[OpenSSL/Apache] ์‚ฌ์„ค ์ธ์ฆ์„œ(Self-Signed Certificate) ์ƒ์„ฑ ๋ฐ ์ ์šฉ ์™„๋ฒฝ ๊ฐ€์ด๋“œ

๊ฐœ๋ฐœ ๋ฐ ํ…Œ์ŠคํŠธ ํ™˜๊ฒฝ์˜ HTTPS ๊ตฌํ˜„์„ ์œ„ํ•ด OpenSSL๋กœ ์‚ฌ์„ค ์ธ์ฆ์„œ๋ฅผ ์ƒ์„ฑํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ์ •๋ฆฌํ•ฉ๋‹ˆ๋‹ค. ์‹ค๋ฌด์—์„œ ํ˜ผ๋™ํ•˜๊ธฐ ์‰ฌ์šด Key, CSR, CRT ํŒŒ์ผ์˜ ์ •ํ™•ํ•œ ์—ญํ•  ์ •์˜๋ถ€ํ„ฐ, ๊ฐœ์ธํ‚ค ํŒจ์Šค์›Œ๋“œ ์ œ๊ฑฐ ๋ฐ Apache ์ ์šฉ๊นŒ์ง€์˜ ์ „์ฒด ํ”„๋กœ์„ธ์Šค๋ฅผ ๋‹ค๋ฃน๋‹ˆ๋‹ค.

0. ๋ฐฐ๊ฒฝ ์ง€์‹: ์ธ์ฆ์„œ ํŒŒ์ผ์˜ ์ข…๋ฅ˜์™€ ์—ญํ• 

SSL ์ธ์ฆ์„œ ๋ฐœ๊ธ‰ ๊ณผ์ •์€ ๊ฐœ์ธํ‚ค ์ƒ์„ฑ → ์ธ์ฆ ์š”์ฒญ(CSR) → ์ธ์ฆ์„œ ๋ฐœ๊ธ‰(CRT)์˜ ์ˆœ์„œ๋กœ ์ง„ํ–‰๋ฉ๋‹ˆ๋‹ค. ๊ฐ ๋‹จ๊ณ„์—์„œ ์ƒ์„ฑ๋˜๋Š” ํŒŒ์ผ์˜ ์—ญํ• ์„ ๋ช…ํ™•ํžˆ ์ดํ•ดํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

  • 1. Private Key (.key):
    • ์„œ๋ฒ„๊ฐ€ ๊ฐ–๋Š” ๋น„๋ฐ€ ์—ด์‡ ์ž…๋‹ˆ๋‹ค. ๋ฐ์ดํ„ฐ๋ฅผ ์•”ํ˜ธํ™”/๋ณตํ˜ธํ™”ํ•˜๋Š” ํ•ต์‹ฌ ํŒŒ์ผ๋กœ, ์ ˆ๋Œ€ ์™ธ๋ถ€๋กœ ์œ ์ถœ๋˜์–ด์„œ๋Š” ์•ˆ ๋ฉ๋‹ˆ๋‹ค.
    • ์ด ํ‚ค๋ฅผ ๋ถ„์‹คํ•˜๋ฉด ์ธ์ฆ์„œ๋ฅผ ์žฌ๋ฐœ๊ธ‰๋ฐ›์•„์•ผ ํ•ฉ๋‹ˆ๋‹ค.
  • 2. CSR (.csr - Certificate Signing Request):
    • ์ธ์ฆ ๊ธฐ๊ด€(CA)์— "๋‚ด ์ธ์ฆ์„œ๋ฅผ ๋งŒ๋“ค์–ด ๋‹ฌ๋ผ"๊ณ  ๋ณด๋‚ด๋Š” ์‹ ์ฒญ์„œ์ž…๋‹ˆ๋‹ค.
    • ๊ณต๊ฐœํ‚ค(Public Key) ์ •๋ณด์™€ ๋„๋ฉ”์ธ, ํšŒ์‚ฌ ์ •๋ณด(DN)๊ฐ€ ํฌํ•จ๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค.
  • 3. Certificate (.crt):
    • ์ตœ์ข…์ ์œผ๋กœ ๋ฐœ๊ธ‰๋œ ์ธ์ฆ์„œ(์‹ ๋ถ„์ฆ)์ž…๋‹ˆ๋‹ค.
    • CSR ๋‚ด์šฉ์„ ๋ฐ”ํƒ•์œผ๋กœ CA(ํ˜น์€ ๋ณธ์ธ)๊ฐ€ ์ „์ž ์„œ๋ช…์„ ํ•œ ํŒŒ์ผ์ด๋ฉฐ, ํด๋ผ์ด์–ธํŠธ(๋ธŒ๋ผ์šฐ์ €)์—๊ฒŒ ์ „์†ก๋ฉ๋‹ˆ๋‹ค.

Test Environment

  • OS: CentOS 7.2
  • Web Server: Apache HTTP Server
  • Tool: OpenSSL

1. ๊ฐœ์ธํ‚ค(Private Key) ์ƒ์„ฑ

๊ฐ€์žฅ ๋จผ์ € ๋ชจ๋“  ์•”ํ˜ธํ™” ํ†ต์‹ ์˜ ๊ธฐ๋ฐ˜์ด ๋˜๋Š” ๊ฐœ์ธํ‚ค๋ฅผ ์ƒ์„ฑํ•ฉ๋‹ˆ๋‹ค.

1) ์•”ํ˜ธํ™”๋œ ๊ฐœ์ธํ‚ค ์ƒ์„ฑ

des3 ์•Œ๊ณ ๋ฆฌ์ฆ˜์„ ์‚ฌ์šฉํ•˜์—ฌ 2048๋น„ํŠธ ๊ธธ์ด์˜ RSA ํ‚ค๋ฅผ ์ƒ์„ฑํ•ฉ๋‹ˆ๋‹ค. ์ด๋•Œ ์„ค์ •ํ•˜๋Š” ํŒจ์Šค์›Œ๋“œ(Pass Phrase)๋Š” ํ‚ค๋ฅผ ๋ณดํ˜ธํ•˜๊ธฐ ์œ„ํ•œ ์žฅ์น˜์ž…๋‹ˆ๋‹ค.

[root@web01 test]# openssl genrsa -des3 -out test.vn.key 2048

Generating RSA private key, 2048 bit long modulus
..........................+++
e is 65537 (0x10001)
Enter pass phrase for test.vn.key: [ํŒจ์Šค์›Œ๋“œ ์ž…๋ ฅ]
Verifying - Enter pass phrase for test.vn.key: [ํŒจ์Šค์›Œ๋“œ ํ™•์ธ]

2) ๊ฐœ์ธํ‚ค ํŒจ์Šค์›Œ๋“œ ์ œ๊ฑฐ (ํ•„์ˆ˜ ๊ถŒ์žฅ)

ํŒจ์Šค์›Œ๋“œ๊ฐ€ ๊ฑธ๋ฆฐ ํ‚ค๋ฅผ ์›น ์„œ๋ฒ„์— ๊ทธ๋Œ€๋กœ ์ ์šฉํ•˜๋ฉด, ์„œ๋ฒ„๊ฐ€ ์žฌ๊ธฐ๋™๋  ๋•Œ๋งˆ๋‹ค ๊ด€๋ฆฌ์ž๊ฐ€ ๋งค๋ฒˆ ํŒจ์Šค์›Œ๋“œ๋ฅผ ์ž…๋ ฅํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ์ž๋™ ์šด์˜์„ ์œ„ํ•ด ํŒจ์Šค์›Œ๋“œ๋ฅผ ์ œ๊ฑฐํ•œ ํ‚ค๋ฅผ ๋‹ค์‹œ ์ƒ์„ฑํ•ฉ๋‹ˆ๋‹ค.

# 1. ์›๋ณธ ํ‚ค ๋ฐฑ์—…
cp test.vn.key test.vn.key.orig

# 2. ํŒจ์Šค์›Œ๋“œ๊ฐ€ ์ œ๊ฑฐ๋œ ํ‚ค ์ƒ์„ฑ (๋ฎ์–ด์“ฐ๊ธฐ)
openssl rsa -in test.vn.key.orig -out test.vn.key

# ๊ฒฐ๊ณผ ๋ฉ”์‹œ์ง€
Enter pass phrase for test.vn.key.orig: [๊ธฐ์กด ํŒจ์Šค์›Œ๋“œ ์ž…๋ ฅ]
writing RSA key

2. ์ธ์ฆ ์š”์ฒญ์„œ(CSR) ์ƒ์„ฑ

์ƒ์„ฑ๋œ ๊ฐœ์ธํ‚ค(.key)๋ฅผ ๋ฐ”ํƒ•์œผ๋กœ ์ธ์ฆ์„œ ๋ฐœ๊ธ‰ ์‹ ์ฒญ์„œ(.csr)๋ฅผ ์ž‘์„ฑํ•ฉ๋‹ˆ๋‹ค.

CSR ์ƒ์„ฑ ๋ช…๋ น์–ด

openssl req -new -key test.vn.key -out test.vn.csr

์ฃผ์š” ์ž…๋ ฅ ์ •๋ณด (DN: Distinguished Name)

๋ช…๋ น ์‹คํ–‰ ํ›„ ์ž…๋ ฅํ•ด์•ผ ํ•  ์ •๋ณด์ž…๋‹ˆ๋‹ค. ๋‹ค๋ฅธ ์ •๋ณด๋Š” ์ž„์˜๋กœ ์ž…๋ ฅํ•ด๋„ ๋˜์ง€๋งŒ, Common Name์€ ๋ฐ˜๋“œ์‹œ ์ •ํ™•ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

  • Country Name: ๊ตญ๊ฐ€ ์ฝ”๋“œ (์˜ˆ: KR, VN)
  • State / Locality: ์ง€์—ญ ์ •๋ณด (์˜ˆ: Seoul)
  • Organization: ํšŒ์‚ฌ๋ช…/๋ถ€์„œ๋ช… (์˜ˆ: IT Team)
  • Common Name (CN): ์„œ๋น„์Šค ๋„๋ฉ”์ธ ์ฃผ์†Œ (๊ฐ€์žฅ ์ค‘์š”! ์˜ˆ: *.test.vn)
Note: ์ถ”๊ฐ€ ์ •๋ณด์ธ 'Challenge password' ๋“ฑ์€ ์ž…๋ ฅํ•˜์ง€ ์•Š๊ณ  Enter๋ฅผ ๋ˆŒ๋Ÿฌ ๋„˜์–ด๊ฐ€๋„ ๋ฌด๋ฐฉํ•ฉ๋‹ˆ๋‹ค.

3. ์‚ฌ์„ค ์ธ์ฆ์„œ(CRT) ์ƒ์„ฑ (Self-Signing)

์šฐ๋ฆฌ๋Š” ๊ณต์ธ ์ธ์ฆ ๊ธฐ๊ด€(VeriSign ๋“ฑ)์ด ์—†์œผ๋ฏ€๋กœ, ์ƒ์„ฑํ•œ CSR์— ๋‚ด ๊ฐœ์ธํ‚ค๋กœ ์ง์ ‘ ์„œ๋ช…(Self-Sign)ํ•˜์—ฌ ์ธ์ฆ์„œ(CRT)๋ฅผ ๋งŒ๋“ญ๋‹ˆ๋‹ค.

์ธ์ฆ์„œ ์ƒ์„ฑ

์œ ํšจ๊ธฐ๊ฐ„์„ 365์ผ๋กœ ์„ค์ •ํ•˜์—ฌ ์ตœ์ข… ์ธ์ฆ์„œ๋ฅผ ์ƒ์„ฑํ•ฉ๋‹ˆ๋‹ค.

# -req : CSR์„ ์ž…๋ ฅ๋ฐ›์Œ
# -signkey : ์Šค์Šค๋กœ ์„œ๋ช…ํ•  ํ‚ค ์ง€์ •
openssl x509 -req -days 365 -in test.vn.csr -signkey test.vn.key -out test.vn.crt

# ์„ฑ๊ณต ์‹œ ์ถœ๋ ฅ ๋ฉ”์‹œ์ง€
Signature ok
subject=/C=VN/ST=Hanoi/L=lotte/O=admin/OU=admin/CN=*.test.vn
Getting Private key

์ตœ์ข… ํŒŒ์ผ ํ™•์ธ

์ž‘์—…์ด ์™„๋ฃŒ๋˜๋ฉด ๋‹ค์Œ 3๊ฐœ์˜ ํŒŒ์ผ์ด ์žˆ์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

  • test.vn.key: ๊ฐœ์ธํ‚ค (ํŒจ์Šค์›Œ๋“œ ์ œ๊ฑฐ๋จ, ์„œ๋ฒ„ ์„ค์ •์— ์‚ฌ์šฉ)
  • test.vn.crt: ์ธ์ฆ์„œ (์„œ๋ฒ„ ์„ค์ •์— ์‚ฌ์šฉ)
  • test.vn.csr: ์‹ ์ฒญ์„œ (๋ฐœ๊ธ‰ ์™„๋ฃŒ ํ›„์—๋Š” ๋ถˆํ•„์š”)

4. Apache ์„ค์ • ๋ฐ ๊ฒ€์ฆ

์ƒ์„ฑ๋œ ํ‚ค์™€ ์ธ์ฆ์„œ๋ฅผ Apache ์„ค์ • ํŒŒ์ผ(httpd.conf ๋˜๋Š” ssl.conf)์— ๋“ฑ๋กํ•˜์—ฌ HTTPS๋ฅผ ํ™œ์„ฑํ™”ํ•ฉ๋‹ˆ๋‹ค.

์„ค์ • ์ ์šฉ

# SSL ์—”์ง„ ํ™œ์„ฑํ™”
SSLEngine on

# 1. ์ธ์ฆ์„œ ํŒŒ์ผ ๊ฒฝ๋กœ ์ง€์ • (.crt)
SSLCertificateFile /etc/httpd/conf/ssl/test.vn.crt

# 2. ๊ฐœ์ธํ‚ค ํŒŒ์ผ ๊ฒฝ๋กœ ์ง€์ • (.key)
SSLCertificateKeyFile /etc/httpd/conf/ssl/test.vn.key

๊ฒ€์ฆ (Verification)

Apache๋ฅผ ์žฌ๊ธฐ๋™ํ•˜๊ณ  ๋ธŒ๋ผ์šฐ์ €๋กœ ์ ‘์†ํ•ด ๋ด…๋‹ˆ๋‹ค. ํŒจ์Šค์›Œ๋“œ๋ฅผ ๋ฌป์ง€ ์•Š๊ณ  ๊ธฐ๋™๋˜์–ด์•ผ ์ •์ƒ์ž…๋‹ˆ๋‹ค.

  1. ์žฌ๊ธฐ๋™: systemctl restart httpd
  2. ๋ธŒ๋ผ์šฐ์ € ์ ‘์†: https://test.vn
์ฃผ์˜ (Warning):
์‚ฌ์„ค ์ธ์ฆ์„œ๋Š” ๋ธŒ๋ผ์šฐ์ €๊ฐ€ ์‹ ๋ขฐํ•˜๋Š” ๊ธฐ๊ด€(CA) ๋ชฉ๋ก์— ์—†์œผ๋ฏ€๋กœ, ์ ‘์† ์‹œ "์ฃผ์˜ ์š”ํ•จ" ๋˜๋Š” "์•ˆ์ „ํ•˜์ง€ ์•Š์Œ" ๊ฒฝ๊ณ ๊ฐ€ ๋œจ๋Š” ๊ฒƒ์ด ์ •์ƒ์ž…๋‹ˆ๋‹ค. ํ…Œ์ŠคํŠธ ํ™˜๊ฒฝ์—์„œ๋Š” ์˜ˆ์™ธ๋ฅผ ์ถ”๊ฐ€ํ•˜์—ฌ ์ง„ํ–‰ํ•˜๋ฉด ๋ฉ๋‹ˆ๋‹ค.

[IBM HTTPServer] SSL(HTTPS) ๊ตฌ์„ฑ ๋ฐ ๊ฐ€์ƒ ํ˜ธ์ŠคํŠธ ์„ค์ • ๊ฐ€์ด๋“œ

IBM HTTP Server(IHS)์— SSL ์ธ์ฆ์„œ๋ฅผ ์ ์šฉํ•˜์—ฌ HTTPS ํ†ต์‹ ์„ ํ™œ์„ฑํ™”ํ•˜๊ณ , WebSphere Application Server(WAS)์™€ ์ •์ƒ์ ์œผ๋กœ ์—ฐ๋™ํ•˜๊ธฐ ์œ„ํ•œ ์„ค์ • ์ ˆ์ฐจ๋ฅผ ์ •๋ฆฌํ•ฉ๋‹ˆ๋‹ค. httpd.conf ์„ค์ •, ํ‚ค ํŒŒ์ผ(KDB) ์ง€์ •, ๊ทธ๋ฆฌ๊ณ  WAS ๊ฐ€์ƒ ํ˜ธ์ŠคํŠธ ํฌํŠธ ๋“ฑ๋ก ๊ณผ์ •์„ ํฌํ•จํ•ฉ๋‹ˆ๋‹ค.

Test Environment

  • OS: CentOS 7.2 (๊ฒฝ๋กœ๋Š” Linux ๊ธฐ์ค€, Windows๋Š” ๋“œ๋ผ์ด๋ธŒ๋ช… ์ฐธ์กฐ)
  • Web Server: IBM HTTP Server v8.5
  • WAS: WebSphere Application Server v8.5

1. ์›น ์„œ๋ฒ„ ์„ค์ • (httpd.conf)

IHS์˜ ๋ฉ”์ธ ์„ค์ • ํŒŒ์ผ์—์„œ SSL ๋ชจ๋“ˆ์„ ๋กœ๋“œํ•˜๊ณ , 443 ํฌํŠธ์— ๋Œ€ํ•œ VirtualHost๋ฅผ ๊ตฌ์„ฑํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

์„ค์ • ํŒŒ์ผ ์ˆ˜์ •

  • ํŒŒ์ผ ์œ„์น˜: [IHS_ROOT]/conf/httpd.conf
  • ์ฃผ์š” ์ž‘์—…: ๋ชจ๋“ˆ ์ฃผ์„ ํ•ด์ œ, ํฌํŠธ ๋ฆฌ์Šจ, ์ธ์ฆ์„œ ํ‚ค ํŒŒ์ผ(KDB) ๊ฒฝ๋กœ ์ง€์ •
### 1. SSL Module Load ###
LoadModule ibm_ssl_module modules/mod_ibm_ssl.so

### 2. Port Listen ###
Listen 0.0.0.0:443

### 3. Virtual Host Configuration ###
# 80 ํฌํŠธ (HTTP) ์„ค์ •
<VirtualHost *:80>
    ServerName ad1.test.com
    DocumentRoot "/opt/IBM/HTTPServer/htdocs"
    # Redirect permanent / https://ad1.test.com/  (ํ•„์š” ์‹œ HTTPS๋กœ ๋ฆฌ๋‹ค์ด๋ ‰ํŠธ)
</VirtualHost>

# 443 ํฌํŠธ (HTTPS) ์„ค์ •
<VirtualHost *:443>
    SSLEnable
    SSLClientAuth none
    ServerName ad1.test.com
    DocumentRoot "/opt/IBM/HTTPServer/htdocs"
    
    # ๋กœ๊ทธ ์„ค์ • (๊ถŒ์žฅ)
    ErrorLog logs/ssl_error_log
    CustomLog logs/ssl_access_log common
</VirtualHost>

### 4. Global SSL Config ###
# VirtualHost ๋ฐ–์—์„œ ์ „์—ญ ์„ค์ •์œผ๋กœ Keyfile ์ง€์ •
SSLDisable
Keyfile "/opt/IBM/HTTPServer/ssl/key.kdb"

# ๋ณด์•ˆ ๊ฐ•ํ™”๋ฅผ ์œ„ํ•œ ํ”„๋กœํ† ์ฝœ ์„ค์ • ์˜ˆ์‹œ (TLS 1.2๋งŒ ํ—ˆ์šฉ ์‹œ)
# SSLProtocolDisable SSLv2 SSLv3 TLSv10 TLSv11
# SSLProtocolEnable TLSv12

Note: Keyfile ์ง€์‹œ์–ด๋Š” kdb ํŒŒ์ผ์˜ ๊ฒฝ๋กœ๋ฅผ ์ง€์ •ํ•ฉ๋‹ˆ๋‹ค. ํ•ด๋‹น ๊ฒฝ๋กœ์— key.sth (Stash file)์ด ํ•จ๊ป˜ ์กด์žฌํ•ด์•ผ ์•”ํ˜ธ๋ฅผ ๋ฌป์ง€ ์•Š๊ณ  ๊ตฌ๋™๋ฉ๋‹ˆ๋‹ค.


2. ์ธ์ฆ์„œ ํ‚ค ํŒŒ์ผ (KDB) ์ค€๋น„

IHS๋Š” CMS Key Database (.kdb) ํฌ๋งท์„ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค. ikeyman GUI ํˆด์ด๋‚˜ gskcapicmd(CLI)๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๊ฐœ์ธํ‚ค์™€ ์ธ์ฆ์„œ๋ฅผ ๊ด€๋ฆฌํ•ฉ๋‹ˆ๋‹ค.

  • ๋„๊ตฌ ์œ„์น˜: [IHS_ROOT]/bin/ikeyman (GUI ์‹คํ–‰ ์‹œ X-Window ํ•„์š”)
  • ์ž‘์—… ๋‚ด์šฉ:
    • ์ƒˆ๋กœ์šด KDB ํŒŒ์ผ ์ƒ์„ฑ (CMS ํƒ€์ž…)
    • ๊ฐœ์ธํ‚ค ์ƒ์„ฑ (CSR) ๋ฐ ๋ฐœ๊ธ‰๋ฐ›์€ ์ธ์ฆ์„œ(Signer, Personal) Import
    • ์ค‘์š”: "Stash password to a file" ์˜ต์…˜์„ ์ฒดํฌํ•˜์—ฌ .sth ํŒŒ์ผ ์ƒ์„ฑ ํ•„์ˆ˜

3. WAS ๊ฐ€์ƒ ํ˜ธ์ŠคํŠธ (Virtual Host) ๋“ฑ๋ก

์›น ์„œ๋ฒ„ ์„ค์ •์„ ๋งˆ์ณค๋”๋ผ๋„, WAS์˜ ๊ฐ€์ƒ ํ˜ธ์ŠคํŠธ ๋ชฉ๋ก์— SSL ํฌํŠธ(443)๊ฐ€ ๋“ฑ๋ก๋˜์–ด ์žˆ์ง€ ์•Š์œผ๋ฉด ํ”Œ๋Ÿฌ๊ทธ์ธ์ด ์š”์ฒญ์„ ๊ฑฐ๋ถ€ํ•˜๊ฑฐ๋‚˜ WAS๊ฐ€ ์š”์ฒญ์„ ์ธ์‹ํ•˜์ง€ ๋ชปํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

๊ด€๋ฆฌ ์ฝ˜์†” ์„ค์ •

  1. ์œ„์น˜: ํ™˜๊ฒฝ(Environment) > ๊ฐ€์ƒ ํ˜ธ์ŠคํŠธ(Virtual Hosts) > default_host (๋˜๋Š” ์‚ฌ์šฉํ•˜๋Š” ๊ฐ€์ƒ ํ˜ธ์ŠคํŠธ) > ํ˜ธ์ŠคํŠธ ๋ณ„๋ช…(Host Aliases)
  2. ์ž‘์—…: ์ƒˆ๋กœ ์ž‘์„ฑ(New) ํด๋ฆญ
  3. ์ž…๋ ฅ:
    • ํ˜ธ์ŠคํŠธ ์ด๋ฆ„: * (๋ชจ๋“  ํ˜ธ์ŠคํŠธ) ๋˜๋Š” ad1.test.com
    • ํฌํŠธ: 443
  4. ์ €์žฅ: ๋งˆ์Šคํ„ฐ ๊ตฌ์„ฑ์— ์ €์žฅ ํ›„ ๋ณ€๊ฒฝ ์‚ฌํ•ญ ๋™๊ธฐํ™”.

4. ๊ฒ€์ฆ ๋ฐ ์žฌ๊ธฐ๋™

์„ค์ • ํŒŒ์ผ์˜ ๋ฌธ๋ฒ• ์˜ค๋ฅ˜๋ฅผ ์ฒดํฌํ•˜๊ณ  ์›น ์„œ๋ฒ„๋ฅผ ์žฌ๊ธฐ๋™ํ•˜์—ฌ ๋ณ€๊ฒฝ ์‚ฌํ•ญ์„ ์ ์šฉํ•ฉ๋‹ˆ๋‹ค.

Syntax Check

# IHS bin ๋””๋ ‰ํ† ๋ฆฌ๋กœ ์ด๋™
./apachectl -t

# ๊ฒฐ๊ณผ๊ฐ€ 'Syntax OK'์—ฌ์•ผ ํ•จ

Server Restart

./apachectl restart

Next Step:
๋ธŒ๋ผ์šฐ์ €์—์„œ https://ad1.test.com์œผ๋กœ ์ ‘์†ํ•˜์—ฌ ์ž๋ฌผ์‡  ์•„์ด์ฝ˜์ด ์ •์ƒ์ ์œผ๋กœ ํ‘œ์‹œ๋˜๋Š”์ง€ ํ™•์ธํ•˜๊ณ , SSL Labs ๋“ฑ์˜ ๋„๊ตฌ๋ฅผ ํ†ตํ•ด ์ ์šฉ๋œ ์•”ํ˜ธํ™” ํ”„๋กœํ† ์ฝœ(TLS 1.2 ๋“ฑ)์˜ ๋ณด์•ˆ ๋“ฑ๊ธ‰์„ ์ ๊ฒ€ํ•ด๋ณด์‹œ๊ธฐ ๋ฐ”๋ž๋‹ˆ๋‹ค.