Sun Java ·Î°í     ÀÌÀü      ¸ñÂ÷      »öÀÎ      ´ÙÀ½     

Sun ·Î°í
Sun Java System Calendar Server 6 2005Q1 °ü¸® ¼³¸í¼­ 

8Àå
SSL ±¸¼º

Calendar Server´Â ´Þ·Â Ŭ¶óÀ̾ðÆ® ÃÖÁ¾ »ç¿ëÀÚ¿Í Calendar Server °£ÀÇ µ¥ÀÌÅÍ ¾Ïȣȭ¸¦ À§ÇØ SSL(Secure Sockets Layer) ÇÁ·ÎÅäÄÝÀ» Áö¿øÇÕ´Ï´Ù. SSLÀ» Áö¿øÇϱâ À§ÇØ Calendar Server´Â Netscape Security Services(NSS)ÀÇ SSL ¶óÀ̺귯¸®¸¦ »ç¿ëÇϸç, Sun Java System Messaging Server¿¡¼­µµ ÀÌ ¶óÀ̺귯¸®¸¦ »ç¿ëÇÕ´Ï´Ù.

Calendar Server ·Î±×ÀÎ ¹× ºñ¹Ð¹øÈ£¸¸ ¾ÏȣȭÇϰųª Àüü ´Þ·Â ¼¼¼ÇÀ» ¾ÏȣȭÇϵµ·Ï ics.conf ÆÄÀÏ¿¡¼­ Calendar Server¸¦ ±¸¼ºÇÒ ¼ö ÀÖ½À´Ï´Ù.

ÀÌ ÀåÀº ´ÙÀ½ ³»¿ëÀ¸·Î ±¸¼ºµÇ¾î ÀÖ½À´Ï´Ù.

 


ÁÖ

Calendar Server´Â Ŭ¶óÀ̾ðÆ® ±â¹Ý SSL ÀÎÁõÀ» Áö¿øÇÏÁö ¾Ê½À´Ï´Ù.



Calendar Server¿¡ ´ëÇØ SSL ±¸¼º

Calendar ServerÀÇ SSLÀ» ±¸¼ºÇÏ·Á¸é ´ÙÀ½ ´Ü°è¸¦ ¼öÇàÇÕ´Ï´Ù.

SSL ÀÎÁõ¼­ µ¥ÀÌÅͺ£À̽º ¸¸µé±â

Calendar Server¸¦ À§ÇØ SSLÀ» ±¸ÇöÇÏ·Á¸é ÀÎÁõ¼­ µ¥ÀÌÅͺ£À̽º°¡ ÇÊ¿äÇÕ´Ï´Ù. ÀÎÁõ¼­ µ¥ÀÌÅͺ£À̽º´Â ÀÎÁõ ±â°ü(CA) ¹× Calendar Server¿ë ÀÎÁõ¼­¸¦ Á¤ÀÇÇØ¾ß ÇÕ´Ï´Ù.

Mozilla µµ±¸

À̹ø ¸±¸®½º¿¡´Â ´ÙÀ½ Mozilla µµ±¸°¡ Æ÷ÇԵǾî ÀÖ½À´Ï´Ù.

ÀÌ À¯Æ¿¸®Æ¼´Â ´ÙÀ½ µð·ºÅ丮¿¡¼­ »ç¿ëÇÒ ¼ö ÀÖ½À´Ï´Ù.

/opt/SUNWics5/cal/lib

 ¶Ç´Â À¥ »çÀÌÆ®¿¡¼­ ÃֽŠ¹öÀüÀ» ´Ù¿î·ÎµåÇÒ ¼ö ÀÖ½À´Ï´Ù.

¶óÀ̺귯¸® °æ·Î º¯¼ö

Mozilla µµ±¸¸¦ »ç¿ëÇϱâ Àü¿¡ LD_LIBRARY_PATH º¯¼ö¸¦ ¿Ã¹Ù¸£°Ô ¼³Á¤ÇÕ´Ï´Ù. ¿¹¸¦ µé¸é ´ÙÀ½°ú °°½À´Ï´Ù.

setenv LD_LIBRARY_PATH /opt/SUNWics5/cal/lib

ÆÄÀÏ ¹× µð·ºÅ丮 ¿¹

À̹ø ÀåÀÇ ¿¹¿¡¼­´Â ´ÙÀ½ ÆÄÀÏ°ú µð·ºÅ丮¸¦ »ç¿ëÇÕ´Ï´Ù.

 

ÀÎÁõ¼­ µ¥ÀÌÅͺ£À̽º¸¦ ¸¸µé·Á¸é

  1. ¼öÆÛÀ¯Àú(root)·Î ·Î±×ÀÎÇÕ´Ï´Ù.
  2. certutilÀÇ ÀÎÁõ¼­ µ¥ÀÌÅͺ£À̽º ºñ¹Ð¹øÈ£¸¦ /etc/opt/SUNWics5/config/sslPasswordFile¿¡ ÁöÁ¤ÇÕ´Ï´Ù. ¿¹¸¦ µé¸é ´ÙÀ½°ú °°½À´Ï´Ù.
  3. # echo ‘password’ > /etc/opt/SUNWics5/config/sslPasswordFile

    ¿©±â¼­ password´Â °íÀ¯ ºñ¹Ð¹øÈ£ÀÔ´Ï´Ù.

  4. ÀÎÁõ¼­ µ¥ÀÌÅͺ£À̽º alias µð·ºÅ丮¸¦ ¸¸µì´Ï´Ù. ¿¹¸¦ µé¸é ´ÙÀ½°ú °°½À´Ï´Ù.
  5. # cd /var/opt/SUNWics5
    # mkdir alias

  6. bin µð·ºÅ丮·Î À̵¿ÇÏ°í ÀÎÁõ¼­ µ¥ÀÌÅͺ£À̽º(cert7.db)¿Í Å° µ¥ÀÌÅͺ£À̽º(key3.db)¸¦ ¸¸µì´Ï´Ù. ¿¹¸¦ µé¸é ´ÙÀ½°ú °°½À´Ï´Ù.
  7. # cd /opt/SUNWics5/cal/bin
    # ./certutil -N -d /var/opt/SUNWics5/alias
    -f /etc/opt/SUNWics5/config/sslPasswordFile


    ÁÖ

    certutil À¯Æ¿¸®Æ¼¸¦ ½ÇÇàÇØ¾ß ÇÏ´Â °æ¿ì¿¡´Â Ç×»ó ´ÙÀ½ ¿¹¸¦ Á¤È®ÇÏ°Ô µû¸£°Å³ª certutil µµ¿ò¸» ÆäÀÌÁö¸¦ ÂüÁ¶ÇÏ¿© ±¸¹®À» ÀÌÇØÇØ¾ß ÇÕ´Ï´Ù.

    ¿¹¸¦ µé¾î, ÀÌ °æ¿ì¿¡´Â -d /file Á¤º¸¸¦ ÇÔ²² ÁöÁ¤ÇÏÁö ¾Ê°í´Â -N ¿É¼Ç°ú ÇÔ²² À¯Æ¿¸®Æ¼¸¦ ½ÇÇàÇÏÁö ¸¶½Ê½Ã¿À.


  8. ÀÚü ¼­¸íµÈ ±âº» ·çÆ® ÀÎÁõ ±â°ü ÀÎÁõ¼­¸¦ »ý¼ºÇÕ´Ï´Ù. ¿¹¸¦ µé¸é ´ÙÀ½°ú °°½À´Ï´Ù.
  9. # ./certutil -S -n SampleRootCA -x -t "CTu,CTu,CTu"
    -s "CN=My Sample Root CA, O=sesta.com" -m 25000
    -d /var/opt/SUNWics5/alias
    -d /var/opt/SUNWics5/alias
    -f /etc/opt/SUNWics5/config/sslPasswordFile
    /etc/passwd

  10. È£½ºÆ®¸¦ À§ÇÑ ÀÎÁõ¼­¸¦ »ý¼ºÇÕ´Ï´Ù. ¿¹¸¦ µé¸é ´ÙÀ½°ú °°½À´Ï´Ù.
  11. # ./certutil -S -n SampleSSLServerCert -c SampleRootCA -t "u,u,u"
    -s "CN=hostname.sesta.com, O=sesta.com" -m 25001
    -o /var/opt/SUNWics5/alias/SampleSSLServer.crt
    -d /var/opt/SUNWics5/alias -f /etc/opt/SUNWics5/config/sslPasswordFile
    -z /etc/passwd

    ¿©±â¼­ hostname.sesta.comÀº ¼­¹ö È£½ºÆ® À̸§ÀÔ´Ï´Ù.

  12. ÀÎÁõ¼­¸¦ °ËÁõÇÕ´Ï´Ù. ¿¹¸¦ µé¸é ´ÙÀ½°ú °°½À´Ï´Ù.
  13. # ./certutil -V -u V -n SampleRootCA -d /var/opt/SUNWics5/alias
    # ./certutil -V -u V -n SampleSSLServerCert -d /var/opt/SUNWics5/alias

  14. ÀÎÁõ¼­¸¦ ³ª¿­ÇÕ´Ï´Ù. ¿¹¸¦ µé¸é ´ÙÀ½°ú °°½À´Ï´Ù.
  15. # ./certutil -L -d /var/opt/SUNWics5/alias
    # ./certutil -L -n SampleSSLServerCert -d /var/opt/SUNWics5/alias

  16. modutilÀ» ÅëÇØ »ç¿ë °¡´ÉÇÑ º¸¾È ¸ðµâÀ» ³ª¿­ÇÕ´Ï´Ù(secmod.db). ¿¹¸¦ µé¸é ´ÙÀ½°ú °°½À´Ï´Ù.
  17. # ./modutil -list -dbdir /var/opt/SUNWics5/alias

  18. alias ÆÄÀÏÀÇ ¼ÒÀ¯ÀÚ¸¦ icsuser ¹× icsgroup(¶Ç´Â Calendar Server¸¦ ½ÇÇàÇÒ »ç¿ëÀÚ ¹× ±×·ì ¾ÆÀ̵ð)À¸·Î º¯°æÇÕ´Ï´Ù. ¿¹¸¦ µé¸é ´ÙÀ½°ú °°½À´Ï´Ù.
  19. # find /var/opt/SUNWics5/alias -exec chown icsuser {} \;
    # find /var/opt/SUNWics5/alias -exec chgrp icsgroup {} \;

 

·çÆ® ÀÎÁõ ±â°ü(CA)¿¡ ÀÎÁõ¼­¸¦ ¿äûÇÏ°í °¡Á®¿À±â

´ÙÀ½ ´Ü°è¿¡¼­´Â ÀÎÁõ¼­ ¿äûÀ» »ý¼ºÇÏ°í À̸¦ PKI(Public Key Infrastructure) À¥ »çÀÌÆ®¿¡ Á¦ÃâÇÏ°í ³ª¼­ ÇØ´ç ÀÎÁõ¼­¸¦ °¡Á®¿É´Ï´Ù.

·çÆ® ÀÎÁõ ±â°ü¿¡ ÀÎÁõ¼­¸¦ ¿äû ¹× °¡Á®¿À·Á¸é

  1. ¼öÆÛÀ¯Àú(root)·Î ·Î±×ÀÎÇÕ´Ï´Ù.
  2. bin µð·ºÅ丮·Î À̵¿ÇÕ´Ï´Ù.
  3. # cd /opt/SUNWics5/cal/bin

  4. certutilÀ» »ç¿ëÇÏ¿© ÀÎÁõ ±â°üÀ̳ª PKI(Public Key Infrastructure) À¥ »çÀÌÆ®¸¦ ±â¹ÝÀ¸·Î ÀÎÁõ¼­ ¿äûÀ» ¸¸µì´Ï´Ù. ¿¹¸¦ µé¸é ´ÙÀ½°ú °°½À´Ï´Ù.
  5. # ./certutil -R -s "CN=hostname.sesta.com, OU=hostname / SSL Web Server, O=Sesta, C=US" -p "408-555-1234" -o hostnameCert.req -g 1024
    -d /var/opt/SUNWics5/alias
    -f /etc/opt/SUNWics5/config/sslPasswordFile
    -z /etc/passwd -a

    ¿©±â¼­ hostname.sesta.comÀº È£½ºÆ® À̸§ÀÔ´Ï´Ù.

  6. ÀÎÁõ ±â°üÀ̳ª PKI(Public Key Infrastructure) À¥ »çÀÌÆ®¿¡ SSL À¥ ¼­¹ö¿¡ ´ëÇÑ Å×½ºÆ® ÀÎÁõ¼­¸¦ ¿äûÇÕ´Ï´Ù. hostnameCert.req ÆÄÀÏÀÇ ³»¿ëÀ» º¹»çÇÏ¿© ÀÎÁõ¼­ ¿äû¿¡ ºÙÀÔ´Ï´Ù.
  7. ÀÎÁõ¼­°¡ ¼­¸íµÇ¾î ã¾Æ°¥ ¼ö ÀÖ°Ô µÇ¸é °ü¸®ÀÚ¿¡°Ô ¾Ë¸³´Ï´Ù.

  8. ÀÎÁõ ±â°ü ÀÎÁõ¼­ üÀÎ ¹× SSL ¼­¹ö ÀÎÁõÀ» ÅؽºÆ® ÆÄÀÏ·Î º¹»çÇÕ´Ï´Ù.
  9. CA ÀÎÁõ¼­ üÀÎÀ» ÀÎÁõ¼­ µ¥ÀÌÅͺ£À̽º·Î °¡Á®¿Í¼­ ÀÎÁõ üÀÎÀ» ¼³Á¤ÇÕ´Ï´Ù. ¿¹¸¦ µé¸é ´ÙÀ½°ú °°½À´Ï´Ù.
  10. # ./certutil -A -n "GTE CyberTrust Root" -t "TCu,TCu,TCuw"
    -d /var/opt/SUNWics5/alias -a -i /export/wspace/Certificates/CA_Certificate_1.txt
    -f /etc/opt/SUNWics5/config/sslPasswordFile

    # ./certutil -A -n "Sesta TEST Root CA" -t "TCu,TCu,TCuw"
    -d /var/opt/SUNWics5/alias -a -i /export/wspace/Certificates/CA_Certificate_2.txt
    -f /etc/opt/SUNWics5/config/sslPasswordFile

  11. ¼­¸íµÈ SSL ¼­¹ö ÀÎÁõ¼­¸¦ °¡Á®¿É´Ï´Ù.
  12. # ./certutil -A -n "hostname SSL Server Test Cert" -t "u,u,u"
    -d /var/opt/SUNWics5/alias -a -i /export/wspace/Certificates/SSL_Server_Certificate.txt
    -f /etc/opt/SUNWics5/config/sslPasswordFile

  13. ÀÎÁõ¼­ µ¥ÀÌÅͺ£À̽ºÀÇ ÀÎÁõ¼­¸¦ ³ª¿­ÇÕ´Ï´Ù.
  14. # ./certutil -L -d /var/opt/SUNWics5/alias

  15. ics.conf ÆÄÀÏÀÇ SSL Server º°¸íÀÌ ¼­¸íµÈ SSL ¼­¹ö ÀÎÁõ¼­°¡ µÇ°Ô ±¸¼ºÇÕ´Ï´Ù.
    ¿¹: "hostname SSL Server Test Cert"
  16. ÁÖ ics.conf ÆÄÀÏ¿¡ ÀÖ´Â service.http.calendarhostname ¹× service.http.ssl.sourceurl ¸Å°³ º¯¼öÀÇ È£½ºÆ® À̸§ÀÌ SSL ÀÎÁõ¼­ÀÇ È£½ºÆ® À̸§°ú ÀÏÄ¡ÇØ¾ß ÇÕ´Ï´Ù(½Ã½ºÅÛ¿¡ ¿©·¯ °³ÀÇ º°¸íÀÌ ÀÖ´Â °æ¿ì).
    ¿¹: calendar.sesta.com

ics.conf ÆÄÀÏÀÇ SSL ¸Å°³ º¯¼ö ±¸¼º

Calendar Server¿¡ SSLÀ» ±¸ÇöÇÏ·Á¸é ics.conf ÆÄÀÏ¿¡ ƯÁ¤ ¸Å°³ º¯¼ö¸¦ ¼³Á¤ÇØ¾ß ÇÕ´Ï´Ù. Ç¥ 8-1¿¡ ³ª¿­µÈ ¸Å°³ º¯¼ö Áß¿¡¼­ ics.conf ÆÄÀÏ¿¡ ¾ø´Â º¯¼ö°¡ ÀÖ´Â °æ¿ì¿¡´Â ÆÄÀÏ¿¡ ÇØ´ç º¯¼ö¸¦ Ãß°¡ÇÏ°í °ªÀ» ÁöÁ¤ÇÕ´Ï´Ù. ics.conf´Â ½Ã½ºÅÛÀ» ½ÃÀÛÇÒ ¶§(start-calÀ» ½ÃÀÛÇÒ ¶§)¿¡¸¸ ÀÐÈ÷±â ¶§¹®¿¡ Calendar Server¸¦ ´Ù½Ã ½ÃÀÛÇÒ ¶§±îÁö »õ °ªÀÌ Àû¿ëµÇÁö ¾Ê½À´Ï´Ù. ÀÌ SSL ¸Å°³ º¯¼ö¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ ³»¿ëÀº SSL ±¸¼ºÀ» ÂüÁ¶ÇϽʽÿÀ.

Ç¥ 8-1 SSL ±¸¼º¿¡ ÇÊ¿äÇÑ ics.conf ¸Å°³ º¯¼ö 

¸Å°³ º¯¼ö

°ª

encryption.rsa.nssslactivation

“on”

encryption.rsa.nssslpersonalityssl

“SampleSSLServerCert”

encryption.rsa.nsssltoken

“internal”

service.http.tmpdir

“/var/opt/SUNWics5/tmp”

service.http.uidir.path

“html”

service.http.ssl.cachedir

“.”

service.http.ssl.cachesize

“10000”

service.http.ssl.certdb.password

anypassword(ÀûÀýÇÑ ºñ¹Ð¹øÈ£ ÀÔ·Â)

service.http.ssl.certdb.path

“/var/opt/SUNWics5/alias”

service.http.ssl.port.enable

“yes”

service.http.ssl.port

“443”(±âº» Æ÷Æ®)

service.http.ssl.securelogin

“yes”(·Î±×ÀÎ ¹× ºñ¹Ð¹øÈ£ ¾Ïȣȭ)

service.http.securesession

“yes”(Àüü ¼¼¼Ç ¾Ïȣȭ)

service.http.ssl.sourceurl

“https”//localhost:port”(·ÎÄà ȣ½ºÆ®ÀÇ À̸§°ú service.http.ssl.port °ª ÀÔ·Â)

service.http.ssl.ssl2.ciphers

““

service.http.ssl.ssl2.sessiontimeout

“0”

service.http.ssl.ssl3.ciphers

"rsa_rc4_40_md5,rsa_rc2_40_md5,rsa_des_sha,
rsa_rc4_128_md5,rsa_3des_sha"

service.http.ssl.ssl3.sessiontimeout

“0”

service.http.sslusessl

“yes”


ÁÖ

service.http.ssl.securelogin, service.http.ssl.securesessionÀ» ¼³Á¤ÇÏ¿© Calendar Server°¡ Calendar Server ·Î±×Àΰú ºñ¹Ð¹øÈ£¸¸ ¾ÏȣȭÇϰųª Àüü ´Þ·Â ¼¼¼ÇÀ» ¾ÏȣȭÇϵµ·Ï ±¸¼ºÇÒ ¼ö ÀÖ½À´Ï´Ù.

·Î±×Àΰú ¼¼¼ÇÀ» ¸ðµÎ ¾ÏȣȭÇÏ·Á¸é µÎ ¸Å°³ º¯¼öÀÇ °ªÀ» ¸ðµÎ "yes"·Î ÁöÁ¤ÇØ¾ß ÇÕ´Ï´Ù.



SSL ¹®Á¦ ÇØ°á

¿ì¼± º¹±¸ ºÒ°¡´ÉÇÑ ¹®Á¦°¡ ¹ß»ýÇÒ °æ¿ì¸¦ ´ëºñÇÏ¿© Á¤±âÀûÀ¸·Î ÀÎÁõ¼­ µ¥ÀÌÅͺ£À̽º¸¦ ¹é¾÷ÇÕ´Ï´Ù. SSL¿¡ ¹®Á¦°¡ ÀÖÀ» °æ¿ì ´ÙÀ½ ³»¿ëÀ» È®ÀÎÇϽʽÿÀ.

 

cshttpd ÇÁ·Î¼¼½º Á¡°Ë

SSLÀ» »ç¿ëÇÏ·Á¸é Calendar Server cshttpd ÇÁ·Î¼¼½º°¡ ½ÇÇà ÁßÀ̾î¾ß ÇÕ´Ï´Ù. cshttpd°¡ ½ÇÇà ÁßÀÎÁö È®ÀÎÇÏ·Á¸é ´ÙÀ½ ¸í·ÉÀ» »ç¿ëÇÕ´Ï´Ù.

# ps -ef | grep cshttpd

ÀÎÁõ¼­ °ËÁõ

ÀÎÁõ¼­ µ¥ÀÌÅͺ£À̽ºÀÇ ÀÎÁõ¼­¸¦ ³ª¿­ÇÏ°í ÇØ´ç À¯È¿ ÀÏÀÚ¸¦ È®ÀÎÇÏ·Á¸é ´ÙÀ½ ¸í·ÉÀ» »ç¿ëÇÕ´Ï´Ù.

# ./certutil -L -d /var/opt/SUNWics5/alias

Calendar Server ·Î±× ÆÄÀÏ È®ÀÎ

Calendar Server ·Î±× ÆÄÀÏ¿¡ SSL ¿À·ù°¡ ÀÖ´ÂÁö È®ÀÎÇÕ´Ï´Ù. ÀÚ¼¼ÇÑ ³»¿ëÀº Calendar Server ·Î±× ÆÄÀÏ »ç¿ëÀ» ÂüÁ¶ÇϽʽÿÀ.

SSL Æ÷Æ®¿¡ ¿¬°á

ºê¶ó¿ìÀú¿Í ´ÙÀ½ URLÀ» »ç¿ëÇÏ¿© SSL Æ÷Æ®¿¡ ¿¬°áÇÕ´Ï´Ù.

https://server-name:ssl-port-number

¿©±â¼­,

server-nameÀº Calendar Server°¡ ½ÇÇà ÁßÀÎ ¼­¹ö À̸§ÀÔ´Ï´Ù.

ssl-port-number´Â ics.conf ÆÄÀÏÀÇ service.http.ssl.port ¸Å°³ º¯¼ö°¡ ÁöÁ¤ÇÏ´Â SSL Æ÷Æ® ¹øÈ£ÀÔ´Ï´Ù. ±âº»°ªÀº 443ÀÔ´Ï´Ù.



ÀÌÀü      ¸ñÂ÷      »öÀÎ      ´ÙÀ½     


ºÎÇ° ¹øÈ£: 819-1477.   Copyright 2005 Sun Microsystems, Inc. ¸ðµç ±Ç¸®´Â ÀúÀÛ±ÇÀÚÀÇ ¼ÒÀ¯ÀÔ´Ï´Ù.