SSL ์ธ์ฆ์„œ

    ์ธ์ฆ์„œ์™€ ์ „์ž ์„œ๋ช…(๋””์ง€ํ„ธ ์„œ๋ช…) ๐Ÿ”’ ๐Ÿ”‘

    1. ์ธ์ฆ์„œ ์ „๋‹ฌ ๊ณผ์ • โ‘  ์ „์ž ์„œ๋ช…๋œ ์ธ์ฆ์„œ(์ธ์ฆ์„œ ์ •๋ณด๋ฅผ Hash ์•Œ๊ณ ๋ฆฌ์ฆ˜์œผ๋กœ ์•”ํ˜ธํ™” ํ›„ CA ๋น„๊ณต๊ฐœํ‚ค๋กœ ์•”ํ˜ธํ™”ํ•œ Signature๋ฅผ ํฌํ•จ)ํ•˜์—ฌ Server -> Client๋กœ ๋ณด๋‚ธ๋‹ค. โ‘ก Client๋Š” ์ „์ž ์„œ๋ช…๋œ ์ธ์ฆ์„œ๋ฅผ ๋ฐ›๊ณ  ๋ธŒ๋ผ์šฐ์ €์—์„œ ๋ณด๊ด€์ค‘์ธ CA List์˜ ๊ณต๊ฐœํ‚ค๋กœ ๋ณตํ˜ธํ™”ํ•˜์—ฌ ํ•ด๋‹น ์ธ์ฆ์„œ๊ฐ€ CA๋กœ๋ถ€ํ„ฐ ๋ฐ›์€ ์ธ์ฆ์„œ์ž„์„ ์‹ ๋ขฐํ•œ๋‹ค. โ‘ข Client๋Š” ์ „๋‹ฌ ๋ฐ›์€ ์ธ์ฆ์„œ๋ฅผ Hash ์•Œ๊ณ ๋ฆฌ์ฆ˜์œผ๋กœ ์•”ํ˜ธํ™”ํ•œ Signature๊ณผ Server๋กœ๋ถ€ํ„ฐ ์ „๋‹ฌ ๋ฐ›์€ Signature๋ฅผ ๋น„๊ตํ•˜์—ฌ ์ธ์ฆ์„œ์˜ ๋ฌด๊ฒฐ์„ฑ์„ ๊ฒ€์ฆํ•œ๋‹ค. 2. ์ธ์ฆ์„œ ํ™•์ธ - ์„œ๋ช… ์•Œ๊ณ ๋ฆฌ์ฆ˜(Signature) : SHA-256(RSA ์•”ํ˜ธํ™”) - ๊ณต๊ฐœํ‚ค ์•Œ๊ณ ๋ฆฌ์ฆ˜ : RSA ์•”ํ˜ธํ™” 3. ๋น„๋Œ€์นญํ‚ค ์•”ํ˜ธํ™” ๋น„๊ณต๊ฐœํ‚ค ์•”ํ˜ธํ™”๋ž€? - ๊ณต๊ฐœํ‚ค/๋น„๊ณต๊ฐœํ‚ค ๋‘๊ฐœ์˜ ..

    HTTP and TLS(SSL)

    1. HTTP vs HTTPS - HTTP(Hypertext Transfer Protocol) : ์ „์†ก์ค‘ ์•”ํ˜ธํ™” X, 80 Port - HTTPS(HTTP Secure) : ์ „์†ก์ค‘ ์•”ํ˜ธํ™” O, 443 Port - ํ•ด์ปค๊ฐ€ HTTP ํŒจํ‚ท์„ ๊ฐˆ์ทจํ•˜๊ฒŒ ๋  ๊ฒฝ์šฐ ํ‰๋ฌธ์˜ ์ •๋ณด๋“ค์ด ๋ณด์ด์ง€๋งŒ HTTPS ํŒจํ‚ท์€ ์•”ํ˜ธํ™”๋˜์–ด์„œ ๋ณด์ด๊ธฐ ๋•Œ๋ฌธ์— ๋ณด์•ˆ ํ–ฅ์ƒ(๋กœ๊ทธ์ธ ํŽ˜์ด์ง€๊ฐ€ ๋งŒ์•ฝ HTTP๋ผ๋ฉด์€ ๋‚˜์˜ ๋กœ๊ทธ์ธ ์ •๋ณด๊ฐ€ ๋‹ค ๋ณด์ด๊ฒŒ ๋œ๋‹ค๋Š”...?! ํ˜„์žฌ๋Š” ์ค‘์š” ํŽ˜์ด์ง€ ์˜ˆ๋ฅผ ๋“ค์–ด ๋กœ๊ทธ์ธ, ๊ฒฐ์ œ ๊ด€๋ จ ํŽ˜์ด์ง€๋Š” ๋ฌด์กฐ๊ฑด HTTPS๋ฅผ ์‚ฌ์šฉ) Handshake ๋Œ€๋ถ€๋ถ„์˜ ๋ฉ”์„ธ์ง€๋ฅผ ์ฃผ๊ณ  ๋ฐ›๋Š” ์—ญํ• ์„ ํ•˜๋ฉฐ ์•”ํ˜ธํ™” ์•Œ๊ณ ๋ฆฌ์ฆ˜ ๊ฒฐ์ •, ํ‚ค ์ „๋‹ฌ, ์ธ์ฆ ๋ฉ”์„ธ์ง€ ์ „๋‹ฌ์„ ๋‹ด๋‹น Change Cipher Spec SSL ์•”ํ˜ธํ™” ํ†ต์‹  ์‹œ ์‚ฌ์šฉํ•  ์•”ํ˜ธํ™” ์•Œ๊ณ ๋ฆฌ์ฆ˜ ์„ค์ • ๊ทœ์•ฝ์ด..