¢º Apache 1.3.xx + mod_ssl 2.8.xx-1.3.xx ¼³Ä¡°¡À̵å

apache °ø½Ä »çÀÌÆ® http://httpd.apache.org/ ¿¡¼­ ¾ÆÆÄÄ¡ ¼Ò½º¿Í ÀڷḦ Âü°íÇÏ½Ç ¼ö ÀÖ½À´Ï´Ù.
modssl °ø½Ä »çÀÌÆ® http://www.modssl.org/ ¿¡¼­´Â mod_ssl ¼Ò½º¿Í ÀڷḦ Âü°íÇÏ½Ç ¼ö ÀÖ½À´Ï´Ù.

apache 1.3.xx Àº ssl ¸ðµâÀÌ ¾ø´Â ¹öÁ¯ÀÌ¶ó¼­ modssl ¸ðµâÀ» apache ¼Ò½º¿¡ ÆÐÄ¡ÇÏ´Â °ÍÀ¸·Î ¼³Ä¡¸¦ ÁøÇàÇÏ°Ô µË´Ï´Ù. ÀÌ¿Í °°Àº ±âº» ±¸Á¶¿¡¼­ ¾Æ·¡ÀÇ ¼³Ä¡ °úÁ¤À» Âü°í ¹Ù¶ø´Ï´Ù. (·¹µåÇò 8.0 ±â¹Ý¿¡¼­ ¼³Ä¡ Å×½ºÆ® µÇ¾ú½À´Ï´Ù.)

¡Ø Apache 1.3.xx + mod_ssl 2.8.xx-1.3.xx ¼³Ä¡ ¼ø¼­

1. openssl ¸ðµâ ¼³Ä¡
2. ÃֽŠapache ¼Ò½º, mod_ssl ¼Ò½º ¾ò±â
3. mod_ssl ¸ðµâ apache ¼Ò½º »ðÀÔ
4. apache ¼³Á¤´Ü°è(./configure)
5. apache ÄÄÆÄÀÏ(make)
6. apache Å×½ºÆ® ÀÎÁõ¼­ ¼³Ä¡(make certificate)
7. apache ¼³Ä¡(make install)
8. apache ¼³Ä¡ ¿¹½Ã(Apache 1.3.31 + mod_ssl 2.8.19-1.3.31 )

1. openssl ¸ðµâ ¼³Ä¡

¸ÕÀú openssl ¶óÀ̺귯¸®°¡ ¼³Ä¡µÇ¾î ÀÖ¾î¾ß ÇÕ´Ï´Ù.
openssl ¼³Ä¡ ÀÚ·á´Â openssl ¼³Ä¡ °¡À̵带 Âü°íÇØ Áֽñ⠹ٶø´Ï´Ù.

2. ÃֽŠapache ¼Ò½º, mod_ssl ¼Ò½º ¾ò±â

apache ¼Ò½º´Â httpd.apache.org/download.cgi ¿¡¼­ ÃֽйöÁ¯ÀÇ ¼Ò½º¸¦ ¹ÞÀ» ¼ö ÀÖ½À´Ï´Ù.

mod_ssl ¼Ò½º´Â www.modssl.org/source/ ¿¡¼­ ÃֽйöÁ¯ÀÇ ¼Ò½º¸¦ È®ÀÎÇÕ´Ï´Ù. [LATEST] °¡ ºÙ¾îÀÖ´Â ¼Ò½º°¡ ÃֽŠ¼Ò½ºÀÔ´Ï´Ù.

mod_ssl-2.8.18-1.3.31.tar.gz [LATEST] ¼Ò½º°¡ ÀÖÀ» °æ¿ì¿¡ À̰ÍÀº mod_ssl-2.8.18 ¹öÁ¯À̸ç, apache 1.3.31 ¹öÁ¯¿¡ mod_sslÀ» ÆÐÄ¡ÇÏ´Â ¼Ò½ºÀÓÀ» ¶æÇÕ´Ï´Ù. Âü°í¹Ù¶ø´Ï´Ù.
´ëºÎºÐÀÇ °æ¿ì¿¡ apache°¡ ¸ÕÀú ¾÷µ¥ÀÌÆ®µÇ¹Ç·Î, mod_ssl¿¡¼­ Áö¿øÇÏ´Â ÃֽŠ¼Ò½º¿¡ ¸Â´Â ¹öÁ¯ÀÇ apache ¸¦ ¼±ÅÃÇØ ÁÖ½Ã¸é µÇ°Ú½À´Ï´Ù.

3. mod_ssl ¸ðµâ apache ¼Ò½º »ðÀÔ

ÃֽŠmod_ssl ¼Ò½º¿Í ±×¿¡ ¸Â´Â apache ¼Ò½º¸¦ ´Ù¿î¹ÞÀº ÈÄ¿¡ ¾ÐÃàÀ» Ç®°í, Ç®·ÁÁø mod_ssl µð·ºÅ丮¿¡¼­ apache ¼Ò½º mod_ssl ÆÐÄ¡¸¦ ÁøÇàÇÕ´Ï´Ù.
--with-apache ¿É¼ÇÀº ¾ÐÃàÀÌ Ç®·ÁÁø ¾ÆÆÄÄ¡ ¼Ò½º °æ·Î /usr/local/src/apache_1.3.xx ¸¦ ¼³Á¤ÇÕ´Ï´Ù.
--with-ssl ¿É¼ÇÀÇ µð·ºÅ丮¸¦ /usr/local/openssl °ú °°ÀÌ openssl ¼³Ä¡½Ã¿¡ --openssldir ¼³Á¤µÈ µð·ºÅ丮¸¦ ÁöÁ¤ÇØ ÁÝ´Ï´Ù.
--prefix ¿É¼ÇÀº ¾ÆÆÄÄ¡ ¼³Ä¡µÉ °æ·Î /usr/local/apache-ssl ¸¦ ÁöÁ¤ÇØ ÁÝ´Ï´Ù.
./configure \
--with-apache=/usr/local/src/apache_1.3.xx \
--with-ssl=/usr/local/openssl \
--prefix=/usr/local/apache-ssl

4. apache ¼³Á¤´Ü°è(./configure)

apache ¼Ò½º ÄÄÆÄÀÏ ¼³Á¤Àü¿¡ SSL ¶óÀ̺귯¸® º¯¼ö ¿É¼ÇÀ» ¸ÕÀú Àâ¾ÆÁÝ´Ï´Ù.
SSL_BASE=/usr/local/openssl
export SSL_BASE
LDFLAGS=-L/usr/local/openssl/lib
export LDFLAGS
CPPFLAGS=-I/usr/local/openssl/include
export CPPFLAGS
apache ¼Ò½º µð·ºÅ丮·Î À̵¿À» ÇÕ´Ï´Ù. apache ¼Ò½º´Â mod_ssl ÆÐÄ¡°¡ µÇ¾úÀ¸¸ç, apache ÄÄÆÄÀÏ ¼³Á¤ ÁøÇàÇÕ´Ï´Ù.
apache ¼Ò½º ¼³Ä¡¿¡´Â µÎ°¡Áö ¹æ½ÄÀ¸·Î ¸ðµâÀ» ¼³Ä¡ÇÒ ¼ö ÀÖ½À´Ï´Ù. statically linking module, DSO(Dynamic Shared Objects) module ¸ðµâ·Î ¼³Ä¡ÇÒ ¼ö ÀÖ½À´Ï´Ù.
Á¤Àû¼³Ä¡¿Í µ¿Àû¼³Ä¡¿¡ ´ëÇÑ ¹®¼­´Â ¾ÆÆÄÄ¡ ¹®¼­¸¦ Âü°íÇØ Áֽùٶø´Ï´Ù.

--prefix ¿É¼ÇÀº ¾ÆÆÄÄ¡ ¼³Ä¡ µð·ºÅ丮¸¦ ¼³Á¤ÇÕ´Ï´Ù.
--enable-module=ssl ¿É¼ÇÀ¸·Î ssl ¸ðµâÀ» ¼³Ä¡ÇÏ´Â °ÍÀ» ¼³Á¤ÇÕ´Ï´Ù.
1. statically linking module ·Î mod_ssl ¸ðµâ ¼³Ä¡
--disable-shared=ssl ¿É¼ÇÀº ssl ¸ðµâÀ» Á¤ÀûÀ¸·Î ¸µÅ©½ÃŰ´Â °ÍÀ» ÁöÁ¤ÇÕ´Ï´Ù.
±× ¹ÛÀÇ ¸ðµâ°ú ¼³Á¤ ¿É¼ÇµéÀ» ´õ Ãß°¡ÇϽðí, ¼³Á¤À» ÁøÇàÇÕ´Ï´Ù.
./configure \
--prefix=/usr/local/apache-ssl \
--enable-module=ssl \
--disable-shared=ssl \
...

2. DSO(Dynamic Shared Objects) module ·Î mod_ssl ¸ðµâ ¼³Ä¡
--enable-shared=ssl ¿É¼ÇÀº ssl ¸ðµâÀ» µ¿ÀûÀ¸·Î ¸µÅ©½ÃŰ´Â °ÍÀ» ÁöÁ¤ÇÕ´Ï´Ù.
±× ¹ÛÀÇ ¸ðµâ°ú ¼³Á¤ ¿É¼ÇµéÀ» ´õ Ãß°¡ÇϽðí, ¼³Á¤À» ÁøÇàÇÕ´Ï´Ù.
./configure \
--prefix=/usr/local/apache-ssl \
--enable-module=ssl \
--enable-shared=ssl \
...

5. apache ÄÄÆÄÀÏ(make)

ÄÄÆÄÀÏÀ» ÁøÇàÇÕ´Ï´Ù.
make

6. apache Å×½ºÆ® ÀÎÁõ¼­ ¼³Ä¡(make certificate)

apache 1.3.xx ´Â ¼³Ä¡½Ã¿¡ Å×½ºÆ® ÀÎÁõ¼­ ¼³Ä¡¸¦ µµ¿Í ÁÝ´Ï´Ù. Å×½ºÆ® ÀÎÁõ¼­¸¦ ¼³Ä¡ÇÕ´Ï´Ù. (ÆÄ¶õ»öÀ¸·Î Ç¥½ÃµÈ °ÍÀÌ ÀÔ·ÂµÈ ¹®ÀÚÀÔ´Ï´Ù.)
À̺κÐÀº CSR »ý¼º °¡ÀÌµå ¹®¼­¸¦ Âü°íÇϽøé ÁÁ½À´Ï´Ù.
make certificate TYPE=test
...
STEP 0: Decide the signature algorithm used for certificate
The generated X.509 CA certificate can contain either
RSA or DSA based ingredients. Select the one you want to use.
Signature Algorithm ((R)SA or (D)SA) [R]:R

STEP 1: Generating RSA private key (1024 bit) [server.key] ...
STEP 2: Generating X.509 certificate signing request [server.csr] ... 1. Country Name (2 letter code) [XY]:KR 2. State or Province Name (full name) [Snake Desert]:seoul 3. Locality Name (eg, city) [Snake Town]:seoul 4. Organization Name (eg, company) [Snake Oil, Ltd]:Dotname Korea 5. Organizational Unit Name (eg, section) [Webserver Team]:Digital Certificate Team 6. Common Name (eg, FQDN) [www.snakeoil.dom]:www.anycert.co.kr 7. Email Address (eg, name@FQDN) [www@snakeoil.dom]:(Àû´çÇÑ À̸ÞÀÏ ÁÖ¼Ò¸¦ ³Ö¾îÁÖ¼¼¿ä) 8. Certificate Validity (days) [365]:365
STEP 3: Generating X.509 certificate signed by Snake Oil CA [server.crt] Certificate Version (1 or 3) [3]:3 ... STEP 4: Enrypting RSA private key with a pass phrase for security [server.key] The contents of the server.key file (the generated private key) has to be kept secret. So we strongly recommend you to encrypt the server.key file with a Triple-DES cipher and a Pass Phrase. Encrypt the private key now? [Y/n]: y writing RSA key Enter PEM pass phrase: (Àû´çÇÑ Å×½ºÆ® ºñ¹Ð¹øÈ£) Verifying - Enter PEM pass phrase: (Àû´çÇÑ Å×½ºÆ® ºñ¹Ð¹øÈ£) Fine, you're using an encrypted RSA private key. ...

7. apache ¼³Ä¡(make install)

apache ¸¦ ¼³Ä¡ÇÕ´Ï´Ù.
make install
apache ÄÄÆÄÀÏ ¿ÀºêÁ§Æ®µéÀ» »èÁ¦ÇÕ´Ï´Ù.
make clean
apache ÄÄÆÄÀÏ SSL ¿É¼Ç º¯¼öµéÀ» ÇØÁ¦ÇÕ´Ï´Ù.
unset SSL_BASE
unset LDFLAGS
unset CPPFLAGS

8. apache ¼³Ä¡ ¿¹½Ã(Apache 1.3.31 + mod_ssl 2.8.19-1.3.31 )

(¸®´ª½º ·¹µåÇò 8.0 ÀÌ»ó ±âÁØ ¼³Ä¡ ¿¹½ÃÀÔ´Ï´Ù.)
¢Ã
[root@web1 root]# cd /usr/local/src
[root@web1 src]# wget http://www.modssl.org/source/mod_ssl-2.8.19-1.3.31.tar.gz
[root@web1 src]# wget http://ftp.apache-kr.org/httpd/apache_1.3.31.tar.gz
[root@web1 src]# tar zxf mod_ssl-2.8.19-1.3.31.tar.gz
[root@web1 src]# tar zxf apache_1.3.31.tar.gz
[root@web1 src]# cd mod_ssl-2.8.19-1.3.31
[root@web1 mod_ssl-2.8.19-1.3.31]# ./configure \
> --with-apache=/usr/local/src/apache_1.3.31 \
> --with-ssl=/usr/local/openssl \
> --prefix=/usr/local/apache-ssl
...
[root@web1 mod_ssl-2.8.19-1.3.31]# cd /usr/local/src/apache_1.3.31
[root@web1 apache_1.3.31]# SSL_BASE=/usr/local/openssl
[root@web1 apache_1.3.31]# export SSL_BASE
[root@web1 apache_1.3.31]# LDFLAGS=-L/usr/local/openssl/lib
[root@web1 apache_1.3.31]# export LDFLAGS
[root@web1 apache_1.3.31]# CPPFLAGS=-I/usr/local/openssl/include
[root@web1 apache_1.3.31]# export CPPFLAGS
[root@web1 apache_1.3.31]# ./configure \
> --prefix=/usr/local/apache-ssl \
> --enable-module=ssl \
...
[root@web1 apache_1.3.31]# make
[root@web1 apache_1.3.31]# make certificate TYPE=test
...
[root@web1 apache_1.3.31]# make install
[root@web1 apache_1.3.31]# make clean
¼­¿ï½Ã °­³²±¸ ¿ª»ï1µ¿ 830-71 ÀÎÁ¤ºôµù 4Ãþ Tel.02-566-0023
Copyright 2001-2012 Dotname Korea Corp. All Rights Reserved.