Sun logo      ÀÌÀü      ¸ñÂ÷      »öÀÎ      ´ÙÀ½     

Sun ONE Portal Server, Secure Remote Access 6.2 °ü¸®ÀÚ ¼³¸í¼­

ºÎ·ÏA
SSL °¡¼Ó±â ±¸¼º

ÀÌ Àå¿¡¼­´Â Sun¢â Portal Server, Secure Remote Access¿¡ ´Ù¾çÇÑ °¡¼Ó±â¸¦ ±¸¼ºÇÏ´Â ¹æ¹ýÀ» ¼³¸íÇÕ´Ï´Ù.

À̹ø Àå¿¡¼­´Â ´ÙÀ½ ÁÖÁ¦¸¦ ´Ù·ì´Ï´Ù.


°³¿ä

¾Ïȣȭ °¡¼Ó±â(Crypto Accelerator)´Â ¼­¹ö CPUÀÇ SSL ±â´ÉÀ» ºÐ´ãÇÔÀ¸·Î½á CPU°¡ ´Ù¸¥ ÀÛ¾÷À» ¼öÇàÇϵµ·Ï ÇÏ¿© SSL Æ®·£Àè¼ÇÀÇ Ã³¸® ¼Óµµ¸¦ ³ôÀÌ´Â Àü¿ë Çϵå¿þ¾î ÄÚÇÁ·Î¼¼¼­ÀÔ´Ï´Ù.


Sun Crypto Accelerator 1000

Sun¢â Crypto Accelerator 1000 (Sun CA1000) º¸µå´Â ¾Ïȣȭ ÄÚÇÁ·Î¼¼¼­·Î ÀÛµ¿ÇÏ¿© °ø¿ë Ű¿Í ´ëĪ ¾Ïȣȭ¸¦ °¡¼ÓÈ­Çϴ ªÀº ÇüÅÂÀÇ PCI º¸µåÀÔ´Ï´Ù. ÀÌ Á¦Ç°¿¡´Â ¿ÜºÎ ÀÎÅÍÆäÀ̽º°¡ ¾ø½À´Ï´Ù. ÀÌ º¸µå´Â ³»ºÎ PCI ¹ö½º ÀÎÅÍÆäÀ̽º¸¦ ÅëÇØ È£½ºÆ®¿Í Åë½ÅÇÕ´Ï´Ù. ÀÌ º¸µå´Â eCommerce ÀÀ¿ëÇÁ·Î±×·¥¿¡¼­ º¸¾È ÇÁ·ÎÅäÄÝÀ» À§ÇÑ ´Ù¾çÇÑ °è»ê Áý¾àÀû ¾Ïȣȭ ¾Ë°í¸®ÁòÀ» °¡¼ÓÈ­Çϱâ À§ÇÑ ¸ñÀûÀ¸·Î »ç¿ëµË´Ï´Ù.

RSA [7] ¹× Triple-DES (3DES) [8]¿Í °°Àº ´Ù¼öÀÇ ÇÙ½É ¾Ïȣȭ ±â´ÉÀ» ÀÀ¿ëÇÁ·Î±×·¥¿¡¼­ Sun CA1000À¸·Î ºÐ´ã½ÃÄÑ º´·Ä·Î ¼öÇàÇÒ ¼ö ÀÖ½À´Ï´Ù. ±×·¯¸é CPU°¡ ÀÚÀ¯·Ó°Ô ´Ù¸¥ ÀÛ¾÷À» ¼öÇàÇÒ ¼ö ÀÖ¾î SSL Æ®·£Àè¼ÇÀÇ Ã³¸® ¼Óµµ°¡ Áõ°¡ÇÕ´Ï´Ù.

Crypto Accelerator 1000 »ç¿ë

Sun¢â ONE Portal Server, Secure Remote Access°¡ ¼³Ä¡µÇ¾î ÀÖ°í °ÔÀÌÆ®¿þÀÌ ¼­¹ö ÀÎÁõ¼­(Á÷Á¢ ¼­¸í ¶Ç´Â CA¿¡¼­ ¹ßÇà)°¡ ¼³Ä¡µÇ¾ú´ÂÁö È®ÀÎÇÕ´Ï´Ù. ´ÙÀ½ Á¡°Ë ¸ñ·ÏÀ¸·Î SSL °¡¼Ó±â¸¦ ¼³Ä¡Çϱâ Àü¿¡ ÇÊ¿äÇÑ Á¤º¸¸¦ ½±°Ô È®ÀÎÇÒ ¼ö ÀÖ½À´Ï´Ù.

Ç¥ 11-1 Àº Crypto Accelerator 1000 ¸Å°³ º¯¼ö¿Í ±× °ªÀ» ³ªÅ¸³À´Ï´Ù. ù ¹øÂ° ¿­Àº ¸Å°³ º¯¼öÀÌ°í µÎ ¹øÂ° ¿­Àº °ªÀÔ´Ï´Ù.

Ç¥ 11-1  Crypto Accelerator 1000 ¼³Ä¡ Á¡°Ë ¸ñ·Ï

¸Å°³ º¯¼ö

°ª

Secure Remote Access ¼³Ä¡ ±âº» µð·ºÅ丮

/opt

Secure Remote Access ÀÎÁõ¼­ µ¥ÀÌÅͺ£À̽º °æ·Î

/etc/opt/SUNWps/cert/default

Secure Remote Access ¼­¹ö ÀÎÁõ¼­ º°¸í

server-cert

¿µ¿ª

sra-keystore

¿µ¿ª »ç¿ëÀÚ

crypta

Crypto Accelerator 1000 ±¸¼º

    Crypto Accelerator 1000À» ±¸¼ºÇÏ·Á¸é
  1. »ç¿ë ¼³¸í¼­ÀÇ Áöħ¿¡ µû¶ó Çϵå¿þ¾î¸¦ ¼³Ä¡ÇÕ´Ï´Ù. ÂüÁ¶:
  2. http://www.sun.com/products-n-solutions/hardware/docs/pdf/816-2450-11.pdf

  3. CD¿¡¼­ ´ÙÀ½ ÆÐŰÁö¸¦ ¼³Ä¡ÇÕ´Ï´Ù.
  4. SUNWcrypm, SUNWcrypu, SUNWcrysu, SUNWdcar, SUNWcrypr, SUNWcrysl, SUNWdcamn, SUNWdcav

  5. ´ÙÀ½ ÆÐÄ¡¸¦ ¼³Ä¡ÇÕ´Ï´Ù. (http://sunsolve.sun.com¿¡¼­ ¾òÀ» ¼ö ÀÖ½À´Ï´Ù.)
  6. 110383-01, 108528-05, 112438-01

  7. pk12util ¹× modutil µµ±¸°¡ ÀÖ´ÂÁö È®ÀÎÇϽʽÿÀ.
  8. SRA 6.0ÀÇ °æ¿ì, ÀÌ µµ±¸´Â /opt/SUNWps/bin ¾Æ·¡¿¡ ¼³Ä¡µÇ¾î ÀÖ½À´Ï´Ù.

    SRA 6.2ÀÇ °æ¿ì, ÀÌ µµ±¸´Â /usr/lib/mps/secv1/bin ¾Æ·¡¿¡ ¼³Ä¡µÇ¾î ÀÖ½À´Ï´Ù.

  9. ½½·Ô ÆÄÀÏÀ» ¸¸µì´Ï´Ù.
  10. vi /etc/opt/SUNWconn/crypto/slots

    ±×¸®°í ÆÄÀÏÀÇ Ã³À½ÀÌÀÚ À¯ÀÏÇÑ ¶óÀÎÀ¸·Î crypta@sra¸¦ ³Ö½À´Ï´Ù.

  11. ¿µ¿ª°ú »ç¿ëÀÚ¸¦ ¸¸µì´Ï´Ù.
  12. cd /opt/SUNWconn/bin/secadm

    secadm> create realm=sra

    ½Ã½ºÅÛ °ü¸®ÀÚ ·Î±×ÀÎÀÌ ÇÊ¿äÇÕ´Ï´Ù.

    ·Î±×ÀÎ: root

    ºñ¹Ð¹øÈ£:

    ¿µ¿ª sra°¡ ¼º°øÀûÀ¸·Î ¸¸µé¾îÁ³½À´Ï´Ù.

    secadm> set realm=sra

    secadm{srap}> su

    ½Ã½ºÅÛ °ü¸®ÀÚ ·Î±×ÀÎÀÌ ÇÊ¿äÇÕ´Ï´Ù.

    ·Î±×ÀÎ: root

    ºñ¹Ð¹øÈ£:

    secadm{root@sra}>create user=crypta

    Ãʱ⠺ñ¹Ð¹øÈ£:

    ºñ¹Ð¹øÈ£ È®ÀÎ:

    »ç¿ëÀÚ crypta°¡ ¼º°øÀûÀ¸·Î ¸¸µé¾îÁ³½À´Ï´Ù.

    secadm{root@sra}> login user=crypta

    ºñ¹Ð¹øÈ£:

    secadm{crypta@sra}> show key

    ÀÌ »ç¿ëÀÚ¿¡°Ô ۰¡ ¾ø½À´Ï´Ù.

  13. Sun Crypto ¸ðµâÀ» ·ÎµåÇÕ´Ï´Ù.
  14. SRA 6.0ÀÇ °æ¿ì, ȯ°æ º¯¼ö LD_LIBRARY_PATH´Â /opt/SUNWps/lib/solaris/sparc¸¦ °¡¸®ÄÑ¾ß ÇÕ´Ï´Ù.

    SRA 6.2ÀÇ °æ¿ì, ȯ°æ º¯¼ö LD_LIBRARY_PATH´Â /usr/lib/mps/secv1/À» °¡¸®ÄÑ¾ß ÇÕ´Ï´Ù.

    ´ÙÀ½À» ÀÔ·ÂÇÕ´Ï´Ù.

    modutil -dbdir /etc/opt/SUNWps/cert/default -add "Sun Crypto Module" -libfile /opt/SUNWconn/crypto/lib/libpkcs11.so

    ´ÙÀ½ ¸í·ÉÀ» »ç¿ëÇÏ¿© ÀÌ ¸ðµâÀÌ ·ÎµåµÇ¾ú´ÂÁö È®ÀÎÇÕ´Ï´Ù.

    modutil -list -dbdir /etc/opt/SUNWps/cert /default

  15. °ÔÀÌÆ®¿þÀÌ ÀÎÁõ¼­¿Í ۸¦ "Sun Crypto Module"·Î ³»º¸³À´Ï´Ù.
  16. SRA 6.0ÀÇ °æ¿ì, ȯ°æ º¯¼ö LD_LIBRARY_PATH´Â /opt/SUNWps/lib/solaris/sparc¸¦ °¡¸®ÄÑ¾ß ÇÕ´Ï´Ù.

    SRA 6.2ÀÇ °æ¿ì, ȯ°æ º¯¼ö LD_LIBRARY_PATH´Â /usr/lib/mps/secv1/À» °¡¸®ÄÑ¾ß ÇÕ´Ï´Ù.

    ´ÙÀ½À» ÀÔ·ÂÇÕ´Ï´Ù.

    pk12util -o servercert.p12 -d /etc/opt/SUNWps/cert/default -n server-cert

    pk12util -i servercert.p12 -d /etc/opt/SUNWps/cert/default -h "crypta@sra"

    ÀÌÁ¦ show key ¸í·ÉÀ» ½ÇÇàÇÕ´Ï´Ù.

    secadm{crypta@sra}> show key

    ÀÌ »ç¿ëÀÚ¿¡°Ô 2°³ÀÇ Å°°¡ ³ªÅ¸³ª¾ß ÇÕ´Ï´Ù.

  17. /etc/opt/SUNWps/cert/default/.nickname ÆÄÀÏ¿¡¼­ º°¸íÀ» º¯°æÇÕ´Ï´Ù.
  18. vi /etc/opt/SUWNps/cert/default/.nickname

    server-cert¸¦ crypta@sra:server-cert·Î ±³Ã¼ÇÕ´Ï´Ù.

  19. °¡¼ÓÈ­¿¡ ´ëÇÑ ¾ÏÈ£¸¦ ¼±ÅÃÇÕ´Ï´Ù.
  20. SUN CA1000Àº RSA ±â´ÉÀ» °¡¼ÓÈ­ÇÏÁö¸¸ DES¿Í 3DES ¾Ïȣȭ¿¡ ´ëÇÑ °¡¼Ó¸¸ Áö¿øÇÕ´Ï´Ù. ÀÌ·¯ÇÑ ¾Ïȣȭ Áß Çϳª¸¦ »ç¿ëÇÏ·Á¸é ´ÙÀ½À» ¼öÇàÇÕ´Ï´Ù.

    SRA 6.0ÀÇ °æ¿ì:

    °ÔÀÌÆ®¿þÀÌ >> SSL ¾Ïȣȭ ¼±Åà »ç¿ë: >> SSL3 ¾Ïȣȭ: >> SSL3_RSA_WITH_3DES_EDE_CBC_SHA ¶Ç´Â SSL3_RSA_WITH_DES_CBC_SHA

    SRA 6.2ÀÇ °æ¿ì:

    °ÔÀÌÆ®¿þÀÌ >> º¸¾È >> SSL ¾Ïȣȭ ¼±Åà »ç¿ë: >> SSL3 ¾Ïȣȭ: >> SSL3_RSA_WITH_3DES_EDE_CBC_SHA ¶Ç´Â SSL3_RSA_WITH_DES_CBC_SHA

  21. °¡¼Ó±â¸¦ »ç¿ëÇϵµ·Ï /etc/opt/SUNWps/platform.conf.gateway-profile-nameÀ» ¼öÁ¤ÇÕ´Ï´Ù.
  22. gateway.enable.accelerator=true

  23. ´Ü¸»±â â¿¡¼­ °ÔÀÌÆ®¿þÀ̸¦ ´Ù½Ã ½ÃÀÛÇÕ´Ï´Ù.
  24. portal-server-install-root/SUNWps/bin/gateway -n gateway-profile-name start


    Âü°í

    °ÔÀÌÆ®¿þÀÌ´Â °ÔÀÌÆ®¿þÀÌ ÇÁ·ÎÇÊ¿¡¼­ https Æ÷Æ®·Î ¾ð±ÞµÈ Æ÷Æ®ÀÇ ÀÏ¹Ý ServerSocket (ºñ SSL)¿¡ ¹ÙÀεùÇÕ´Ï´Ù.

    µé¾î¿À´Â Ŭ¶óÀÌ¾ðÆ® Æ®·¡ÇÈ¿¡ ´ëÇØ SSL ¾Ïȣȭ ¶Ç´Â º¹È£È­°¡ ¼öÇàµÇÁö ¾Ê½À´Ï´Ù. °¡¼Ó±â¿¡¼­ ÀÌ ÀÛ¾÷À» ¼öÇàÇÕ´Ï´Ù.

    PDC´Â ÀÌ ¸ðµå¿¡¼­ ÀÛµ¿ÇÏÁö ¾Ê½À´Ï´Ù.



Sun Crypto Accelerator 4000

Sun¢â Crypto Accelerator 4000 º¸µå´Â Sun ¼­¹ö¿¡¼­ IPsec ¹× SSL (´ëħ ¹× ºñ´ëĪ ¸ðµÎ)¿¡ ´ëÇÑ ¾Ïȣȭ Çϵå¿þ¾î °¡¼ÓÀ» Áö¿øÇÏ´Â ±â°¡ºñÆ® ÀÌ´õ³Ý ±â¹Ý ³×Æ®¿öÅ© ÀÎÅÍÆäÀ̽º Ä«µåÀÔ´Ï´Ù.

¾ÏȣȭµÇÁö ¾ÊÀº ³×Æ®¿öÅ© Æ®·¡ÇÈÀ» À§ÇÑ Ç¥ÁØ ±â°¡ºñÆ® ÀÌ´õ³Ý ³×Æ®¿öÅ© Ä«µå·Î ÀÛµ¿ÇÏ´Â ¿Ü¿¡ ÀÌ º¸µå¿¡´Â ¾Ïȣȭ IPsec Æ®·¡ÇÈ¿¡ ³ôÀº ó¸® ¼Óµµ¸¦ Áö¿øÇÒ ¾Ïȣȭ Çϵå¿þ¾î°¡ Æ÷ÇԵǾî ÀÖ½À´Ï´Ù.

Crypto Accelerator 4000 º¸µå´Â Çϵå¿þ¾î¿Í ¼ÒÇÁÆ®¿þ¾î ¸ðµÎ¿¡¼­ ¾Ïȣȭ ¾Ë°í¸®ÁòÀ» °¡¼ÓÈ­ÇÕ´Ï´Ù. ¾Ïȣȭ DES ¹× 3DES¿¡ ´ëÇÑ ´ë·® ¾Ïȣȭµµ Áö¿øÇÕ´Ï´Ù.

Crypto Accelerator 4000 »ç¿ë

Secure Remote Access°¡ ¼³Ä¡µÇ¾î ÀÖ°í °ÔÀÌÆ®¿þÀÌ ¼­¹ö ÀÎÁõ¼­(Á÷Á¢ ¼­¸í ¶Ç´Â CA¿¡¼­ ¹ßÇà)°¡ ¼³Ä¡µÇ¾ú´ÂÁö È®ÀÎÇÕ´Ï´Ù. ´ÙÀ½ Á¡°Ë ¸ñ·ÏÀ¸·Î SSL °¡¼Ó±â¸¦ ¼³Ä¡Çϱâ Àü¿¡ ÇÊ¿äÇÑ Á¤º¸¸¦ ½±°Ô È®ÀÎÇÒ ¼ö ÀÖ½À´Ï´Ù.

Ç¥ 11-1 Àº Crypto Accelerator 4000 ¸Å°³ º¯¼ö¿Í ±× °ªÀ» ³ªÅ¸³À´Ï´Ù. ù ¹øÂ° ¿­Àº ¸Å°³ º¯¼öÀÌ°í µÎ ¹øÂ° ¿­Àº °ªÀÔ´Ï´Ù.

Ç¥ 11-2  Crypto Accelerator 4000 ¼³Ä¡ Á¡°Ë ¸ñ·Ï

¸Å°³ º¯¼ö

°ª

Secure Remote Access ¼³Ä¡ ±âº» µð·ºÅ丮

/opt

Secure Remote Access ÀνºÅϽº

±âº»°ª

Secure Remote Access ÀÎÁõ¼­ µ¥ÀÌÅͺ£À̽º °æ·Î

/etc/opt/SUNWps/cert/default

Secure Remote Access ¼­¹ö ÀÎÁõ¼­ º°¸í

server-cert

CA4000 Ű ÀúÀå¼Ò

srap

CA4000 Ű ÀúÀå¼Ò »ç¿ëÀÚ

crypta

Crypto Accelerator 4000 ±¸¼º

    Crypto Accelerator 4000À» ±¸¼ºÇÏ·Á¸é
  1. »ç¿ë ¼³¸í¼­ÀÇ Áöħ¿¡ µû¶ó Çϵå¿þ¾î¿Í ¼ÒÇÁÆ®¿þ¾î ÆÐŰÁö¸¦ ¼³Ä¡ÇÕ´Ï´Ù. ÂüÁ¶:
  2. http://www.sun.com/products-n-solutions/hardware/docs/pdf/816-2450-11.pdf

  3. ´ÙÀ½ ÆÐÄ¡¸¦ ¼³Ä¡ÇÕ´Ï´Ù. (http://sunsolve.sun.com¿¡¼­ ¾òÀ» ¼ö ÀÖ½À´Ï´Ù.) 114795
  4. certutil, pk12util ¹× modutil µµ±¸°¡ ÀÖ´ÂÁö È®ÀÎÇϽʽÿÀ.
  5. SRA 6.0ÀÇ °æ¿ì, ÀÌ µµ±¸´Â /opt/SUNWps/bin ¾Æ·¡¿¡ ¼³Ä¡µÇ¾î ÀÖ½À´Ï´Ù.

    SRA 6.2ÀÇ °æ¿ì, ÀÌ µµ±¸´Â /usr/lib/mps/secv1/bin ¾Æ·¡¿¡ ¼³Ä¡µÇ¾î ÀÖ½À´Ï´Ù.

  6. º¸µå¸¦ ÃʱâÈ­ÇÕ´Ï´Ù.
  7. /opt/SUNWconn/bin/vcadm µµ±¸¸¦ ½ÇÇàÇÏ¿© ¾Ïȣȭ º¸µå¸¦ ÃʱâÈ­ÇÏ°í ´ÙÀ½ °ªÀ» ¼³Á¤ÇÕ´Ï´Ù.

    Ãʱ⠺¸¾È °ü¸® À̸§: sec_officer

    Ű ÀúÀå¼Ò À̸§: sra-keystore

    FIPS 140-2 ¸ðµå¿¡¼­ ½ÇÇà: No

  8. »ç¿ëÀÚ¸¦ ¸¸µì´Ï´Ù.
  9. vcaadm{vca0@localhost, sec_officer}> create user

    »õ »ç¿ëÀÚ À̸§: crypta

    »õ »ç¿ëÀÚ ºñ¹Ð¹øÈ£ ÀÔ·Â:

    ºñ¹Ð¹øÈ£ È®ÀÎ:

    »ç¿ëÀÚ crypta°¡ ¼º°øÀûÀ¸·Î ¸¸µé¾îÁ³½À´Ï´Ù.

  10. Ű ÀúÀå¼Ò¿¡ ÅäÅ«À» ¸ÅÇÎÇÕ´Ï´Ù.
  11. vi /opt/SUNWconn/cryptov2/tokens

    ±×¸®°í ÆÄÀÏ¿¡ sra-keystore¸¦ Ãß°¡ÇÕ´Ï´Ù.

  12. ´ë·® ¾ÏȣȭÀÇ »ç¿ëÀ» ¼³Á¤ÇÕ´Ï´Ù.
  13. touch /opt/SUNWconn/cryptov2/sslreg

  14. Sun Crypto ¸ðµâÀ» ·ÎµåÇÕ´Ï´Ù.
  15. SRA 6.0ÀÇ °æ¿ì, ȯ°æ º¯¼ö LD_LIBRARY_PATH´Â /opt/SUNWps/lib/solaris/sparc¸¦ °¡¸®ÄÑ¾ß ÇÕ´Ï´Ù.

    SRA 6.2ÀÇ °æ¿ì¿¡´Â /usr/lib/mps/secv1/À» °¡¸®ÄÑ¾ß ÇÕ´Ï´Ù.

    ´ÙÀ½À» ÀÔ·ÂÇÕ´Ï´Ù.

    modutil -dbdir /etc/opt/SUNWps/cert/default -add "Sun Crypto Module" -libfile /opt/SUNWconn/cryptov2/lib/libvpkcs11.so

    ´ÙÀ½ ¸í·ÉÀ» »ç¿ëÇÏ¿© ÀÌ ¸ðµâÀÌ ·ÎµåµÇ¾ú´ÂÁö È®ÀÎÇÒ ¼ö ÀÖ½À´Ï´Ù.

    modutil -list -dbdir /etc/opt/SUNWps/cert /default

  16. °ÔÀÌÆ®¿þÀÌ ÀÎÁõ¼­¿Í ۸¦ "Sun Crypto Module"·Î ³»º¸³À´Ï´Ù.
  17. SRA 6.0ÀÇ °æ¿ì, ȯ°æ º¯¼ö LD_LIBRARY_PATH´Â /opt/SUNWps/lib/solaris/sparc¸¦ °¡¸®ÄÑ¾ß ÇÕ´Ï´Ù.

    SRA 6.2ÀÇ °æ¿ì¿¡´Â /usr/lib/mps/secv1/À» °¡¸®ÄÑ¾ß ÇÕ´Ï´Ù.

    pk12util -o servercert.p12 -d /etc/opt/SUNWps/cert/default -n server-cert

    pk12util -i servercert.p12 -d /etc/opt/SUNWps/cert/default -h "sra-keystore"

    ´ÙÀ½ ¸í·ÉÀ» »ç¿ëÇÏ¿© ۰¡ ³»º¸³»Á³´ÂÁö È®ÀÎÇÒ ¼ö ÀÖ½À´Ï´Ù.

    certutil -K -h "sra-keystore" -d /etc/opt/SUNWps/cert/default

  18. /etc/opt/SUWNps/cert/default/.nickname ÆÄÀÏ¿¡¼­ º°¸íÀ» º¯°æÇÕ´Ï´Ù.
  19. vi /etc/opt/SUWNps/cert/default/.nickname

    server-cert¸¦ sra-keystore:server-cert·Î ±³Ã¼ÇÕ´Ï´Ù.

  20. °¡¼ÓÈ­¿¡ ´ëÇÑ ¾ÏÈ£¸¦ ¼±ÅÃÇÕ´Ï´Ù.
  21. SUN CA4000Àº RSA ±â´ÉÀ» °¡¼ÓÈ­ÇÏÁö¸¸ DES¿Í 3DES ¾Ïȣȭ¿¡ ´ëÇÑ °¡¼Ó¸¸ Áö¿øÇÕ´Ï´Ù. ÀÌ·¯ÇÑ ¾Ïȣȭ Áß Çϳª¸¦ »ç¿ëÇÏ·Á¸é ´ÙÀ½À» ¼öÇàÇÕ´Ï´Ù.

    SRA 6.0ÀÇ °æ¿ì:

    °ÔÀÌÆ®¿þÀÌ >> SSL ¾Ïȣȭ ¼±Åà »ç¿ë: >> SSL3 ¾Ïȣȭ: >> SSL3_RSA_WITH_3DES_EDE_CBC_SHA ¶Ç´Â SSL3_RSA_WITH_DES_CBC_SHA

    SRA 6.2ÀÇ °æ¿ì:

    °ÔÀÌÆ®¿þÀÌ >> º¸¾È >> SSL ¾Ïȣȭ ¼±Åà »ç¿ë: >> SSL3 ¾Ïȣȭ: >> SSL3_RSA_WITH_3DES_EDE_CBC_SHA ¶Ç´Â SSL3_RSA_WITH_DES_CBC_SHA

  22. ´Ü¸»±â â¿¡¼­ °ÔÀÌÆ®¿þÀ̸¦ ´Ù½Ã ½ÃÀÛÇÕ´Ï´Ù.
  23. portal-server-install-root/SUNWps/bin/gateway -n gateway-profile-name start

    °ÔÀÌÆ®¿þÀ̰¡ Ű ÀúÀå¼Ò ºñ¹Ð¹øÈ£¸¦ ÀÔ·ÂÇϵµ·Ï ¿äûÇÕ´Ï´Ù.

    "sra-keystore":crypta:crytpa-password¿¡ ´ëÇÑ ºñ¹Ð¹øÈ£ ¶Ç´Â PINÀ» ÀÔ·ÂÇÕ´Ï´Ù.


    Âü°í

    °ÔÀÌÆ®¿þÀÌ´Â °ÔÀÌÆ®¿þÀÌ ÇÁ·ÎÇÊ¿¡¼­ https Æ÷Æ®·Î ¾ð±ÞµÈ Æ÷Æ®ÀÇ ÀÏ¹Ý ServerSocket (ºñ SSL)¿¡ ¹ÙÀεùÇÕ´Ï´Ù.

    µé¾î¿À´Â Ŭ¶óÀÌ¾ðÆ® Æ®·¡ÇÈ¿¡ ´ëÇØ SSL ¾Ïȣȭ ¶Ç´Â º¹È£È­°¡ ¼öÇàµÇÁö ¾Ê½À´Ï´Ù. °¡¼Ó±â¿¡¼­ ÀÌ ÀÛ¾÷À» ¼öÇàÇÕ´Ï´Ù.

    PDC´Â ÀÌ ¸ðµå¿¡¼­ ÀÛµ¿ÇÏÁö ¾Ê½À´Ï´Ù.



¿ÜºÎ SSL ÀåÄ¡ ¹× ÇÁ¶ô½Ã °¡¼Ó±â

¿­¸° ¸ðµå¿¡¼­ ¿ÜºÎ SSL ÀåÄ¡¸¦ Secure Remote Access Àü¹æ¿¡¼­ ½ÇÇàÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ ÀåÄ¡´Â Ŭ¶óÀÌ¾ðÆ®¿Í Secure Remote Access »çÀÌ¿¡¼­ SSL ¸µÅ©¸¦ Á¦°øÇÕ´Ï´Ù.

¿ÜºÎ SSL ÀåÄ¡ °¡¼Ó±â »ç¿ë

Secure Remote Access°¡ ¼³Ä¡µÇ¾î ÀÖ°í °ÔÀÌÆ®¿þÀ̰¡ º¸¾È ¸ðµå(HTTPS ¸ðµå)¿¡¼­ ½ÇÇàµÇ¾î¾ß ÇÕ´Ï´Ù.

°ÔÀÌÆ®¿þÀÌ >> HTTPS ¿¬°á »ç¿ë

°ÔÀÌÆ®¿þÀÌ>> HTTP Æ÷Æ®: 880

Ç¥ 11-3 Àº ¿ÜºÎ SSL ÀåÄ¡¿Í ÇÁ¶ô½Ã °¡¼Ó±â ¸Å°³ º¯¼ö ¹× °ªÀ» ³ªÅ¸³À´Ï´Ù. ù ¹øÂ° ¿­Àº ¸Å°³ º¯¼öÀÌ°í µÎ ¹øÂ° ¿­Àº °ªÀÔ´Ï´Ù.

Ç¥ 11-3  ¿ÜºÎ SSL ÀåÄ¡ ¹× ÇÁ¶ô½Ã °¡¼Ó±â Á¡°Ë ¸ñ·Ï

¸Å°³ º¯¼ö

°ª

SRA ÀνºÅϽº

±âº»°ª

°ÔÀÌÆ®¿þÀÌ ¸ðµå

https

°ÔÀÌÆ®¿þÀÌ Æ÷Æ®

880

¿ÜºÎ ÀåÄ¡/ÇÁ¶ô½Ã Æ÷Æ®

443

¿ÜºÎ SSL ÀåÄ¡ °¡¼Ó±â ±¸¼º

    ¿ÜºÎ SSL ÀåÄ¡ °¡¼Ó±â¸¦ ±¸¼ºÇÏ·Á¸é
  1. »ç¿ë ¼³¸í¼­ÀÇ Áöħ¿¡ µû¶ó Çϵå¿þ¾î¿Í ¼ÒÇÁÆ®¿þ¾î ÆÐŰÁö¸¦ ¼³Ä¡ÇÕ´Ï´Ù.
  2. ÇØ´çÇÏ´Â °æ¿ì ÇÊ¿äÇÑ/±ÇÀåµÇ´Â ÆÐÄ¡¸¦ ¼³Ä¡ÇÕ´Ï´Ù.
  3. SSL ÀåÄ¡/ÇÁ¶ô½Ã Áö¿øÀ» Ȱ¼ºÈ­ÇÕ´Ï´Ù.
  4. vi /etc/opt/SUNWps/platform.conf.default

    gateway.enable.accelerator=true

    ¿ÜºÎ ÀåÄ¡/ÇÁ¶ô½Ã È£½ºÆ® À̸§ÀÌ °ÔÀÌÆ®¿þÀÌ È£½ºÆ® À̸§°ú ´Ù¸¥ °æ¿ì,

    gateway.enable.customurl=true

    gateway.httpsurl=external-device.domain.subdomain/proxy-URL

  5. µÎ °¡Áö ¹æ¹ýÀ¸·Î °ÔÀÌÆ®¿þÀÌ ¾Ë¸²À» ±¸¼ºÇÒ ¼ö ÀÖ½À´Ï´Ù.
    • Identity ¼­¹ö°¡ Æ÷Æ® 880¿¡¼­ °ÔÀÌÆ®¿þÀÌ ÄÄÇ»ÅÍ¿Í Á¢¼ÓÇÒ ¼ö ÀÖ´Â °æ¿ì(http·Î ¼¼¼Ç ¾Ë¸²)

      vi /etc/opt/SUNWps/platform.conf.default

      gateway.protocol=http

      gateway.port=880

    • Identity ¼­¹ö°¡ Æ÷Æ® 443¿¡¼­ ¿ÜºÎ ÀåÄ¡/ÇÁ¶ô½Ã¿Í Á¢¼ÓÇÒ ¼ö ÀÖ´Â °æ¿ì(HTTPS ¼¼¼Ç ¾Ë¸²)

      vi /etc/opt/SUNWps/platform.conf.default

      gateway.host=External Device/Proxy Host Name

      gateway.protocol=https

      gateway.port=443

  6. SSL ÀåÄ¡/ÇÁ¶ô½Ã°¡ ÀÛµ¿Çϰí ÀÖÀ¸¸ç °ÔÀÌÆ®¿þÀÌ Æ÷Æ®·Î Æ®·¡ÇÈÀ» ³Ñ±âµµ·Ï ±¸¼ºµÇ¾î ÀÖ´ÂÁö È®ÀÎÇÕ´Ï´Ù.
  7. ´Ü¸»±â â¿¡¼­ °ÔÀÌÆ®¿þÀ̸¦ ´Ù½Ã ½ÃÀÛÇÕ´Ï´Ù.
  8. gateway-install-root/SUNWps/bin/gateway -n gateway-profile-name start



ÀÌÀü      ¸ñÂ÷      »öÀÎ      ´ÙÀ½     


Copyright 2003 Sun Microsystems, Inc. ¸ðµç ±Ç¸®´Â ÀúÀÛ±ÇÀÚÀÇ ¼ÒÀ¯ÀÔ´Ï´Ù.