IT/development

[WebServer]Apache Web Server SSL ์„ค์ •

์•Œ ์ˆ˜ ์—†๋Š” ์‚ฌ์šฉ์ž 2022. 11. 26.

๋ชฉ์ฐจ

    APACHE SSL ์„ค์น˜ํ•˜๋Š” ๋ฒ• ๐Ÿ˜ƒ

    ๋ฐฉํ™”๋ฒฝ ํ—ˆ์šฉ(443 port)
    SSL ์ธ์ฆ์„œ์™€ ssl_auth.sh ํŒŒ์ผ
    httpd.conf, ssl.conf
    ssl ์ธ์ฆ์„œ(SSLCertificateFile, SSLCertificateKeyFile, SSLCertificateChainFile)์™€ ssl_auth.sh ํŒŒ์ผ์„ ์ •ํ•ด์ง„ ๊ฒฝ๋กœ์— ์œ„์น˜
    ex) /WebServer/APACHE/jboss-ews-2.1/httpd/ssl ํด๋” ๋ฐ‘์— ์œ„์น˜

    ssl.conf(์›น์„œ๋ฒ„์˜ ํ™˜๊ฒฝ์„ค์ • ํŒŒ์ผ - ssl์„ค์น˜ ๊ด€๋ จ ์ •๋ณด) ํŒŒ์ผ์„ ์„œ๋ฒ„์— ๋งก๊ฒŒ ์„ค์ •
    ex) /WebServer/APACHE/jboss-ews-2.1/httpd/conf.d ํด๋” ๋ฐ‘์— ์œ„์น˜


    Listen 443 ์ฃผ์„ ํ•ด์ œ

    NameVirtualHost *:443 ์ฃผ์„์ฒ˜๋ฆฌ ํ•  ๊ฒƒ(apache 2.4์ด์ƒ ์ง€์›์•ˆํ•จ)

    SSLMutex default ์ฃผ์„์ฒ˜๋ฆฌ ํ•  ๊ฒƒ(apache 2.4์ด์ƒ ์ง€์›์•ˆํ•จ)

    ๋ถ€๋ถ„์˜ ์ธ์ฆ์„œ ๊ฒฝ๋กœ๋ฅผ ์„œ๋ฒ„์— ๋งก๊ฒŒ ์„ค์ •

    DocumentRoot ๋ฅผ ๋ฉ”์ธjsp๊ฐ€ ์žˆ๋Š” ๊ฒฝ๋กœ๋กœ ์ˆ˜์ • ex)/var/www/html

    #SSLPassPhraseDialog builtin ์˜ ์ฃผ์„ ํ•ด์ œ(๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ๋ถˆ๋Ÿฌ์˜ค๋Š” ๋ฌธ๊ตฌ)

    ์™€์ผ๋“œ์นด๋“œ ์ธ์ฆ์„œ ์‚ฌ์šฉ์‹œ, serverName์„ xxx.xxx.xx.xx:443์œผ๋กœ ๋ณ€๊ฒฝ

    httpd.conf ํŒŒ์ผ์„ ์„œ๋ฒ„์— ๋งก๊ฒŒ ์„ค์ •
    ex) /WebServer/APACHE/jboss-ews-2.1/httpd/conf ํด๋” ๋ฐ‘์— ์œ„์น˜
    Listen 443์ด ์„ ์–ธ๋˜์–ด ์žˆ๋Š”๋ฐ ์ฃผ์„์ฒ˜๋ฆฌ ํ•  ๊ฒƒ(ssl.conf์— ์žˆ์Œ)
    ssl.conf์— ์ง€์ •๋œ ๋กœ๊ทธ ํŒŒ์ผ๋กœ ๋กœ๊ทธ ๋ณด๋ฉด์„œ ๋ฐ˜์˜ํ•˜๋ฉด ๋จ

    ๋Œ“๊ธ€