
IMPORTANT! Please read this Security Advisory - March 1, 2002
Â÷·Ê

ÆÐÄ¡¸¦ ±¸ÇÒ ¼ö ÀÖ´Â FTP ¹Ì·¯ »çÀÌÆ®ÀÇ ¸ñ·ÏÀÔ´Ï´Ù.
¾ÆÆÄÄ¡(1.2.0+ °ú 1.3.0+ ¹öÀü¿¡¼ °¡´É) ÆÐÄ¡¿Í README, ¼³Á¤ ¿¹Á¦, º°µµÀÇ ¼Ò½º ÆÄÀÏÀ» ¾ò°Ô µË´Ï´Ù. ÆÐÄ¡´Â ¾ÆÆÄÄ¡ ¼Ò½º¿¡ Àû¿ëµÈ ÈÄ¿¡ ÄÄÆÄÀÏ µÇ°í, SSLeay(¹öÀü 0.5.1b+) ¶Ç´Â OpenSSL°ú ¿¬°áµË´Ï´Ù. º¯°æµÈ ¼Ò½º´Â Apache-SSL »Ó¸¸¾Æ´Ï¶ó Ç¥ÁØ Apache ¶ÇÇÑ ÄÄÆÄÀÏÇÒ ¼ö ÀÖ½À´Ï´Ù.
¸ÞÀϸµ ¸®½ºÆ®¿¡ °¡ÀÔÇϽøé ÃֽйöÀüÀÌ ³ª¿Ã ¶§¸¶´Ù ¾÷±×·¹À̵忡 ´ëÇÑ ³»¿ëÀ» ¸ÞÀÏ·Î º¸³»µå¸³´Ï´Ù.
ÇÁ·Î±×·¥ »óÀÇ ¹ö±×¸¦ ¹ß°ßÇ߰ųª °³¼±»çÇ×ÀÌ ÀÖ´Â °æ¿ì¿¡´Â ben@algroup.co.uk·Î ¸ÞÀÏÀ» Áֽñ⠹ٶø´Ï´Ù.
»ç¼³ ÀÎÁõ¼ »ç¿ë¶ÇÇÑ °¡´ÉÇÕ´Ï´Ù.
ben@algroup.co.ukÀ¸·Î ¸ÞÀÏÀ» Áֽô °æ¿ì¿¡ Á¦ PGP۸¦ »ç¿ëÇÏ½Ç ¼ö ÀÖ½À´Ï´Ù. ²À ÇÊ¿äÇÑ °æ¿ì°¡ ¾Æ´Ï¶ó¸é ÀÌ¿ëÀ» »ï°¡ÇØ Áֽñ⠹ٶø´Ï´Ù.
¾Æ´Õ´Ï´Ù, ±×¸¸Å µû·Î °³¼±ÇÒ Çʿ䰡 ¾ø´Ù´Â ¾ê±âÁÒ. ÀúÈñ´Â ºÐ¸íÇÑ ¹ö±×°¡ ¹ß°ßµÇ°Å³ª »õ ¹öÀüÀÇ Apache°¡ ³ª¿ÔÀ» ¶§, ¶Ç´Â »õ·Î¿î ±â´É¿¡ ´ëÇØ ¿äûÀ» ¹Þ¾ÒÀ» ¶§¿¡¸¸ ¾÷µ¥ÀÌÆ®¸¦ ÇÕ´Ï´Ù.
¿Ö ³» ºê¶ó¿ìÀú´Â Apache-SSL¿¡ Á¢¼ÓÇÏ¸é °è¼Ó ¸ØÃçÀÖÁÒ?
https: ´ë½Å¿¡ http://¸¦ »ç¿ëÇ߱⠶§¹®ÀÔ´Ï´Ù.
¶Ç, ¿¡·¯ ·Î±×¿¡¼ ´ÙÀ½°ú ¸Þ½ÃÁö°¡ ³ª¿À´Â °æ¿ì¿¡µµ °°Àº ¹®Á¦Á¡À¸·Î º¼ ¼ö ÀÖ½À´Ï´Ù.
SSL_Accept failed error:140760EB:SSL routines:SSL23_GET_CLIENT_HELLO:unknown protocol
ÆÐÄ¡°¡ Àû¿ëÀÌ ¾ÈµÇ´Âµ¥, ¹¹°¡ À߸øµÈ°Ì´Ï±î?
´ÙÀ½°ú °°Àº °á°ú°¡ ³ª¿Â´Ù¸é,
$patch < SSLpatch Looks like a new-style context diff. File to patch:ÆÐÄ¡°¡ ±¸ ¹öÀüÀ̱⠶§¹®¿¡ ³ªÅ¸³ª´Â °á°úÀÔ´Ï´Ù. 2.1 ÀÌ»óÀÇ ¹öÀüÀ¸·Î ¹Ù²Ù°í ´Ù½Ã ½ÃµµÇØ º¸½Ê½Ã¿À.
HTTP°¡ Æ÷Æ®(port) 80À» ¾²´Â°Ç ¾Æ´Âµ¥, HTTPS´Â ¾î¶² Æ÷Æ®¸¦ ¾¹´Ï±î?
HTTPS´Â ¾Æ¹« Æ÷Æ®¿¡¼³ª µ¹¸± ¼ö ÀÖÁö¸¸, ´ëºÎºÐÀÇ ºê¶ó¿ìÀú°¡ ±âº»À¸·Î ã´Â Ç¥ÁØ Æ÷Æ®´Â 443ÀÔ´Ï´Ù. ´ÙÀ½°ú °°ÀÌ URL¿¡ Æ÷Æ®¹øÈ£¸¦ ÁöÁ¤ÇÏ¸é ºê¶ó¿ìÀú°¡ ´Ù¸¥ Æ÷Æ®¸¦ ãµµ·Ï ¼³Á¤ÇÒ ¼ö ÀÖ½À´Ï´Ù. https://secure.server.hell:666
ÇÑ ¸Ó½Å¿¡¼ º¸¾È(secure), ºñº¸¾È(non-secure) ¼¹ö¸¦ °°ÀÌ µ¹¸®°í ½ÍÀºµ¥ °¡´ÉÇѰ¡¿ä?
µÎ°¡Áö ¹æ¹ýÀÌ ÀÖ½À´Ï´Ù. µÎ°³ÀÇ ¼¹ö ´ë¸óÀ» µ¹¸®°Å³ª, ÇÑ ´ë¸ó¿¡¼ µÎ°¡Áö ¼ºñ½º¸¦ µ¿½Ã¿¡ ÇÏ¸é µË´Ï´Ù. º¸ÅëÀº °£´ÜÇÏ°Ô ÇÑ ¼¹ö¸¦ µ¹¸®°í SSLÀÌ ÇÊ¿ä¾ø´Â ºÎºÐÀº °¡»ó È£½ºÆ®·Î ±× ±â´ÉÀ» ²¨ ¹ö¸®´Â °æ¿ì°¡ ¸¹½À´Ï´Ù. ¸¸¾à µÎ°³ÀÇ ´ë¸óÀ» µ¹¸®´Â °æ¿ì¿¡´Â °¢ ¼¹ö°¡ Á¤ÇØÁø Æ÷Æ®(º¸Åë ºñº¸¾ÈÀº Æ÷Æ® 80, º¸¾ÈÀº 443)¿¡¸¸ ¿¬°áµÇµµ·Ï ÇØ¾ß ÇÕ´Ï´Ù. ÇϳªÀÇ ´ë¸ó¸¸ µ¹¸®°í ½Í´Ù¸é, ¾î¶»°Ô ¼³Á¤ÇÏ´ÂÁö ¿¹Á¦ ¼³Á¤À» Âü°íÇØÁֽñ⠹ٶø´Ï´Ù.
ÀÌÁ¦ ¸· ¼¹ö¸¦ ¼³Ä¡ Çߴµ¥ Å×½ºÆ® ÀÎÁõ¼´Â ¾î¶»°Ô ¸¸µéÁÒ?
1. Ű(key)¿Í ¿äû(request)¸¦ ¸¸µì´Ï´Ù.
openssl req -new > new.cert.csr
2. Ű¿¡¼ ÆÐ½º¹®(passphrase)¸¦ Áö¿ó´Ï´Ù.
openssl rsa -in privkey.pem -out new.cert.key
3. ¿äû(request)À» ¼¸íµÈ Áõ¸í(cert)À¸·Î ¹Ù²ß´Ï´Ù.
openssl x509 -in new.cert.csr -out neww.cert.cert -req -signkey new.cert.key -days 365
4. À§ °á°ú¸¦ Apache-SSLÀÇ Áö½ÃÀÚ·Î ´ÙÀ½°ú °°ÀÌ »ç¿ëÇÕ´Ï´Ù.
SSLCertificateFile /path/to/certs/new.cert.cert SSLCertificateKeyFile /path/to/certs/new.cert.key
Ŭ¶óÀÌ¾ðÆ® Áõ¸í¼´Â ¾î¶»°Ô ¸¸µì´Ï±î?
1. À§ ó·³ CA Áõ¸í/Ű ½ÖÀ» ¸¸µì´Ï´Ù.
2. CA Ű·Î °í°´ ¿äû¿¡ ¼¸íÇÑ´Ù.
openssl x509 -req -in client.cert.csr -out client.cert.cert -signkey my.CA.key -CA my.CA.cert -CAkey my.CA.key -CAcreateserial -days 365
3. 'client.cert.cert' ÆÄÀÏÀ» ½ÅûÀÚ¿¡°Ô Àü´ÞÇÕ´Ï´Ù.
4. Apache-SSLÀº ´ÙÀ½ ³»¿ëÀ» ÀÔ·ÂÇϸé ÇØ´ç Áõ¸í¼ÀÇ È®ÀÎÀÌ °¡´ÉÇÕ´Ï´Ù.
SSLCACertificateFile /path/to/certs/my.CA.cert SSLVerifyClient 2
³» CGI·Î ¾î¶»°Ô Ŭ¶óÀÌ¾ðÆ® Áõ¸í¿¡ Á¢±ÙÇÒ ¼ö ÀÖÁÒ?
¸±¸®Áî apache_1.3.2+ssl_1.27 À̻󿡼´Â ´ÙÀ½ Áö½ÃÀÚ¸¦ »ç¿ëÇÕ´Ï´Ù.
SSLExportClientCertificatesÀÌ Áö½ÃÀÚ¸¦ ÀÔ·ÂÇϸé Ŭ¶óÀÌ¾ðÆ® Áõ¸íÀÇ ³»¿ëÀ» Æ÷ÇÔÇϴ ȯ°æº¯¼ö°¡ »ý¼ºµË´Ï´Ù. ´õ ÀÚ¼¼ÇÑ »çÇ×Àº, docs ¼½¼ÇÀÇ SSLExportClientCertificates¸¦ º¸½Ã¸éµË´Ï´Ù. ÀÛµ¿ ¿¹Á¦´Â https://www.apache-ssl.org/cgi/cert-exportÀÔ´Ï´Ù.
FrontPage98 Extensions with Apache-SSLÀº ¾î¶»°Ô ¼³Ä¡Çմϱî?
Bertrand Renuart°¡ ÀÌ¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ ³»¿ëÀ» http://www.itma.lu/howto/apache¿¡ ±â¼úÇØ ³õ¾Ò½À´Ï´Ù.
Verisign ÀÎÁõ¼¸¦ ¼³Ä¡ÇÒ ¶§, ¿Ö "getca", "getverisign"À» ãÀ» ¼ö ¾ø´Â°ÅÁÒ?
VerisignÀÇ ÃÖ±Ù ¾ÆÆÄÄ¡SSLÀº http://www.verisign.com/support/install/apache/v01.html¿¡¼ ãÀ¸½Ç ¼ö ÀÖ½À´Ï´Ù.
¾î¶»°Ô Çϸé Apache-SSLÀ» °øÀ¯°¡´ÉÇÑ (DSO) ¸ðµâ·Î µ¹¸± ¼ö ÀÖ³ª¿ä?
¿ì¼±, ´ÙÀ½°ú °°ÀÌ ¼Ò½º³»ÀÇ °øÀ¯¸ðµâÀ» ¼³Á¤ÇÕ´Ï´Ù.
./configure --enable-shared=apache_ssl
±×¸®°í httpd.conf¿¡¼ ¸ðµâÀ» Ȱ¼ºÈ ½Ãŵ´Ï´Ù.
LoadModule apache_ssl_module modules/libssl.so
gcc -c -I../os/unix -I../include -I/usr/local/ssl/include -funsigned-char -DTARGET=\"httpsd\" -DAPACHE_SSL `../apaci` -DAPACHE_SSL buff.c
buff.c: In function `ap_read':
buff.c:259: structure has no member named `stats'
buff.c:267: structure has no member named `stats'
buff.c:268: structure has no member named `stats'
buff.c:269: structure has no member named `stats'
buff.c:271: structure has no member named `stats'
buff.c: In function `ap_write':
buff.c:346: warning: passing arg 2 of `SSL_write' discards `const' from pointer target type
*** Error code 1
ÀÌ °æ¿ì¿¡´Â OpenSSLÀ» ¾÷±×·¹À̵å ÇØ¾ß ÇÕ´Ï´Ù.
Y2K ¹®Á¦´Â ¾ø³ª¿ä?
¾ÆÆÄÄ¡´Â Á¦´ë·Î ±¸µ¿µÇ¾ú´Âµ¥, º¸¾ÈµÈ ÆäÀÌÁö¸¦ º¼‹š ´ÙÀ½°ú °°Àº ¿¡·¯°¡ ³³´Ï´Ù
¸¸ÀÏ ´ÙÀ½°ú °°Àº ¿¡·¯·Î±×°¡ ³´Ù¸é
[Fri Apr 28 16:24:08 2000] [error] SSL_accept failed
[Fri Apr 28 16:24:08 2000] [error] error:24064064:random number generator:SSLEAY_RAND_BYTES:prng not seeded
[Fri Apr 28 16:24:08 2000] [error] error:04069003:rsa routines:RSA_generate_key:BN lib
[Fri Apr 28 16:24:08 2000] [error] error:1409B444:SSL routines:SSL3_SEND_SERVER_KEY_EXCHANGE:error generating tmp rsa key
random number generator°¡ ÇÊ¿äÇÕ´Ï´Ù(OpenSSL 0.9.5a ¹öÀüºÎÅÍ Áö¿ø°¡´É). »ó¼¼ÇÑ Á¤º¸´Âhttp://www.apache-ssl.org/docs.html#SSLRandomFile¿¡ ÀÖ½À´Ï´Ù.
¾î¶»°Ô Çϸé Apache-SSL°ú EGD¸¦ °°ÀÌ »ç¿ëÇÒ ¼ö ÀÖÁÒ?
Ben Srour °¡ ¿©±â¿¡ ¼³¸íÇØ ³õ¾Ò½À´Ï´Ù. Á¶ÀÛ°úÁ¤Àº Unix ȣȯ±âÁ¾°ú ¸Å¿ì À¯»çÇÕ´Ï´Ù.
»õ·Î¿î Á¦Ç°¿¡ ´ëÇÑ ¾È³»³ª °øÁö»çÇ׸¸À» ¹Þ¾Æº¸±æ ¿øÇϽŴٸé apache-sslannounce-help@lists.aldigital.co.uk¸¦ ÂüÁ¶ÇØÁֽñ⠹ٶø´Ï´Ù.

A.L. Digital Ltd.°¡ ÇÏ´ÂÀÏ¿¡ ´ëÇØ¼ ¾Ë°í ½ÍÀ¸½Ã¸é »ó´ÜÀÇ ·Î°í¸¦ Ŭ¸¯ÇØÁֽñ⠹ٶø´Ï´Ù. ±×¸®°í ¼öÇàÁßÀÎ cracking ÇÁ·ÎÁ§Æ®¿¡ ´ëÇØ¼ ¾Ë°í ½ÍÀ¸½Ã¸é »ó´ÜÀÇ ¹è³Ê¸¦ Ŭ¸¯ÇØÁÖ½Ã¸é µË´Ï´Ù. ¸¸¾à ¿ì¸®ÆÀ¿¡ ÇÕ·ùÇÏ°í ½ÍÀ¸½Ã´Ù¸é ÆÀ No. 5209·Î ȸ¿ø°¡ÀÔÀ» ÇØÁֽʽÿÀ. °³ÀÎÁ¤º¸ º¸È£¸¦ À§ÇØ ÆÀ ¸â¹ö ¸í´ÜÀº °ø°³µÇÁö ¾ÊÀ¸¸ç ±× Á¤º¸´Â Àý´ë ¹«´ÜÀ¸·Î »ç¿ëµÇÁö ¾Ê½À´Ï´Ù.
Copyright © 1995,6,7,8,9;2000,1 Ben Laurie, Adam Laurie.
Contact ben@algroup.co.uk for more information.