๋ณธ๋ฌธ์œผ๋กœ ๊ฑด๋„ˆ๋›ฐ๊ธฐ

๊ฐœ์š”

๐Ÿ“ŒSSL์ธ์ฆ์„œโ€‹

SSL(Secure Sockets Layer) ์ธ์ฆ์„œ๋Š” ์›น์‚ฌ์ดํŠธ์™€ ์‚ฌ์šฉ์ž ๊ฐ„์˜ ๋ฐ์ดํ„ฐ ํ†ต์‹ ์„ ์•”ํ˜ธํ™”ํ•˜์—ฌ ๋ณด์•ˆ์„ ๊ฐ•ํ™”ํ•˜๋Š” ๋””์ง€ํ„ธ ์ธ์ฆ์„œ์ž…๋‹ˆ๋‹ค.

ํ˜„์žฌ๋Š” TLS(Transport Layer Security) ํ”„๋กœํ† ์ฝœ์ด ํ‘œ์ค€์œผ๋กœ ์‚ฌ์šฉ๋˜์ง€๋งŒ, ์ผ๋ฐ˜์ ์œผ๋กœ "SSL ์ธ์ฆ์„œ"๋ผ๋Š” ์šฉ์–ด๋ฅผ ๊ด€์šฉ์ ์œผ๋กœ ์‚ฌ์šฉํ•˜๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค.

SSL ์ธ์ฆ์„œ๋ฅผ ์ ์šฉํ•˜๋ฉด ์›น์‚ฌ์ดํŠธ URL์ด https://๋กœ ํ‘œ์‹œ๋˜๋ฉฐ, ๋ธŒ๋ผ์šฐ์ €์—์„œ ์ž๋ฌผ์‡  ์•„์ด์ฝ˜๐Ÿ”’์ด ๋‚˜ํƒ€๋‚˜ ์•ˆ์ „ํ•œ ์—ฐ๊ฒฐ์ž„์„ ์•Œ๋ฆฝ๋‹ˆ๋‹ค.

๋ฐ์ดํ„ฐ ๋ณด์•ˆ, ๊ฐœ์ธ์ •๋ณด ๋ณดํ˜ธ, ์›น์‚ฌ์ดํŠธ ์‹ ๋ขฐ์„ฑ ํ–ฅ์ƒ์— ํ•„์ˆ˜์ ์ธ ์š”์†Œ์ด๋ฉฐ
๊ด€๋ จ ๋ฒ•๋ น์— ๋”ฐ๋ผ ๊ฐœ์ธ์ •๋ณด๋ฅผ ์ทจ๊ธ‰ํ•˜๋Š” ๋ชจ๋“  ์‚ฌ์ดํŠธ๋Š” ๋ณด์•ˆ์„œ๋ฒ„๋ฅผ ๊ตฌ์ถ•ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

๐Ÿ“Œ SSL ์ธ์ฆ์„œ ๊ตฌ์กฐโ€‹

ํ‚ค(Key), ์ธ์ฆ์„œ (PEM), ์ฒด์ธ์ธ์ฆ์„œ(Chain), ๋ฃจํŠธ CA ์ธ์ฆ์„œ (Root CA)

โœ… Key (Private Key)
SSL/TLS ์•”ํ˜ธํ™”์˜ ํ•ต์‹ฌ ์š”์†Œ๋กœ, ๋ฐ์ดํ„ฐ ์•”ํ˜ธํ™” ๋ฐ ์ธ์ฆ์„œ ์„œ๋ช…์— ์‚ฌ์šฉ๋˜๋Š” ๋น„๋ฐ€ํ‚ค
์ธ์ฆ์„œ๋ฅผ ์„ค์น˜ํ•  ๋•Œ ์„œ๋ฒ„(์›น ์„œ๋ฒ„ ๋˜๋Š” ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜)์—๋งŒ ๋ณด๊ด€ํ•ด์•ผ ํ•˜๋ฉฐ, ์ ˆ๋Œ€ ์™ธ๋ถ€๋กœ ๋…ธ์ถœ๋˜๋ฉด ์•ˆ ๋จ ๋ณดํ†ต .key ํ™•์žฅ์ž๋ฅผ ๊ฐ€์ง€๋ฉฐ, RSA ๋˜๋Š” ECDSA ๋ฐฉ์‹์œผ๋กœ ์ƒ์„ฑ๋จ

ex)

-----BEGIN RSA PRIVATE KEY-----
MIIEowIBAAKCAQEA...
-----END RSA PRIVATE KEY-----

โœ… PEM(Privacy Enhanced Mail - Certificate File)
์„œ๋ช…๋œ ๊ณต๊ฐœํ‚ค(Public Key) ๋ฐ ๋„๋ฉ”์ธ ์ •๋ณด๊ฐ€ ํฌํ•จ๋œ ์ธ์ฆ์„œ ํŒŒ์ผ ์„œ๋ฒ„์— ์„ค์น˜ํ•˜์—ฌ ํด๋ผ์ด์–ธํŠธ๊ฐ€ ๊ฒ€์ฆ ํ• ์ˆ˜ ์žˆ๋„๋ก ๊ณต๊ฐœ ์ œ๊ณต SSL ์ธ์ฆ์„œ๋Š” ์ผ๋ฐ˜์ ์œผ๋กœ PEM(Privacy Enhanced Mail) ํ˜•์‹์œผ๋กœ ์ €์žฅ๋˜๋ฉฐ, .pem, .crt, .cer ๋“ฑ์˜ ํ™•์žฅ์ž๋ฅผ ๊ฐ€์ง

ex)

-----BEGIN CERTIFICATE-----
MIIGJzC......
-----END CERTIFICATE-----

โœ… Chain (์ฒด์ธ ์ธ์ฆ์„œ, Intermediate CA Certificate)
SSL ์ธ์ฆ์„œ๊ฐ€ ์ตœ์ƒ์œ„ ๋ฃจํŠธ CA๋กœ๋ถ€ํ„ฐ ์‹ ๋ขฐ์„ฑ์„ ์ฆ๋ช…๋ฐ›๊ธฐ ์œ„ํ•œ ์—ฐ๊ฒฐ๊ณ ๋ฆฌ ์—ญํ• 
SSL ์ธ์ฆ์„œ๋Š” ์ผ๋ฐ˜์ ์œผ๋กœ ์ง์ ‘ ๋ฃจํŠธ CA์—์„œ ๋ฐœ๊ธ‰๋˜์ง€ ์•Š๊ณ , ์ค‘๊ฐ„ ์ธ์ฆ๊ธฐ๊ด€(Intermediate CA)์„ ํ†ตํ•ด ๋ฐœ๊ธ‰๋จ
์ฒด์ธ ์ธ์ฆ์„œ๋ฅผ ์‚ฌ์šฉํ•˜๋ฉด ๋ธŒ๋ผ์šฐ์ €์™€ ์„œ๋ฒ„ ๊ฐ„์˜ ์‹ ๋ขฐ์„ฑ์„ ๋ณด์žฅํ•  ์ˆ˜ ์žˆ์Œ

โœ… Root CA (Root Certificate Authority)
SSL ์ธ์ฆ์„œ๋ฅผ ๋ฐœ๊ธ‰ํ•˜๋Š” ์ตœ์ƒ์œ„ ์‹ ๋ขฐ ๊ธฐ๊ด€์—์„œ ๋ฐœํ–‰ํ•˜๋Š” ์ธ์ฆ์„œ
๋ฃจํŠธ CA ์ธ์ฆ์„œ๋Š” ์šด์˜ ์ฒด์ œ(OS)์™€ ๋ธŒ๋ผ์šฐ์ €์— ์‚ฌ์ „ ์„ค์น˜๋˜์–ด ์‹ ๋ขฐ ๋ฆฌ์ŠคํŠธ(Trusted Root Store)์— ํฌํ•จ๋จ
์‹ ๋ขฐํ•  ์ˆ˜ ์žˆ๋Š” ์ธ์ฆ๊ธฐ๊ด€(์˜ˆ: Sectigo, DigiCert, GlobalSign, Verisign)์ด ๊ด€๋ฆฌ

๐Ÿ“Œ SSL ์ธ์ฆ์„œ ์ž‘๋™ ๊ณผ์ •

  1. ํด๋ผ์ด์–ธํŠธ(๋ธŒ๋ผ์šฐ์ €)๊ฐ€ ์›น์‚ฌ์ดํŠธ ์ ‘์† ์‹œ SSL ์ธ์ฆ์„œ๋ฅผ ์š”์ฒญ

  2. ์„œ๋ฒ„๋Š” SSL ์ธ์ฆ์„œ(PEM)์™€ ์ฒด์ธ ์ธ์ฆ์„œ(Chain)๋ฅผ ํด๋ผ์ด์–ธํŠธ์—๊ฒŒ ์ œ๊ณต

  3. ํด๋ผ์ด์–ธํŠธ๋Š” ๊ฐ€์ง€๊ณ  ์žˆ๋Š” ๋ฃจํŠธ CA๋ฅผ ํ™•์ธํ•˜์—ฌ ์ฒด์ธ(Chain of Trust)์„ ๊ฒ€์ฆ

  4. SSL ํ•ธ๋“œ์…ฐ์ดํฌ๊ฐ€ ์™„๋ฃŒ๋˜๋ฉด ์•ˆ์ „ํ•œ HTTPS ํ†ต์‹ ์ด ์‹œ์ž‘๋จ