PKI/X509 Profile 22

[X509] ์ธ์ฆ์„œ ํ๊ธฐ๋ชฉ๋ก ๋ถ„๋ฐฐ์ ( CRL Distribution Points ) ์ด๋ž€?

์ธ์ฆ์„œ ํ๊ธฐ ๋ชฉ๋ก ๋ถ„๋ฐฐ์ ์€ Version 3 ์˜ ํ™•์žฅ ํ•„๋“œ๋กœ์„œ ์ธ์ฆ์„œ์˜ ์ƒํƒœ ์ •๋ณด๋ฅผ ํ™•์ธํ•˜๋Š” CRL ์˜ ์œ„์น˜ ์ •๋ณด๋ฅผ ๋‚˜ํƒ€๋‚ด๋Š” ํ•„๋“œ ์ด๋‹ค. ์ฆ‰ ํ•ด๋‹น ์ธ์ฆ์„œ์˜ ํ๊ธฐ์— ๊ด€ํ•œ ์ •๋ณด๋ฅผ ๊ณต๊ฐœ๋œ ์œ„์น˜์— ๊ฒŒ์‹œ๋ฅผ ํ•˜๊ฒŒ ๋˜๊ณ  ์ด ํ™•์žฅ ํ•„๋“œ์—์„œ ๊ทธ ์œ„์น˜ ์ •๋ณด๋ฅผ ์–ป๊ฒŒ ๋˜๋Š” ๊ฒƒ์ด๋‹ค. ์•„๋ž˜ ๊ทธ๋ฆผ์€ CRL Distribution Points ์˜ ์˜ˆ์ œ ๊ทธ๋ฆผ์ด๋‹ค. ์œ„ ๊ทธ๋ฆผ์—์„œ ๋ณด๋ฉด http://crl3.digicert.com/DigiCertTLSRSASHA2562020CA1-4.crl ์ด ์œ„์น˜์— ํ•ด๋‹น CRL ํŒŒ์ผ์„ ์–ป์„ ์ˆ˜ ์žˆ์Œ์„ ์•Œ๋ ค์ค€๋‹ค. ๋ฌผ๋ก  2๋ฒˆ์งธ ์œ„์น˜์—์„œ๋„ ๊ฐ€์ ธ ์˜ฌ ์ˆ˜ ์žˆ๋‹ค. ์ธ์ฆ์„œ ํ๊ธฐ ๋ชฉ๋ก ๋ถ„๋ฐฐ์  ASN.1 id-ce-cRLDistributionPoints OBJECT IDENTIFIER ::= { id-ce 31 } CR..

PKI/X509 Profile 2023.09.08

[X509] ๋ฐœ๊ธ‰์ž ์ •๋ณด ์ ‘๊ทผ (Authority Information Access)

๋ฐœ๊ธ‰์ž ์ •๋ณด ์ ‘๊ทผ ( Authority Information Access) ์€ X509 Version3 ์—์„œ ์ •์˜ ๋œ ํ™•์žฅ ํ•„๋“œ์ด๋‹ค. ์ด ํ™•์žฅ ํ•„๋“œ๋Š” ์ธ์ฆ์„œ๋ฅผ ๋ฐœ๊ธ‰ํ•œ ์ธ์ฆ๊ธฐ๊ด€์— ๋Œ€ํ•œ ์ •๋ณด๋ฅผ ๋ณด์—ฌ์ค€๋‹ค. ์ฆ‰ ์ธ์ฆ์„œ๋ฅผ ๋ฐœ๊ธ‰ํ•œ ์ธ์ฆ๊ธฐ๊ด€ ์œ„์น˜์™€ ์ธ์ฆ์„œ์˜ ์ƒํƒœ๋ฅผ ์•Œ ์ˆ˜ ์žˆ๋Š” OCSP ์ •๋ณด๋ฅผ ๋‚˜ํƒ€๋‚ธ๋‹ค. ์•„๋ž˜ ๊ทธ๋ฆผ์ด ๋ฐœ๊ธ‰์ž ์ •๋ณด ์ ‘๊ทผ์˜ ์˜ˆ์ œ ํ™”๋ฉด์ด๋‹ค. ์˜ˆ์ œ ๊ทธ๋ฆผ์—์„œ ๋ณด๋ฉด OCSP URI ์™€ CA Issuers ์˜ URI ์ •๋ณด๋ฅผ ๋ณผ ์ˆ˜ ์žˆ๋‹ค. ๋ฐœ๊ธ‰์ž ์ •๋ณด ์ ‘๊ทผ ASN.1 id-pe-authorityInfoAccess OBJECT IDENTIFIER ::= { id-pe 1 } AuthorityInfoAccessSyntax ::= SEQUENCE SIZE (1..MAX) OF AccessDescription AccessD..

PKI/X509 Profile 2023.09.05

[X509] ์ธ์ฆ์„œ์™€ CRL ๋ฒ„์ „์— ๊ด€ํ•˜์—ฌ

X509ํ”„๋กœํŒŒ์ผ์—์„œ ๊ฐ€์žฅ ๊ธฐ๋ณธ์ ์ธ ํ•„๋“œ์ธ ๋ฒ„์ „์— ๋Œ€ํ•ด์„œ ์•Œ์•„๋ณด์ž ์ผ๋ฐ˜์ ์œผ๋กœ ์‚ฌ์šฉํ•˜๋Š” ์ธ์ฆ์„œ์™€ CRL ํ•„๋“œ์— ๋Œ€ํ•œ ์ •์˜๋ฅผ ํ•˜๋ฉด์„œ ์ง€์› ํ•„๋“œ๊ฐ€ ์ •ํ•ด์งˆ ๋•Œ ๋ฒ„์ „ ๊ฐ’์ด ์žˆ๋‹ค. ํ˜„์žฌ ์ผ๋ฐ˜์ ์œผ๋กœ ์‚ฌ์šฉ๋˜๋Š” ์ธ์ฆ์„œ์˜ ๋ฒ„์ „์€ V3 ๋ฒ„์ „์„ ์‚ฌ์šฉํ•œ๋‹ค. ๊ทธ๋ฆฌ๊ณ  CRL ์˜ ๊ฒฝ์šฐ ์ผ๋ฐ˜์ ์œผ๋กœ ์‚ฌ์šฉํ•˜๋Š” ๋ฒ„์ „์€ V2 ๋ฒ„์ „์„ ์‚ฌ์šฉํ•œ๋‹ค. ์ฆ‰ ์ธ์ฆ์„œ ๊ฒฝ์šฐ V1, V2, V3 ์˜ 3๋ฒˆ์˜ ๋ณ€๊ฒฝ์ด ๋˜์—ˆ๊ตฌ CRL ๊ฒฝ์šฐ V1, V2๋กœ ๋‘๋ฒˆ์ด ๋ณ€๊ฒฝ ๋˜์—ˆ๋‹ค๊ณ  ๋ณด๋ฉด ๋œ๋‹ค. ์•„๋ž˜ ๊ทธ๋ฆผ์€ ํ˜„์žฌ ์‚ฌ์šฉํ•˜๊ณ  ์žˆ๋Š” ์ธ์ฆ์„œ์™€ CRL ๋ฒ„์ „์„ ๊ฐญ์ณ ํ•œ๊ฒƒ์ด๋‹ค. Version์— ๋Œ€ํ•œ ASN.1 # X509 Certificate Version Version ::= INTEGER { v1(0), v2(1), v3(2) } # X509 CRL Version version Ver..

PKI/X509 Profile 2023.08.31

[X.509] ์†Œ์œ ์ž ๋Œ€์ฒด ๋ช…์นญ(Subject Alternative Name) ์ด๋ž€

์†Œ์œ ์ž ๋Œ€์ฒด ๋ช…์นญ ํ™•์žฅ ํ•„๋“œ๋Š” ์†Œ์œ ์ž์— ๋Œ€ํ•œ ์ถ”๊ฐ€์ ์ธ ๋ช…์นญ์„ ๋‚˜ํƒ€๋‚ธ๋‹ค. ์ฆ‰ Subject DN์˜ ์ถ”๊ฐ€ ๋ช…์นญ ์ •๋ณด๋ฅผ ๋‚˜ํƒ€๋‚ธ๋‹ค. ์ฐธ๊ณ ๋กœ ์†Œ์œ ์ž ๋Œ€์ฒด ๋ช…์นญ๊ณผ ๊ฐ™์€ ํ˜•์‹์„ ์‚ฌ์šฉํ•˜๋Š” ๋ฐœ๊ธ‰์ž ๋Œ€์ฒด ๋ช…์นญ (Issuer Alternative Name) ๋„ ์กด์žฌ ํ•˜๋Š”๋ฐ ์ด ๊ฐ’์€ ๋ฐœ๊ธ‰์ž ์ฆ‰ ์ธ์ฆ๊ธฐ๊ด€์˜ ์ถ”๊ฐ€ ์ ์ธ ๋ช…์นญ์„ ๋‚˜ํƒ€๋‚ธ๋‹ค. ์•„๋ž˜ ๊ทธ๋ฆผ์€ Subject Alternative Name ์„ ์‚ฌ์šฉํ•œ ์ธ์ฆ์„œ ์˜ˆ์ œ ์ด๋‹ค. ์ด ๊ทธ๋ฆผ์—์„œ๋Š” DNS ์ด๋ฆ„ ์ •๋ณด๋ฅผ ์†Œ์œ ์ž ๋Œ€์ฒด ๋ช…์นญ์œผ๋กœ ์‚ฌ์šฉ ๋˜์—ˆ๋‹ค. ์†Œ์œ ์ž ๋Œ€์ฒด ๋ช…์นญ์˜ ์ข…๋ฅ˜ ์†Œ์œ ์ž ๋Œ€์ฒด ๋ช…์นญ์˜ ํƒ€์ž…์—๋Š” 9๊ฐ€์ง€ ํ˜•์‹์ด ์ง€์› ๋œ๋‹ค. rfc822Name : ์ธํ„ฐ๋„ท ์ „์ž ๋ฉ”์ผ dNSName : DNS ์ด๋ฆ„ iPAddress : IP ์ฃผ์†Œ uniformResourceIdentifier : URL ..

PKI/X509 Profile 2023.08.22

[X.509] ์ธ์ฆ์„œ ์œ ํšจ๊ธฐ๊ฐ„ (Validity) ์— ๋Œ€ํ•ด์„œ

์ธ์ฆ์„œ ์œ ํšจ ๊ธฐ๊ฐ„ (Validty) ์ด๋ž€? ์ธ์ฆ์„œ ์œ ํšจ ๊ธฐ๊ฐ„์€ CA ์ธ์ฆ์„œ๊ฐ€ ๋ฐœ๊ธ‰ํ•œ ์ธ์ฆ์„œ ์ •๋ณด์— ๋Œ€ํ•œ ์œ ํšจํ•œ ์ƒํƒœ๋ฅผ ๋‚˜ํƒ€๋‚ด๋Š” ์‹œ๊ฐ„์˜ ๊ฐ„๊ฒฉ์„ ๋งํ•œ๋‹ค. ์ฆ‰ ํ•ด๋‹น ์ธ์ฆ์„œ์˜ ์œ ํšจํ•œ ๊ธฐ๊ฐ„์„ ๋งํ•˜๋Š” ๊ฒƒ์ด๋‹ค. ์ด ํ•„๋“œ๋Š” ๋‘๊ฐœ์˜ ๋‚ ์งœ๋ฅผ SEQUENCE ํ˜•์‹์œผ๋กœ ๊ฐ’์ด ํ‘œํ˜„ ๋œ๋‹ค. ASN.1 ํ˜•์‹ Validity ::= SEQUENCE { notBefore Time, notAfter Time } Time ::= CHOICE { utcTime UTCTime, generalTime GeneralizedTime } ์œ ํšจ ๊ธฐ๊ฐ„์˜ ์ •๋ณด์—๋Š” ๋‘๊ฐ€์ง€ ํ•„๋“œ๊ฐ€ ์กด์žฌ ํ•˜๋Š”๋ฐ notBefore ํ•„๋“œ์™€ notAfter ํ•„๋“œ์ด๋‹ค. ์•„๋ž˜ ๊ทธ๋ฆผ ์ฐธ์กฐ ์ด ์˜ˆ์ œ ๊ทธ๋ฆผ์˜ ์ธ์ฆ์„œ์˜ ์œ ํšจ ๊ธฐ๊ฐ„์€ 2022๋…„ 5์›” 23์ผ 09์‹œ ๋ถ€ํ„ฐ 2023๋…„ 6์›” 8์ผ 0..

PKI/X509 Profile 2023.08.17

[X.509] ์ธ์ฆ์„œ ์ •์ฑ… (Ceritifcate Policies) ํ™•์žฅ ํ•„๋“œ๋ž€?

์ธ์ฆ์„œ ์ •์ฑ… (Certificate Policies ) ์šฉ๋„ ์ธ์ฆ์„œ ์ •์ฑ…์€ X.509 ์ธ์ฆ์„œ์˜ ํ™•์žฅ ํ•„๋“œ์ด๋‹ค. ์ด ํ•„๋“œ๋Š” ์ธ์ฆ์„œ๋ฅผ ๋ฐœ๊ธ‰ํ•˜๋Š” CA์—์„œ ํ•ด๋‹น ๋ฐœ๊ธ‰๋œ ์ธ์ฆ์„œ ์ •์ฑ…์„ ๋‚˜ํƒ€๋‚ด๋Š” ๊ฒƒ์ด๋‹ค. ์ฆ‰ ํ•œ๋งˆ๋””๋กœ ํ•ด๋‹น ์ธ์ฆ์„œ์˜ ์šฉ๋„๋ฅผ ์•Œ๋ ค ์ฃผ๋Š” ํ™•์žฅ ํ•„๋“œ ์ด๋‹ค. ์ธ์ฆ์„œ ์ •์ฑ… ์˜ˆ์ œ ์•„๋ž˜ ๊ทธ๋ฆผ์€ SSL ์ธ์ฆ์„œ์—์„œ ์ธ์ฆ์„œ ์ •์ฑ… ํ•„๋“œ์— ๋Œ€ํ•œ ์˜ˆ์ œ์ด๋‹ค. ํ•ด๋‹น ๊ทธ๋ฆผ์—์„œ ์ฒ˜๋Ÿผ ์ธ์ฆ์„œ ์ •์ฑ… OID ์ •๋ณด์™€ CPS ( Certificate Practice Statement ) ์ •๋ณด๊ฐ€ ๋‚˜์˜จ๋‹ค. ์—ฌ๊ธฐ์„œ CPS ๋Š” URI ํ˜•์‹์˜ ์ •๋ณด์ด๋‹ค. ํ•ด๋‹น CPS ์ •๋ณด์˜ URI ์ฃผ์†Œ๋ฅผ ์ฐธ์กฐ ํ•˜๋ฉด ํ•ด๋‹น ์ธ์ฆ์„œ ์šฉ๋„์— ๋Œ€ํ•œ ๋‚ด์šฉ์„ ํ™•์ธ ํ•  ์ˆ˜ ์žˆ๋‹ค. ๊ทธ๋ฆฌ๊ณ  ์ธ์ฆ์„œ ์ •์ฑ… ์ •๋ณด์—๋Š” User Notice ์ •๋ณด๋„ ์กด์žฌ ํ•˜๋Š”๋ฐ ์ด ์ •๋ณด๋Š” ์‹ ๋ขฐ ๋‹น์‚ฌ์ž์—๊ฒŒ ์ธ์ฆ..

PKI/X509 Profile 2023.08.16

[X.509] ์ธ์ฆ์„œ ์ฃผ์ฒดํ‚ค ์‹๋ณ„์ž(Subject Key Identifier) ์™€ ๊ธฐ๊ด€ํ‚ค ์‹๋ณ„์ž(Authority Key Identifier)

X.509 ์ธ์ฆ์„œ ๊ธฐ๋ณธ ํ”„๋กœํŒŒ์ผ์—์„œ ์ฃผ์ฒดํ‚ค ์‹๋ณ„์ž์™€ ๊ธฐ๊ด€ํ‚ค ์‹๋ณ„์ž ๊ฐ’์ด ์กด์žฌํ•œ๋‹ค. ์ด ์‹๋ณ„์ž๋Š” ์ธ์ฆ์„œ์˜ ๊ฒฝ๋กœ ๊ตฌ์„ฑ์„ ํ•˜๊ธฐ ์œ„ํ•˜์—ฌ ๊ณต๊ฐœํ‚ค์— ๋Œ€ํ•œ ๊ตฌ๋ณ„ ๊ฐ’์œผ๋กœ ์‚ฌ์šฉ๋˜๋Š” ๊ฐ’์ด๋‹ค. ์ด ํ•„๋“œ๋Š” X.509 v3 ์—์„œ ํ™•์žฅ ํ•„๋“œ์˜ ๊ฐ’์ด๋‹ค. ์ฃผ์ฒดํ‚ค ์‹๋ณ„์ž (Subject Key Identifier) ์ฃผ์ฒดํ‚ค ์‹๋ณ„์ž๋Š” ํ•ด๋‹น ์ธ์ฆ์„œ์˜ ๊ณต๊ฐœํ‚ค๋ฅผ ๊ตฌ๋ณ„ํ•˜๊ธฐ ์œ„ํ•œ ๊ฐ’์ด๋‹ค. ์ฃผ์ฒดํ‚ค ์‹๋ณ„์ž ASN.1 id-ce-subjectKeyIdentifier OBJECT IDENTIFIER ::= { id-ce 14 } SubjectKeyIdentifier ::= KeyIdentifier์ด๋ ‡๊ฒŒ KeyIdentifier ๊ฐ’ ํ•˜๋‚˜๋ฅผ ์‚ฌ์šฉํ•œ๋‹ค. ์•„๋ž˜ ์ธ์ฆ์„œ ๊ทธ๋ฆผ์—์„œ ํŒŒ๋ž€์ƒ‰ ๋ถ€๋ถ„์ด ์ฃผ์ฒดํ‚ค ์‹๋ณ„์ž(Subject Key Identifier) ๊ฐ’์ด๋‹ค ์ด ๊ฐ’..

PKI/X509 Profile 2023.07.13

[X.509] ์ธ์ฆ์„œ ๊ธฐ๋ณธ ์ œํ•œ(Basic Constraints)์— ๋Œ€ํ•ด์„œ

X.509 ์—์„œ CA ์ธ์ฆ์„œ์˜ ํ•„์ˆ˜ ๊ฐ’์ธ Basic Constraints ์— ๋Œ€ํ•ด์„œ ์•Œ์•„๋ณด์ž. ๋ณดํ†ต ํ•œ๊ธ€๋กœ๋Š” ๊ธฐ๋ณธ ์ œํ•œ ์ด๋ผ๊ณ  ํ‘œํ˜„ํ•œ๋‹ค. ์•„๋ž˜ ๊ทธ๋ฆผ์„ ๋ณด๋ฉด X.509 CA ์ธ์ฆ์„œ์—์„œ basicConstrains ๊ฐ’์ด ์กด์žฌ ํ•œ๋‹ค. CA( RootCA ํฌํ•จ) ์ธ์ฆ์„œ์—์„œ๋Š” ํ•„์ˆ˜๋กœ ์ด ๊ฐ’์ด ์กด์žฌํ•œ๋‹ค. ํ•œ๋งˆ๋””๋กœ CA ์ธ์ฆ์„œ๋ฅผ ๋งŒ๋“ค๋ ค๋ฉด ์ด ํ™•์žฅ ํ•„๋“œ๊ฐ€ ํ•„์ˆ˜ ๊ฐ’์ด๋‹ค. Basic Constrains ASN.1 ์ •์˜ id-ce-basicConstraints OBJECT IDENTIFIER ::= { id-ce 19 } BasicConstraints ::= SEQUENCE { cA BOOLEAN DEFAULT FALSE, pathLenConstraint INTEGER (0..MAX) OPTIONAL } ์œ„ ASN.1 ์ •์˜..

PKI/X509 Profile 2023.07.06

[X.509] ์ธ์ฆ์„œ ํ‚ค ์šฉ๋„(KeyUsage) ์„ค๋ช…

X.509 ์ธ์ฆ์„œ ํ•„๋“œ ์ค‘์— KeyUsage ๋ผ๋Š” ํ•„๋“œ๊ฐ€ ์žˆ๋‹ค. ์ด ํ•„๋“œ๋Š” ํ•ด๋‹น ์ธ์ฆ์„œ์— ์žˆ๋Š” ๋น„๋Œ€์นญํ‚ค์˜ ์‚ฌ์šฉ ๋ชฉ์ ์„ ์ •์˜ํ•œ ํ•„๋“œ์ด๋‹ค. ์•„๋ž˜ ๊ทธ๋ฆผ์€ RootCA ์ธ์ฆ์„œ์˜ KeyUsage ํ•„๋“œ๋ฅผ ๋ณผ ์ˆ˜ ์žˆ๋‹ค. ์ด ์ธ์ฆ์„œ์˜ keyUsage ๋‚ด์šฉ์€ keyCertSign, cRLSign ์œผ๋กœ ๋‚˜์˜ค๋Š”๋ฐ ์ธ์ฆ์„œ ์„œ๋ช… ๋ฐ CRL ์„œ๋ช…์šฉ์ด๋ผ๋Š” ๋œป์ด๋‹ค. ํ•ด๋‹น ํ•„๋“œ์˜ ASN.1 ํ˜•์‹์€ ๋‹ค์Œ๊ณผ ๊ฐ™๋‹ค. id-ce-keyUsage OBJECT IDENTIFIER ::= { id-ce 15 } KeyUsage ::= BIT STRING { digitalSignature (0), nonRepudiation (1), keyEncipherment (2), dataEncipherment (3), keyAgreement (4), keyC..

PKI/X509 Profile 2023.06.28

[X509] ์ธ์ฆ์„œ DN ( Distinguished Name ) ์ด๋ž€?

์ธ์ฆ์„œ DN ์— ๋Œ€ํ•ด์„œ ์•Œ์•„ ๋ณด์ž ์—ฌ๊ธฐ์„œ DN ์€ Distinguished Name ์˜ ์•ฝ์ž์ด๋‹ค. ๊ทธ๋ฆฌ๊ณ  ์ธ์ฆ์„œ์—์„œ๋Š” DN ์ด ๋‘๊ตฐ๋ฐ ์กด์žฌ ํ•œ๋‹ค ์ฆ‰ ์ฃผ์ฒด์ž์˜ DN ๊ณผ ๋ฐœ๊ธ‰์ž์˜ DN ์ด ์žˆ๋‹ค. ํ•œ๋งˆ๋””๋กœ ์ด ์ธ์ฆ์„œ์˜ ์ฃผ์ฒด์ž์™€ ๋ฐœ๊ธ‰์ž์— ๋Œ€ํ•œ ์ด๋ฆ„์ด DN ์ด๋‹ค. ์ฆ‰ ์ฃผ์ฒด์ž์˜ DN ์€ ํ•ด๋‹น ์ธ์ฆ์„œ์˜ ์ฃผ์ฒด์˜ ์ด๋ฆ„์ด๊ณ  ๋ฐœ๊ธ‰์ž์˜ DN ์€ ํ•ด๋‹น ์ธ์ฆ์„œ๋ฅผ ๋ฐœ๊ธ‰ํ•œ CA ์ธ์ฆ์„œ์˜ ์ด๋ฆ„์ด๋‹ค. ๊ทธ๋Ÿผ DN์— ๋Œ€ํ•˜์—ฌ ์ข€๋” ๊ตฌ์ฒด์ ์œผ๋กœ ๋ถ„์„์„ ํ•ด๋ณด์ž. DN์€ ํ•˜๋‚˜ ์ด์ƒ์˜ RDN ( Relative Distinguished Name ) ์ด ์ˆœ์„œ๋ฅผ ๊ฐ€์ง€๊ณ  ๊ตฌ์„ฑ ๋˜์–ด ์žˆ๋‹ค. DN์˜ ASN.1 ํ˜•์‹ Name ::= CHOICE { RDNSequence } RDNSequence ::= SEQUENCE OF RelativeDistinguished..

PKI/X509 Profile 2023.06.13