PKI/X509 Profile

[X509] CRL ๋ฐœ๊ธ‰ ๋ถ„๋ฐฐ ์ ( Issuing Distribution Point )

JayKim๐Ÿ™‚ 2023. 9. 19. 11:02

CRL ๋ฐœ๊ธ‰ ๋ถ„๋ฐฐ ์ ์€ ( Issuing Distribution Point ) ๋Š” CRL Version2 ์—์„œ ์ •์˜ ํ•œ ํ™•์žฅ ํ•„๋“œ์ด๋‹ค.
์ด ๋ฐœ๊ธ‰ ๋ถ„๋ฐฐ ์  ์ •๋ณด๋Š” CRL ํŒŒ์ผ์„ ์–ป์„ ์ˆ˜ ์žˆ๋Š” ์œ„์น˜ ์ •๋ณด๋ฅผ ๋‚˜ํƒ€๋‚ธ๋‹ค.
์ฆ‰ ํ•ด๋‹น CRL ์ด ์–ป์–ด ์˜ฌ ์ˆ˜ ์žˆ๋Š” ์œ„์น˜ ์ •๋ณด๋ฅผ ๋‚˜ํƒ€๋‚ธ๋‹ค.

์•„๋ž˜ ๊ทธ๋ฆผ์€ CRL ๋ฐœ๊ธ‰ ๋ถ„๋ฐฐ์ ์˜ ์˜ˆ์‹œ ํ™”๋ฉด์ด๋‹ค.

CRL ๋ฐœ๊ธ‰ ๋ถ„๋ฐฐ ์ 

์˜ˆ์‹œ ํ™”๋ฉด์€ CRL ํŒŒ์ผ์„ ์ƒ์„ธ ๋ณด๊ธฐํ•œ ํ™”๋ฉด์ด๊ตฌ ํ•ด๋‹น CRL ํŒŒ์ผ์€
URI=ldap://ldap.signgate.com:389/ou=dp7p27928,ou=crldp,ou=AccreditedCA,o=KICA,c=KR
์œ„์น˜์—์„œ ์–ป์„ ์ˆ˜ ์žˆ๋‹ค๋Š” ๊ฒƒ์ด๋‹ค.

CRL ๋ฐœ๊ธ‰ ๋ถ„๋ฐฐ ์  ASN.1

   id-ce-issuingDistributionPoint OBJECT IDENTIFIER ::= { id-ce 28 }

   IssuingDistributionPoint ::= SEQUENCE {
        distributionPoint          [0] DistributionPointName OPTIONAL,
        onlyContainsUserCerts      [1] BOOLEAN DEFAULT FALSE,
        onlyContainsCACerts        [2] BOOLEAN DEFAULT FALSE,
        onlySomeReasons            [3] ReasonFlags OPTIONAL,
        indirectCRL                [4] BOOLEAN DEFAULT FALSE,
        onlyContainsAttributeCerts [5] BOOLEAN DEFAULT FALSE }

CRL ๋ฐœ๊ธ‰ ๋ถ„๋ฐฐ์  ํŠน์„ฑ

  • CRL ์€ CRL ๋ฐœ๊ธ‰์ž์˜ ๊ฐœ์ธํ‚ค๋กœ ์„œ๋ช…์„ ํ•˜๋Š”๋ฐ CRL ๋ฐฐํฌ์ง€์ ์€ ํŠน๋ณ„ํžˆ ์ž์ฒด ํ‚ค ์Œ์ด ์กด์žฌ ํ•˜์ง€ ์•Š๋Š”๋‹ค.
  • onlySomeReason ์€ ํ๊ธฐ ์ด์œ ๋ฅผ ๋‚˜ํƒ€๋‚ด๋Š”๋ฐ ๋งŒ์•ฝ ์ด ํ•„๋“œ๊ฐ€ ์—†์œผ๋ฉด ๋ชจ๋“  ์ด์œ ๋ฅผ ์‚ฌ์šฉํ•œ๋‹ค.
    ๋งŒ์•ฝ ์ด ํ•„๋“œ๊ฐ€ ์กด์žฌํ•˜๋ฉด ํ•ด๋‹น ์ด์œ ๋งŒ์œผ๋กœ CRL ํ๊ธฐ ์‚ฌ์œ ๋ฅผ ์‚ฌ์šฉํ•œ๋‹ค.
  • CA๋Š” ํ๊ธฐ ์‚ฌ์œ ์— ๋”ฐ๋ฅธ CRL ์„ ๋ถ„ํ•  ํ•  ์ˆ˜ ์žˆ๋‹ค.
    ์ฆ‰ ๋‹ค๋ฅธ ์‚ฌ์œ ๋Š” ๋‹ค๋ฅธ IssuingDistributionPoint๋ฅผ ์‚ฌ์šฉํ•˜๊ธฐ๋„ ํ•œ๋‹ค.
  • ์ด ํ•„๋“œ๋Š” ์‚ฌ์‹ค ์ธ์ฆ์„œ์˜ CRLDP ํ•„๋“œ์™€ ๋™์ผํ•œ ํ˜•์‹๊ณผ ์˜๋ฏธ์ด๋‹ค.
  • ๋งŒ์•ฝ์— CRL ์—์„œ CRL ๋ฐœ๊ธ‰ ๋ถ„๋ฐฐ์ ์ด ์—†๋Š” ๊ฒฝ์šฐ๋Š” ํ•ด๋‹น CRL์€ ํ๊ธฐ๋œ ๋ชจ๋“  ์ธ์ฆ์„œ๋ฅผ ๊ฐ€์ ธ์•ผ ํ•œ๋‹ค.
  • CRL ๋ฒ”์œ„์—์„œ CRL ๋ฐœ๊ธ‰์ž์˜ ์ธ์ฆ์„œ๋งŒ ๋Œ€์ƒ์ด๋ฉด indirectCRL ์€ FALSE ๋กœ ํ•ด์•ผ ํ•˜๊ณ 
    ๋งŒ์•ฝ CRL ๋ฐœ๊ธ‰์ž ์ด์™ธ์˜ ํ•˜๋‚˜ ์ด์ƒ์˜ ๊ธฐ๊ด€์—์„œ ๋ฐœ๊ธ‰ํ•œ ์ธ์ฆ์„œ๋ฅผ ํฌํ•จํ•˜๋ฉด indirectCRL ์€ TRUE ๋กœ ์„ค์ • ํ•œ๋‹ค.
  • CRL ์ด ์ตœ์ข… ์—”ํ„ฐํ‹ฐ ๊ณต๊ฐœํ‚ค๋งŒ ํ‘œํ˜„ํ•˜๋Š” ๊ฒฝ์šฐ๋Š” onlyContaintsUserCerts ๊ฐ€ TRUE ๋กœ ์„ค์ •
    CA ์ธ์ฆ์„œ๋งŒ ํฌํ•จํ•˜๋Š” ๊ฒฝ์šฐ๋Š” onlyContainsCACerts ๊ฐ€ TRUE ๋กœ ์„ค์ •
  • onlyContainsUserCert, onlyContainsCACerts, indirectCRL ๊ณผ onlyContainsAttributeCerts ๋ชจ๋‘๊ฐ€ FALSE ๋ผ๋ฉด
    distributionPoint ํ•„๋“œ ๋˜๋Š” onlySomeReasons ํ•„๋“œ๊ฐ€ ํ•˜๋‚˜๋Š” ์žˆ์–ด์•ผ ํ•œ๋‹ค.

๋งˆ๋ฌด๋ฆฌ

์ธ์ฆ์„œ์˜ ์ƒํƒœ ํ™•์ธ์„ ํ•˜๊ธฐ ์œ„ํ•ด CRL ์„ ์ฒดํฌ ํ•˜๊ณ 
๊ทธ๋ฆฌ๊ณ  ํ•ด๋‹น CRL ์˜ ์œ„์น˜๋ฅผ ํ™•์ธ ํ•˜๊ธฐ ์œ„ํ•ด์„œ CRL ๋ฐœ๊ธ‰ ๋ถ„๋ฐฐ์  ์ •๋ณด๋ฅผ ์ด์šฉํ•œ๋‹ค.
์‚ฌ์‹ค CRL ์„œ๋ช… ์ •๋ณด๋งŒ ๋งž์œผ๋ฉด ๋˜๊ณ  ์ผ๋ฐ˜์ ์œผ๋กœ ์ธ์ฆ์„œ์˜ CRL ์œ„์น˜๋Š” ์ธ์ฆ์„œ CRLDP ์ •๋ณด๋ฅผ ์ฃผ๋กœ ์ฐธ์กฐํ•˜๋ฉด ๋œ๋‹ค.