Manual/OpenSSL 23

[OpenSSL] ML-KEM ML-DSA SLH-DSA ํ‚ค ์‚ฌ์šฉ

ML-KEM encapsulation / decapsulationopenssl pkeyutl -encap -inkey mlkem768_pub.pem -secret secret.bit -out ciphertextopenssl pkeyutl -decap -inkey mlkem768_priv.pem -in ciphertext -secret decapsulated_secret.binML-DSA sign / verifyopenssl pkeyutl -sign -in test.txt -inkey mldsa65_priv.pem -out sigopenssl pkeyutl -verify -in test.txt -inkey mldsa65_pub.pem -pubin -sigfile sig์ฐธ๊ณ ๋กœ BerEditor ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ..

Manual/OpenSSL 2025.10.10

[OpenSSL] PQC ์•Œ๊ณ ๋ฆฌ์ฆ˜ ML-KEM ML-DSA SLH-DSA ํ‚ค ์Œ ์ƒ์„ฑ

ml-kem ํ‚ค ์Œ ์ƒ์„ฑ# ๊ฐœ์ธํ‚ค ์ƒ์„ฑopenssl genpkey -algorithm ML-KEM-768 -out mlkem768_priv.pem# ๊ณต๊ฐœํ‚ค ์ถ”์ถœopenssl pkey -in mlkem768_priv.pem -pubout -out mlkem768_pub.pem# ASN.1 ๋ฐ์ดํƒ€ ๋ณด๊ธฐopenssl asn1parse -in mlkem768_priv.pem -dumpml-dsa ํ‚ค ์Œ ์ƒ์„ฑ# ๊ฐœ์ธํ‚ค ์ƒ์„ฑopenssl genpkey -algorithm ML-DSA-65 -out mldsa65_priv.pem# ๊ณต๊ฐœํ‚ค ์ถ”์ถœopenssl pkey -in mldsa65_priv.pem -pubout -out mldsa65_pub.pemslh-dsa ํ‚ค ์Œ ์ƒ์„ฑ# ๊ฐœ์ธํ‚ค ์ƒ์„ฑopenssl genpkey..

Manual/OpenSSL 2025.10.10

[OpenSSL] ECDH ํ‚ค ์œ ๋„ (Derive Key) ๋ช…๋ น์–ด

OpenSSL ๋ช…๋ น์–ด๋ฅผ ์‚ฌ์šฉํ•ด ECDH ๊ณต์œ  ํ‚ค๋ฅผ ๋งŒ๋“ค์–ด ๋ณด์ž ECDH ๊ฐ’์„ ์ƒ์„ฑ ํ•˜๊ธฐ ์œ„ํ•ด์„œ๋Š” ๋‘ ์Œ์˜ ECDSA ์šฉ ํ‚ค ์Œ์ด ํ•„์š”ํ•˜๋‹ค. ํ‚ค ์Œ์˜ ์ด๋ฆ„์„ alice ์™€ bob ์ด๋ผ๋Š” ์ด๋ฆ„ ์œผ๋กœ ๋งŒ๋“ค์–ด ๋ณด์ž ๊ทธ๋Ÿผ ECDH ๊ณต์œ  ํ‚ค๋ฅผ ๋งŒ๋“ ๋Š”๊ฒƒ์€ alice ์˜ ๊ฐœ์ธํ‚ค์™€ Bob์˜ ๊ณต์œ ํ‚ค๋ฅผ ์ด์šฉํ•ด์„œ ๋งŒ๋“ค๊ณ  ๋˜ bob์˜ ๊ฐœ์ธํ‚ค์™€ alice ์˜ ๊ณต์œ ํ‚ค๋ฅผ ๊ฐ€์ง€๊ณ  ๋งŒ๋“ค๊ฒŒ ๋˜๋Š”๋ฐ ์ด๋•Œ ์„œ๋กœ ๋งŒ๋“  ๊ณต์œ ํ‚ค ๊ฐ’์ด ๊ฐ™์€ ๊ฐ’์ด ๋‚˜์˜ค๊ฒŒ ๋˜๋Š” ๊ฒƒ์ด๋‹ค. Alice ECDSA ์šฉ ํ‚ค ์Œ ๋งŒ๋“ค๊ธฐ // ECDSA ์šฉ alice์˜ ๊ฐœ์ธํ‚ค ๋งŒ๋“ค๊ธฐ openssl genpkey -out alice.pem -algorithm EC -pkeyopt ec_paramgen_curve:P-256 -pkeyopt ec_param_enc:named_curve..

Manual/OpenSSL 2024.04.03

[OpenSSL] DSA ํ‚ค ์Œ ๋งŒ๋“ค๊ธฐ

DSA ํ‚ค ์Œ์„ ๋งŒ๋“ค๊ธฐ๋ฅผ ํ•˜๋ ค๋ฉด ์šฐ์„  DSA ํŒŒ๋ผ๋ฏธํ„ฐ ์ƒ์„ฑ ํ›„ DSA ํ‚ค ์Œ์„ ๋งŒ๋“ค ์ˆ˜ ์žˆ๋‹ค. ๋จผ์ € DSA ํŒŒ๋ผ๋ฏธํ„ฐ๋ฅผ ์ƒ์„ฑ ํ•˜์ž openssl dsaparam -out dsaparam.pem 2048 ์ƒ์„ฑ ๋œ DSA ํŒŒ๋ผ๋ฏธํ„ฐ -----BEGIN DSA PARAMETERS----- MIICKQKCAQEAz3b/DxqaD6NWa0q23jg3SJ8B/IPycYm7YClyMEh7OIqUhr0cckxm +JosmcqD/S+vEHraQFCF05shdWVjDiY1eyxCo6S9NOgmkDsUTLHFI/5lw4Kf+cum dd4FkMljKmSDybymg1NOggwVMQjbJ4LYS+35nktjLwGIWxo06Jjzt20AYCWpRkJo JmLX1x2dtua1BFgdhhWinxlPNRNLVtLTcLtPgx16TuYP9N..

Manual/OpenSSL 2023.07.04

[OpenSSL] EdDSA ์•Œ๊ณ ๋ฆฌ์ฆ˜ Ed25519 Ed448 ํ‚ค ์ƒ์„ฑ

EdDSA ( Edwards-Curve Digital Signature Algorithm ) ์˜ ์•ฝ์ž๋กœ ECC ์ฒ˜๋Ÿผ ๋””์ง€ํ„ธ ์„œ๋ช…์šฉ ์•Œ๊ณ ๋ฆฌ์ฆ˜์ด๋‹ค. ECDSA์— ๋น„ํ•˜๋ฉด ์—ฐ์‚ฐ ์†๋„๊ฐ€ ECDSA ๋ณด๋‹ค๋Š” ์กฐ๊ธˆ ๋น ๋ฅธ ์•Œ๊ณ ๋ฆฌ์ฆ˜์ด๋‹ค. ํ˜„์žฌ EdDSA ์•Œ๊ณ ๋ฆฌ์ฆ˜์€ ECDSA ๋ณด๋‹ค๋Š” ๋„๋ฆฌ ์‚ฌ์šฉ๋˜์ง€๋Š” ์•Š์ง€๋งŒ ์ ์  ๋Š˜์–ด๋‚˜๊ณ  ์žˆ๋‹ค๊ณ  ํ•œ๋‹ค. EdDSA ์—์„œ ์ฃผ๋กœ ์‚ฌ์šฉํ•˜๋Š” Curve ๊ฐ€ Ed25519 ์™€ Ed448 ์ด๋‹ค. ๊ทธ๋Ÿผ OpenSSL ๋ช…๋ น์–ด๋กœ ed25519์™€ ed448 ํ‚ค ์Œ์„ ๋งŒ๋“ค์–ด ๋ณด์ž. ed25519 ๊ฐœ์ธํ‚ค ์ƒ์„ฑ openssl genpkey -algorithm ed25519 -out private.pem ed25519 ๊ฐœ์ธํ‚ค ๊ฒฐ๊ณผ -----BEGIN PRIVATE KEY----- MC4CAQAwBQYDK2VwBCIEIJ..

Manual/OpenSSL 2023.06.14

[OpenSSL] ca ๋ช…๋ น์–ด

์ด ๋ช…๋ น์–ด๋Š” CA ํ”„๋กœ๊ทธ๋žจ ๊ธฐ๋Šฅ์„ ํ•˜๋Š” ๋ช…๋ น์–ด์ด๋‹ค. https://www.openssl.org/docs/man3.0/man1/openssl-ca.html ์ •๋ณด๋ฅผ ์ฐธ๊ณ  ํ•จ CA ๊ธฐ๋Šฅ์„ ํ•˜๊ธฐ ์œ„ํ•ด์„œ๋Š” ์„ค์ • ํŒŒ์ผ์˜ ํ™˜๊ฒฝ์— ๋งž๋Š” ๋ฐ์ดํƒ€๊ฐ€ ์žˆ์–ด์•ผ ํ•œ๋‹ค. openssl.cnf ์„ค์ • #################################################################### [ ca ] default_ca = CA_default # The default ca section #################################################################### [ CA_default ] dir = ./demoCA # Where everything is ..

Manual/OpenSSL 2023.05.24

[OpenSSL] crl ๋ช…๋ น์–ด

์ด ๋ช…๋ น์–ด๋Š” CRL ํŒŒ์ผ์„ DER ๋˜๋Š” PEM ํ˜•์‹์„ ๋งŒ๋“ค๊ธฐ ์œ„ํ•œ ๋ช…๋ น์–ด ์ด๋‹ค https://www.openssl.org/docs/man3.0/man1/openssl-crl.html ์ฐธ์กฐ ํ•˜์˜€๋‹ค. PEM ํ˜•์‹์˜ CRL ํŒŒ์ผ์„ DER ๋กœ ๋ฐ”๊พธ๊ธฐ openssl crl -in crl.pem -outform DER -out crl.der CRL ํŒŒ์ผ ์ •๋ณด ๋ณด๊ธฐ openssl crl -in crl.der -text -noout CRL ํŒŒ์ผ ์ •๋ณด ๋ณด๊ธฐ ๊ฒฐ๊ณผ ertificate Revocation List (CRL): Version 2 (0x1) Signature Algorithm: sha256WithRSAEncryption Issuer: C = KR, ST = Korea, O = TEST, CN = CA Last ..

Manual/OpenSSL 2023.05.21

[OpenSSL] x509 ๋ช…๋ น์–ด

์ด๋ช…๋ น์–ด๋Š” ๋‹ค์–‘ํ•œ ๋ชฉ์ ์œผ๋กœ ์ธ์ฆ์„œ๋ฅผ ๋‹ค๋ฃจ๋Š” ๋ช…๋ น์–ด์ด๋‹ค. https://www.openssl.org/docs/man3.0/man1/openssl-x509.html ์ด ์„ค๋ช…์„œ๋ฅผ ์ฐธ์กฐ ํ•ด์„œ ๋งŒ๋“ค์—ˆ๋‹ค. PEM ํ˜•์‹์˜ ์ธ์ฆ์„œ ์ •๋ณด ๋ณด๊ธฐ ์ถœ๋ ฅ openssl x509 -text -noout -in test_cert.crtDER ํ˜•์‹์˜ ์ธ์ฆ์„œ ์ •๋ณด ๋ณด๊ธฐ ๊ฒฐ๊ณผ openssl x509 -inform der -noout -text -in test_cert.der๊ฒฐ๊ณผ ํ™”๋ฉด Certificate: Data: Version: 3 (0x2) Serial Number: 53:14:62:20:a1:a5:29:73 Signature Algorithm: ecdsa-with-SHA256 Issuer: C = KR, O = Ranix, OU..

Manual/OpenSSL 2023.05.20

[OpenSSL] pkeyutl ๋ช…๋ น์–ด

์ด ๋ช…๋ น์–ด๋Š” ๊ณต๊ฐœํ‚ค ์•Œ๊ณ ๋ฆฌ์ฆ˜ ์‹คํ–‰ ๋ช…๋ น์–ด์ด๋‹ค. ์ด ๋ฌธ์„œ๋Š” https://www.openssl.org/docs/man3.0/man1/openssl-pkeyutl.html ์ฐธ์กฐ ํ•˜์—ฌ ๋งŒ๋“ค์—ˆ๋‹ค. ๊ฐœ์ธํ‚ค๋ฅผ ์ด์šฉ ์ „์ž ์„œ๋ช… ์ƒ์„ฑ ์ด๋•Œ ์ž…๋ ฅ ๊ฐ’์€ ํ•ด์‰ฌ ๊ฐ’์ด์–ด์•ผ ํ•œ๋‹ค( ์›๋ฌธ ์•„๋‹˜ ) openssl pkeyutl -sign in data.txt -inkey rsa_key.pem -out sig์ƒ์„ฑ๋œ sig ๊ฐ’์€ ์ „์ž ์„œ๋ช… ๋ฐ”์ด๋„ˆ๋ฆฌ ๊ฐ’์ด๋‹ค. (ASN.1 ๋””์ฝ”๋”ฉ ์•ˆ๋จ ) ์„œ๋ช… ๋ฐ์ดํƒ€ ๊ฒ€์ฆ ์ž…๋ ฅ๋œ ์„œ๋ช… ๊ฒ€์ฆ openssl pkeyutl -verify -in data.txt -sigfile sig -inkey rsa_key.pem ๋ณต๊ตฌ ์„œ๋ช… ๊ฒ€์ฆ ์ด ๊ธฐ๋Šฅ์€ ์„œ๋ช… ๊ฒ€์ฆํ•˜๊ณ  ์„œ๋ช…์— ์‚ฌ์šฉ๋œ ํ•ด์‰ฌ ๊ฐ’์„ ๋ณต๊ตฌ ํ•ด์ฃผ๋Š” ๋ช…๋ น์–ด ์ด๋‹ค. o..

Manual/OpenSSL 2023.05.19