PKI/X509 Profile

[X509] ํ๊ธฐ๋œ ์ธ์ฆ์„œ (Revoked Certificates ) ์™€ CRL ์—”ํŠธ๋ฆฌ ํ™•์žฅ ํ•„๋“œ (CRL Entry Extensions)

JayKim๐Ÿ™‚ 2023. 9. 20. 09:07

์ธ์ฆ์„œ๋ฅผ ์‚ฌ์šฉ ํ•˜๋‹ค ๋ณด๋ฉด ์ธ์ฆ์„œ๊ฐ€ ๋งŒ๋ฃŒ ๋˜์ง€ ์ „์— ํ๊ธฐ๋ฅผ ํ•ด์•ผ ํ•˜๋Š” ๊ฒฝ์šฐ๊ฐ€ ์žˆ๋‹ค.
์ธ์ฆ์„œ ์‚ฌ์šฉ์ž๋Š” ์‚ฌ์šฉ ์ธ์ฆ์„œ๋ฅผ CA์—๊ฒŒ ์š”์ฒญ์„ ํ•˜๊ณ  CA๋Š” ์ธ์ฆ์„œ๋ฅผ ํ๊ธฐ ํ›„ CRL์— ๊ฒŒ์‹œ๋ฅผ ํ•œ๋‹ค.

CRL ํŒŒ์ผ์—๋Š” ํ๊ธฐ๋œ ์ธ์ฆ์„œ ์ •๋ณด(Revoked Certificates ) ๊ฐ€ ๋“ค์–ด ์žˆ๋Š”๋ฐ
์ด ์ •๋ณด๊ฐ€ ์ธ์ฆ์„œ์˜ ํ๊ธฐ ๋˜์—ˆ๋‹ค๋Š” ๊ฒƒ์„ ํ‘œ์‹œ ํ•˜๋Š” ์ •๋ณด์ด๋‹ค.
ํ๊ธฐ ์ •๋ณด์—๋Š” ๊ธฐ๋ณธ์ ์œผ๋กœ ์ธ์ฆ์„œ์˜ ์ผ๋ จ ๋ฒˆํ˜ธ์™€ ํ์ง€ ๋‚ ์งœ๊ฐ€ ์žˆ๋‹ค. ๊ทธ๋ฆฌ๊ณ  CRL ์—”ํŠธ๋ฆฌ ํ™•์žฅ ํ•„๋“œ๋ฅผ ์‚ฌ์šฉํ•ด ์ถ”๊ฐ€์ ์ธ ์ •๋ณด๊ฐ€ ์ œ๊ณต๋œ๋‹ค.

์ผ๋ จ ๋ฒˆํ˜ธ๋Š” ํ•ด๋‹น ์ธ์ฆ์„œ์˜ ์ผ๋ จ๋ฒˆํ˜ธ ๊ฐ’์ด๋‹ค.
ํ์ง€ ๋‚ ์งœ๋Š” ์ธ์ฆ์„œ๋ฅผ ํ๊ธฐํ•œ ์‹œ๊ฐ„ ๊ฐ’์ด๋‹ค.
๊ทธ๋ฆฌ๊ณ  CRL ์—”ํŠธ๋ฆฌ ํ™•์žฅ ํ•„๋“œ๋ฅผ ์‚ฌ์šฉํ•˜๋Š”๋ฐ ์ผ๋ฐ˜์ ์œผ๋กœ CRL ์—”ํŠธ๋ฆฌ ํ™•์žฅ ํ•„๋“œ์˜ Reason Code ๊ฐ’์„ ์‚ฌ์šฉํ•œ๋‹ค.

์•„๋ž˜ ๊ทธ๋ฆผ์ด ์˜ˆ์ œ ํ™”๋ฉด์ด๋‹ค.

Revoked Certificates

ํ๊ธฐ ์ธ์ฆ์„œ ASN.1

     revokedCertificates     SEQUENCE OF SEQUENCE  {
          userCertificate         CertificateSerialNumber,
          revocationDate          Time,
          crlEntryExtensions      Extensions OPTIONAL
                                   -- if present, version MUST be v2
                               }  OPTIONAL,
     crlExtensions           [0] Extensions OPTIONAL }
                                   -- if present, version MUST be v2

CRL ์—”ํŠธ๋ฆฌ ํ™•์žฅ ํ•„๋“œ๋ž€

์ด ํ˜•์‹์€ ๋ฐœ๊ธ‰๋œ ์ธ์ฆ์„œ์˜ ํšจ๋ ฅ์ •์ง€ ๋ฐ ํ๊ธฐ ์‚ฌ์œ  ๋ฐ ํ๊ธฐ ์‹œ๊ฐ„ ์ •๋ณด๋ฅผ ๋‚˜ํƒ€๋‚ธ๋‹ค.
CRL ์—”ํŠธ๋ฆฌ ํ™•์žฅ ํ•„๋“œ์— ๋‚˜ํƒ€๋‚˜๋Š” ์ •๋ณด๋Š” 3๊ฐ€์ง€์ด๋‹ค

  1. ํ๊ธฐ ์‚ฌ์œ  ( Reason Code )
  2. ํ๊ธฐ ์‹œ๊ฐ„ ( Invalidity Date )
  3. ์ธ์ฆ์„œ ๋ฐœ๊ธ‰์ž ( Certificate Issuer )

์ด๋ ‡๊ฒŒ 3๊ฐ€์ง€ ์ด๋‹ค.

ํ๊ธฐ ์‚ฌ์œ  (Reason Code)

   id-ce-cRLReasons OBJECT IDENTIFIER ::= { id-ce 21 }

   -- reasonCode ::= { CRLReason }

   CRLReason ::= ENUMERATED {
        unspecified             (0),
        keyCompromise           (1),
        cACompromise            (2),
        affiliationChanged      (3),
        superseded              (4),
        cessationOfOperation    (5),
        certificateHold         (6),
             -- value 7 is not used
        removeFromCRL           (8),
        privilegeWithdrawn      (9),
        aACompromise           (10) }
  • unspecified : ํŠน๋ณ„ํ•œ ํ์ง€ ์‚ฌ์œ ๊ฐ€ ์—†๋Š” ๊ฒฝ์šฐ
  • keyCompromise : ์ธ์ฆ์„œ ์†Œ์œ ์ž์˜ ํ‚ค๊ฐ€ ์†์ƒ๋œ ๊ฒฝ์šฐ ์‚ฌ์šฉ
  • cACompromise : ์ธ์ฆ์„œ ๋ฐœ๊ธ‰์ž์˜ ํ‚ค๊ฐ€ ์†์ƒ๋œ ๊ฒฝ์šฐ ์‚ฌ์šฉ
  • affiliationChanged : ์†Œ์œ ์ž์˜ ๋ช…์นญ ๋˜๋Š” ๊ธฐํƒ€ ์ •๋ณด๊ฐ€ ๋ณ€๊ฒฝ ๋œ ๊ฒฝ์šฐ ์‚ฌ์šฉ
  • superseded : ํ‚ค ์†์ƒ ์—†์ด ์ธ์ฆ์„œ๋ฅผ ํ์ง€ ํ•˜๊ณ ์ž ํ•˜๋Š” ๊ฒฝ์šฐ ์‚ฌ์šฉ, ์ธ์ฆ์„œ ๊ฐฑ์‹  ์ฒ˜๋Ÿผ ์ด์ „ ์ธ์ฆ์„œ ํ๊ธฐ ๋•Œ ์‚ฌ์šฉ
  • cessationOfOperation : ๋” ์ด์ƒ ์ง€์ •๋œ ๋ชฉ์ ์œผ๋กœ ์ธ์ฆ์„œ๋ฅผ ์‚ฌ์šฉํ•˜์ง€ ์•Š๋Š” ๊ฒฝ์šฐ ์‚ฌ์šฉ
  • certificateHold : ์ธ์ฆ์„œ ํšจ๋ ฅ ์ •์ง€์— ์‚ฌ์šฉ
  • removeFromCRL : ๋ธํƒ€ ์ธ์ฆ์„œ ํšจ๋ ฅ ์ •์ง€ ๋ฐ ํ์ง€ ๋ชฉ๋ก๊ณผ ํ•จ๊ป˜ ์‚ฌ์šฉ

ํ์ง€ ์ผ์ž (Invalidity Date )

ํšจ๋ ฅ ์ •์ง€ ๋ฐ ํ์ง€ ์‚ฌ์œ ๊ฐ€ ๋ฐœ์ƒํ•œ ์‹œ์ ์— ๋Œ€ํ•œ ์ •๋ณด๋ฅผ ๋‚˜ํƒ€๋‚ธ๋‹ค.
์‹œ๊ฐ ์ •๋ณด๋Š” GMT๋กœ ํ‘œํ˜„ํ•˜๋ฉฐ 2049๋…„๊นŒ์ง€๋Š” UTCTime ํ˜•์‹์„ ์‚ฌ์šฉํ•˜๊ณ  2050๋…„์€ GeneralizedTime ํ˜•์‹์„ ์‚ฌ์šฉํ•œ๋‹ค.

์ธ์ฆ์„œ ๋ฐœ๊ธ‰์ž ( Certificate Issuer )

์ด ํ•„๋“œ๋Š” ๊ฐ„์ ‘ CRL๊ณผ ๊ด€๋ จํ•˜์—ฌ CRL ๋‚ด์— ํšจ๋ ฅ ์ •์ง€ ๋ฐ ํ์ง€๋œ ์ธ์ฆ์„œ์˜ ๋ฐœ๊ธ‰๊ธฐ๊ด€์— ๋Œ€ํ•œ ๋ช…์นญ์„ ๋‚˜ํƒ€๋‚ธ๋‹ค.
๊ฐ„์ ‘ CRL์˜ ์ฒซ๋ฒˆ์งธ๊ฐ€ ์ด ํ™•์žฅ ํ•„๋“œ๋ฅผ ์‚ฌ์šฉํ•˜์ง€ ์•Š์•˜๋‹ค๋ฉด ์ธ์ฆ์„œ์˜ ๋ฐœ๊ธ‰์ž๊ฐ€ CRL ๋ฐœ๊ธ‰์ž์™€ ๋™์ผํ•˜๋‹ค๋Š” ์˜๋ฏธ์ด๋‹ค.
์ฒซ๋ฒˆ์งธ ์—”ํŠธ๋ฆฌ ์ดํ›„ ํ›„์† ์—”ํŠธ๋ฆฌ๊ฐ€ ์—†๋‹ค๋ฉด ์ง์ „ ์—”ํŠธ๋ฆฌ์˜ ์ธ์ฆ์„œ ๋ฐœ๊ธ‰์ž์™€ ๋™์ผ ํ•˜๋‹ค๊ณ  ๊ฐ„์ฃผ ํ•œ๋‹ค.

๋งˆ๋ฌด๋ฆฌ

CRL์„ ์‚ฌ์šฉํ•˜์—ฌ ํ•ด๋‹น ์ธ์ฆ์„œ์˜ ์‹ค์ œ ๋ชฉ๋ก ๊ฐ’์„ ํ‘œ์‹œํ•œ ์˜์—ญ์ด๋‹ค.
๋ณดํ†ต ์ธ์ฆ์„œ ๊ฒ€์ฆ์‹œ ํ๊ธฐ ์œ ๋ฌด๋ฅผ ํ™•์ธํ•˜๊ฒŒ ๋˜์–ด์„œ ์ด ์‚ฌ์šฉํ•˜๋Š” ์ธ์ฆ์„œ์˜ ์‹œ๋ฆฌ์–ผ ๋ฒˆํ˜ธ๊ฐ€ ์กด์žฌ ์œ ๋ฌด๋ฅผ ํ™•์ธ ํ•˜๊ธฐ ์œ„ํ•˜์—ฌ ์‚ฌ์šฉํ•˜๋Š” ๊ฒƒ์ด๋‹ค.