Sun ONE Portal Server, Secure Remote Access 6.2 °ü¸®ÀÚ ¼³¸í¼ |
ºÎ·ÏA
SSL °¡¼Ó±â ±¸¼ºÀÌ Àå¿¡¼´Â Sun¢â Portal Server, Secure Remote Access¿¡ ´Ù¾çÇÑ °¡¼Ó±â¸¦ ±¸¼ºÇÏ´Â ¹æ¹ýÀ» ¼³¸íÇÕ´Ï´Ù.
À̹ø Àå¿¡¼´Â ´ÙÀ½ ÁÖÁ¦¸¦ ´Ù·ì´Ï´Ù.
°³¿ä¾ÏÈ£È °¡¼Ó±â(Crypto Accelerator)´Â ¼¹ö CPUÀÇ SSL ±â´ÉÀ» ºÐ´ãÇÔÀ¸·Î½á CPU°¡ ´Ù¸¥ ÀÛ¾÷À» ¼öÇàÇϵµ·Ï ÇÏ¿© SSL Æ®·£Àè¼ÇÀÇ Ã³¸® ¼Óµµ¸¦ ³ôÀÌ´Â Àü¿ë Çϵå¿þ¾î ÄÚÇÁ·Î¼¼¼ÀÔ´Ï´Ù.
Sun Crypto Accelerator 1000Sun¢â Crypto Accelerator 1000 (Sun CA1000) º¸µå´Â ¾ÏÈ£È ÄÚÇÁ·Î¼¼¼·Î ÀÛµ¿ÇÏ¿© °ø¿ë Ű¿Í ´ëĪ ¾Ïȣȸ¦ °¡¼ÓÈÇϴ ªÀº ÇüÅÂÀÇ PCI º¸µåÀÔ´Ï´Ù. ÀÌ Á¦Ç°¿¡´Â ¿ÜºÎ ÀÎÅÍÆäÀ̽º°¡ ¾ø½À´Ï´Ù. ÀÌ º¸µå´Â ³»ºÎ PCI ¹ö½º ÀÎÅÍÆäÀ̽º¸¦ ÅëÇØ È£½ºÆ®¿Í Åë½ÅÇÕ´Ï´Ù. ÀÌ º¸µå´Â eCommerce ÀÀ¿ëÇÁ·Î±×·¥¿¡¼ º¸¾È ÇÁ·ÎÅäÄÝÀ» À§ÇÑ ´Ù¾çÇÑ °è»ê Áý¾àÀû ¾ÏÈ£È ¾Ë°í¸®ÁòÀ» °¡¼ÓÈÇϱâ À§ÇÑ ¸ñÀûÀ¸·Î »ç¿ëµË´Ï´Ù.
RSA [7] ¹× Triple-DES (3DES) [8]¿Í °°Àº ´Ù¼öÀÇ ÇÙ½É ¾ÏÈ£È ±â´ÉÀ» ÀÀ¿ëÇÁ·Î±×·¥¿¡¼ Sun CA1000À¸·Î ºÐ´ã½ÃÄÑ º´·Ä·Î ¼öÇàÇÒ ¼ö ÀÖ½À´Ï´Ù. ±×·¯¸é CPU°¡ ÀÚÀ¯·Ó°Ô ´Ù¸¥ ÀÛ¾÷À» ¼öÇàÇÒ ¼ö ÀÖ¾î SSL Æ®·£Àè¼ÇÀÇ Ã³¸® ¼Óµµ°¡ Áõ°¡ÇÕ´Ï´Ù.
Crypto Accelerator 1000 »ç¿ë
Sun¢â ONE Portal Server, Secure Remote Access°¡ ¼³Ä¡µÇ¾î ÀÖ°í °ÔÀÌÆ®¿þÀÌ ¼¹ö ÀÎÁõ¼(Á÷Á¢ ¼¸í ¶Ç´Â CA¿¡¼ ¹ßÇà)°¡ ¼³Ä¡µÇ¾ú´ÂÁö È®ÀÎÇÕ´Ï´Ù. ´ÙÀ½ Á¡°Ë ¸ñ·ÏÀ¸·Î SSL °¡¼Ó±â¸¦ ¼³Ä¡Çϱâ Àü¿¡ ÇÊ¿äÇÑ Á¤º¸¸¦ ½±°Ô È®ÀÎÇÒ ¼ö ÀÖ½À´Ï´Ù.
Ç¥ 11-1 Àº Crypto Accelerator 1000 ¸Å°³ º¯¼ö¿Í ±× °ªÀ» ³ªÅ¸³À´Ï´Ù. ù ¹øÂ° ¿Àº ¸Å°³ º¯¼öÀÌ°í µÎ ¹øÂ° ¿Àº °ªÀÔ´Ï´Ù.
Crypto Accelerator 1000 ±¸¼º
Crypto Accelerator 1000À» ±¸¼ºÇÏ·Á¸é
- »ç¿ë ¼³¸í¼ÀÇ Áöħ¿¡ µû¶ó Çϵå¿þ¾î¸¦ ¼³Ä¡ÇÕ´Ï´Ù. ÂüÁ¶:
http://www.sun.com/products-n-solutions/hardware/docs/pdf/816-2450-11.pdf
- CD¿¡¼ ´ÙÀ½ ÆÐŰÁö¸¦ ¼³Ä¡ÇÕ´Ï´Ù.
SUNWcrypm, SUNWcrypu, SUNWcrysu, SUNWdcar, SUNWcrypr, SUNWcrysl, SUNWdcamn, SUNWdcav
- ´ÙÀ½ ÆÐÄ¡¸¦ ¼³Ä¡ÇÕ´Ï´Ù. (http://sunsolve.sun.com¿¡¼ ¾òÀ» ¼ö ÀÖ½À´Ï´Ù.)
110383-01, 108528-05, 112438-01
- pk12util ¹× modutil µµ±¸°¡ ÀÖ´ÂÁö È®ÀÎÇϽʽÿÀ.
SRA 6.0ÀÇ °æ¿ì, ÀÌ µµ±¸´Â /opt/SUNWps/bin ¾Æ·¡¿¡ ¼³Ä¡µÇ¾î ÀÖ½À´Ï´Ù.
SRA 6.2ÀÇ °æ¿ì, ÀÌ µµ±¸´Â /usr/lib/mps/secv1/bin ¾Æ·¡¿¡ ¼³Ä¡µÇ¾î ÀÖ½À´Ï´Ù.
- ½½·Ô ÆÄÀÏÀ» ¸¸µì´Ï´Ù.
vi /etc/opt/SUNWconn/crypto/slots
±×¸®°í ÆÄÀÏÀÇ Ã³À½ÀÌÀÚ À¯ÀÏÇÑ ¶óÀÎÀ¸·Î crypta@sra¸¦ ³Ö½À´Ï´Ù.
- ¿µ¿ª°ú »ç¿ëÀÚ¸¦ ¸¸µì´Ï´Ù.
cd /opt/SUNWconn/bin/secadm
secadm> create realm=sra
½Ã½ºÅÛ °ü¸®ÀÚ ·Î±×ÀÎÀÌ ÇÊ¿äÇÕ´Ï´Ù.
·Î±×ÀÎ: root
ºñ¹Ð¹øÈ£:
¿µ¿ª sra°¡ ¼º°øÀûÀ¸·Î ¸¸µé¾îÁ³½À´Ï´Ù.
secadm> set realm=sra
secadm{srap}> su
½Ã½ºÅÛ °ü¸®ÀÚ ·Î±×ÀÎÀÌ ÇÊ¿äÇÕ´Ï´Ù.
·Î±×ÀÎ: root
ºñ¹Ð¹øÈ£:
secadm{root@sra}>create user=crypta
Ãʱ⠺ñ¹Ð¹øÈ£:
ºñ¹Ð¹øÈ£ È®ÀÎ:
»ç¿ëÀÚ crypta°¡ ¼º°øÀûÀ¸·Î ¸¸µé¾îÁ³½À´Ï´Ù.
secadm{root@sra}> login user=crypta
ºñ¹Ð¹øÈ£:
secadm{crypta@sra}> show key
ÀÌ »ç¿ëÀÚ¿¡°Ô ۰¡ ¾ø½À´Ï´Ù.
- Sun Crypto ¸ðµâÀ» ·ÎµåÇÕ´Ï´Ù.
SRA 6.0ÀÇ °æ¿ì, ȯ°æ º¯¼ö LD_LIBRARY_PATH´Â /opt/SUNWps/lib/solaris/sparc¸¦ °¡¸®ÄÑ¾ß ÇÕ´Ï´Ù.
SRA 6.2ÀÇ °æ¿ì, ȯ°æ º¯¼ö LD_LIBRARY_PATH´Â /usr/lib/mps/secv1/À» °¡¸®ÄÑ¾ß ÇÕ´Ï´Ù.
´ÙÀ½À» ÀÔ·ÂÇÕ´Ï´Ù.
modutil -dbdir /etc/opt/SUNWps/cert/default -add "Sun Crypto Module" -libfile /opt/SUNWconn/crypto/lib/libpkcs11.so
´ÙÀ½ ¸í·ÉÀ» »ç¿ëÇÏ¿© ÀÌ ¸ðµâÀÌ ·ÎµåµÇ¾ú´ÂÁö È®ÀÎÇÕ´Ï´Ù.
modutil -list -dbdir /etc/opt/SUNWps/cert /default
- °ÔÀÌÆ®¿þÀÌ ÀÎÁõ¼¿Í ۸¦ "Sun Crypto Module"·Î ³»º¸³À´Ï´Ù.
SRA 6.0ÀÇ °æ¿ì, ȯ°æ º¯¼ö LD_LIBRARY_PATH´Â /opt/SUNWps/lib/solaris/sparc¸¦ °¡¸®ÄÑ¾ß ÇÕ´Ï´Ù.
SRA 6.2ÀÇ °æ¿ì, ȯ°æ º¯¼ö LD_LIBRARY_PATH´Â /usr/lib/mps/secv1/À» °¡¸®ÄÑ¾ß ÇÕ´Ï´Ù.
´ÙÀ½À» ÀÔ·ÂÇÕ´Ï´Ù.
pk12util -o servercert.p12 -d /etc/opt/SUNWps/cert/default -n server-cert
pk12util -i servercert.p12 -d /etc/opt/SUNWps/cert/default -h "crypta@sra"
ÀÌÁ¦ show key ¸í·ÉÀ» ½ÇÇàÇÕ´Ï´Ù.
secadm{crypta@sra}> show key
ÀÌ »ç¿ëÀÚ¿¡°Ô 2°³ÀÇ Å°°¡ ³ªÅ¸³ª¾ß ÇÕ´Ï´Ù.
- /etc/opt/SUNWps/cert/default/.nickname ÆÄÀÏ¿¡¼ º°¸íÀ» º¯°æÇÕ´Ï´Ù.
vi /etc/opt/SUWNps/cert/default/.nickname
server-cert¸¦ crypta@sra:server-cert·Î ±³Ã¼ÇÕ´Ï´Ù.
- °¡¼ÓÈ¿¡ ´ëÇÑ ¾ÏÈ£¸¦ ¼±ÅÃÇÕ´Ï´Ù.
SUN CA1000Àº RSA ±â´ÉÀ» °¡¼ÓÈÇÏÁö¸¸ DES¿Í 3DES ¾Ïȣȿ¡ ´ëÇÑ °¡¼Ó¸¸ Áö¿øÇÕ´Ï´Ù. ÀÌ·¯ÇÑ ¾ÏÈ£È Áß Çϳª¸¦ »ç¿ëÇÏ·Á¸é ´ÙÀ½À» ¼öÇàÇÕ´Ï´Ù.
SRA 6.0ÀÇ °æ¿ì:
°ÔÀÌÆ®¿þÀÌ >> SSL ¾ÏÈ£È ¼±Åà »ç¿ë: >> SSL3 ¾ÏÈ£È: >> SSL3_RSA_WITH_3DES_EDE_CBC_SHA ¶Ç´Â SSL3_RSA_WITH_DES_CBC_SHA
SRA 6.2ÀÇ °æ¿ì:
°ÔÀÌÆ®¿þÀÌ >> º¸¾È >> SSL ¾ÏÈ£È ¼±Åà »ç¿ë: >> SSL3 ¾ÏÈ£È: >> SSL3_RSA_WITH_3DES_EDE_CBC_SHA ¶Ç´Â SSL3_RSA_WITH_DES_CBC_SHA
- °¡¼Ó±â¸¦ »ç¿ëÇϵµ·Ï /etc/opt/SUNWps/platform.conf.gateway-profile-nameÀ» ¼öÁ¤ÇÕ´Ï´Ù.
gateway.enable.accelerator=true
- ´Ü¸»±â â¿¡¼ °ÔÀÌÆ®¿þÀ̸¦ ´Ù½Ã ½ÃÀÛÇÕ´Ï´Ù.
portal-server-install-root/SUNWps/bin/gateway -n gateway-profile-name start
Sun Crypto Accelerator 4000Sun¢â Crypto Accelerator 4000 º¸µå´Â Sun ¼¹ö¿¡¼ IPsec ¹× SSL (´ëħ ¹× ºñ´ëĪ ¸ðµÎ)¿¡ ´ëÇÑ ¾ÏÈ£È Çϵå¿þ¾î °¡¼ÓÀ» Áö¿øÇÏ´Â ±â°¡ºñÆ® ÀÌ´õ³Ý ±â¹Ý ³×Æ®¿öÅ© ÀÎÅÍÆäÀ̽º Ä«µåÀÔ´Ï´Ù.
¾ÏȣȵÇÁö ¾ÊÀº ³×Æ®¿öÅ© Æ®·¡ÇÈÀ» À§ÇÑ Ç¥ÁØ ±â°¡ºñÆ® ÀÌ´õ³Ý ³×Æ®¿öÅ© Ä«µå·Î ÀÛµ¿ÇÏ´Â ¿Ü¿¡ ÀÌ º¸µå¿¡´Â ¾ÏÈ£È IPsec Æ®·¡ÇÈ¿¡ ³ôÀº ó¸® ¼Óµµ¸¦ Áö¿øÇÒ ¾ÏÈ£È Çϵå¿þ¾î°¡ Æ÷ÇԵǾî ÀÖ½À´Ï´Ù.
Crypto Accelerator 4000 º¸µå´Â Çϵå¿þ¾î¿Í ¼ÒÇÁÆ®¿þ¾î ¸ðµÎ¿¡¼ ¾ÏÈ£È ¾Ë°í¸®ÁòÀ» °¡¼ÓÈÇÕ´Ï´Ù. ¾ÏÈ£È DES ¹× 3DES¿¡ ´ëÇÑ ´ë·® ¾Ïȣȵµ Áö¿øÇÕ´Ï´Ù.
Crypto Accelerator 4000 »ç¿ë
Secure Remote Access°¡ ¼³Ä¡µÇ¾î ÀÖ°í °ÔÀÌÆ®¿þÀÌ ¼¹ö ÀÎÁõ¼(Á÷Á¢ ¼¸í ¶Ç´Â CA¿¡¼ ¹ßÇà)°¡ ¼³Ä¡µÇ¾ú´ÂÁö È®ÀÎÇÕ´Ï´Ù. ´ÙÀ½ Á¡°Ë ¸ñ·ÏÀ¸·Î SSL °¡¼Ó±â¸¦ ¼³Ä¡Çϱâ Àü¿¡ ÇÊ¿äÇÑ Á¤º¸¸¦ ½±°Ô È®ÀÎÇÒ ¼ö ÀÖ½À´Ï´Ù.
Ç¥ 11-1 Àº Crypto Accelerator 4000 ¸Å°³ º¯¼ö¿Í ±× °ªÀ» ³ªÅ¸³À´Ï´Ù. ù ¹øÂ° ¿Àº ¸Å°³ º¯¼öÀÌ°í µÎ ¹øÂ° ¿Àº °ªÀÔ´Ï´Ù.
Crypto Accelerator 4000 ±¸¼º
Crypto Accelerator 4000À» ±¸¼ºÇÏ·Á¸é
- »ç¿ë ¼³¸í¼ÀÇ Áöħ¿¡ µû¶ó Çϵå¿þ¾î¿Í ¼ÒÇÁÆ®¿þ¾î ÆÐŰÁö¸¦ ¼³Ä¡ÇÕ´Ï´Ù. ÂüÁ¶:
http://www.sun.com/products-n-solutions/hardware/docs/pdf/816-2450-11.pdf
- ´ÙÀ½ ÆÐÄ¡¸¦ ¼³Ä¡ÇÕ´Ï´Ù. (http://sunsolve.sun.com¿¡¼ ¾òÀ» ¼ö ÀÖ½À´Ï´Ù.) 114795
- certutil, pk12util ¹× modutil µµ±¸°¡ ÀÖ´ÂÁö È®ÀÎÇϽʽÿÀ.
SRA 6.0ÀÇ °æ¿ì, ÀÌ µµ±¸´Â /opt/SUNWps/bin ¾Æ·¡¿¡ ¼³Ä¡µÇ¾î ÀÖ½À´Ï´Ù.
SRA 6.2ÀÇ °æ¿ì, ÀÌ µµ±¸´Â /usr/lib/mps/secv1/bin ¾Æ·¡¿¡ ¼³Ä¡µÇ¾î ÀÖ½À´Ï´Ù.
- º¸µå¸¦ ÃʱâÈÇÕ´Ï´Ù.
/opt/SUNWconn/bin/vcadm µµ±¸¸¦ ½ÇÇàÇÏ¿© ¾ÏÈ£È º¸µå¸¦ ÃʱâÈÇÏ°í ´ÙÀ½ °ªÀ» ¼³Á¤ÇÕ´Ï´Ù.
Ãʱ⠺¸¾È °ü¸® À̸§: sec_officer
Ű ÀúÀå¼Ò À̸§: sra-keystore
FIPS 140-2 ¸ðµå¿¡¼ ½ÇÇà: No
- »ç¿ëÀÚ¸¦ ¸¸µì´Ï´Ù.
vcaadm{vca0@localhost, sec_officer}> create user
»õ »ç¿ëÀÚ À̸§: crypta
»õ »ç¿ëÀÚ ºñ¹Ð¹øÈ£ ÀÔ·Â:
ºñ¹Ð¹øÈ£ È®ÀÎ:
»ç¿ëÀÚ crypta°¡ ¼º°øÀûÀ¸·Î ¸¸µé¾îÁ³½À´Ï´Ù.
- Ű ÀúÀå¼Ò¿¡ ÅäÅ«À» ¸ÅÇÎÇÕ´Ï´Ù.
vi /opt/SUNWconn/cryptov2/tokens
±×¸®°í ÆÄÀÏ¿¡ sra-keystore¸¦ Ãß°¡ÇÕ´Ï´Ù.
- ´ë·® ¾ÏÈ£ÈÀÇ »ç¿ëÀ» ¼³Á¤ÇÕ´Ï´Ù.
touch /opt/SUNWconn/cryptov2/sslreg
- Sun Crypto ¸ðµâÀ» ·ÎµåÇÕ´Ï´Ù.
SRA 6.0ÀÇ °æ¿ì, ȯ°æ º¯¼ö LD_LIBRARY_PATH´Â /opt/SUNWps/lib/solaris/sparc¸¦ °¡¸®ÄÑ¾ß ÇÕ´Ï´Ù.
SRA 6.2ÀÇ °æ¿ì¿¡´Â /usr/lib/mps/secv1/À» °¡¸®ÄÑ¾ß ÇÕ´Ï´Ù.
´ÙÀ½À» ÀÔ·ÂÇÕ´Ï´Ù.
modutil -dbdir /etc/opt/SUNWps/cert/default -add "Sun Crypto Module" -libfile /opt/SUNWconn/cryptov2/lib/libvpkcs11.so
´ÙÀ½ ¸í·ÉÀ» »ç¿ëÇÏ¿© ÀÌ ¸ðµâÀÌ ·ÎµåµÇ¾ú´ÂÁö È®ÀÎÇÒ ¼ö ÀÖ½À´Ï´Ù.
modutil -list -dbdir /etc/opt/SUNWps/cert /default
- °ÔÀÌÆ®¿þÀÌ ÀÎÁõ¼¿Í ۸¦ "Sun Crypto Module"·Î ³»º¸³À´Ï´Ù.
SRA 6.0ÀÇ °æ¿ì, ȯ°æ º¯¼ö LD_LIBRARY_PATH´Â /opt/SUNWps/lib/solaris/sparc¸¦ °¡¸®ÄÑ¾ß ÇÕ´Ï´Ù.
SRA 6.2ÀÇ °æ¿ì¿¡´Â /usr/lib/mps/secv1/À» °¡¸®ÄÑ¾ß ÇÕ´Ï´Ù.
pk12util -o servercert.p12 -d /etc/opt/SUNWps/cert/default -n server-cert
pk12util -i servercert.p12 -d /etc/opt/SUNWps/cert/default -h "sra-keystore"
´ÙÀ½ ¸í·ÉÀ» »ç¿ëÇÏ¿© ۰¡ ³»º¸³»Á³´ÂÁö È®ÀÎÇÒ ¼ö ÀÖ½À´Ï´Ù.
certutil -K -h "sra-keystore" -d /etc/opt/SUNWps/cert/default
- /etc/opt/SUWNps/cert/default/.nickname ÆÄÀÏ¿¡¼ º°¸íÀ» º¯°æÇÕ´Ï´Ù.
vi /etc/opt/SUWNps/cert/default/.nickname
server-cert¸¦ sra-keystore:server-cert·Î ±³Ã¼ÇÕ´Ï´Ù.
- °¡¼ÓÈ¿¡ ´ëÇÑ ¾ÏÈ£¸¦ ¼±ÅÃÇÕ´Ï´Ù.
SUN CA4000Àº RSA ±â´ÉÀ» °¡¼ÓÈÇÏÁö¸¸ DES¿Í 3DES ¾Ïȣȿ¡ ´ëÇÑ °¡¼Ó¸¸ Áö¿øÇÕ´Ï´Ù. ÀÌ·¯ÇÑ ¾ÏÈ£È Áß Çϳª¸¦ »ç¿ëÇÏ·Á¸é ´ÙÀ½À» ¼öÇàÇÕ´Ï´Ù.
SRA 6.0ÀÇ °æ¿ì:
°ÔÀÌÆ®¿þÀÌ >> SSL ¾ÏÈ£È ¼±Åà »ç¿ë: >> SSL3 ¾ÏÈ£È: >> SSL3_RSA_WITH_3DES_EDE_CBC_SHA ¶Ç´Â SSL3_RSA_WITH_DES_CBC_SHA
SRA 6.2ÀÇ °æ¿ì:
°ÔÀÌÆ®¿þÀÌ >> º¸¾È >> SSL ¾ÏÈ£È ¼±Åà »ç¿ë: >> SSL3 ¾ÏÈ£È: >> SSL3_RSA_WITH_3DES_EDE_CBC_SHA ¶Ç´Â SSL3_RSA_WITH_DES_CBC_SHA
- ´Ü¸»±â â¿¡¼ °ÔÀÌÆ®¿þÀ̸¦ ´Ù½Ã ½ÃÀÛÇÕ´Ï´Ù.
portal-server-install-root/SUNWps/bin/gateway -n gateway-profile-name start
°ÔÀÌÆ®¿þÀ̰¡ Ű ÀúÀå¼Ò ºñ¹Ð¹øÈ£¸¦ ÀÔ·ÂÇϵµ·Ï ¿äûÇÕ´Ï´Ù.
"sra-keystore":crypta:crytpa-password¿¡ ´ëÇÑ ºñ¹Ð¹øÈ£ ¶Ç´Â PINÀ» ÀÔ·ÂÇÕ´Ï´Ù.
¿ÜºÎ SSL ÀåÄ¡ ¹× ÇÁ¶ô½Ã °¡¼Ó±â¿¸° ¸ðµå¿¡¼ ¿ÜºÎ SSL ÀåÄ¡¸¦ Secure Remote Access Àü¹æ¿¡¼ ½ÇÇàÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ ÀåÄ¡´Â Ŭ¶óÀÌ¾ðÆ®¿Í Secure Remote Access »çÀÌ¿¡¼ SSL ¸µÅ©¸¦ Á¦°øÇÕ´Ï´Ù.
¿ÜºÎ SSL ÀåÄ¡ °¡¼Ó±â »ç¿ë
Secure Remote Access°¡ ¼³Ä¡µÇ¾î ÀÖ°í °ÔÀÌÆ®¿þÀ̰¡ º¸¾È ¸ðµå(HTTPS ¸ðµå)¿¡¼ ½ÇÇàµÇ¾î¾ß ÇÕ´Ï´Ù.
°ÔÀÌÆ®¿þÀÌ >> HTTPS ¿¬°á »ç¿ë
°ÔÀÌÆ®¿þÀÌ>> HTTP Æ÷Æ®: 880
Ç¥ 11-3 Àº ¿ÜºÎ SSL ÀåÄ¡¿Í ÇÁ¶ô½Ã °¡¼Ó±â ¸Å°³ º¯¼ö ¹× °ªÀ» ³ªÅ¸³À´Ï´Ù. ù ¹øÂ° ¿Àº ¸Å°³ º¯¼öÀÌ°í µÎ ¹øÂ° ¿Àº °ªÀÔ´Ï´Ù.
Ç¥ 11-3 ¿ÜºÎ SSL ÀåÄ¡ ¹× ÇÁ¶ô½Ã °¡¼Ó±â Á¡°Ë ¸ñ·Ï
¸Å°³ º¯¼ö
°ª
SRA ÀνºÅϽº
±âº»°ª
°ÔÀÌÆ®¿þÀÌ ¸ðµå
https
°ÔÀÌÆ®¿þÀÌ Æ÷Æ®
880
¿ÜºÎ ÀåÄ¡/ÇÁ¶ô½Ã Æ÷Æ®
443
¿ÜºÎ SSL ÀåÄ¡ °¡¼Ó±â ±¸¼º
¿ÜºÎ SSL ÀåÄ¡ °¡¼Ó±â¸¦ ±¸¼ºÇÏ·Á¸é
- »ç¿ë ¼³¸í¼ÀÇ Áöħ¿¡ µû¶ó Çϵå¿þ¾î¿Í ¼ÒÇÁÆ®¿þ¾î ÆÐŰÁö¸¦ ¼³Ä¡ÇÕ´Ï´Ù.
- ÇØ´çÇÏ´Â °æ¿ì ÇÊ¿äÇÑ/±ÇÀåµÇ´Â ÆÐÄ¡¸¦ ¼³Ä¡ÇÕ´Ï´Ù.
- SSL ÀåÄ¡/ÇÁ¶ô½Ã Áö¿øÀ» Ȱ¼ºÈÇÕ´Ï´Ù.
vi /etc/opt/SUNWps/platform.conf.default
gateway.enable.accelerator=true
¿ÜºÎ ÀåÄ¡/ÇÁ¶ô½Ã È£½ºÆ® À̸§ÀÌ °ÔÀÌÆ®¿þÀÌ È£½ºÆ® À̸§°ú ´Ù¸¥ °æ¿ì,
gateway.enable.customurl=true
gateway.httpsurl=external-device.domain.subdomain/proxy-URL
- µÎ °¡Áö ¹æ¹ýÀ¸·Î °ÔÀÌÆ®¿þÀÌ ¾Ë¸²À» ±¸¼ºÇÒ ¼ö ÀÖ½À´Ï´Ù.
- SSL ÀåÄ¡/ÇÁ¶ô½Ã°¡ ÀÛµ¿Çϰí ÀÖÀ¸¸ç °ÔÀÌÆ®¿þÀÌ Æ÷Æ®·Î Æ®·¡ÇÈÀ» ³Ñ±âµµ·Ï ±¸¼ºµÇ¾î ÀÖ´ÂÁö È®ÀÎÇÕ´Ï´Ù.
- ´Ü¸»±â â¿¡¼ °ÔÀÌÆ®¿þÀ̸¦ ´Ù½Ã ½ÃÀÛÇÕ´Ï´Ù.
gateway-install-root/SUNWps/bin/gateway -n gateway-profile-name start