PKI/X509 Profile

[X509] ๋ฐœ๊ธ‰์ž ์ •๋ณด ์ ‘๊ทผ (Authority Information Access)

JayKim๐Ÿ™‚ 2023. 9. 5. 13:24

๋ฐœ๊ธ‰์ž ์ •๋ณด ์ ‘๊ทผ ( Authority Information Access) ์€ X509 Version3 ์—์„œ ์ •์˜ ๋œ ํ™•์žฅ ํ•„๋“œ์ด๋‹ค.
์ด ํ™•์žฅ ํ•„๋“œ๋Š” ์ธ์ฆ์„œ๋ฅผ ๋ฐœ๊ธ‰ํ•œ ์ธ์ฆ๊ธฐ๊ด€์— ๋Œ€ํ•œ ์ •๋ณด๋ฅผ ๋ณด์—ฌ์ค€๋‹ค.
์ฆ‰ ์ธ์ฆ์„œ๋ฅผ ๋ฐœ๊ธ‰ํ•œ ์ธ์ฆ๊ธฐ๊ด€ ์œ„์น˜์™€ ์ธ์ฆ์„œ์˜ ์ƒํƒœ๋ฅผ ์•Œ ์ˆ˜ ์žˆ๋Š” OCSP ์ •๋ณด๋ฅผ ๋‚˜ํƒ€๋‚ธ๋‹ค.

์•„๋ž˜ ๊ทธ๋ฆผ์ด ๋ฐœ๊ธ‰์ž ์ •๋ณด ์ ‘๊ทผ์˜ ์˜ˆ์ œ ํ™”๋ฉด์ด๋‹ค.

๋ฐœ๊ธ‰์ž ์ •๋ณด ์ ‘๊ทผ ( Authority Inforamtion Access )

์˜ˆ์ œ ๊ทธ๋ฆผ์—์„œ ๋ณด๋ฉด OCSP URI ์™€ CA Issuers ์˜ URI ์ •๋ณด๋ฅผ ๋ณผ ์ˆ˜ ์žˆ๋‹ค.

๋ฐœ๊ธ‰์ž ์ •๋ณด ์ ‘๊ทผ ASN.1

   id-pe-authorityInfoAccess OBJECT IDENTIFIER ::= { id-pe 1 }

   AuthorityInfoAccessSyntax  ::=
           SEQUENCE SIZE (1..MAX) OF AccessDescription

   AccessDescription  ::=  SEQUENCE {
           accessMethod          OBJECT IDENTIFIER,
           accessLocation        GeneralName  }

   id-ad OBJECT IDENTIFIER ::= { id-pkix 48 }

   id-ad-caIssuers OBJECT IDENTIFIER ::= { id-ad 2 }

   id-ad-ocsp OBJECT IDENTIFIER ::= { id-ad 1 }

ASN.1 ์ •๋ณด๋ฅผ ๋ณด๋ฉด id-ad-caIssuers ๋Š” ๋ฐœ๊ธ‰์ž ์ธ์ฆ์„œ์˜ ์œ„์น˜ ์ •๋ณด๋ฅผ ์œ„ํ•œ ๊ฒƒ์ด๊ณ 
id-ad-ocsp ์ •๋ณด๋Š” OCSP ์ •๋ณด๋ฅผ ํ‘œ์‹œํ•˜๋Š” ํ•„๋“œ์ด๋‹ค.

๋ฐœ๊ธ‰์ž ์ •๋ณด ์ ‘๊ทผ ํŠน์„ฑ

CA ์ธ์ฆ์„œ์˜ ์ •๋ณด๋ฅผ ๋‚˜ํƒ€๋‚ด์ง€๋งŒ ์ธ์ฆ๊ธฐ๊ด€์ด ๋ฐœํ–‰ํ•˜๋Š” ๋˜ํ•˜๋‚˜์ธ CRL ์˜ ์œ„์น˜ ์ •๋ณด๋Š” ์—†๋‹ค.
CRL ์œ„์น˜์˜ ๊ฒฝ์šฐ๋Š” cRLDistributionPoints ๋ผ๋Š” ๋ณ„๋„์˜ ํ™•์žฅ ํ•„๋“œ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ํ‘œ์‹œ ํ•œ๋‹ค.
ํ•ด๋‹น ์ธ์ฆ์„œ์˜ ์œ„์น˜ ์ •๋ณด๋Š” HTTP, FTP ๋ฐ LDAP ํ”„๋กœํ† ์ฝœ์„ ์‚ฌ์šฉํ•˜์—ฌ ๋‚˜ํƒ€๋‚ธ๋‹ค.

๋งŒ์•ฝ HTTP ํ”„๋กœํ† ์ฝœ์„ ์‚ฌ์šฉํ•˜๊ฒŒ ๋˜๋ฉด Http ํ—ค๋” ์ •๋ณด์— application/pkix-cert ๋ฅผ ํฌํ•จํ•˜์—ฌ
DER ์ธ์ฝ”๋”ฉ ํ˜•์‹์˜ ๋ฐ์ดํƒ€๋ฅผ ์ „๋‹ฌ ํ•œ๋‹ค.

๊ทธ๋ฆฌ๊ณ  OCSP ์ •๋ณด๋Š” RFC2560 ์— ๋”ฐ๋ฅธ OCSP ์‘๋‹ต ๋ฉ”์„ธ์ง€๋ฅผ ๋ฐ›์•„ ์˜ฌ ์ˆ˜ ์žˆ๋‹ค.

๋งˆ๋ฌด๋ฆฌ

๋ฐœ๊ธ‰์ž ์ •๋ณด ์ ‘๊ทผ ์ •๋ณด๋กœ ๋ถ€ํ„ฐ ์ธ์ฆ์„œ ๋ฐœ๊ธ‰์ž์˜ ์ธ์ฆ์„œ ์œ„์น˜๋ฅผ ์•Œ ์ˆ˜ ์žˆ๊ณ 
๋˜ํ•œ ์ธ์ฆ์„œ ์ƒํƒœ๋ฅผ ์‹ค์‹œ๊ฐ„์œผ๋กœ ์•Œ ์ˆ˜ ์žˆ๋Š” OCSP ์ ‘๊ทผ ์ฃผ์†Œ๋ฅผ ์–ป์–ด ์˜ฌ ์ˆ˜ ์žˆ๋Š” ๊ฒƒ์ด๋‹ค.