๋Œ€์นญํ‚ค

    OpenSSL์„ ์ด์šฉํ•œ ๋Œ€์นญํ‚ค ์•”ํ˜ธํ™”

    1. ๋Œ€์นญํ‚ค ์ƒ์„ฑ - DES ์•Œ๊ณ ๋ฆฌ์ฆ˜ ์‚ฌ์šฉ openssl genrsa -des3 -out privatekey.pem 2. ์•”ํ˜ธํ™” - ๋น„๊ณต๊ฐœํ‚ค ์‚ฌ์šฉ openssl rsautl -encrypt -inkey privatekey.pem -in plaintext.txt -out ciphertext.txt 3. ๋ณตํ˜ธํ™” - ๋น„๊ณต๊ฐœํ‚ค ์‚ฌ์šฉ openssl rsautl -decrypt -inkey privatekey.pem -in ciphertext.txt -out plaintext_out.txt

    HTTP and TLS(SSL)

    1. HTTP vs HTTPS - HTTP(Hypertext Transfer Protocol) : ์ „์†ก์ค‘ ์•”ํ˜ธํ™” X, 80 Port - HTTPS(HTTP Secure) : ์ „์†ก์ค‘ ์•”ํ˜ธํ™” O, 443 Port - ํ•ด์ปค๊ฐ€ HTTP ํŒจํ‚ท์„ ๊ฐˆ์ทจํ•˜๊ฒŒ ๋  ๊ฒฝ์šฐ ํ‰๋ฌธ์˜ ์ •๋ณด๋“ค์ด ๋ณด์ด์ง€๋งŒ HTTPS ํŒจํ‚ท์€ ์•”ํ˜ธํ™”๋˜์–ด์„œ ๋ณด์ด๊ธฐ ๋•Œ๋ฌธ์— ๋ณด์•ˆ ํ–ฅ์ƒ(๋กœ๊ทธ์ธ ํŽ˜์ด์ง€๊ฐ€ ๋งŒ์•ฝ HTTP๋ผ๋ฉด์€ ๋‚˜์˜ ๋กœ๊ทธ์ธ ์ •๋ณด๊ฐ€ ๋‹ค ๋ณด์ด๊ฒŒ ๋œ๋‹ค๋Š”...?! ํ˜„์žฌ๋Š” ์ค‘์š” ํŽ˜์ด์ง€ ์˜ˆ๋ฅผ ๋“ค์–ด ๋กœ๊ทธ์ธ, ๊ฒฐ์ œ ๊ด€๋ จ ํŽ˜์ด์ง€๋Š” ๋ฌด์กฐ๊ฑด HTTPS๋ฅผ ์‚ฌ์šฉ) Handshake ๋Œ€๋ถ€๋ถ„์˜ ๋ฉ”์„ธ์ง€๋ฅผ ์ฃผ๊ณ  ๋ฐ›๋Š” ์—ญํ• ์„ ํ•˜๋ฉฐ ์•”ํ˜ธํ™” ์•Œ๊ณ ๋ฆฌ์ฆ˜ ๊ฒฐ์ •, ํ‚ค ์ „๋‹ฌ, ์ธ์ฆ ๋ฉ”์„ธ์ง€ ์ „๋‹ฌ์„ ๋‹ด๋‹น Change Cipher Spec SSL ์•”ํ˜ธํ™” ํ†ต์‹  ์‹œ ์‚ฌ์šฉํ•  ์•”ํ˜ธํ™” ์•Œ๊ณ ๋ฆฌ์ฆ˜ ์„ค์ • ๊ทœ์•ฝ์ด..