20.7. CA¿¡ º¸³¾ ÀÎÁõ ¿ä±¸¼­ »ý¼ºÇϱâ

ÀÏ´Ü Å°¸¦ ¸¸µå¼ÌÀ¸¸é, ´ÙÀ½ ´Ü°è´Â ¿©·¯ºÐÀÌ ¼±ÅÃÇϽŠCA¿¡ º¸³¾ ÀÎÁõ ¿ä±¸¼­¸¦ ¸¸µå´Â °ÍÀÔ´Ï´Ù. /usr/share/ssl/certs µð·ºÅ丮·Î À̵¿ÇϽŠÈÄ ´ÙÀ½ ¸í·ÉÀ» ÀÔ·ÂÇØ ÁֽʽÿÀ:

make certreq

½Ã½ºÅÛÀº ´ÙÀ½°ú °°Àº °á°ú¸¦ Ãâ·ÂÇÑ ÈÄ ¾ÏÈ£¸¦ ¿äûÇÒ °ÍÀÔ´Ï´Ù (¾ÏÈ£ ¿É¼ÇÀ» ¾ïÁ¦ÇÏÁö ¾ÊÀº °æ¿ì):

umask 77 ; \
/usr/bin/openssl req -new -key /etc/httpd/conf/ssl.key/server.key 
-out /etc/httpd/conf/ssl.csr/server.csr
Using configuration from /usr/share/ssl/openssl.cnf
Enter PEM pass phrase:
	

Å°¸¦ »ý¼ºÇÒ ¶§ ¼±ÅÃÇϽŠ¾ÏÈ£¸¦ ÀÔ·ÂÇϽñ⠹ٶø´Ï´Ù. ÀϺΠÁö½Ã »çÇ×µéÀÌ Ãâ·ÂµÈ ÈÄ ÀÏ·ÃÀÇ Áú¹® »çÇ×µéÀÌ ³ªÅ¸³¯ °ÍÀÔ´Ï´Ù. ¿©·¯ºÐÀÌ ÀÔ·ÂÇϽŠ³»¿ëÀº ÀÎÁõ ¿ä±¸¼­¿¡ Æ÷ÇԵ˴ϴÙ. Áú¹® »çÇ×µé°ú ¿¹½Ã ´äº¯Àº ´ÙÀ½°ú °°ÀÌ ³ªÅ¸³³´Ï´Ù:

You are about to be asked to enter information that will be incorporated
into your certificate request.
What you are about to enter is what is called a Distinguished Name or a
DN.
There are quite a few fields but you can leave some blank
For some fields there will be a default value,
If you enter '.', the field will be left blank.
-----
Country Name (2 letter code) [GB]:US
State or Province Name (full name) [Berkshire]:North Carolina
Locality Name (eg, city) [Newbury]:Raleigh
Organization Name (eg, company) [My Company Ltd]:Test Company
Organizational Unit Name (eg, section) []:Testing
Common Name (your name or server's hostname) []:test.example.com
Email Address []:admin@example.com
Please enter the following 'extra' attributes
to be sent with your certificate request
A challenge password []:
An optional company name []:

°¢°¢ÀÇ Áú¹®¿¡ ´ëÇÑ µðÆúÆ® ÀԷ°ªÀº Áú¹® ¹Ù·Î ´ÙÀ½ [] °ýÈ£ ¾È¿¡ ³ªÅ¸³³´Ï´Ù. ¿¹·Î µé¸é ÀÎÁõ¼­°¡ »ç¿ëµÉ ±¹°¡ Äڵ忡 ´ëÇÑ Ã¹ Áú¹®Àº ´ÙÀ½°ú °°ÀÌ ³ªÅ¸³³´Ï´Ù:

Country Name (2 letter code) [GB]:

°ýÈ£ ¾È¿¡ ÀÖ´Â µðÆúÆ® ÀԷ°ªÀº GB ÀÔ´Ï´Ù. µðÆúÆ® °ªÀ» ¼ö¶ôÇϱâ À§Çؼ­´Â ´Ü¼øÈ÷ [Enter] Å°¸¦ ´©¸£½Ê½Ã¿À. ´Ù¸¥ °ªÀ» ÀÔ·ÂÇϽ÷Á¸é ÇØ´ç ±¹°¡ÀÇ µÎÀÚ¸® ¹®ÀÚ Äڵ带 ÀÔ·ÂÇϽñ⠹ٶø´Ï´Ù.

³ª¸ÓÁö ÀԷ°ªÀº ¿©·¯ºÐÀÌ ÀÔ·ÂÇÏ¼Å¾ß ÇÕ´Ï´Ù. ÀÌ °ªµéÀº ½±°Ô ÀÔ·Â °¡´ÉÇÏÁö¸¸ ´ÙÀ½°ú °°Àº Áö½Ã »çÇ×À» µû¸£¼Å¾ß ÇÕ´Ï´Ù:

¸ðµç ÀÔ·ÂÁ¤º¸¸¦ ä¿ì½Ã¸é /etc/httpd/conf/ssl.csr/server.csrÀ̶ó´Â ÆÄÀÏÀÌ »ý¼ºµË´Ï´Ù. ÀÌ ÆÄÀÏÀº ¿©·¯ºÐÀÇ ÀÎÁõ ¿ä±¸¼­·Î¼­ CA¿¡ º¸³»Áú Áغñ°¡ µÇ¾ú½À´Ï´Ù.

ÀÎÁõ ¿ä±¸¼­¸¦ º¸³¾ CA¸¦ ¼±ÅÃÇϽŠÈÄ CA À¥»çÀÌÆ®¿¡ ³ª¿Â Áö½Ã »çÇ×À» µû¸£½Ê½Ã¿À. ÀÎÁõ ¿ä±¸¼­¸¦ º¸³»´Â ¹æ¹ý°ú ÇÊ¿äÇÑ ¹®¼­, ÁöºÒ ¹æ¹ý¿¡ ´ëÇÑ ³»¿ëÀ» ¾Ë·ÁÁÙ °ÍÀÔ´Ï´Ù.

CAÀÇ ¿ä±¸ Á¶°ÇÀ» ¸¸Á·½Ãų °æ¿ì¿¡ CA´Â ÀÎÁõ¼­¸¦ (´ëºÎºÐÀÇ °æ¿ì À̸ÞÀÏÀ» ÅëÇØ) º¸³»ÁÝ´Ï´Ù. CA¿¡¼­ ¹ÞÀº ÀÎÁõ¼­ÀÎ /etc/httpd/conf/ssl.crt/server.crt¸¦ ÀúÀå (¶Ç´Â º¹»ç ÈÄ ºÙ¿©³Ö±â) ÇϽʽÿÀ. ÀÌ ÆÄÀÏÀÇ ¹é¾÷À» ¸¸µå½Ã´Â °Íµµ ÀØÁö ¸¶½Ê½Ã¿À.