Building a Secure RedHat Apache Server HOWTO

Sigle Richard

richard.sigle@equifax.com

서정룡

s_ryong@hotmail.com

영문 버전 : 0.1 2001-02-6

최종수정일 : 0.1 2001년 3월 19일


차례
1. 지침의 목적/범위
1.1. Secure Sockets Layer (SSL)에 대해
1.2. 피드백
1.3. Copyrights and Trademarks
1.4. Acknowledgements and Thanks
2. Secure Sockets Layer/Private Key Infrastructure 소개
2.1. SSL/PKI의 책임
2.2. 어떻게 SSL이 작동하는가
2.3. 어떻게 PKI가 작동하는가
2.4. 인증서(x509 Standard)
2.5. 디지털 인증서 비밀키
2.6. 디지털 인증서 공개키
2.7. 인증서 서명 요청(Certificate Signing Request,CSR)
3. 인증서 관련 작업
3.1. 비밀키 생성하기
3.2. CSR 생성하기
3.3. 자필 서명 인증서 생성하기
3.4. 웹서버 인증서 설치하기
4. 아파치 서버 설정하기
9
4.1. 보안 가상 호스트 정의하기
4.2. 인증서 예
4.3. 웹 서버 재구동하기
5. 문제해결
5.1. 서버는 구동된 듯 한데, 보안 사이트에 액세스 할 수 없다(Server Appears to start, but you cannot access the secure site).
5.2. 클라이언트 브라우저에서 인증서 이름 체크 경고가 나타난다(Certificate Name Check Warning is issued by the client's browser).
5.3. 클라이언트 웹브라우저가 "인증서가 신뢰되지 않는 CA에 의해 서명되었다"라는 경고를 나타낸다(Certificate was Signed by an Untrusted Certificate Authority Warning is issued by the client's browser).
5.4. 아파치를 구동할 때 SSLEngine on 이 인식되지 않는 명령어이다(SSLEngine on is an un-recognized command (when starting Apache)).
5.5. PEM passphrase를 잊었는데 이를 재설정하는 방법을 알고 싶다(You have forgotten your "PEM Passphrase" and you would like to know how to reset it).
6. 용어 해설
2

이 지침은 PKI와 SSL이 함께 작동하는 방법을 설명하기 위한 것으로 보안 서버를 성공적으로 설치하기 위해서는 SSL 프로토콜의 작동 원리를 이해하는 것이 필수적이다.

1. 지침의 목적/범위

이 지침의 목적은 레드햇 리눅스 사용자들에게 아파치 웹서버를 사용해 서버 (SSL) 인증서를 설치하는데 있어 도움을 주기 위한 것으로 시간뿐만아니라 많은 경우 비용을 절약할 수 있는 명백한 절차를 제공하는 것이다.

우선 SSL 프로토콜과 디지털 인증서(digital certificate)에 관해 알아야 할 사항을 다룰 것인데 저자의 경험에 비추면 ModSSL 및 OpenSSL과 함께 아파치 웹서버를 구축하는 것이 가장 유익하다. OpenSSL은 SSL v2/v3와 TLS v1 프로토콜을 지원하는 범용 암호법 라이브러리이고 ModSSL은 아파치와 OpenSSL사이의 인터페이스로 작용하도록 설계된 아파치 API 모듈이다. 물론 가장 큰 장점은 세가지 소프트웨어 패키지 모두 'free"라는 것이다.

4.1절부터 시작하여 ModSSL과 OpenSSL과 함께 컴파일된 레드햇 아파치 서버에 키 생성 및 인증서 설치의 단계적 절차를 자세히 검토할 것이다. 4절의 절차는 아파치와 밀접하게 관련된 Stronghold와 Raven과 같은 상용 SSL-서버 패키지에서도 또한 작용할 것이다.

Disclaimer: I am a technical support engineer for Equifax Secure Inc., a Certificate Authority. Therefore, I use Equifax Secure certificates and examples geared towards installing Equifax Secure certificates. However, the instructions will also work with certificates issued by other Certificate Authorities. Since this document was written at my own initiative, Equifax Secure Inc. is neither liable nor accountable for any consequences resulting from the use of these procedures.

My comments to the reader is in this style (emphasized).

Example lines are in plain roman style.

Note that extra comments and advice is found in comments within the SGML source.

1.1. Secure Sockets Layer (SSL)에 대해

SSL은 TCP와 애플리케이션 계층 사이에 존재하는 presentation 계층 서비스 (OSI 7 계층)로 플랫폼과 애플리케이션에 독립적이다. SSL은 클라이언트와 서버사이의 안전한 통신 채널 관리를 담당하며 이들 사이에 전달되는 데이터를 암호하는데 있어 강력한 기구를 제공한다.

1.2. 피드백

이 지침에 대한 의견을 저자에게 보내주기 바란다 (richard.sigle@equifax.com).

1.3. Copyrights and Trademarks

Copyright (c) 2001 by Richard L. Sigle

Please freely copy and distribute this document in any format. It's requested that corrections and/or comments be forwarded to the document maintainer. You may create a derivative work and distribute it provided that you:

  • Send your derivative work (in the most suitable format such as sgml) to the LDP (Linux Documentation Project) or the like for posting on the Internet. If not the LDP, then let the LDP know where it is available.

  • License the derivative work with this same license or use GPL. Include a copyright notice and at least a pointer to the license used.

  • Give due credit to previous authors and major contributors.

If you're considering making a derived work other than a translation, it's requested that you discuss your plans with the current maintainer.

1.4. Acknowledgements and Thanks

I would like to thank Tony Villasenor for tirelessly reading my drafts and offering his input and advice. Without Tony, this document would never have been finished.