡ Ç¥½ÃµÇ°í ÀÎÁõ¼­¸¦ Ãß°¡Çϱâ À§ÇÑ ¹öưÀÌ Á¦°øµË´Ï´Ù.

  27. ÀÎÁõ¼­ ¼³Ä¡¸¦ Ŭ¸¯ÇÕ´Ï´Ù.
  28. ½Å·ÚÇÒ ¼ö ÀÖ´Â ÀÎÁõ ±â°ü¿¡ ´ëÇÑ ÀÎÁõ¼­¸¦ ´©¸¨´Ï´Ù.
  29. ´Ü°è 16ºÎÅÍ ´Ü°è 21±îÁö ¼³¸íµÈ °Í°ú µ¿ÀÏÇÑ ¹æ¹ýÀ¸·Î ·çÆ® CA ÀÎÁõ¼­¸¦ ¼³Ä¡ÇÕ´Ï´Ù.
  30. µÎ ÀÎÁõ¼­°¡ ¸ðµÎ ¼³Ä¡µÇ¸é Web Server ÄܼÖÀÇ Preferences tab(±âº» ¼³Á¤ ÅÇ)À» ´©¸¨´Ï´Ù.
  31. SSLÀ» ´Ù¸¥ Æ÷Æ®¿¡¼­ »ç¿ë °¡´ÉÇÏ°Ô ÇÏ·Á¸é ¼ö½Å ¼ÒÄÏ Ãß°¡¸¦ ¼±ÅÃÇÕ´Ï´Ù. ±×·± ´ÙÀ½ Edit Listen Socket(¼ö½Å ¼ÒÄÏ ÆíÁý)À» ¼±ÅÃÇÕ´Ï´Ù.
  32. º¸¾È »óŸ¦ »ç¿ë ºÒ°¡´É¿¡¼­ »ç¿ë °¡´ÉÀ¸·Î º¯°æÇϰí OK(È®ÀÎ)¸¦ ´­·¯ º¯°æ ³»¿ëÀ» Á¦ÃâÇÕ´Ï´Ù.

´Ü°è 26ºÎÅÍ ´Ü°è 28±îÁö´Â Access Manager¸¦ ¼³¸íÇÕ´Ï´Ù.

  1. AMConfig.properties ÆÄÀÏÀ» ¿±´Ï´Ù. ±âº»ÀûÀ¸·Î ÀÌ ÆÄÀÏÀÇ À§Ä¡´Â /etc/opt/SUNWam/configÀÔ´Ï´Ù.
  2. Web Server ÀνºÅϽº µð·ºÅ丮¸¦ Á¦¿ÜÇϰí http://ÀÇ ¸ðµç ÇÁ·ÎÅäÄÝ Ç׸ñÀ» https://·Î ±³Ã¼ÇÕ´Ï´Ù. Web Server ÀνºÅϽº µð·ºÅ丮µµ AMConfig.properties¿¡ ÁöÁ¤µÇ¾î ÀÖÁö¸¸ ±×´ë·Î À¯ÁöµÇ¾î¾ß ÇÕ´Ï´Ù.
  3. AMConfig.properties ÆÄÀÏÀ» ÀúÀåÇÕ´Ï´Ù.
  4. Web Server Äֿܼ¡¼­ Web Server ÀνºÅϽº¸¦ È£½ºÆ®ÇÏ´Â Access Manager¿¡ ´ëÇÑ ON/OFF(¼³Á¤/ÇØÁ¦) ¹öưÀ» ´©¸¨´Ï´Ù.
  5. Web ServerÀÇ Start/Stop(½ÃÀÛ/ÁßÁö) ÆäÀÌÁö¿¡ ÀԷ¶õÀÌ Ç¥½ÃµË´Ï´Ù.

  6. ÅØ½ºÆ® Çʵ忡 ÀÎÁõ¼­ µ¥ÀÌÅͺ£À̽º ºñ¹Ð¹øÈ£¸¦ ÀÔ·ÂÇÏ°í ½ÃÀÛÀ» ¼±ÅÃÇÕ´Ï´Ù.


º¸¾È Sun Java System Application Server¸¦ »ç¿ëÇÏ¿© Access Manager ±¸¼º

SSL »ç¿ë °¡´É Sun Java System Application Server¿¡¼­ ½ÇÇàÇϵµ·Ï Access Manager¸¦ ¼³Á¤ÇÏ·Á¸é µÎ ´Ü°è¸¦ °ÅĨ´Ï´Ù. ¸ÕÀú ¼³Ä¡µÈ Access Manager¿¡ ´ëÇÑ Application Server ÀνºÅϽº¿¡ º¸¾ÈÀ» ¼³Á¤ÇÑ ´ÙÀ½ Access Manager¸¦ ±¸¼ºÇÕ´Ï´Ù.

SSLÀ» »ç¿ëÇÏ¿© Application Server 6.2 ¼³Á¤

Application Server ÀνºÅϽº¿¡ º¸¾ÈÀ» ¼³Á¤ÇÏ·Á¸é ´ÙÀ½À» ¼öÇàÇÕ´Ï´Ù.

  1. ºê¶ó¿ìÀú¿¡ ´ÙÀ½ ÁÖ¼Ò¸¦ ÀÔ·ÂÇÏ¿© Sun Java System Application Server Äֿܼ¡ °ü¸®ÀÚ·Î ·Î±×ÀÎÇÕ´Ï´Ù.
  2. http://fullservername:port

    ±âº» Æ÷Æ®´Â 4848ÀÔ´Ï´Ù.

  3. ¼³Ä¡ÇÏ´Â µ¿¾È ÀÔ·ÂÇÑ ¾ÆÀ̵ð¿Í ºñ¹Ð¹øÈ£¸¦ ÀÔ·ÂÇÕ´Ï´Ù.
  4. Access Manager¸¦ ¼³Ä¡Ç߰ųª ¼³Ä¡ÇÒ Application Server ÀνºÅϽº¸¦ ¼±ÅÃÇÕ´Ï´Ù. ¿À¸¥ÂÊ ÇÁ·¹ÀÓ¿¡ ±¸¼ºÀÌ º¯°æµÇ¾ú´Ù´Â ¸Þ½ÃÁö°¡ Ç¥½ÃµË´Ï´Ù.
  5. º¯°æ ³»¿ë Àû¿ëÀ» Ŭ¸¯ÇÕ´Ï´Ù.
  6. Àç½ÃÀÛÀ» Ŭ¸¯ÇÕ´Ï´Ù. Application Server°¡ ÀÚµ¿À¸·Î ´Ù½Ã ½ÃÀ۵Ǿî¾ß ÇÕ´Ï´Ù.
  7. ¿ÞÂÊ ÇÁ·¹ÀÓ¿¡¼­ º¸¾ÈÀ» ´©¸¨´Ï´Ù.
  8. µ¥ÀÌÅͺ£À̽º °ü¸® ÅÇÀ» ´©¸¨´Ï´Ù.
  9. µ¥ÀÌÅͺ£À̽º ¸¸µé±â¸¦ ´©¸¨´Ï´Ù(¼±ÅÃÇÏÁö ¾ÊÀº °æ¿ì).
  10. »õ µ¥ÀÌÅͺ£À̽º ºñ¹Ð¹øÈ£¸¦ ÀÔ·ÂÇϰí È®ÀÎÇÑ ´ÙÀ½ È®ÀÎ ¹öưÀ» ´©¸¨´Ï´Ù. ³ªÁß¿¡ »ç¿ëÇÒ ¼ö ÀÖµµ·Ï µ¥ÀÌÅͺ£À̽º ºñ¹Ð¹øÈ£¸¦ ±â·ÏÇØ µÎ½Ê½Ã¿À.
  11. ÀÎÁõ¼­ µ¥ÀÌÅͺ£À̽º¸¦ ÀÛ¼ºÇÑ ÈÄ ÀÎÁõ¼­ °ü¸® ÅÇÀ» ´©¸¨´Ï´Ù.
  12. ¿äû ¸µÅ©¸¦ ´©¸¨´Ï´Ù(¼±ÅÃÇÏÁö ¾ÊÀº °æ¿ì).
  13. ÀÎÁõ¼­¿¡ ´ëÇØ ´ÙÀ½ ¿äû µ¥ÀÌÅ͸¦ ÀÔ·ÂÇÕ´Ï´Ù.
    1. »õ ÀÎÁõ¼­ÀÎÁö ÀÎÁõ¼­ ¾÷µ¥ÀÌÆ®ÀÎÁö¸¦ ¼±ÅÃÇÕ´Ï´Ù. ƯÁ¤ ±â°£ÀÌ °æ°úÇÏ¸é ¸¹Àº ÀÎÁõ¼­°¡ ¸¸·áµÇ°í ÀϺΠÀÎÁõ ±â°ü(CA)¿¡¼­´Â ¾÷µ¥ÀÌÆ® ¾Ë¸²À» ÀÚµ¿À¸·Î º¸³À´Ï´Ù.
    2. ÀÎÁõ¼­¿¡ ´ëÇÑ ¿äûÀ» Á¦ÃâÇÒ ¹æ¹ýÀ» ÁöÁ¤ÇÕ´Ï´Ù.
    3. CA°¡ ÀüÀÚ ¸ÞÀÏ ¸Þ½ÃÁö·Î ¿äûÀ» ¹Þ´Â °æ¿ì CA ÀüÀÚ ¸ÞÀÏÀ» ¼±ÅÃÇϰí CAÀÇ ÀüÀÚ ¸ÞÀÏ ÁÖ¼Ò¸¦ ÀÔ·ÂÇÕ´Ï´Ù. CA ¸ñ·Ï¿¡¼­ »ç¿ë °¡´ÉÇÑ ÀÎÁõ ±â°ü ¸ñ·ÏÀ» ´©¸¨´Ï´Ù.

      Sun Java System Certificate Server¸¦ »ç¿ëÇÏ´Â ³»ºÎ CA·ÎºÎÅÍ ÀÎÁõ¼­¸¦ ¿äûÇÒ °æ¿ì CA URLÀ» ´©¸£°í Certificate Server¿¡ ´ëÇÑ URLÀ» ÀÔ·ÂÇÕ´Ï´Ù. ÀÌ URLÀº ÀÎÁõ¼­ ¿äûÀ» ó¸®ÇÏ´Â ÀÎÁõ¼­ ¼­¹öÀÇ ÇÁ·Î±×·¥À» °¡¸®ÄÑ¾ß ÇÕ´Ï´Ù.

    4. Ű ½Ö ÆÄÀÏ¿¡ ´ëÇÑ ºñ¹Ð¹øÈ£(´Ü°è 9¿¡¼­ ÁöÁ¤ÇÑ ºñ¹Ð¹øÈ£)¸¦ ÀÔ·ÂÇÕ´Ï´Ù.
    5. ´ÙÀ½ ½Äº° Á¤º¸¸¦ ÀÔ·ÂÇÕ´Ï´Ù.
    6. °øÅë À̸§. Æ÷Æ® ¹øÈ£¸¦ Æ÷ÇÔÇÏ¿© ¼­¹öÀÇ ¼º¸íÀÔ´Ï´Ù.

      ¿äûÀÚ À̸§. ¿äûÀÚÀÇ À̸§ÀÔ´Ï´Ù.

      ÀüÈ­ ¹øÈ£. ¿äûÀÚÀÇ ÀüÈ­ ¹øÈ£ÀÔ´Ï´Ù.

      °øÅë À̸§. µðÁöÅÐ ÀÎÁõ¼­¸¦ ¼³Ä¡ÇÒ Sun Java System Application ServerÀÇ Á¤±ÔÈ­µÈ À̸§ÀÔ´Ï´Ù.

      ÀüÀÚ ¸ÞÀÏ ÁÖ¼Ò. °ü¸®ÀÚÀÇ ÀüÀÚ ¸ÞÀÏ ÁÖ¼ÒÀÔ´Ï´Ù.

      Á¶Á÷ À̸§. Á¶Á÷ÀÇ À̸§ÀÔ´Ï´Ù. ÀÎÁõ ±â°üÀº ÀÌ Á¶Á÷¿¡ µî·ÏµÈ µµ¸ÞÀο¡ ¼ÓÇÏ´Â ÀÌ ¼Ó¼º¿¡ ÀÔ·ÂµÈ È£½ºÆ® À̸§À» ¿ä±¸ÇÒ ¼ö ÀÖ½À´Ï´Ù.

      Á¶Á÷ ±¸¼º ´ÜÀ§ À̸§. °ú, ºÎ¼­ ¹× ±âŸ Á¶Á÷ ¿î¿µ ´ÜÀ§ÀÇ À̸§ÀÔ´Ï´Ù.

      ±¸/±º/½Ã À̸§. »ç¿ëÀÚÀÇ ±¸/±º/½Ã À̸§ÀÔ´Ï´Ù.

      ½Ã/µµ À̸§. Á¶Á÷ÀÌ ¹Ì±¹ ¶Ç´Â ij³ª´Ù¿¡ ÀÖ´Â °æ¿ì °¢°¢ Á¶Á÷ÀÌ ¿î¿µµÇ´Â ½Ã ¶Ç´Â µµÀÇ À̸§ÀÔ´Ï´Ù. ¾à¾î¸¦ »ç¿ëÇÏÁö ¸¶½Ê½Ã¿À.

      ±¹°¡ ÄÚµå. ±¹°¡¿¡ ´ëÇÑ 2¹®ÀÚ ISO ÄÚµåÀÔ´Ï´Ù. ¿¹¸¦ µé¾î, ¹Ì±¹ÀÇ ±¹°¡ ÄÚµå´Â USÀÔ´Ï´Ù.

  14. È®ÀÎ ¹öưÀ» ´©¸¨´Ï´Ù. ¸Þ½ÃÁö°¡ Ç¥½ÃµË´Ï´Ù. ¿¹¸¦ µé¸é ´ÙÀ½°ú °°½À´Ï´Ù.
  15. --BEGIN NEW CERTIFICATE REQUEST---

    afajsdllwqeroisdaoi234rlkqwelkasjlasnvdknbslajowijalsdkjfalsdfla

    alsfjawoeirjoi2ejowdnlkswnvnwofijwoeijfwiepwerfoiqeroijeprwpfrwl

    --END NEW CERTIFICATE REQUEST--

  16. ÀÌ ÅØ½ºÆ®¸¦ ¸ðµÎ ÆÄÀÏ¿¡ º¹»çÇϰí È®ÀÎÀ» ´©¸¨´Ï´Ù. ·çÆ® CA ÀÎÁõ¼­¸¦ °¡Á®¿Í¾ß ÇÕ´Ï´Ù.
  17. CA¸¦ ¼±ÅÃÇϰí ÇØ´ç ±â°üÀÇ À¥ »çÀÌÆ® Áö½Ã¿¡ µû¶ó µðÁöÅÐ ÀÎÁõ¼­¸¦ °¡Á®¿É´Ï´Ù. CMS, Verisign ¶Ç´Â Entrust.net¿¡¼­ ÀÎÁõ¼­¸¦ °¡Á®¿Ã ¼ö ÀÖ½À´Ï´Ù.
  18. ÀÎÁõ ±â°üÀ¸·ÎºÎÅÍ µðÁöÅÐ ÀÎÁõ¼­¸¦ ¹ÞÀº ÈÄ ÅØ½ºÆ®¸¦ Ŭ¸³º¸µå¿¡ º¹»çÇϰųª ÆÄÀÏ·Î ÀúÀåÇÒ ¼ö ÀÖ½À´Ï´Ù.
  19. Sun Java System Application Server ÄַܼΠÀ̵¿ÇÏ¿© ¼³Ä¡ ¸µÅ©¸¦ ´©¸¨´Ï´Ù.
  20. ÀÌ ¼­¹ö¿¡ ´ëÇÑ ÀÎÁõ¼­¸¦ ¼±ÅÃÇÕ´Ï´Ù.
  21. Ű ½Ö ÆÄÀÏ ºñ¹Ð¹øÈ£ Çʵ忡 ÀÎÁõ¼­ µ¥ÀÌÅͺ£À̽º ºñ¹Ð¹øÈ£¸¦ ÀÔ·ÂÇÕ´Ï´Ù(´Ü°è 9¿¡ ÀÔ·ÂÇÑ ºñ¹Ð¹øÈ£).
  22. ÀÎÁõ¼­¸¦ Á¦°øµÈ ÅØ½ºÆ® ÇʵåÀÎ ¸Þ½ÃÁö ÅØ½ºÆ®(Çì´õ ÀÖÀ½)¿¡ ºÙ¿© ³Ö°Å³ª ÀÌ ÆÄÀÏ ÀԷ¶õ¿¡ ÀÖ´Â ¸Þ½ÃÁö¿¡ ÆÄÀÏ À̸§À» ÀÔ·ÂÇÕ´Ï´Ù. ÇØ´ç ¶óµð¿À ¹öưÀ» ¼±ÅÃÇÕ´Ï´Ù.
  23. È®ÀÎ ¹öưÀ» ´©¸¨´Ï´Ù. ºê¶ó¿ìÀú¿¡ ÀÎÁõ¼­°¡ Ç¥½ÃµÇ°í ÀÎÁõ¼­¸¦ Ãß°¡ÇÒ ¼ö ÀÖ´Â ¹öưÀÌ Á¦°øµË´Ï´Ù.
  24. ¼­¹ö ÀÎÁõ¼­ Ãß°¡¸¦ ´©¸¨´Ï´Ù.
  25. ´Ü°è 10ºÎÅÍ ´Ü°è 22±îÁö ¼³¸íµÈ °Í°ú µ¿ÀÏÇÑ ¹æ¹ýÀ¸·Î ·çÆ® CA ÀÎÁõ¼­¸¦ ¼³Ä¡ÇÕ´Ï´Ù. ±×·¯³ª ´Ü°è 18¿¡¼­´Â ½Å·ÚÇÒ ¼ö ÀÖ´Â ÀÎÁõ ±â°ü¿¡ ´ëÇÑ ÀÎÁõ¼­¸¦ ¼±ÅÃÇÕ´Ï´Ù.
  26. ÀÎÁõ¼­ ¼³Ä¡°¡ ¿Ï·áµÈ °æ¿ì ¿ÞÂÊ ÇÁ·¹ÀÓ¿¡¼­ HTTP Server ³ëµå¸¦ È®ÀåÇÕ´Ï´Ù.
  27. HTTP Server¿¡¼­ HTTP Listeners¸¦ ¼±ÅÃÇÕ´Ï´Ù.
  28. http-listener-1À» ¼±ÅÃÇÕ´Ï´Ù. ºê¶ó¿ìÀú¿¡ ¼ÒÄÏ Á¤º¸°¡ Ç¥½ÃµË´Ï´Ù.
  29. http-listener-1¿¡ »ç¿ëµÇ´Â Æ÷Æ® °ªÀ» ÀÀ¿ë ÇÁ·Î±×·¥ ¼­¹ö¸¦ ¼³Ä¡ÇÏ´Â µ¿¾È ÀÔ·ÂÇÑ °ª¿¡¼­ ÇØ´ç °ª(¿¹: 443)À¸·Î º¯°æÇÕ´Ï´Ù.
  30. SSL/TLS »ç¿ë °¡´ÉÀ» ¼±ÅÃÇÕ´Ï´Ù.
  31. ÀÎÁõ¼­ º°¸íÀ» ¼±ÅÃÇÕ´Ï´Ù.
  32. ¹Ýȯ ¼­¹ö¸¦ ÁöÁ¤ÇÕ´Ï´Ù. ÀÌ À̸§Àº ´Ü°è 12¿¡ ÁöÁ¤µÈ °øÅë À̸§°ú ÀÏÄ¡ÇØ¾ß ÇÕ´Ï´Ù.
  33. ÀúÀåÀ» ´©¸¨´Ï´Ù.
  34. Sun Java System Access Manager ¼ÒÇÁÆ®¿þ¾î¸¦ ¼³Ä¡ÇÒ Application Server ÀνºÅϽº¸¦ ¼±ÅÃÇÕ´Ï´Ù. ¿À¸¥ÂÊ ÇÁ·¹ÀÓ¿¡ ±¸¼ºÀÌ º¯°æµÇ¾ú´Ù´Â ¸Þ½ÃÁö°¡ Ç¥½ÃµË´Ï´Ù.
  35. º¯°æ ³»¿ë Àû¿ëÀ» Ŭ¸¯ÇÕ´Ï´Ù.
  36. Àç½ÃÀÛÀ» Ŭ¸¯ÇÕ´Ï´Ù. ÀÀ¿ëÇÁ·Î±×·¥ ¼­¹ö°¡ ÀÚµ¿À¸·Î ´Ù½Ã ½ÃÀ۵˴ϴÙ.

SSLÀ» »ç¿ëÇÏ¿© Application Server 8.1 ¼³Á¤

Application Server ÀνºÅϽº¿¡ º¸¾ÈÀ» ¼³Á¤ÇÏ·Á¸é ´ÙÀ½À» ¼öÇàÇÕ´Ï´Ù.

  1. Application Server ÀνºÅϽº°¡ ÁßÁöµÇ¾ú´ÂÁö È®ÀÎÇÕ´Ï´Ù.
  2. asadmin>change-master-password ¸í·ÉÀ» »ç¿ëÇÏ¿© ÅäÅ« ºñ¹Ð¹øÈ£¸¦ º¯°æÇÕ´Ï´Ù.
  3. Application Server ÄַܼΠÀ̵¿ÇÏ¿© ±¸¼º> HTTP ¼­ºñ½º> HTTP Listeners¸¦ ¼±ÅÃÇÕ´Ï´Ù.
  4. »ç¿ëÇÒ ¼ö½Å±â¸¦ ´©¸£°í ¿À¸¥ÂÊ Ã¢¿¡¼­ Security:Enabled¸¦ ¼±ÅÃÇÕ´Ï´Ù.
  5. certutilÀÌ ¼³Ä¡µÇ¾î ÀÖ´ÂÁö È®ÀÎÇÕ´Ï´Ù.
    1. /usr/sfw/binÀ¸·Î À̵¿ÇÕ´Ï´Ù.
    2. ¼³Ä¡µÇ¾î ÀÖÁö ¾ÊÀ¸¸é ´ÙÀ½ µð·ºÅ丮¿¡¼­ SUNWtlsu ÆÐŰÁö¸¦ ¼³Ä¡ÇÕ´Ï´Ù.
    3. /share/builds/integration/security/SECURITY_3_9_3_03B4/packages/~platform~

    4. ½© ȯ°æ º¯¼ö LD_LIBRARY_PATH
    5. LD_LIBRARY_PATH has to have /usr/lib/mps/secv1

  6. certutilÀ» »ç¿ëÇÏ¿© certdb¿¡ ¼³Ä¡µÈ ÀÎÁõ¼­¸¦ È®ÀÎÇÕ´Ï´Ù.
    1. /var/opt/SUNWappserver/domains/domain1/config·Î À̵¿ÇÕ´Ï´Ù.
    2. certutil -L -d
    3. ´ÙÀ½ Ãâ·ÂÀÌ ³ªÅ¸³³´Ï´Ù.
    4. /var/opt/SUNWappserver/domains/domain1/config/% certutil -L -d

      Application Server 8.1Àº ¼³Ä¡ ½Ã ÀÚü ¼­¸íµÈ ¼­¹ö ÀÎÁõ¼­(º°¸í s1as)¸¦ ¼³Ä¡Çϰí ssl »ç¿ë Æ÷Æ® 4848, 8181¿¡ À̸¦ »ç¿ëÇÕ´Ï´Ù.

  7. ÀÎÁõ¼­ ¿äûÀ» »ý¼ºÇÕ´Ï´Ù. ±¸¹®Àº ´ÙÀ½°ú °°½À´Ï´Ù.
  8. certutil -R -s subj -o cert-request-file [-d certdir] [-P dbprefix] [-p phone] [-a]

    ¿¹¸¦ µé¸é ´ÙÀ½°ú °°½À´Ï´Ù.

    certutil -R -s "CN=test.company1.com, O=company1.com, C=US" -o cert.req -d . -a

  9. ´ÙÀ½ ¸í·ÉÀ» »ç¿ëÇÏ¿© CA·ÎºÎÅÍ ÀÎÁõ¼­¸¦ °Ë»öÇÕ´Ï´Ù.
  10. certutil -A -n cert-name -t trustargs [-d certdir] [-P dbprefix] [-a] [-i input]

  11. ¼­¹ö ÀÎÁõ¼­¸¦ ÆÄÀÏ·Î ÀúÀåÇÕ´Ï´Ù.
  12. ´ÙÀ½ ¸í·É ±¸¹®À» »ç¿ëÇÏ¿© ½Å·ÚÇÒ ¼ö ÀÖ´Â CA ÀÎÁõ¼­¸¦ ¼³Ä¡ÇÕ´Ï´Ù.
  13. certutil -A -n cert-name -t trustargs [-d certdir] [-P dbprefix] [-a] [-i input]

    ½Å·ÚÇÒ ¼ö ÀÖ´Â CA ÀÎÁõ¼­¸¦ ÆÄÀÏ(¿¹: cacert.txt)·Î ÀúÀåÇÕ´Ï´Ù.

  14. certdb¸¦ ³ª¿­ÇÏ¿© ¼³Ä¡°¡ ¼º°øÇß´ÂÁö È®ÀÎÇÕ´Ï´Ù. ´ÙÀ½ ¸í·ÉÀ» ÀÔ·ÂÇÕ´Ï´Ù.
  15. /var/opt/SUNWappserver/domains/domain1/config/% certutil -L -d

  16. Application Server °ü¸® ÄַܼΠÀ̵¿ÇÏ¿© HTTP Listeners¸¦ ¼±ÅÃÇÕ´Ï´Ù.
  17. ÀÏ¹Ý ¼³Á¤¿¡¼­ »õ ¼­¹ö ÀÎÁõ¼­·Î HTTP Listener¸¦ ±¸¼ºÇÕ´Ï´Ù.

  18. Application Server¸¦ ´Ù½Ã ½ÃÀÛÇÕ´Ï´Ù.

SSL ¸ðµå¿¡¼­ Access Manager ±¸¼º

SSL ¸ðµå¿¡¼­ Access Manager¸¦ ±¸¼ºÇÏ·Á¸é ´ÙÀ½À» ¼öÇàÇÕ´Ï´Ù.

  1. Access Manager Äֿܼ¡¼­ ¼­ºñ½º ±¸¼º ¸ðµâ·Î À̵¿ÇÏ¿© Ç÷§Æû ¼­ºñ½º¸¦ ¼±ÅÃÇÕ´Ï´Ù. ¼­¹ö ¸ñ·Ï ¼Ó¼º¿¡¼­ HTTPS ÇÁ·ÎÅäÄݰú µ¿ÀÏÇÑ URL ¹× SSL »ç¿ë °¡´É Æ÷Æ® ¹øÈ£¸¦ Ãß°¡ÇÕ´Ï´Ù. ÀúÀåÀ» ´©¸¨´Ï´Ù.

  2. ÁÖ

    ´ÜÀÏ Access Manager ÀνºÅϽº°¡ HTTP¿Í HTTPS °¢°¢ Çϳª¾¿ µÎ °³ÀÇ Æ÷Æ®¸¦ ¼ö½ÅÇϰí ÀÖ°í Äí۸¦ »ç¿ëÇÏ¿© Access Manager¿¡ ¾×¼¼½ºÇÏ·Á°í ½ÃµµÇÒ °æ¿ì Access Manager´Â ÀÀ´äÇÏÁö ¾Ê´Â »óŰ¡ µË´Ï´Ù. ÀÌ·¯ÇÑ ±¸¼ºÀº Áö¿øµÇÁö ¾Ê½À´Ï´Ù.


  3. ´ÙÀ½ ±âº» À§Ä¡¿¡¼­ AMConfig.properties ÆÄÀÏÀ» ¿±´Ï´Ù.
  4. /etc/opt/SUNWam/config

  5. http://ÀÇ ¸ðµç ÇÁ·ÎÅäÄÝ Ç׸ñÀ» https://·Î ±³Ã¼ÇÏ°í Æ÷Æ® ¹øÈ£¸¦ SSL »ç¿ë °¡´É Æ÷Æ® ¹øÈ£·Î º¯°æÇÕ´Ï´Ù.
  6. AMConfig.properties ÆÄÀÏÀ» ÀúÀåÇÕ´Ï´Ù.
  7. Application Server¸¦ ´Ù½Ã ½ÃÀÛÇÕ´Ï´Ù.


º¸¾È BEA WebLogic Server·Î AMSDK ±¸¼º

SSL¿¡¼­ AMSDK·Î BEA WebLogic Server¸¦ ±¸¼ºÇϱâ Àü¿¡ ¸ÕÀú À¥ ÄÁÅ×À̳ʷμ­ BEA WebLogic Server¸¦ ¼³Ä¡ÇØ¾ß ÇÕ´Ï´Ù. ¼³Ä¡ ÁöħÀ» º¸·Á¸é BEA WebLogic Server ¼³¸í¼­¸¦ ÂüÁ¶ÇϽʽÿÀ. Access Manager¿¡ ´ëÇÑ À¥ ÄÁÅ×À̳ʷμ­ WebLogicÀ» ±¸¼ºÇÏ·Á¸é 1Àå, "Access Manager 2005Q1 ±¸¼º ½ºÅ©¸³Æ®"¸¦ ÂüÁ¶ÇϽʽÿÀ.

º¸¾È WebLogic ÀνºÅϽº¸¦ ±¸¼ºÇÏ·Á¸é ´ÙÀ½À» ¼öÇàÇÕ´Ï´Ù.

  1. Áï¼® ½Ãµ¿ ¸Þ´º¸¦ »ç¿ëÇÏ¿© µµ¸ÞÀÎÀ» ¸¸µì´Ï´Ù.
  2. WebLogic ¼³Ä¡ µð·ºÅ丮·Î À̵¿ÇÏ¿© ÀÎÁõ¼­ ¿äûÀ» »ý¼ºÇÕ´Ï´Ù.
  3. vetri_csr.txt CSRÀ» »ç¿ëÇÏ¿© ÀÌ ¼­¹ö ÀÎÁõ¼­¸¦ CA¿¡ Á¦ÃâÇÕ´Ï´Ù.
  4. ½ÂÀÎµÈ ÀÎÁõ¼­¸¦ ÅØ½ºÆ® ÆÄÀÏ·Î ÀúÀåÇÕ´Ï´Ù. ¿¹¸¦ µé¸é approvedcert.txtÀÔ´Ï´Ù.
  5. ´ÙÀ½ ¸í·ÉÀ» »ç¿ëÇÏ¿© ·çÆ® CA¸¦ cacerts¿¡ ·ÎµåÇÕ´Ï´Ù.
  6. cd jdk141_03/jre/lib/security/

    jdk141_03/jre/bin/keytool -keystore cacerts -keyalg RSA -import -trustcacerts -alias "Greenday CA" -storepass changeit -file /opt/bea81/cacert.txt

  7. ´ÙÀ½ ¸í·ÉÀ» »ç¿ëÇÏ¿© ¼­¹ö ÀÎÁõ¼­¸¦ ·ÎµåÇÕ´Ï´Ù.
  8. jdk141_03/jre/bin/keytool -import -keystore keystore -keyalg RSA -import -trustcacerts -file approvedcert.txt -alias "mykey"

  9. »ç¿ëÀÚ À̸§°ú ºñ¹Ð¹øÈ£¸¦ »ç¿ëÇÏ¿© WebLogic Äֿܼ¡ ·Î±×ÀÎÇÕ´Ï´Ù.
  10. ´ÙÀ½ À§Ä¡·Î À̵¿ÇÕ´Ï´Ù.
  11. yourdomain> Servers> myserver> Configure Keystores

  12. »ç¿ëÀÚ Á¤ÀÇ ID¸¦ ¼±ÅÃÇÑ ´ÙÀ½ Java Standard Trust¸¦ ¼±ÅÃÇÕ´Ï´Ù.
  13. Ű ÀúÀå¼Ò À§Ä¡¸¦ ÀÔ·ÂÇÕ´Ï´Ù. ¿¹¸¦ µé¸é /opt/bea81/keystoreÀÔ´Ï´Ù.
  14. Ű ÀúÀå¼Ò ºñ¹Ð¹øÈ£¿Í Ű ÀúÀå¼Ò ºñ¹Ð ¹®±¸¸¦ ÀÔ·ÂÇÕ´Ï´Ù. ¿¹¸¦ µé¸é ´ÙÀ½°ú °°½À´Ï´Ù.
  15. Ű ÀúÀå¼Ò ºñ¹Ð¹øÈ£: JKS/Java Standard Trust(WL 8.1ÀÇ °æ¿ì JKS¸¸ »ç¿ë)

    Ű ÀúÀå¼Ò ºñ¹Ð ¹®±¸: changeit

  16. ÀÌ ´Ü°è¿¡¼­´Â SSL °³ÀΠŰ ¼³Á¤ °³ÀΠŰ º°Äª: mykey ¹× ºñ¹Ð¹øÈ£: secret12¸¦ °ËÅäÇÕ´Ï´Ù.

  17. ÁÖ

    °¡Àå °­µµ°¡ ³ôÀº SSL ¶óÀ̼¾½º¸¦ »ç¿ëÇØ¾ß ÇÕ´Ï´Ù. ±×·¸Áö ¾ÊÀ¸¸é SSL ½ÃÀÛÀÌ ½ÇÆÐÇÕ´Ï´Ù.


  18. Access ManagerÀÇ °æ¿ì ¼³Ä¡ ½Ã AmConfig.propertiesÀÇ ´ÙÀ½ ¸Å°³ º¯¼ö°¡ ÀÚµ¿À¸·Î ±¸¼ºµË´Ï´Ù. ÀÚµ¿ ±¸¼ºµÇÁö ¾ÊÀ» °æ¿ì¿¡´Â »ç¿ëÀÚ°¡ ÀûÀýÇÏ°Ô ÆíÁýÇÒ ¼ö ÀÖ½À´Ï´Ù.
  19. com.sun.identity.jss.donotInstallAtHighestPriority=true [ this is not required for AM 6.3 and above]

    com.iplanet.security.SecureRandomFactoryImpl=com.iplanet.am.util.SecureRandomFactoryImpl

    com.iplanet.security.SSLSocketFactoryImpl=netscape.ldap.factory.JSSESocketFactory

    com.iplanet.security.encryptor=com.iplanet.services.util.JCEEncryption2

    JDK °æ·Î°¡ ´ÙÀ½°ú °°Àº °æ¿ì

    com.iplanet.am.jdk.path=/usr/jdk/entsys-j2se

    Ű µµ±¸ À¯Æ¿¸®Æ¼¸¦ »ç¿ëÇÏ¿© ·çÆ® CA¸¦ ÀÎÁõ¼­ µ¥ÀÌÅͺ£À̽º·Î °¡Á®¿Í¾ß ÇÕ´Ï´Ù. ¿¹¸¦ µé¸é ´ÙÀ½°ú °°½À´Ï´Ù.

    /usr/jdk/entsys-j2se/jre/lib/security

    /usr/jdk/entsys-j2se/jre/bin/keytool -keystore cacerts -keyalg RSA -import -trustcacerts -alias "machinename" -storepass changeit -file

    /opt/bea81/cacert.txt

    Ű µµ±¸ À¯Æ¿¸®Æ¼´Â ´ÙÀ½ µð·ºÅ丮¿¡ ÀÖ½À´Ï´Ù.

    /usr/jdk/entsys-j2se/jre/bin/keytool

  20. Access Manager amadmin ¸í·ÉÁÙ À¯Æ¿¸®Æ¼¿¡¼­ -D"java.protocol.handler.pkgs=com.iplanet.services.comm"À» Á¦°ÅÇÕ´Ï´Ù.
  21. SSL ¸ðµå¿¡¼­ Access Manager¸¦ ±¸¼ºÇÕ´Ï´Ù. ¼¼ºÎ »çÇ׿¡ ´ëÇØ¼­´Â SSL ¸ðµå¿¡¼­ Access Manager ±¸¼ºÀ» ÂüÁ¶ÇϽʽÿÀ.


º¸¾È IBM WebSphere Application Server·Î AMSDK ±¸¼º

SSL¿¡¼­ AMSDK¸¦ »ç¿ëÇÏ¿© IBM WebShpere Server¸¦ ±¸¼ºÇϱâ Àü¿¡ ¸ÕÀú IBM WebShpere Server¸¦ ¼³Ä¡Çϰí À¥ ÄÁÅ×À̳ʷμ­ ±¸¼ºÇØ¾ß ÇÕ´Ï´Ù. ÀÚ¼¼ÇÑ ³»¿ëÀº WebSphere Server ¼³¸í¼­¸¦ ÂüÁ¶ÇϽʽÿÀ. Access ManagerÀÇ À¥ ÄÁÅ×À̳ʷμ­ WebLogic¸¦ ±¸¼ºÇÏ·Á¸é 1Àå, "Access Manager 2005Q1 ±¸¼º ½ºÅ©¸³Æ®"¸¦ ÂüÁ¶ÇϽʽÿÀ.

º¸¾È WebSphere ÀνºÅϽº¸¦ ±¸¼ºÇÏ·Á¸é ´ÙÀ½À» ¼öÇàÇÕ´Ï´Ù.

  1. Websphere /bin µð·ºÅ丮¿¡ ÀÖ´Â ikeyman.sh¸¦ ½ÃÀÛÇÕ´Ï´Ù.
  2. ¼­¸íÀÚ ¸Þ´º¿¡¼­ ÀÎÁõ ±â°ü(CA)ÀÇ ÀÎÁõ¼­¸¦ °¡Á®¿É´Ï´Ù.
  3. °³ÀÎ ÀÎÁõ¼­ ¸Þ´º¿¡¼­ CSRÀ» »ý¼ºÇÕ´Ï´Ù.
  4. ÀÌÀü ´Ü°è¿¡¼­ ¸¸µç ÀÎÁõ¼­¸¦ °ËÅäÇÕ´Ï´Ù.
  5. °³ÀÎ ÀÎÁõ¼­¸¦ ¼±ÅÃÇÏ°í ¼­¹ö ÀÎÁõ¼­¸¦ °¡Á®¿É´Ï´Ù.
  6. WebSphere Äֿܼ¡¼­ ±âº» SSL ¼³Á¤À» ¹Ù²Ù°í ¾Ïȣȭ¸¦ ¼±ÅÃÇÕ´Ï´Ù.
  7. ±âº» IBMJSSE SSL °ø±ÞÀÚ¸¦ ¼³Á¤ÇÕ´Ï´Ù.
  8. ´ÙÀ½ ¸í·ÉÀ» ÀÔ·ÂÇÏ¿© ¹æ±Ý ¸¸µç ÆÄÀÏ¿¡¼­ CA ÀÎÁõ¼­¸¦ ÀÀ¿ë ÇÁ·Î±×·¥ ¼­¹ö JVM Ű ÀúÀå¼Ò·Î °¡Á®¿É´Ï´Ù.
  9. $ appserver_root-dir/java/bin/ keytool -import -trustcacerts -alias cmscacert -keystore ../jre/lib/security/cacerts -file /full_path_cacert_filename.txt

    app-server-root-dir ´Â ÀÀ¿ë ÇÁ·Î±×·¥ ¼­¹öÀÇ ·çÆ® µð·ºÅ丮À̸ç full_path_cacert_filename.txt ´Â ÀÎÁõ¼­°¡ ÀÖ´Â ÆÄÀÏÀÇ Àüü °æ·ÎÀÔ´Ï´Ù.

  10. Access Manager¿¡¼­ JSSE¸¦ »ç¿ëÇϵµ·Ï AmConfig.propertiesÀÇ ´ÙÀ½ ¸Å°³ º¯¼ö¸¦ ¾÷µ¥ÀÌÆ®ÇÕ´Ï´Ù.
  11. com.sun.identity.jss.donotInstallAtHighestPriority=true

    com.iplanet.security.SecureRandomFactoryImpl=com.iplanet.am.util.SecureRandomFactoryImpl

    com.iplanet.security.SSLSocketFactorImpl=netscape.ldap.factory.JSSESocketFactory

    com.iplanet.security.encyptor=com.iplanet.services.unil.JCEEncryption

  12. SSL ¸ðµå¿¡¼­ Access Manager¸¦ ±¸¼ºÇÕ´Ï´Ù. ¼¼ºÎ »çÇ׿¡ ´ëÇØ¼­´Â SSL ¸ðµå¿¡¼­ Access Manager ±¸¼ºÀ» ÂüÁ¶ÇϽʽÿÀ.


SSL ¸ðµå¿¡¼­ Access Manager¸¦ Directory Server·Î ±¸¼º

³×Æ®¿öÅ©¸¦ ÅëÇÑ º¸¾È Åë½ÅÀ» Á¦°øÇϱâ À§ÇØ Access Manager¿¡´Â LDAPS Åë½Å ÇÁ·ÎÅäÄÝÀÌ Æ÷ÇԵǾî ÀÖ½À´Ï´Ù. LDAPS´Â Ç¥ÁØ LDAP ÇÁ·ÎÅäÄÝÀÌÁö¸¸ SSL(Secure Sockets Layer)ÀÇ »óÀ§¿¡¼­ ½ÇÇàµË´Ï´Ù. SSL Åë½ÅÀ» »ç¿ëÇÏ·Á¸é ¸ÕÀú Directory Server¸¦ SSL ¸ðµå¿¡¼­ ±¸¼ºÇÑ ´ÙÀ½ Access Manager¸¦ Directory Server·Î ¿¬°áÇÕ´Ï´Ù. ±âº»ÀûÀÎ ´Ü°Ô´Â ´ÙÀ½°ú °°½À´Ï´Ù.

  1. Directory ServerÀÇ ÀÎÁõ¼­¸¦ ±¸ÇÏ¿© ¼³Ä¡Çϰí ÀÎÁõ ±â°ü(CA)ÀÇ ÀÎÁõ¼­¸¦ ½Å·ÚÇϵµ·Ï Directory Server¸¦ ±¸¼ºÇÕ´Ï´Ù.
  2. µð·ºÅ丮¿¡¼­ SSLÀ» Ȱ¼ºÈ­ÇÕ´Ï´Ù.
  3. ÀÎÁõ, Á¤Ã¥ ¹× Ç÷§Æû ¼­ºñ½º¸¦ ±¸¼ºÇÏ¿© SSL »ç¿ë Directory Server·Î ¿¬°áÇÕ´Ï´Ù.
  4. Access Manager¸¦ Directory Server ¹é¿£µå¿¡ ¾ÈÀüÇÏ°Ô ¿¬°áµÇµµ·Ï ±¸¼ºÇÕ´Ï´Ù.

SSL ¸ðµå¿¡¼­ Directory Server ±¸¼º

Directory Server¸¦ SSL ¸ðµå¿¡¼­ ±¸¼ºÇÏ·Á¸é ¼­¹ö ÀÎÁõ¼­¸¦ ±¸ÇÏ¿© ¼³Ä¡Çϰí ÀÎÁõ ±â°üÀÇ ÀÎÁõ¼­¸¦ ½Å·ÚÇϵµ·Ï Directory Server¸¦ ±¸¼ºÇÑ ´ÙÀ½ SSLÀ» Ȱ¼ºÈ­ÇØ¾ß ÇÕ´Ï´Ù. ÀÚ¼¼ÇÑ ³»¿ëÀº Directory Server °ü¸® ¼³¸í¼­ÀÇ 11Àå "ÀÎÁõ ¹× ¾Ïȣȭ °ü¸®"¿¡ ÀÖ½À´Ï´Ù. ÀÌ ¹®¼­´Â ´ÙÀ½ À§Ä¡¿¡ ÀÖ½À´Ï´Ù.

¶ÇÇÑ ´ÙÀ½ À§Ä¡¿¡¼­ PDF ÇüÅÂÀÇ ¼³¸í¼­¸¦ ´Ù¿î·ÎµåÇÒ ¼ö ÀÖ½À´Ï´Ù.

http://docs.sun.com/coll/DirectoryServer_04q2 ¹×
http://docs.sun.com/coll/DirectoryServer_04q2?l=ko

Directory Server°¡ ÀÌ¹Ì SSL »ç¿ë °¡´É »óÅÂÀ̸é Access Manager¸¦ Directory Server·Î ¿¬°áÇÏ´Â ¹æ¹ýÀ» ÀÚ¼¼È÷ ¼³¸íÇÏ´Â ´ÙÀ½ Àý·Î À̵¿ÇÕ´Ï´Ù.

Access Manager¸¦ SSL »ç¿ë Directory Server·Î ¿¬°á

ÀÏ´Ü SSL ¸ðµå·Î Directory Server°¡ ±¸¼ºµÈ ´ÙÀ½¿¡´Â Access Manager¸¦ Directory Server ¹é¿£µå·Î ¿¬°áÇØ¾ß ÇÕ´Ï´Ù. ¼öÇà ¹æ¹ýÀº ´ÙÀ½°ú °°½À´Ï´Ù.

  1. Access Manager Äֿܼ¡¼­ ¼­ºñ½º ±¸¼º ¸ðµâÀÇ LDAP ÀÎÁõ ¼­ºñ½º·Î À̵¿ÇÕ´Ï´Ù.
    1. Directory Server Æ÷Æ®¸¦ SSL Æ÷Æ®·Î º¯°æÇÕ´Ï´Ù.
    2. LDAP ¼­¹ö¿¡ ´ëÇÑ SSL ¾×¼¼½º °¡´É ¼Ó¼ºÀ» ¼±ÅÃÇÕ´Ï´Ù.
  2. ¼­ºñ½º ±¸¼º ¸ðµâÀÇ ±¸¼º¿ø ÀÎÁõ ¼­ºñ½º·Î À̵¿ÇÕ´Ï´Ù.
    1. Directory Server Æ÷Æ®¸¦ SSL Æ÷Æ®·Î º¯°æÇÕ´Ï´Ù.
    2. LDAP ¼­¹ö¿¡ ´ëÇÑ SSL ¾×¼¼½º °¡´É ¼Ó¼ºÀ» ¼±ÅÃÇÕ´Ï´Ù.
  3. ¼­ºñ½º ±¸¼º¿¡ ÀÖ´Â Á¤Ã¥ ±¸¼º ¼­ºñ½º·Î À̵¿ÇÕ´Ï´Ù.
    1. Directory Server Æ÷Æ®¸¦ SSL Æ÷Æ®·Î º¯°æÇÕ´Ï´Ù.
    2. LDAP ¼­¹ö¿¡ ´ëÇÑ SSL ¾×¼¼½º °¡´É ¼Ó¼ºÀ» ¼±ÅÃÇÕ´Ï´Ù.
  4. ÅØ½ºÆ® ÆíÁý±â¿¡¼­ serverconfig.xml ÆÄÀÏÀ» ¿±´Ï´Ù. ÀÌ ÆÄÀÏÀº ´ÙÀ½ À§Ä¡¿¡ ÀÖ½À´Ï´Ù.
  5. /etc/opt/SUNWam/config

    1. <Server> ¿ä¼Ò¿¡¼­ ´ÙÀ½ °ªÀ» º¯°æÇÕ´Ï´Ù.
    2. port - Access Manager°¡ ¼ö½ÅÇÏ´Â º¸¾È Æ÷Æ®ÀÇ Æ÷Æ® ¹øÈ£¸¦ ÀÔ·ÂÇÕ´Ï´Ù(±âº»°ª: 636).

      type- SIMPLEÀ» SSL·Î º¯°æÇÕ´Ï´Ù.

    3. serverconfig.xml ÆÄÀÏÀ» ÀúÀåÇÑ ´ÙÀ½ ´Ý½À´Ï´Ù.
  6. ´ÙÀ½ ±âº» À§Ä¡¿¡¼­ AMConfig.properties ÆÄÀÏÀ» ¿±´Ï´Ù.
  7. AcessManager-base/SUNWam/config

    ´ÙÀ½ µî·Ï Á¤º¸¸¦ º¯°æÇÕ´Ï´Ù.

    1. Directory Port = 636(±âº»°ªÀ» »ç¿ëÇÒ °æ¿ì)
    2. ssl.enabed = true
    3. AMConfig.properties¸¦ ÀúÀåÇÕ´Ï´Ù.
  8. ¼­¹ö¸¦ ´Ù½Ã ½ÃÀÛÇÕ´Ï´Ù.


ÀÌÀü      ¸ñÂ÷      »öÀÎ      ´ÙÀ½     


ºÎǰ ¹øÈ£: 819-1939. Copyright 2005 Sun Microsystems, Inc. ¸ðµç ±Ç¸®´Â ÀúÀÛ±ÇÀÚÀÇ ¼ÒÀ¯ÀÔ´Ï´Ù.