์ „์ฒด ๊ธ€ 177

X.509 CRL ํ”„๋กœํŒŒ์ผ

CRL(Certificate RevocationList) ๊ตฌ์กฐ CRL ํ”„๋กœํŒŒ์ผ * CRL Entry Extension Reason Code ์ธ์ฆ์„œ ํ์ง€ ๋ฐ ํšจ๋ ฅ์ •์ง€์˜ ์‚ฌ์œ  ์ •์˜ * CRL Extension Authority Key Identifier ๋ฐœ๊ธ‰์ž๊ฐ€ ๋ณต์ˆ˜์˜ ์ „์ž์„œ๋ช…ํ‚ค๋ฅผ ๊ฐ€์ง€๊ณ  ์žˆ์„ ๋•Œ, ๊ณต๊ฐœํ‚ค๋ฅผ ๊ตฌ๋ถ„ํ•˜๊ธฐ ์œ„ํ•œ ๋ชฉ์  ํ‚ค์‹๋ณ„์ž(์ผ๋ฐ˜์ ์œผ๋กœ ๋ฐœ๊ธ‰์ž ๊ณต๊ฐœํ‚ค ํ•ด์‰ฌ๊ฐ’), ๋ฐœ๊ธ‰์ž๋ช…, ๋ฐœ๊ธ‰์ž ์ธ์ฆ์„œ ์ผ๋ จ๋ฒˆํ˜ธ๋กœ ๊ตฌ์„ฑ CRL Number ์‚ฌ์šฉ์ž๋กœ ํ•˜์—ฌ๊ธˆ ํŠน์ • CRL์ด ๋‹ค๋ฅธ CRL์— ์šฐ์„ ํ•˜๋Š”์ง€ ๊ฒฐ์ •ํ•  ์ˆ˜ ์žˆ๋„๋ก ํ•จ ๋‹จ์กฐ์ฆ๊ฐ€ํ•˜๋Š” ์–‘์˜ ์ •์ˆ˜ Issuing Distribution Point ํ•ด๋‹น CRL์— ๋Œ€ํ•œ ๋ถ„๋ฐฐ์ ์„ ์‹๋ณ„ํ•˜๊ณ  ํŠน์ • CRL์— ๋Œ€ํ•œ ๋ฒ”์œ„๋ฅผ ์ง€์ •ํ•จ CRL ASN.1 Syntax * RFC 3280 ์—์„œ CRL..

PKI/X509 Profile 2022.11.21

X.509 ์ธ์ฆ์„œ ํ”„๋กœํŒŒ์ผ

X509 ์ธ์ฆ์„œ ๊ตฌ์กฐ X509 ์ธ์ฆ์„œ ํ”„๋กœํŒŒ์ผ Authority Key Identifier ๋ฐœ๊ธ‰์ž๊ฐ€ ๋ณต์ˆ˜์˜ ์ „์ž์„œ๋ช…ํ‚ค๋ฅผ ๊ฐ€์ง€๊ณ  ์žˆ์„ ๋•Œ, ๊ณต๊ฐœํ‚ค๋ฅผ ๊ตฌ๋ถ„ํ•˜๊ธฐ ์œ„ํ•œ ๋ชฉ์  ํ‚ค์‹๋ณ„์ž(์ผ๋ฐ˜์ ์œผ๋กœ ๋ฐœ๊ธ‰์ž ๊ณต๊ฐœํ‚ค ํ•ด์‰ฌ๊ฐ’), ๋ฐœ๊ธ‰์ž๋ช…, ๋ฐœ๊ธ‰์ž ์ธ์ฆ์„œ ์ผ๋ จ๋ฒˆํ˜ธ๋กœ ๊ตฌ์„ฑ Subject Key Identifier ํŠน์ • ๊ณต๊ฐœํ‚ค๋ฅผ ํฌํ•จํ•˜๋Š” ์ธ์ฆ์„œ๋ฅผ ๊ตฌ๋ถ„ํ•˜๊ธฐ ์œ„ํ•œ ๋ชฉ์  CA ์ธ์ฆ์„œ์ธ ๊ฒฝ์šฐ, ํ•ด๋‹น ์†Œ์œ ์ž์— ์˜ํ•ด ๋ฐœ๊ธ‰๋˜๋Š” ์ธ์ฆ์„œ์˜ AKI ํ™•์žฅํ•„๋“œ์˜ ํ‚ค์‹๋ณ„์ž๊ฐ’๊ณผ ๋™์ผ ํ‚ค์‹๋ณ„์ž(์ผ๋ฐ˜์ ์œผ๋กœ ์†Œ์œ ์ž ๊ณต๊ฐœํ‚ค ํ•ด์‰ฌ๊ฐ’)๋กœ ๊ตฌ์„ฑ Key Usage ์ธ์ฆ์„œ์™€ ์—ฐ๊ด€๋œ ๊ณต๊ฐœํ‚ค์Œ์˜ ์‚ฌ์šฉ๋ชฉ์ ์„ ์ •์˜ํ•จ ์ผ๋ฐ˜์ ์œผ๋กœ ๊ณต๊ฐœํ‚ค์Œ์˜ ์‚ฌ์šฉ ์šฉ๋„๋ฅผ ์ œํ•œํ•˜๊ธฐ ์œ„ํ•œ ๋ชฉ์  ์ „์ž์„œ๋ช…, ๋ถ€์ธ๋ด‰์‡„, ํ‚ค์ „์†ก, ๋ฐ์ดํ„ฐ์•”ํ˜ธํ™”, ํ‚ค๊ณต์œ , ์ธ์ฆ์„œ์„œ๋ช…, CRL์„œ๋ช…, ํ‚ค๊ณต์œ ์‹œ ์•”ํ˜ธํ™” ์ˆ˜ํ–‰, ํ‚ค๊ณต..

PKI/X509 Profile 2022.11.21

PKCS ๋ฌธ์„œ ๋ฒˆํ˜ธ ์ •์˜

PKI ๊ด€๋ จ ๊ธฐ์ˆ  ์ผ์„ ํ•˜๋‹ค ๋ณด๋ฉด PKIX ๋ผ๋Š” ํ‘œ์ค€๋“ค์ด ์žˆ๋‹ค. ์ด ๋ฌธ์„œ์— ๋Œ€ํ•œ ๊ฐ„๋žตํ•œ ์„ค๋ช…์ด๋‹ค. PKCS #1: RSA Cryptography Standard RSA ํ‚ค, ์•”/๋ณตํ˜ธํ™” ASN.1 ์— ๋Œ€ํ•œ ํ‘œ์ค€ PKCS #2: PKCS#1 ์— ํฌํ•จ ๋จ PKCS #3: Diffie-Hellman Key Agreement Standard DH ์•Œ๊ณ ๋ฆฌ์ฆ˜์— ๋Œ€ํ•œ ํ‘œ์ค€ ๋ฌธ์„œ PKCS #4: PKCS#1 ์— ํฌํ•จ ๋จ PKCS #5: Password-Based Cryptography Standard KDF ๋ฐ ๊ฐœ์ธํ‚ค ์•”ํ˜ธ์— ๋Œ€ํ•œ ์ •๋ณด PKCS #6: Extended-Certificate Syntax Standard PKCS #7: Cryptographic Message Syntax Standard CMS ๋ฉ”์„ธ์ง€ ์ฒ˜๋ฆฌ์—..

Distinguished Encoding Rules

BER๊ณผ ๋น„์Šทํ•˜๋‚˜ BER์— ๋ช‡ ๊ฐ€์ง€ ์ œ์•ฝ์‚ฌํ•ญ์„ ๊ฐ€์ง DER ์ œ์•ฝ์‚ฌํ•ญ Length Octets · ์ตœ์†Œ์˜ octets ์ˆ˜ ์•ˆ์—์„œ definite form length๋ฅผ ์‚ฌ์šฉ BIT STRING, OCTET STRING · Constructed form์„ ์‚ฌ์šฉํ•˜์ง€ ์•Š์Œ BOOLEAN value · TRUE์ด๋ฉด ๋ชจ๋“  8bits ๊ฐ’์€ 1 (0xFF) BIT STRING · ๋งˆ์ง€๋ง‰ octet์˜ ์‚ฌ์šฉ๋˜์ง€ ์•Š๋Š” bit๋Š” ‘0’์œผ๋กœ ์„ค์ • · tailing 0 bits๋Š” ์ธ์ฝ”๋”ฉ ํ•˜์ง€ ์•Š์Œ · 1bit๋„ ๊ฐ’์œผ๋กœ ๊ฐ€์ง€์ง€ ์•Š์œผ๋ฉด, “03 01 00”์œผ๋กœ ์ธ์ฝ”๋”ฉ ํ•จ Time · ์˜๋ฏธ์—†์ด ๋”ฐ๋ผ์˜ค๋Š” 0์€ ์ธ์ฝ”๋”ฉ ํ•˜์ง€ ์•Š์Œ · UTCTime์ผ ๊ฒฝ์šฐ, ์†Œ์ˆ˜์  ์ดํ•˜๊ฐ€ ์—†์œผ๋ฉด ‘.’ ์‚ฌ์šฉํ•˜์ง€ ์•Š์Œ · GeneralizedTime์ผ ๊ฒฝ์šฐ,..

PKI/ASN.1 2022.11.07

ASN.1 ์ฐธ๊ณ  ์‚ฌ์ดํŠธ

ASN.1 ์ •๋ณด ์‚ฌ์ดํŠธ https://obj-sys.com/asn1tutorial/asn1only.html https://www.oss.com/asn1/resources/asn1-made-simple/introduction.html ASN.1 Analyzer https://asn1.io/analyzer/ BER / DER ์ฐธ๊ณ  ๊ธฐ์ˆ  http://luca.ntop.org/Teaching/Appunti/asn1.html BER / DER viewer https://jykim74.tistory.com/36 Book (PDF) https://www.oss.com/asn1/resources/books-whitepapers-pubs/dubuisson-asn1-book.PDF https://www.oss.com/as..

PKI/ASN.1 2022.11.03

ASN.1 Value Notation (2/2)

* Tagged Type - tagged type์€ value notation์„ ๊ฐ€์งˆ ์ˆ˜ ์—†์Œ ( ์ง์  ๊ฐ’๋งŒ ์ง€์ •ํ•˜๊ณ  ๊ฐ’๋‚ด์— value notation์„ ๋ชป์“ด๋‹ค ์ธ๊ฐ€? ) - tag๋Š” value notation์—๋Š” ๋‚˜ํƒ€๋‚˜์ง€ ์•Š์Œ Present ::= [21] BOOLEAN status Present ::= TRUE IDNumber ::= [PRIVATE 1] IMPLICIT INTEGER unassigned IDNumber ::= 9999 Color ::= [13] BIT STRING {red(0), blue(1), yellow(2)} defaultColor Color ::= {red, yellow} * SEQUENCE / SEQUENCE OF - ์ˆœ์„œ ์žˆ๋Š” ๊ฐ’๋“ค์˜ ๋‚˜์—ด / ๋™์ผํ•œ type์˜ ์ˆœ์„œ ์žˆ๋Š” ..

PKI/ASN.1 2022.11.03