Manual 54

[OpenSSL] crl ๋ช…๋ น์–ด

์ด ๋ช…๋ น์–ด๋Š” CRL ํŒŒ์ผ์„ DER ๋˜๋Š” PEM ํ˜•์‹์„ ๋งŒ๋“ค๊ธฐ ์œ„ํ•œ ๋ช…๋ น์–ด ์ด๋‹ค https://www.openssl.org/docs/man3.0/man1/openssl-crl.html ์ฐธ์กฐ ํ•˜์˜€๋‹ค. PEM ํ˜•์‹์˜ CRL ํŒŒ์ผ์„ DER ๋กœ ๋ฐ”๊พธ๊ธฐ openssl crl -in crl.pem -outform DER -out crl.der CRL ํŒŒ์ผ ์ •๋ณด ๋ณด๊ธฐ openssl crl -in crl.der -text -noout CRL ํŒŒ์ผ ์ •๋ณด ๋ณด๊ธฐ ๊ฒฐ๊ณผ ertificate Revocation List (CRL): Version 2 (0x1) Signature Algorithm: sha256WithRSAEncryption Issuer: C = KR, ST = Korea, O = TEST, CN = CA Last ..

Manual/OpenSSL 2023.05.21

[OpenSSL] x509 ๋ช…๋ น์–ด

์ด๋ช…๋ น์–ด๋Š” ๋‹ค์–‘ํ•œ ๋ชฉ์ ์œผ๋กœ ์ธ์ฆ์„œ๋ฅผ ๋‹ค๋ฃจ๋Š” ๋ช…๋ น์–ด์ด๋‹ค. https://www.openssl.org/docs/man3.0/man1/openssl-x509.html ์ด ์„ค๋ช…์„œ๋ฅผ ์ฐธ์กฐ ํ•ด์„œ ๋งŒ๋“ค์—ˆ๋‹ค. PEM ํ˜•์‹์˜ ์ธ์ฆ์„œ ์ •๋ณด ๋ณด๊ธฐ ์ถœ๋ ฅ openssl x509 -text -noout -in test_cert.crtDER ํ˜•์‹์˜ ์ธ์ฆ์„œ ์ •๋ณด ๋ณด๊ธฐ ๊ฒฐ๊ณผ openssl x509 -inform der -noout -text -in test_cert.der๊ฒฐ๊ณผ ํ™”๋ฉด Certificate: Data: Version: 3 (0x2) Serial Number: 53:14:62:20:a1:a5:29:73 Signature Algorithm: ecdsa-with-SHA256 Issuer: C = KR, O = Ranix, OU..

Manual/OpenSSL 2023.05.20

[OpenSSL] pkeyutl ๋ช…๋ น์–ด

์ด ๋ช…๋ น์–ด๋Š” ๊ณต๊ฐœํ‚ค ์•Œ๊ณ ๋ฆฌ์ฆ˜ ์‹คํ–‰ ๋ช…๋ น์–ด์ด๋‹ค. ์ด ๋ฌธ์„œ๋Š” https://www.openssl.org/docs/man3.0/man1/openssl-pkeyutl.html ์ฐธ์กฐ ํ•˜์—ฌ ๋งŒ๋“ค์—ˆ๋‹ค. ๊ฐœ์ธํ‚ค๋ฅผ ์ด์šฉ ์ „์ž ์„œ๋ช… ์ƒ์„ฑ ์ด๋•Œ ์ž…๋ ฅ ๊ฐ’์€ ํ•ด์‰ฌ ๊ฐ’์ด์–ด์•ผ ํ•œ๋‹ค( ์›๋ฌธ ์•„๋‹˜ ) openssl pkeyutl -sign in data.txt -inkey rsa_key.pem -out sig์ƒ์„ฑ๋œ sig ๊ฐ’์€ ์ „์ž ์„œ๋ช… ๋ฐ”์ด๋„ˆ๋ฆฌ ๊ฐ’์ด๋‹ค. (ASN.1 ๋””์ฝ”๋”ฉ ์•ˆ๋จ ) ์„œ๋ช… ๋ฐ์ดํƒ€ ๊ฒ€์ฆ ์ž…๋ ฅ๋œ ์„œ๋ช… ๊ฒ€์ฆ openssl pkeyutl -verify -in data.txt -sigfile sig -inkey rsa_key.pem ๋ณต๊ตฌ ์„œ๋ช… ๊ฒ€์ฆ ์ด ๊ธฐ๋Šฅ์€ ์„œ๋ช… ๊ฒ€์ฆํ•˜๊ณ  ์„œ๋ช…์— ์‚ฌ์šฉ๋œ ํ•ด์‰ฌ ๊ฐ’์„ ๋ณต๊ตฌ ํ•ด์ฃผ๋Š” ๋ช…๋ น์–ด ์ด๋‹ค. o..

Manual/OpenSSL 2023.05.19

[CryptokiMan] SoftHSM ๋ชจ๋“ˆ ์ดˆ๊ธฐํ™” ํ•˜๊ธฐ

[์ด ๊ธฐ๋Šฅ์€ ๋ผ์ด์„ ์Šค ๋ฒ„์ „ ๊ธฐ๋Šฅ์ž…๋‹ˆ๋‹ค]๋ผ์ด์„ ์Šค๊ฐ€ ํ•„์š”ํ•œ ๋ถ„์€ [ํ”„๋กœ๊ทธ๋žจ ํ‚ค ๋ฐœ๊ธ‰] ํŽ˜์ด์ง€์—์„œ 30์ผ ๋ผ์ด์„ ์Šค ๋ฐœ๊ธ‰ ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹คSoftHSM ์ฒ˜์Œ ์„ค์น˜ ํ•˜๋ฉด ์ดˆ๊ธฐ ์…‹ํŒ…์ด ํ•„์š”ํ•˜๋‹ค.์ด๋ฒˆ์—๋Š” softhsm2-util ์„ ์ด์šฉํ•ด์„œ๊ฐ€ ์•„๋‹ˆ๋ผ CryptokiMan ์„ ์ด์šฉํ•ด์„œ ์ดˆ๊ธฐํ™”๋ฅผ ํ•ด๋ณด์ž์ดˆ๊ธฐ ์…‹ํŒ…์„ ์œ„ํ•ด SoftHSM ์—์„œ ์ œ๊ณตํ•˜๋Š” Cryptoki Library ์˜ PKCS#11 API๋ฅผ CryptokiMan ์—์„œ ์‚ฌ์šฉํ•ด ์ดˆ๊ธฐํ™”๋ฅผ ํ•œ๋‹ค.SoftHSM ์ฒ˜์Œ ์„ค์น˜๋Š” ์˜คํ”ˆ์†Œ์Šค SoftHSM ์‚ฌ์šฉ๋ฒ• ( Windows ํ™˜๊ฒฝ ) ๋ฌธ์„œ๋ฅผ ์ฐธ์กฐํ•˜์žํ•ด๋‹น ๋ฌธ์„œ์—์„œ SoftHSM ์ฒ˜์Œ ์ƒํƒœ ํ™•์ธ ๊นŒ์ง€๋งŒ ์ง„ํ–‰์„ ํ•˜์ž์ด๋ฒˆ์—๋Š” SoftHSM ์ฒ˜์Œ ์„ค์น˜๋ฅผ ํ•˜๊ณ  ์ƒํƒœํ™•์ธ์„ ํ•ด๋ณด๋ฉด ๋‹ค์Œ ์ฒ˜๋Ÿผ ๋‚˜์˜จ๋‹ค.softhsm2-util.exe --show..

Manual/CryptokiMan 2023.05.16

[CryptokiMan] Cryptoki ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ ๊ธฐ๋ณธ ์‚ฌ์šฉ๋ฒ•

CryptokiMan ์€ cryptoki ๋™์  ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ๋ฅผ ์ฝ์–ด์„œ PKCS#11 API ๊ธฐ๋Šฅ์„ ์ˆ˜ํ–‰ํ•˜๊ณ  ํ…Œ์ŠคํŠธ ํ•ด๋ณด๊ธฐ ์œ„ํ•œ ํ”„๋กœ๊ทธ๋žจ์ด๋‹ค. ๋ณดํ†ต HSM ์žฅ์น˜๋Š” ํ•˜๋“œ์›จ์–ด ์žฅ์น˜์ด์ง€๋งŒ ์—ฌ๊ธฐ์„œ๋Š” ํ…Œ์ŠคํŠธ๋ฅผ ์œ„ํ•ด SoftHSM ์„ ์ด์šฉํ•œ๋‹ค. ๊ทธ๋Ÿผ ์–ด๋–ป๊ฒŒ ์‚ฌ์šฉํ•˜๋Š”์ง€ ๊ธฐ๋ณธ ๊ณผ์ •์€ ๋‹ค์Œ๊ณผ ๊ฐ™๋‹ค ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ ๋ถˆ๋Ÿฌ์˜ค๊ธฐ ์ดˆ๊ธฐํ™” ํ•˜๊ธฐ ์„ธ์…˜ ์—ด๊ธฐ ๋กœ๊ทธ์ธ HSM ๊ธฐ๋Šฅ ์‚ฌ์šฉํ•˜๊ธฐ ์ผ๋ฐ˜์ ์œผ๋กœ HSM ์žฅ์น˜๋ฅผ ์‚ฌ์šฉ ํ• ๋•Œ ์ดˆ๊ธฐํ™”๋ฅผ ํ•ด์•ผ ํ•œ๋‹ค. ๋ณดํ†ต HSM ์žฅ์น˜ ๊ฒฝ์šฐ ์ดˆ๊ธฐํ™” ํˆด์„ ์ œ๊ณตํ•œ๋‹ค ์—ฌ๊ธฐ์„œ๋Š” ๊ธฐ๋ณธ์ ์ธ ์„ค๋ช…์„ ์œ„ํ•ด์„œ ์žฅ์น˜ ์ดˆ๊ธฐํ™”๊ฐ€ ๋œ ์ƒํƒœ๋กœ ์„ค๋ช…์„ ํ•œ๋‹ค. 1. ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ ๋ถˆ๋Ÿฌ์˜ค๊ธฐ ์ฒ˜์Œ HSM ์—์„œ ์ œ๊ณตํ•˜๋Š” ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ๋ฅผ ํ˜ธ์ถœ ํ•˜๋Š” ๊ณผ์ •์ด๋‹ค. ํ˜„์žฌ ํ…Œ์ŠคํŠธ ํˆด์ด 64๋น„ํŠธ ์œˆ๋„์šฐ์šฉ์ด๋ผ๋ฉด 64๋น„ํŠธ ์œˆ๋„์šฐ์šฉ ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ๋ฅผ ๋ถˆ๋Ÿฌ ์ฃผ์–ด์•ผ ํ•œ๋‹ค. ๊ทธ๋ฆผ ์ฒ˜๋Ÿผ ์—ด..

Manual/CryptokiMan 2023.05.15

[OpenSSL] asn1parse ๋ช…๋ น์–ด

OpenSSL ์—์„œ asn1 ์ธ์ฝ”๋”ฉ ๋””์ฝ”๋”ฉ ๋ช…๋ น์–ด ์‚ฌ์šฉ๋ฒ•์„ ์•Œ์•„ ๋ณด์ž ํ•ด๋‹น ๊ธฐ๋Šฅ์— ๋Œ€ํ•œ ๋ฌธ์„œ ํŽ˜์ด์ง€๋Š” ๋ฉ”๋‰ด์–ผ์„ ์ฐธ๊ณ  ํ•˜์—ฌ ๋งŒ๋“ค์—ˆ๋‹ค. asn1parse ๋ช…๋ น์–ด๋กœ ๊ฐ„๋‹จํžˆ ๋ฌธ์ž ์ธ์ฝ”๋”ฉ/๋””์ฝ”๋”ฉ์„ ํ• ์ˆ˜ ์žˆ๊ณ  ๋ณต์žกํ•œ ๋ฐ์ดํƒ€๋Š” ์„ค์ •์„ ์ด์šฉํ•ด ๋งŒ๋“ค ์ˆ˜ ์žˆ๋‹ค. ๊ธฐ๋ณธ์ ์œผ๋กœ ASN.1 PEM ํ˜•์‹ ํŒŒ์‹ฑ ํ•ด์„œ ๋ณด๊ธฐ openssl asn1parse -in file.pem ASN1 DER ํ˜•์‹ ํŒŒ์ผ ๋ณด๊ธฐ openssl asn1parse -inform DER -in file.der UTF8String ๋ฌธ์ž ์ƒ์„ฑํ•˜๊ธฐ openssl asn1parse -genstr "UTF8:Hello world" ๊ฒฐ๊ณผ ๊ฐ’ 0:d=0 hl=2 l= 11 prim: UTF8STRING :Hello world UTF8String DER ํŒŒ์ผ๋กœ ์ƒ์„ฑํ•˜๊ธฐ o..

Manual/OpenSSL 2023.05.15

[OpenSSL] MAC ( Message Authentication Code ) ๋ช…๋ น์–ด

๋ฉ”์„ธ์ง€ ์ธ์ฆ ์ฝ”๋“œ๋ผ๋Š” MAC ๊ธฐ๋Šฅ์„ OpenSSL ๋ช…๋ น์–ด๋ฅผ ์‚ฌ์šฉํ•ด ๊ตฌํ•ด ๋ณด์ž ์‚ฌ์‹ค MAC ๊ฐ’์„ ๊ตฌํ•˜๊ธฐ ์œ„ํ•ด ๋ฐฉ์‹์€ ์—ฌ๋Ÿฌ๊ฐ€์ง€๊ฐ€ ์žˆ๋‹ค. ์ผ๋ฐ˜์ ์œผ๋กœ๋Š” Hash๋ฅผ ์‚ฌ์šฉํ•˜๋Š” HMAC๊ณผ Cipher-based MAC ์ธ CMAC์ด ๊ฐ€์žฅ ๋Œ€ํ‘œ์ ์ด๋‹ค. ๊ทธ๋ฆฌ๊ณ  ๋ธ”๋ก ์•”ํ˜ธ์—์„œ ์‚ฌ์šฉ๋˜๋Š” GCM ๋ชจ๋“œ๋ฅผ ์ด์šฉํ•œ GMAC ๋“ฑ์ด ์žˆ๋‹ค. ์ด ๋ช…๋ น์–ด์— ๋Œ€ํ•œ ๋ฉ”๋‰ด์–ผ์„ ์ฐธ๊ณ  ํ•˜์—ฌ ๋งŒ๋“ค์—ˆ๋‹ค. HMAC-SHA1 MAC openssl mac -digest SHA1 -macopt hexkey:000102030405060708090A0B0C0D0E0F10111213 -in msg.bin HMAC HMAC ์ง€์› ๋ชฉ๋ก ํ™•์ธ openssl list -digest-commands HMAC ์ง€์› ๋ชฉ๋ก ๊ฒฐ๊ณผ ํ™”๋ฉด blake2b512 blake2s256 md..

Manual/OpenSSL 2023.05.10

[BerEditor] PBKDF (Password-Based Key Derivation Function) ์‚ฌ์šฉ๋ฒ•

[์ด ๊ธฐ๋Šฅ์€ ๋ผ์ด์„ ์Šค ๋ฒ„์ „ ๊ธฐ๋Šฅ์ž…๋‹ˆ๋‹ค]๋ผ์ด์„ ์Šค๊ฐ€ ํ•„์š”ํ•œ ๋ถ„์€ [ํ”„๋กœ๊ทธ๋žจ ํ‚ค ๋ฐœ๊ธ‰] ํŽ˜์ด์ง€์—์„œ 30์ผ ๋ผ์ด์„ ์Šค ๋ฐœ๊ธ‰ ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค๋ณดํ†ต ๋ธ”๋ก ์•”ํ˜ธ ์‚ฌ์šฉ์‹œ ๋Œ€์นญํ‚ค๋ฅผ ์‚ฌ์šฉํ•ด์•ผ ํ•˜๋Š”๋ฐ์‚ฌ์‹ค ์‚ฌ๋žŒ๋“ค์ด ๊ธฐ์–ตํ•  ์ˆ˜ ์žˆ๋Š” ํŒจ์Šค์›Œ๋“œ๋ฅผ ์‚ฌ์šฉํ•ด ํ‚ค๋ฅผ ๋งŒ๋“ค์–ด์•ผ ํ•˜๋Š” ๊ฒฝ์šฐ๊ฐ€ ์žˆ๋‹ค.ํŒจ์Šค์›Œ๋“œ๋ฅผ ์‚ฌ์šฉํ•ด ํ‚ค๋ฅผ ์ถ”์ถœ ํ• ๋•Œ ์‚ฌ์šฉํ•˜๋Š”๊ฒƒ์ด PBKDF ์ด๋‹ค.์˜ˆ๋ฅผ ๋“ค๋ฉด ์šฐ๋ฆฌ๊ฐ€ ์ธํ„ฐ๋„ท ๋ฑ…ํ‚ค์—์„œ ์ธ์ฆ์„œ๋ฅผ ์‚ฌ์šฉํ•˜๋Š”๋ฐ ๊ทธ๋•Œ ์‚ฌ์šฉ์ž๋Š” ์ธ์ฆ์„œ ์„ ํƒํ›„ ํŒจ์Šค์›Œ๋“œ๋ฅผ ์ž…๋ ฅํ•œ๋‹ค.์ด๋•Œ ์ž…๋ ฅํ•œ ํŒจ์Šค์›Œ๋“œ๋ฅผ ๊ฐ€์ง€๊ณ  ํ•ด๋‹น ์ธ์ฆ์„œ์˜ ๊ฐœ์ธํ‚ค๋ฅผ ๋ณตํ˜ธํ™” ํ•œ๋‹ค.์•”ํ˜ธํ™”๋œ ๊ฐœ์ธํ‚ค๋ฅผ ๋ณตํ˜ธํ™”๋Š” ๋Œ€์นญํ‚ค ์•”ํ˜ธํ™” ๋ฐฉ์‹์œผ๋กœ ์‚ฌ์šฉํ•˜๋Š” ํ‚ค๋Š” ํŒจ์Šค์›Œ๋“œ๋ฅผ ์ง์ ‘ ์‚ฌ์šฉํ•˜๋Š”๊ฒŒ ์•„๋‹ŒPBKDF ๋ฅผ ํ†ตํ•ด์„œ ํ‚ค๋ฅผ ๋งŒ๋“ค์–ด์„œ ์‚ฌ์šฉํ•˜๋Š” ๊ฒƒ์ด๋‹ค.๊ธฐ๋ณธ์ ์œผ๋กœ PBKDF ๋Š” Password-Based Key Derivation Fun..

Manual/BerEditor 2023.05.08

[OpenSSL] Message Digest ( Hash function ) ๋ช…๋ น์–ด

Message Digest๋Š” ์ž„์˜์˜ ๊ธธ์ด๋ฅผ ๋‹จ๋ฐฉํ–ฅ ํ•ด์‰ฌ ํ•จ์ˆ˜์— ์ ์šฉํ•˜์—ฌ ์ผ์ •ํ•œ ๊ธธ์ด๋กœ ์ƒ์„ฑ๋œ ๋น„ํŠธ์—ด์ด๋‹ค. ์ฆ‰ ํ•ด์‰ฌ์˜ ๊ฒฐ๊ณผ ๊ฐ’์œผ๋กœ ๋ณด๋ฉด ๋œ๋‹ค. ํ•ด์‰ฌ ํ•จ์ˆ˜ ์ฆ‰ ํ•ด์‰ฌ ๋ผ๊ณ  ๋งํ•˜๋Š” ์ž„์˜์˜ ๊ธธ์ด๋ฅผ ๊ฐ–๋Š” ๋ฐ์ดํƒ€์— ๋Œ€ํ•ด ๊ณ ์ •๋œ ๊ธธ์ด๋กœ ๋ฐ์ดํƒ€๋ฅผ ๋งคํ•‘ํ•˜๋Š” ๋‹จ๋ฐฉํ–ฅ ํ•จ์ˆ˜๋ฅผ ๋งํ•œ๋‹ค. OpenSSL ์„ ์ด์šฉํ•ด ํ•ด์‰ฌ ํ•จ์ˆ˜ ๊ธฐ๋Šฅ์„ ์ด์šฉํ•ด Message Digest ๊ฐ’์„ ๊ตฌํ•ด ๋ณด์ž. ์—ฌ๊ธฐ์„œ ์ž‘์„ฑํ•œ ๊ธฐ๋Šฅ์€ ๋ฉ”๋‰ด์–ผ ๋ฌธ์„œ๋ฅผ ์ฐธ์กฐ ํ•˜์—ฌ ๋งŒ๋“ค์—ˆ๋‹ค. ๋จผ์ € ์ง€์› ํ•˜๋Š” ๋ฉ”์„ธ์ง€ ๋‹ค์ด์ œ์ŠคํŠธ ๋ชฉ๋ก์„ ํ™•์ธ ํ•˜์ž openssl dgst -list Supported digests: -blake2b512 -blake2s256 -md5 -md5-sha1 -ripemd -ripemd160 -rmd160 -sha1 -sha224 -sha256 -sha3-224 -..

Manual/OpenSSL 2023.05.08

[OpenSSL] enc ( ์•”ํ˜ธํ™” ) ๋ช…๋ น์–ด

OpenSSL ๋ช…๋ น์–ด๋ฅผ ์ด์šฉํ•˜์—ฌ ์•”/๋ณตํ˜ธํ™”๋ฅผ ํ•ด๋ณด์ž ํ•ด๋‹น ๋ช…๋ น์–ด์— ๋Œ€ํ•œ ๋ฉ”๋‰ด์–ผ์„ ์ฐธ์กฐ ํ•˜์˜€๋‹ค. ๋จผ์ž ์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ ๋ธ”๋Ÿญ ์•”ํ˜ธ ๋ชฉ๋ก์„ ํ™•์ธ ํ•ด๋ณด์ž openssl enc -ciphers [RANIX@DESKTOP-VOGBKQM ~]$ openssl enc -ciphers Supported ciphers: -aes-128-cbc -aes-128-cfb -aes-128-cfb1 -aes-128-cfb8 -aes-128-ctr -aes-128-ecb -aes-128-ofb -aes-192-cbc -aes-192-cfb -aes-192-cfb1 -aes-192-cfb8 -aes-192-ctr -aes-192-ecb -aes-192-ofb -aes-256-cbc -aes-256-cfb -aes-256-cfb1 -aes..

Manual/OpenSSL 2023.05.04