30๋…„ 2020์›” XNUMX์ผ ์ดํ›„ Sectigo ์ธ์ฆ์„œ ๋ฌธ์ œ ๋ฐ ํ•ด๊ฒฐ ๋ฐฉ๋ฒ•

30๋…„ 2020์›” XNUMX์ผ ํ† ์š”์ผ, ๊ณต๊ธ‰์—…์ฒด Sectigo(์ด์ „ Comodo)์˜ ๋„๋ฆฌ ์‚ฌ์šฉ๋˜๋Š” SSL/TLS ์ธ์ฆ์„œ์— ์ฆ‰์‹œ ๋ช…ํ™•ํ•˜์ง€ ์•Š์€ ๋ฌธ์ œ๊ฐ€ ๋ฐœ์ƒํ–ˆ์Šต๋‹ˆ๋‹ค. ์ธ์ฆ์„œ ์ž์ฒด๋Š” ๊ณ„์†ํ•ด์„œ ์™„๋ฒฝํ•œ ์ˆœ์„œ๋ฅผ ์œ ์ง€ํ–ˆ์ง€๋งŒ ์ด๋Ÿฌํ•œ ์ธ์ฆ์„œ๊ฐ€ ์ œ๊ณต๋˜๋Š” ์ฒด์ธ์˜ ์ค‘๊ฐ„ CA ์ธ์ฆ์„œ ์ค‘ ํ•˜๋‚˜๊ฐ€ ์ฉ์—ˆ์Šต๋‹ˆ๋‹ค. ์ƒํ™ฉ์€ ์น˜๋ช…์ ์ด์ง€๋Š” ์•Š์ง€๋งŒ ๋ถˆ์พŒํ•ฉ๋‹ˆ๋‹ค. ํ˜„์žฌ ๋ฒ„์ „์˜ ๋ธŒ๋ผ์šฐ์ €๋Š” ์•„๋ฌด๊ฒƒ๋„ ๋ˆˆ์น˜ ์ฑ„์ง€ ๋ชปํ–ˆ์ง€๋งŒ ๋Œ€๋ถ€๋ถ„์˜ ์ž๋™ํ™” ๋ฐ ์ด์ „ ๋ธŒ๋ผ์šฐ์ € / OS๋Š” ๊ทธ๋Ÿฌํ•œ ์ „ํ™˜์— ๋Œ€๋น„ํ•˜์ง€ ๋ชปํ–ˆ์Šต๋‹ˆ๋‹ค.

30๋…„ 2020์›” XNUMX์ผ ์ดํ›„ Sectigo ์ธ์ฆ์„œ ๋ฌธ์ œ ๋ฐ ํ•ด๊ฒฐ ๋ฐฉ๋ฒ•

Habr๋„ ์˜ˆ์™ธ๋Š” ์•„๋‹ˆ์—ˆ๊ณ , ์ด๊ฒƒ์ด ์ด ๊ต์œก ํ”„๋กœ๊ทธ๋žจ/์‚ฌํ›„ ๋ถ„์„์ด ์ž‘์„ฑ๋œ ์ด์œ ์ž…๋‹ˆ๋‹ค.

TL; DR ๋งจ ๋งˆ์ง€๋ง‰์— ์†”๋ฃจ์…˜.

PKI, SSL/TLS, https ๋“ฑ์— ๋Œ€ํ•œ ๊ธฐ๋ณธ ์ด๋ก ์€ ๊ฑด๋„ˆ๋›ฐ์ž. ๋„๋ฉ”์ธ ๋ณด์•ˆ ์ธ์ฆ์„œ๋ฅผ ์‚ฌ์šฉํ•œ ์ธ์ฆ ๋ฉ”์ปค๋‹ˆ์ฆ˜์€ ์†Œ์œ„ Trust Store์— ์ €์žฅ๋˜๋Š” ๋ธŒ๋ผ์šฐ์ € ๋˜๋Š” ์šด์˜ ์ฒด์ œ์—์„œ ์‹ ๋ขฐํ•˜๋Š” ์ธ์ฆ์„œ ์ค‘ ํ•˜๋‚˜์— ๋Œ€ํ•œ ์—ฌ๋Ÿฌ ์ธ์ฆ์„œ ์ฒด์ธ์„ ๊ตฌ์ถ•ํ•˜๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค. ์ด ๋ชฉ๋ก์€ ์šด์˜ ์ฒด์ œ, ์ฝ”๋“œ ๋Ÿฐํƒ€์ž„ ์—์ฝ”์‹œ์Šคํ…œ ๋˜๋Š” ๋ธŒ๋ผ์šฐ์ €์™€ ํ•จ๊ป˜ ๋ฐฐํฌ๋ฉ๋‹ˆ๋‹ค. ๋ชจ๋“  ์ธ์ฆ์„œ์—๋Š” ์‹ ๋ขฐ ์ €์žฅ์†Œ์˜ ์ธ์ฆ์„œ๋ฅผ ํฌํ•จํ•˜์—ฌ ์‹ ๋ขฐํ•  ์ˆ˜ ์—†๋Š” ๊ฒƒ์œผ๋กœ ๊ฐ„์ฃผ๋˜๋Š” ๋งŒ๋ฃŒ ๋‚ ์งœ๊ฐ€ ์žˆ์Šต๋‹ˆ๋‹ค. ์šด๋ช…์˜ ๋‚  ์ด์ „์˜ ์‹ ๋ขฐ์˜ ์‚ฌ์Šฌ์€ ์–ด๋–ค ๋ชจ์Šต์ด์—ˆ์„๊นŒ์š”? ์›น ์œ ํ‹ธ๋ฆฌํ‹ฐ๋Š” ์šฐ๋ฆฌ๊ฐ€ ๊ทธ๊ฒƒ์„ ์•Œ์•„๋‚ด๋Š” ๋ฐ ๋„์›€์ด ๋  ๊ฒƒ์ž…๋‹ˆ๋‹ค SSL ๋ณด๊ณ ์„œ ํ€„๋ฆฌ์Šค์—์„œ.

๋”ฐ๋ผ์„œ ๊ฐ€์žฅ ์ธ๊ธฐ ์žˆ๋Š” "์ƒ์šฉ" ์ธ์ฆ์„œ ์ค‘ ํ•˜๋‚˜๋Š” Sectigo Positive SSL(์ด์ „ Comodo Positive SSL, ์ด ์ด๋ฆ„์„ ๊ฐ€์ง„ ์ธ์ฆ์„œ๋Š” ์—ฌ์ „ํžˆ ์‚ฌ์šฉ ์ค‘์ž„)์ด๋ฉฐ ์†Œ์œ„ DV ์ธ์ฆ์„œ์ž…๋‹ˆ๋‹ค. DV๋Š” ๊ฐ€์žฅ ์›์‹œ์ ์ธ ์ˆ˜์ค€์˜ ์ธ์ฆ์œผ๋กœ, ํ•ด๋‹น ์ธ์ฆ์„œ ๋ฐœ๊ธ‰์ž๊ฐ€ ๋„๋ฉ”์ธ ๊ด€๋ฆฌ์— ๋Œ€ํ•œ ์•ก์„ธ์Šค๋ฅผ ํ™•์ธํ•˜๋Š” ๊ฒƒ์„ ์˜๋ฏธํ•ฉ๋‹ˆ๋‹ค. ์‹ค์ œ๋กœ DV๋Š” "๋„๋ฉ”์ธ ์œ ํšจ์„ฑ ๊ฒ€์‚ฌ"๋ฅผ ๋‚˜ํƒ€๋ƒ…๋‹ˆ๋‹ค. ์ฐธ๊ณ ๋กœ OV(์กฐ์ง ์œ ํšจ์„ฑ ๊ฒ€์‚ฌ)์™€ EV(ํ™•์žฅ ์œ ํšจ์„ฑ ๊ฒ€์‚ฌ)๋„ ์žˆ๊ณ  Let's Encrypt์˜ ๋ฌด๋ฃŒ ์ธ์ฆ์„œ๋„ DV์ž…๋‹ˆ๋‹ค. ์–ด๋–ค ์ด์œ ๋กœ ACME ๋ฉ”์ปค๋‹ˆ์ฆ˜์— ๋งŒ์กฑํ•˜์ง€ ๋ชปํ•˜๋Š” ์‚ฌ๋žŒ๋“ค์—๊ฒŒ๋Š” Positive SSL ์ œํ’ˆ์ด ๊ฐ€๊ฒฉ/๊ธฐ๋Šฅ๋ฉด์—์„œ ๊ฐ€์žฅ ์ ํ•ฉํ•ฉ๋‹ˆ๋‹ค. (๋‹จ์ผ ๋„๋ฉ”์ธ ์ธ์ฆ์„œ๋Š” ์—ฐ๊ฐ„ ์•ฝ 5-7 ๋‹ฌ๋Ÿฌ์ด๋ฉฐ ์ด ์ธ์ฆ์„œ ์œ ํšจ ๊ธฐ๊ฐ„์€ ์ตœ๋Œ€ 2๋…„ 3๊ฐœ์›”).

Sectigo DV ์ผ๋ฐ˜ ์ธ์ฆ์„œ(RSA)๋Š” ์ตœ๊ทผ๊นŒ์ง€ ์ด ์ค‘๊ฐ„ CA ์ฒด์ธ๊ณผ ํ•จ๊ป˜ ์ œ๊ณต๋˜์—ˆ์Šต๋‹ˆ๋‹ค.

Certificate #1:
  Data:
    Version: 3 (0x2)
    Serial Number:
      7d:5b:51:26:b4:76:ba:11:db:74:16:0b:bc:53:0d:a7
    Signature Algorithm: sha384WithRSAEncryption
      Issuer: C=US, ST=New Jersey, L=Jersey City, O=The USERTRUST Network, CN=USERTrust RSA Certification Authority
      Validity
        Not Before: Nov  2 00:00:00 2018 GMT
        Not After : Dec 31 23:59:59 2030 GMT
      Subject: C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo RSA Domain Validation Secure Server CA
Certificate #2:
  Data:
    Version: 3 (0x2)
    Serial Number:
      13:ea:28:70:5b:f4:ec:ed:0c:36:63:09:80:61:43:36
    Signature Algorithm: sha384WithRSAEncryption
      Issuer: C=SE, O=AddTrust AB, OU=AddTrust External TTP Network, CN=AddTrust External CA Root
      Validity
        Not Before: May 30 10:48:38 2000 GMT
        Not After : May 30 10:48:38 2020 GMT
      Subject: C=US, ST=New Jersey, L=Jersey City, O=The USERTRUST Network, CN=USERTrust RSA Certification Authority

AddTrust AB์—์„œ ์ž์ฒด ์„œ๋ช…ํ•œ "์„ธ ๋ฒˆ์งธ ์ธ์ฆ์„œ"๋Š” ์—†์Šต๋‹ˆ๋‹ค. ์–ด๋Š ์‹œ์ ์—์„œ ์ž์ฒด ์„œ๋ช…๋œ ๋ฃจํŠธ ์ธ์ฆ์„œ๋ฅผ ์ฒด์ธ์— ํฌํ•จํ•˜๋Š” ๊ฒƒ์ด ๋‚˜์œ ๋งค๋„ˆ๋กœ ๊ฐ„์ฃผ๋˜๊ธฐ ๋•Œ๋ฌธ์ž…๋‹ˆ๋‹ค. AddTrust์˜ UserTrust์—์„œ ๋ฐœ๊ธ‰ํ•œ ์ค‘๊ฐ„ CA์˜ ๋งŒ๋ฃŒ ๋‚ ์งœ๋Š” 30๋…„ 2020์›” 30์ผ์ž…๋‹ˆ๋‹ค. ์ด CA์— ๋Œ€ํ•œ ํ๊ธฐ ์ ˆ์ฐจ๊ฐ€ ๊ณ„ํš๋˜์—ˆ์œผ๋ฏ€๋กœ ์‰ฝ์ง€ ์•Š์Šต๋‹ˆ๋‹ค. 2020๋…„ XNUMX์›” XNUMX์ผ๊นŒ์ง€ UserTrust์˜ ๊ต์ฐจ ์„œ๋ช…๋œ ์ธ์ฆ์„œ๊ฐ€ ์ด๋•Œ๊นŒ์ง€ ๋ชจ๋“  ํŠธ๋Ÿฌ์ŠคํŠธ ์Šคํ† ์–ด(ํ›„๋“œ ์•„๋ž˜์—์„œ ์ด๊ฒƒ์€ ๋™์ผํ•œ ์ธ์ฆ์„œ ๋˜๋Š” ์˜คํžˆ๋ ค ๊ณต๊ฐœ ํ‚ค์ž„)์™€ ์ฒด์ธ์— ํ‘œ์‹œ๋  ๊ฒƒ์ด๋ผ๊ณ  ๋ฏฟ์—ˆ์Šต๋‹ˆ๋‹ค. ์ด๋ฏธ ์‹ ๋ขฐํ•  ์ˆ˜ ์—†๋Š” ์ธ์ฆ์„œ๊ฐ€ ํฌํ•จ๋˜์–ด ์žˆ์œผ๋ฉด ๋Œ€์ฒด ๊ฒฝ๋กœ๊ฐ€ ๊ตฌ์ถ•๋˜๋ฉฐ ์•„๋ฌด๋„ ์•Œ์•„์ฐจ๋ฆฌ์ง€ ๋ชปํ•ฉ๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ๊ณ„ํš์€ ํ˜„์‹ค, ์ฆ‰ "๋ ˆ๊ฑฐ์‹œ ์‹œ์Šคํ…œ"์ด๋ผ๋Š” ๊ธด ์šฉ์–ด๋กœ ์ถฉ๋Œํ–ˆ์Šต๋‹ˆ๋‹ค. ์‹ค์ œ๋กœ ํ˜„์žฌ ๋ฒ„์ „์˜ ๋ธŒ๋ผ์šฐ์ € ์†Œ์œ ์ž๋Š” ์•„๋ฌด ๊ฒƒ๋„ ๋ˆˆ์น˜ ์ฑ„์ง€ ๋ชปํ–ˆ์ง€๋งŒ ์—ฌ๋Ÿฌ ํ”„๋กœ๊ทธ๋ž˜๋ฐ ์–ธ์–ด ๋ฐ ์ฝ”๋“œ ์‹คํ–‰ ํ™˜๊ฒฝ์˜ curl ๋ฐ ssl / tls ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ๋ฅผ ๊ธฐ๋ฐ˜์œผ๋กœ ๊ตฌ์ถ• ๋œ ์ž๋™ํ™” ์‚ฐ์ด ๊นจ์กŒ์Šต๋‹ˆ๋‹ค. ๋งŽ์€ ์ œํ’ˆ์ด OS์— ๋‚ด์žฅ๋œ ์ฒด์ธ ๊ตฌ์ถ• ๋„๊ตฌ์— ์˜ํ•ด ์•ˆ๋‚ด๋˜์ง€ ์•Š๊ณ  ์‹ ๋ขฐ ์ €์žฅ์†Œ๋ฅผ "์šด๋ฐ˜"ํ•œ๋‹ค๋Š” ์ ์„ ์ดํ•ดํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ๊ทธ๋ฆฌ๊ณ  ๊ทธ๋“ค์ด ๋ณด๊ณ  ์‹ถ์€ ๊ฒƒ์„ ํ•ญ์ƒ ๋‹ด๊ณ  ์žˆ๋Š” ๊ฒƒ์€ ์•„๋‹™๋‹ˆ๋‹ค. CA / ๋ธŒ๋ผ์šฐ์ € ํฌ๋Ÿผ. ๊ทธ๋ฆฌ๊ณ  Linux์—์„œ๋Š” ca-certificates์™€ ๊ฐ™์€ ํŒจํ‚ค์ง€๊ฐ€ ํ•ญ์ƒ ์—…๋ฐ์ดํŠธ๋˜๋Š” ๊ฒƒ์€ ์•„๋‹™๋‹ˆ๋‹ค. ๊ฒฐ๊ตญ ๋ชจ๋“  ๊ฒƒ์ด ์ˆœ์กฐ๋กœ์›Œ ๋ณด์ด์ง€๋งŒ ์—ฌ๊ธฐ์ €๊ธฐ์„œ ๋ญ”๊ฐ€ ์ž˜ ํ’€๋ฆฌ์ง€ ์•Š๋Š”๋‹ค.

๊ทธ๋ฆผ 1์—์„œ ๋Œ€๋ถ€๋ถ„์˜ ์‚ฌ๋žŒ๋“ค์—๊ฒŒ๋Š” ๋ชจ๋“  ๊ฒƒ์ด ์ •์ƒ์œผ๋กœ ๋ณด์˜€์ง€๋งŒ ๋ˆ„๊ตฐ๊ฐ€์—๊ฒŒ๋Š” ๋ฌธ์ œ๊ฐ€ ๋ฐœ์ƒํ•˜์—ฌ ํŠธ๋ž˜ํ”ฝ์ด ๋ˆˆ์— ๋„๊ฒŒ ๊ฐ์†Œํ–ˆ๊ณ (์™ผ์ชฝ ๋นจ๊ฐ„์ƒ‰ ์„ ) ํ‚ค ์ธ์ฆ์„œ ์ค‘ ํ•˜๋‚˜๊ฐ€ ๊ต์ฒด๋˜์—ˆ์„ ๋•Œ ํŠธ๋ž˜ํ”ฝ์ด ์ฆ๊ฐ€ํ–ˆ์Šต๋‹ˆ๋‹ค(์˜ค๋ฅธ์ชฝ ์„ )๋Š” ๊ฒƒ์ด ๋ถ„๋ช…ํ•ฉ๋‹ˆ๋‹ค. ์ค‘๊ฐ„์— ๋ฌด์–ธ๊ฐ€๊ฐ€ ์˜์กดํ•˜๋Š” ๋‹ค๋ฅธ ์ธ์ฆ์„œ๊ฐ€ ๋ณ€๊ฒฝ๋˜์—ˆ์„ ๋•Œ ๋ฒ„์ŠคํŠธ๊ฐ€ ๋ฐœ์ƒํ–ˆ์Šต๋‹ˆ๋‹ค. ๋Œ€๋‹ค์ˆ˜์˜ ๊ฒฝ์šฐ ์‹œ๊ฐ์ ์œผ๋กœ ๋ชจ๋“  ๊ฒƒ์ด ๋‹ค์†Œ ๊ทœ์น™์ ์œผ๋กœ ๊ณ„์† ์ž‘๋™ํ–ˆ๊ธฐ ๋•Œ๋ฌธ์—(Habrastorage์—์„œ ์‚ฌ์ง„์„ ๋กœ๋“œํ•  ์ˆ˜ ์—†๋Š” ๊ฒƒ๊ณผ ๊ฐ™์€ ์ด์ƒํ•œ ๊ฒฐํ•จ์„ ์ œ์™ธํ•˜๊ณ ) Habrรฉ์˜ ๋ ˆ๊ฑฐ์‹œ ํด๋ผ์ด์–ธํŠธ ๋ฐ ๋ด‡ ์ˆ˜์— ๋Œ€ํ•ด ๊ฐ„์ ‘์ ์ธ ๊ฒฐ๋ก ์„ ๋‚ด๋ฆด ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

30๋…„ 2020์›” XNUMX์ผ ์ดํ›„ Sectigo ์ธ์ฆ์„œ ๋ฌธ์ œ ๋ฐ ํ•ด๊ฒฐ ๋ฐฉ๋ฒ•๊ทธ๋ฆผ 1. Habrรฉ์˜ "ํŠธ๋ž˜ํ”ฝ" ๊ทธ๋ž˜ํ”„.

๊ทธ๋ฆผ 2๋Š” ์ฒด์ธ์— "์ฉ์€" ์ธ์ฆ์„œ๊ฐ€ ์žˆ๋Š” ๊ฒฝ์šฐ์—๋„ ํ˜„์žฌ ๋ฒ„์ „์˜ ๋ธŒ๋ผ์šฐ์ €์—์„œ ์‚ฌ์šฉ์ž ๋ธŒ๋ผ์šฐ์ €์˜ ์‹ ๋ขฐํ•  ์ˆ˜ ์žˆ๋Š” CA ์ธ์ฆ์„œ์— ๋Œ€ํ•œ "๋Œ€์ฒด" ์ฒด์ธ์ด ์–ด๋–ป๊ฒŒ ๊ตฌ์ถ•๋˜๋Š”์ง€ ๋ณด์—ฌ์ค๋‹ˆ๋‹ค. ์ด๊ฒƒ์€ Sectigo ์ž์‹ ์ด ๋ฏฟ์—ˆ๋˜ ๊ฒƒ์ฒ˜๋Ÿผ ์•„๋ฌด๊ฒƒ๋„ ํ•˜์ง€ ์•Š๋Š” ๋ฐ”๋กœ ๊ทธ ์ด์œ ์ž…๋‹ˆ๋‹ค.

30๋…„ 2020์›” XNUMX์ผ ์ดํ›„ Sectigo ์ธ์ฆ์„œ ๋ฌธ์ œ ๋ฐ ํ•ด๊ฒฐ ๋ฐฉ๋ฒ•๊ทธ๋ฆผ 2. ์ตœ์‹  ๋ธŒ๋ผ์šฐ์ € ๋ฒ„์ „์˜ ์‹ ๋ขฐํ•  ์ˆ˜ ์žˆ๋Š” ์ธ์ฆ์„œ์— ์—ฐ๊ฒฐ.

๊ทธ๋Ÿฌ๋‚˜ ๊ทธ๋ฆผ 3์—์„œ๋Š” ๋ฌธ์ œ๊ฐ€ ๋ฐœ์ƒํ•˜๊ณ  ๋ ˆ๊ฑฐ์‹œ ์‹œ์Šคํ…œ์ด ์žˆ์„ ๋•Œ ๋ชจ๋“  ๊ฒƒ์ด ์‹ค์ œ๋กœ ์–ด๋–ป๊ฒŒ ๋ณด์ด๋Š”์ง€ ํ™•์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด ๊ฒฝ์šฐ HTTPS ์—ฐ๊ฒฐ์ด ์„ค์ •๋˜์ง€ ์•Š๊ณ  "์ธ์ฆ์„œ ์œ ํšจ์„ฑ ๊ฒ€์‚ฌ ์‹คํŒจ" ๋˜๋Š” ์ด์™€ ์œ ์‚ฌํ•œ ์˜ค๋ฅ˜๊ฐ€ ํ‘œ์‹œ๋ฉ๋‹ˆ๋‹ค.

30๋…„ 2020์›” XNUMX์ผ ์ดํ›„ Sectigo ์ธ์ฆ์„œ ๋ฌธ์ œ ๋ฐ ํ•ด๊ฒฐ ๋ฐฉ๋ฒ•๊ทธ๋ฆผ 3. ๋ฃจํŠธ ์ธ์ฆ์„œ์™€ ์ด์— ์˜ํ•ด ์„œ๋ช…๋œ ์ค‘๊ฐ„ ์ธ์ฆ์„œ๊ฐ€ "์ฉ์—ˆ๊ธฐ" ๋•Œ๋ฌธ์— ์ฒด์ธ์ด ๋ฌดํšจํ™”๋˜์—ˆ์Šต๋‹ˆ๋‹ค.

๊ทธ๋ฆผ 4์—์„œ ์ด๋ฏธ ๋ ˆ๊ฑฐ์‹œ ์‹œ์Šคํ…œ์— ๋Œ€ํ•œ "์†”๋ฃจ์…˜"์„ ๋ณผ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ผ๋ฐ˜์ ์œผ๋กœ ๋ ˆ๊ฑฐ์‹œ ์‹œ์Šคํ…œ์— ์‚ฌ์ „ ์„ค์น˜๋œ ๋˜ ๋‹ค๋ฅธ ์ค‘๊ฐ„ ์ธ์ฆ์„œ ๋˜๋Š” ๋‹ค๋ฅธ CA์˜ "๊ต์ฐจ ์„œ๋ช…"์ด ์žˆ์Šต๋‹ˆ๋‹ค. ํ•ด์•ผ ํ•  ์ผ์€ ์ด ์ธ์ฆ์„œ(์ถ”๊ฐ€ ๋‹ค์šด๋กœ๋“œ๋กœ ํ‘œ์‹œ๋จ)๋ฅผ ์ฐพ์•„ "์ฉ์€" ์ธ์ฆ์„œ๋กœ ๊ต์ฒดํ•˜๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค.

30๋…„ 2020์›” XNUMX์ผ ์ดํ›„ Sectigo ์ธ์ฆ์„œ ๋ฌธ์ œ ๋ฐ ํ•ด๊ฒฐ ๋ฐฉ๋ฒ•๊ทธ๋ฆผ 4. ๋ ˆ๊ฑฐ์‹œ ์‹œ์Šคํ…œ์„ ์œ„ํ•œ ๋Œ€์ฒด ์ฒด์ธ.

๊ทธ๊ฑด ๊ทธ๋ ‡๊ณ , ๋ฌธ์ œ๋Š” Sectigo์˜ ๊ณผ๋„ํ•œ ์˜ค๋งŒํ•จ์„ ํฌํ•จํ•˜์—ฌ ๊ด‘๋ฒ”์œ„ํ•œ ํ™๋ณด์™€ ์ผ์ข…์˜ ๊ณต๊ฐœ ํ† ๋ก ์ด ์—†์—ˆ์Šต๋‹ˆ๋‹ค. ์˜ˆ๋ฅผ ๋“ค์–ด ๋‹ค์Œ์€ ์ธ์ฆ์„œ ์ œ๊ณต์ž ์ค‘ ํ•œ ์‚ฌ๋žŒ์˜ ์˜๊ฒฌ์ž…๋‹ˆ๋‹ค. ์กด์ค‘ ์ด ์ƒํ™ฉ์—:

์ด์ „์— ๊ทธ๋“ค์€ [์„นํ‹ฐ๊ณ ] ๋ฌธ์ œ๊ฐ€ ์—†์„ ๊ฒƒ์ด๋ผ๊ณ  ๋ชจ๋“  ์‚ฌ๋žŒ์—๊ฒŒ ํ™•์‹ ์‹œ์ผฐ์Šต๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ์ผ๋ถ€ ๋ ˆ๊ฑฐ์‹œ ์„œ๋ฒ„/์žฅ์น˜๊ฐ€ ์˜ํ–ฅ์„ ๋ฐ›๋Š” ๊ฒƒ์ด ํ˜„์‹ค์ž…๋‹ˆ๋‹ค.

๋ง๋„ ์•ˆ๋˜๋Š” ์ƒํ™ฉ์ž…๋‹ˆ๋‹ค. ์šฐ๋ฆฌ๋Š” ๋งŒ๋ฃŒ๋˜๋Š” AddTrust RSA/ECC์— ๋Œ€ํ•ด XNUMX๋…„ ์ด๋‚ด์— ์—ฌ๋Ÿฌ ๋ฒˆ ์ฃผ์˜๋ฅผ ํ™˜๊ธฐ์‹œ์ผฐ๊ณ  Sectigo๋Š” ๋งค๋ฒˆ ๋ฌธ์ œ๊ฐ€ ์—†์„ ๊ฒƒ์ด๋ผ๊ณ  ํ™•์‹ ํ–ˆ์Šต๋‹ˆ๋‹ค.

๋‚˜๋Š” ๊ฐœ์ธ์ ์œผ๋กœ ๋ฌผ์—ˆ๋‹ค ๋ฌธ์ œ ํ•œ ๋‹ฌ ์ „์— Stack Overflow์—์„œ ์ด๊ฒƒ์— ๋Œ€ํ•ด ์ด์•ผ๊ธฐํ–ˆ์ง€๋งŒ ํ”„๋กœ์ ํŠธ์˜ ์ฒญ์ค‘์€ ๊ทธ๋Ÿฌํ•œ ์งˆ๋ฌธ์— ์ ํ•ฉํ•˜์ง€ ์•Š์€ ๊ฒƒ ๊ฐ™์•„์„œ ๋ถ„์„ ํ›„ ์ง์ ‘ ๋Œ€๋‹ตํ•ด์•ผํ–ˆ์Šต๋‹ˆ๋‹ค.

์„น ํ‹ฐ๊ณ  ์„๋ฐฉ ๋œ ์ด ์ฃผ์ œ์— ๋Œ€ํ•œ FAQ๊ฐ€ ์žˆ์ง€๋งŒ ๋„ˆ๋ฌด ์ฝ๊ธฐ ์–ด๋ ต๊ณ  ๊ธธ์–ด์„œ ์‚ฌ์šฉํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค. ๋‹ค์Œ์€ ์ „์ฒด ์ถœํŒ๋ฌผ์˜ ์ •์ˆ˜์ธ ์ธ์šฉ๋ฌธ์ž…๋‹ˆ๋‹ค.

๋‹น์‹ ์ดํ•ด์•ผ ํ•  ์ผ
์ตœ์‹  ํด๋ผ์ด์–ธํŠธ ๋˜๋Š” ์„œ๋ฒ„ ์‹œ์Šคํ…œ์— ์„œ๋น„์Šค๋ฅผ ์ œ๊ณตํ•˜๋Š” ์ธ์ฆ์„œ๋ฅผ ํฌํ•จํ•˜์—ฌ ๋Œ€๋ถ€๋ถ„์˜ ์‚ฌ์šฉ ์‚ฌ๋ก€์—์„œ AddTrust ๋ฃจํŠธ์— ๊ต์ฐจ ์—ฐ๊ฒฐ๋œ ์ธ์ฆ์„œ๋ฅผ ๋ฐœ๊ธ‰ํ–ˆ๋Š”์ง€ ์—ฌ๋ถ€์— ๊ด€๊ณ„์—†์ด ์กฐ์น˜๊ฐ€ ํ•„์š”ํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

4์›” 30, 2020์˜๋กœ: ๋งค์šฐ ์˜ค๋ž˜๋œ ์‹œ์Šคํ…œ์— ์˜์กดํ•˜๋Š” ๋น„์ฆˆ๋‹ˆ์Šค ํ”„๋กœ์„ธ์Šค๋ฅผ ์œ„ํ•ด Sectigo๋Š” ๊ต์ฐจ ์„œ๋ช…์„ ์œ„ํ•œ ์ƒˆ๋กœ์šด ๋ ˆ๊ฑฐ์‹œ ๋ฃจํŠธ์ธ "AAA ์ธ์ฆ์„œ ์„œ๋น„์Šค" ๋ฃจํŠธ๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋„๋ก ํ–ˆ์Šต๋‹ˆ๋‹ค(๊ธฐ๋ณธ์ ์œผ๋กœ ์ธ์ฆ์„œ ๋ฒˆ๋“ค์—์„œ). ๊ทธ๋Ÿฌ๋‚˜ ๋งค์šฐ ์˜ค๋ž˜๋œ ๋ ˆ๊ฑฐ์‹œ ์‹œ์Šคํ…œ์— ์˜์กดํ•˜๋Š” ๋ชจ๋“  ํ”„๋กœ์„ธ์Šค์— ๋Œ€ํ•ด ๊ทน๋„์˜ ์ฃผ์˜๋ฅผ ๊ธฐ์šธ์ด์‹ญ์‹œ์˜ค. Sectigo์˜ COMODO ๋ฃจํŠธ์™€ ๊ฐ™์€ ์ตœ์‹  ๋ฃจํŠธ๋ฅผ ์ง€์›ํ•˜๋Š” ๋ฐ ํ•„์š”ํ•œ ์—…๋ฐ์ดํŠธ๋ฅผ ๋ฐ›์ง€ ๋ชปํ•œ ์‹œ์Šคํ…œ์€ ํ•„์—ฐ์ ์œผ๋กœ ๋‹ค๋ฅธ ํ•„์ˆ˜ ๋ณด์•ˆ ์—…๋ฐ์ดํŠธ๊ฐ€ ๋ˆ„๋ฝ๋˜๋ฉฐ ์•ˆ์ „ํ•˜์ง€ ์•Š์€ ๊ฒƒ์œผ๋กœ ๊ฐ„์ฃผ๋˜์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ์—ฌ์ „ํžˆ AAA ์ธ์ฆ์„œ ์„œ๋น„์Šค ๋ฃจํŠธ์— ๊ต์ฐจ ์„œ๋ช…ํ•˜๋ ค๋ฉด Sectigo์— ์ง์ ‘ ๋ฌธ์˜ํ•˜์‹ญ์‹œ์˜ค.

๋ฌผ๋ก  ๋‚˜๋Š” "๋งค์šฐ ์˜ค๋ž˜๋œ"๋…ผ๋ฌธ์„ ์ •๋ง ์ข‹์•„ํ•ฉ๋‹ˆ๋‹ค. ์˜ˆ๋ฅผ ๋“ค์–ด ์ตœ์‹  ์—…๋ฐ์ดํŠธ๊ฐ€ ํ•œ ๋‹ฌ๋„ ์•ˆ ๋œ Ubuntu Linux 18.04 LTS(ํ˜„์žฌ ๊ธฐ๋ณธ OS) ์ฝ˜์†”์˜ curl์€ ๋งค์šฐ ์˜ค๋ž˜๋œ ๊ฒƒ์œผ๋กœ ๋ถ€๋ฅด๊ธฐ๊ฐ€ ์–ด๋ ต์ง€๋งŒ ์ž‘๋™ํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

๋Œ€๋ถ€๋ถ„์˜ ์ธ์ฆ์„œ ๋ฐฐํฌ์ž๋Š” 30์›” XNUMX์ผ ๋Šฆ์€ ์˜คํ›„์— ๊ฒฐ์ • ๋…ธํŠธ๋ฅผ ๋ฐœํ‘œํ–ˆ์Šต๋‹ˆ๋‹ค. ์˜ˆ๋ฅผ ๋“ค์–ด, ๊ธฐ์ˆ  ์šฉ์–ด๋กœ ๋งค์šฐ ์ ํ•ฉํ•ฉ๋‹ˆ๋‹ค. NameCheap (ํ•ด์•ผ ํ•  ์ผ์— ๋Œ€ํ•œ ๊ตฌ์ฒด์ ์ธ ์„ค๋ช…๊ณผ zip ์•„์นด์ด๋ธŒ์— ๊ธฐ์„ฑํ’ˆ CA ๋ฒˆ๋“ค์ด ์žˆ์ง€๋งŒ RSA๋งŒ ์žˆ์Œ):

30๋…„ 2020์›” XNUMX์ผ ์ดํ›„ Sectigo ์ธ์ฆ์„œ ๋ฌธ์ œ ๋ฐ ํ•ด๊ฒฐ ๋ฐฉ๋ฒ•๊ทธ๋ฆผ 5. ์‹ ์†ํ•˜๊ฒŒ ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•˜๊ธฐ ์œ„ํ•œ XNUMX๋‹จ๊ณ„.

์ด ์ข‹์€ ๊ธฐ์‚ฌ Redhat์—์„œ ์ œ๊ณตํ•˜์ง€๋งŒ ์ ์  ๋” ๋งŽ์€ ๋ ˆ๊ฑฐ์‹œ๊ฐ€ ์žˆ์œผ๋ฉฐ ๋ชจ๋“  ๊ฒƒ์ด ์ž‘๋™ํ•˜๋ ค๋ฉด Comodo์—์„œ ํ›จ์”ฌ ๋” ๋งŽ์€ ๋ฃจํŠธ ๋ ˆ๊ฑฐ์‹œ ์ธ์ฆ์„œ๋ฅผ ์„ค์น˜ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

๊ฒฐ์ •

์—ฌ๊ธฐ์—์„œ๋„ ์†”๋ฃจ์…˜์„ ๋ณต์ œํ•  ๊ฐ€์น˜๊ฐ€ ์žˆ์Šต๋‹ˆ๋‹ค. ๋‹ค์Œ์€ ์ธ์ฆ์„œ์— ๋Œ€ํ•œ ๋‘ ์„ธํŠธ์˜ ์ฒด์ธ์ž…๋‹ˆ๋‹ค. DV Sectigo(Comodo ์•„๋‹˜!), ํ•˜๋‚˜๋Š” ์ต์ˆ™ํ•œ RSA ์ธ์ฆ์„œ์šฉ์ด๊ณ  ๋‹ค๋ฅธ ํ•˜๋‚˜๋Š” ๋œ ์นœ์ˆ™ํ•œ ECC(ECDSA) ์ธ์ฆ์„œ์šฉ์ž…๋‹ˆ๋‹ค(์šฐ๋ฆฌ๋Š” ์˜ค๋žซ๋™์•ˆ ๋‘ ๊ฐœ์˜ ์ฒด์ธ์„ ์‚ฌ์šฉํ•ด ์™”์Šต๋‹ˆ๋‹ค). ECC๋ฅผ ์‚ฌ์šฉํ•˜๋ฉด ๋Œ€๋ถ€๋ถ„์˜ ์†”๋ฃจ์…˜์ด ๋ณด๊ธ‰๋ฅ ์ด ๋‚ฎ๊ธฐ ๋•Œ๋ฌธ์— ์ด๋Ÿฌํ•œ ์ธ์ฆ์„œ์˜ ์กด์žฌ๋ฅผ ๊ณ ๋ คํ•˜์ง€ ์•Š๊ธฐ ๋•Œ๋ฌธ์— ๋” ์–ด๋ ค์› ์Šต๋‹ˆ๋‹ค. ๊ทธ ๊ฒฐ๊ณผ ํ•„์š”ํ•œ ์ค‘๊ฐ„ ์ธ์ฆ์„œ๊ฐ€ crt.sh.

ํ‚ค ์•Œ๊ณ ๋ฆฌ์ฆ˜ ๊ธฐ๋ฐ˜ ์ธ์ฆ์„œ์šฉ ์ฒด์ธ RSA. ์ฒด์ธ๊ณผ ๋น„๊ตํ•˜์—ฌ ์•„๋ž˜์ชฝ ์ธ์ฆ์„œ๋งŒ ๊ต์ฒด๋˜๊ณ  ์œ„์ชฝ ์ธ์ฆ์„œ๋Š” ๋™์ผํ•˜๊ฒŒ ์œ ์ง€๋˜์—ˆ์Œ์„ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค. ์ง‘์—์„œ base64 ๋ธ”๋ก์˜ ๋งˆ์ง€๋ง‰ XNUMX๊ฐœ ๋ฌธ์ž๋กœ ๊ตฌ๋ณ„ํ•˜๊ณ  "๋™์ผ" ๋ฌธ์ž(์ด ๊ฒฝ์šฐ En8= ะธ 1+V):

# Subject: /C=GB/ST=Greater Manchester/L=Salford/O=Sectigo Limited/CN=Sectigo RSA Domain Validation Secure Server CA
# Algo: RSA, key size: 2048
# Issuer: /C=US/ST=New Jersey/L=Jersey City/O=The USERTRUST Network/CN=USERTrust RSA Certification Authority
# Not valid before: 2018-11-02T00:00:00Z
# Not valid after: 2030-12-31T23:59:59Z
# SHA-1 Fingerprint: 33:E4:E8:08:07:20:4C:2B:61:82:A3:A1:4B:59:1A:CD:25:B5:F0:DB
# SHA-256 Fingerprint: 7F:A4:FF:68:EC:04:A9:9D:75:28:D5:08:5F:94:90:7F:4D:1D:D1:C5:38:1B:AC:DC:83:2E:D5:C9:60:21:46:76
-----BEGIN CERTIFICATE-----
MIIGEzCCA/ugAwIBAgIQfVtRJrR2uhHbdBYLvFMNpzANBgkqhkiG9w0BAQwFADCB
iDELMAkGA1UEBhMCVVMxEzARBgNVBAgTCk5ldyBKZXJzZXkxFDASBgNVBAcTC0pl
cnNleSBDaXR5MR4wHAYDVQQKExVUaGUgVVNFUlRSVVNUIE5ldHdvcmsxLjAsBgNV
BAMTJVVTRVJUcnVzdCBSU0EgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkwHhcNMTgx
MTAyMDAwMDAwWhcNMzAxMjMxMjM1OTU5WjCBjzELMAkGA1UEBhMCR0IxGzAZBgNV
BAgTEkdyZWF0ZXIgTWFuY2hlc3RlcjEQMA4GA1UEBxMHU2FsZm9yZDEYMBYGA1UE
ChMPU2VjdGlnbyBMaW1pdGVkMTcwNQYDVQQDEy5TZWN0aWdvIFJTQSBEb21haW4g
VmFsaWRhdGlvbiBTZWN1cmUgU2VydmVyIENBMIIBIjANBgkqhkiG9w0BAQEFAAOC
AQ8AMIIBCgKCAQEA1nMz1tc8INAA0hdFuNY+B6I/x0HuMjDJsGz99J/LEpgPLT+N
TQEMgg8Xf2Iu6bhIefsWg06t1zIlk7cHv7lQP6lMw0Aq6Tn/2YHKHxYyQdqAJrkj
eocgHuP/IJo8lURvh3UGkEC0MpMWCRAIIz7S3YcPb11RFGoKacVPAXJpz9OTTG0E
oKMbgn6xmrntxZ7FN3ifmgg0+1YuWMQJDgZkW7w33PGfKGioVrCSo1yfu4iYCBsk
Haswha6vsC6eep3BwEIc4gLw6uBK0u+QDrTBQBbwb4VCSmT3pDCg/r8uoydajotY
uK3DGReEY+1vVv2Dy2A0xHS+5p3b4eTlygxfFQIDAQABo4IBbjCCAWowHwYDVR0j
BBgwFoAUU3m/WqorSs9UgOHYm8Cd8rIDZsswHQYDVR0OBBYEFI2MXsRUrYrhd+mb
+ZsF4bgBjWHhMA4GA1UdDwEB/wQEAwIBhjASBgNVHRMBAf8ECDAGAQH/AgEAMB0G
A1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAbBgNVHSAEFDASMAYGBFUdIAAw
CAYGZ4EMAQIBMFAGA1UdHwRJMEcwRaBDoEGGP2h0dHA6Ly9jcmwudXNlcnRydXN0
LmNvbS9VU0VSVHJ1c3RSU0FDZXJ0aWZpY2F0aW9uQXV0aG9yaXR5LmNybDB2Bggr
BgEFBQcBAQRqMGgwPwYIKwYBBQUHMAKGM2h0dHA6Ly9jcnQudXNlcnRydXN0LmNv
bS9VU0VSVHJ1c3RSU0FBZGRUcnVzdENBLmNydDAlBggrBgEFBQcwAYYZaHR0cDov
L29jc3AudXNlcnRydXN0LmNvbTANBgkqhkiG9w0BAQwFAAOCAgEAMr9hvQ5Iw0/H
ukdN+Jx4GQHcEx2Ab/zDcLRSmjEzmldS+zGea6TvVKqJjUAXaPgREHzSyrHxVYbH
7rM2kYb2OVG/Rr8PoLq0935JxCo2F57kaDl6r5ROVm+yezu/Coa9zcV3HAO4OLGi
H19+24rcRki2aArPsrW04jTkZ6k4Zgle0rj8nSg6F0AnwnJOKf0hPHzPE/uWLMUx
RP0T7dWbqWlod3zu4f+k+TY4CFM5ooQ0nBnzvg6s1SQ36yOoeNDT5++SR2RiOSLv
xvcRviKFxmZEJCaOEDKNyJOuB56DPi/Z+fVGjmO+wea03KbNIaiGCpXZLoUmGv38
sbZXQm2V0TP2ORQGgkE49Y9Y3IBbpNV9lXj9p5v//cWoaasm56ekBYdbqbe4oyAL
l6lFhd2zi+WJN44pDfwGF/Y4QA5C5BIG+3vzxhFoYt/jmPQT2BVPi7Fp2RBgvGQq
6jG35LWjOhSbJuMLe/0CjraZwTiXWTb2qHSihrZe68Zk6s+go/lunrotEbaGmAhY
LcmsJWTyXnW0OMGuf1pGg+pRyrbxmRE1a6Vqe8YAsOf4vmSyrcjC8azjUeqkk+B5
yOGBQMkKW+ESPMFgKuOXwIlCypTPRpgSabuY0MLTDXJLR27lk8QyKGOHQ+SwMj4K
00u/I5sUKUErmgQfky3xxzlIPK1aEn8=
-----END CERTIFICATE-----

# Subject: /C=US/ST=New Jersey/L=Jersey City/O=The USERTRUST Network/CN=USERTrust RSA Certification Authority
# Algo: RSA, key size: 4096
# Issuer: /C=GB/ST=Greater Manchester/L=Salford/O=Comodo CA Limited/CN=AAA Certificate Services
# Not valid before: 2019-03-12T00:00:00Z
# Not valid after: 2028-12-31T23:59:59Z
# SHA-1 Fingerprint: D8:9E:3B:D4:3D:5D:90:9B:47:A1:89:77:AA:9D:5C:E3:6C:EE:18:4C
# SHA-256 Fingerprint: 68:B9:C7:61:21:9A:5B:1F:01:31:78:44:74:66:5D:B6:1B:BD:B1:09:E0:0F:05:CA:9F:74:24:4E:E5:F5:F5:2B
-----BEGIN CERTIFICATE-----
MIIFgTCCBGmgAwIBAgIQOXJEOvkit1HX02wQ3TE1lTANBgkqhkiG9w0BAQwFADB7
MQswCQYDVQQGEwJHQjEbMBkGA1UECAwSR3JlYXRlciBNYW5jaGVzdGVyMRAwDgYD
VQQHDAdTYWxmb3JkMRowGAYDVQQKDBFDb21vZG8gQ0EgTGltaXRlZDEhMB8GA1UE
AwwYQUFBIENlcnRpZmljYXRlIFNlcnZpY2VzMB4XDTE5MDMxMjAwMDAwMFoXDTI4
MTIzMTIzNTk1OVowgYgxCzAJBgNVBAYTAlVTMRMwEQYDVQQIEwpOZXcgSmVyc2V5
MRQwEgYDVQQHEwtKZXJzZXkgQ2l0eTEeMBwGA1UEChMVVGhlIFVTRVJUUlVTVCBO
ZXR3b3JrMS4wLAYDVQQDEyVVU0VSVHJ1c3QgUlNBIENlcnRpZmljYXRpb24gQXV0
aG9yaXR5MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAgBJlFzYOw9sI
s9CsVw127c0n00ytUINh4qogTQktZAnczomfzD2p7PbPwdzx07HWezcoEStH2jnG
vDoZtF+mvX2do2NCtnbyqTsrkfjib9DsFiCQCT7i6HTJGLSR1GJk23+jBvGIGGqQ
Ijy8/hPwhxR79uQfjtTkUcYRZ0YIUcuGFFQ/vDP+fmyc/xadGL1RjjWmp2bIcmfb
IWax1Jt4A8BQOujM8Ny8nkz+rwWWNR9XWrf/zvk9tyy29lTdyOcSOk2uTIq3XJq0
tyA9yn8iNK5+O2hmAUTnAU5GU5szYPeUvlM3kHND8zLDU+/bqv50TmnHa4xgk97E
xwzf4TKuzJM7UXiVZ4vuPVb+DNBpDxsP8yUmazNt925H+nND5X4OpWaxKXwyhGNV
icQNwZNUMBkTrNN9N6frXTpsNVzbQdcS2qlJC9/YgIoJk2KOtWbPJYjNhLixP6Q5
D9kCnusSTJV882sFqV4Wg8y4Z+LoE53MW4LTTLPtW//e5XOsIzstAL81VXQJSdhJ
WBp/kjbmUZIO8yZ9HE0XvMnsQybQv0FfQKlERPSZ51eHnlAfV1SoPv10Yy+xUGUJ
5lhCLkMaTLTwJUdZ+gQek9QmRkpQgbLevni3/GcV4clXhB4PY9bpYrrWX1Uu6lzG
KAgEJTm4Diup8kyXHAc/DVL17e8vgg8CAwEAAaOB8jCB7zAfBgNVHSMEGDAWgBSg
EQojPpbxB+zirynvgqV/0DCktDAdBgNVHQ4EFgQUU3m/WqorSs9UgOHYm8Cd8rID
ZsswDgYDVR0PAQH/BAQDAgGGMA8GA1UdEwEB/wQFMAMBAf8wEQYDVR0gBAowCDAG
BgRVHSAAMEMGA1UdHwQ8MDowOKA2oDSGMmh0dHA6Ly9jcmwuY29tb2RvY2EuY29t
L0FBQUNlcnRpZmljYXRlU2VydmljZXMuY3JsMDQGCCsGAQUFBwEBBCgwJjAkBggr
BgEFBQcwAYYYaHR0cDovL29jc3AuY29tb2RvY2EuY29tMA0GCSqGSIb3DQEBDAUA
A4IBAQAYh1HcdCE9nIrgJ7cz0C7M7PDmy14R3iJvm3WOnnL+5Nb+qh+cli3vA0p+
rvSNb3I8QzvAP+u431yqqcau8vzY7qN7Q/aGNnwU4M309z/+3ri0ivCRlv79Q2R+
/czSAaF9ffgZGclCKxO/WIu6pKJmBHaIkU4MiRTOok3JMrO66BQavHHxW/BBC5gA
CiIDEOUMsfnNkjcZ7Tvx5Dq2+UUTJnWvu6rvP3t3O9LEApE9GQDTF1w52z97GA1F
zZOFli9d31kWTz9RvdVFGD/tSo7oBmF0Ixa1DVBzJ0RHfxBdiSprhTEUxOipakyA
vGp4z7h/jnZymQyd/teRCBaho1+V
-----END CERTIFICATE-----

ํ‚ค ์•Œ๊ณ ๋ฆฌ์ฆ˜ ๊ธฐ๋ฐ˜ ์ธ์ฆ์„œ์šฉ ์ฒด์ธ ECC. RSA ์ฒด์ธ๊ณผ ๋งˆ์ฐฌ๊ฐ€์ง€๋กœ ํ•˜์œ„ ์ธ์ฆ์„œ๋งŒ ๊ต์ฒด๋˜๊ณ  ์ƒ์œ„ ์ธ์ฆ์„œ๋Š” ๋™์ผํ•˜๊ฒŒ ์œ ์ง€๋˜์—ˆ์Šต๋‹ˆ๋‹ค(์ด ๊ฒฝ์šฐ fmA== ะธ v/c=):

# Subject: /C=GB/ST=Greater Manchester/L=Salford/O=Sectigo Limited/CN=Sectigo ECC Domain Validation Secure Server CA
# Algo: EC secp256r1, key size: 256
# Issuer: /C=US/ST=New Jersey/L=Jersey City/O=The USERTRUST Network/CN=USERTrust ECC Certification Authority
# Not valid before: 2018-11-02T00:00:00Z
# Not valid after: 2030-12-31T23:59:59Z
# SHA-1 Fingerprint: E8:49:90:CB:9B:F8:E3:AB:0B:CA:E8:A6:49:CB:30:FE:4D:C4:D7:67
# SHA-256 Fingerprint: 61:E9:73:75:E9:F6:DA:98:2F:F5:C1:9E:2F:94:E6:6C:4E:35:B6:83:7C:E3:B9:14:D2:24:5C:7F:5F:65:82:5F
-----BEGIN CERTIFICATE-----
MIIDqDCCAy6gAwIBAgIRAPNkTmtuAFAjfglGvXvh9R0wCgYIKoZIzj0EAwMwgYgx
CzAJBgNVBAYTAlVTMRMwEQYDVQQIEwpOZXcgSmVyc2V5MRQwEgYDVQQHEwtKZXJz
ZXkgQ2l0eTEeMBwGA1UEChMVVGhlIFVTRVJUUlVTVCBOZXR3b3JrMS4wLAYDVQQD
EyVVU0VSVHJ1c3QgRUNDIENlcnRpZmljYXRpb24gQXV0aG9yaXR5MB4XDTE4MTEw
MjAwMDAwMFoXDTMwMTIzMTIzNTk1OVowgY8xCzAJBgNVBAYTAkdCMRswGQYDVQQI
ExJHcmVhdGVyIE1hbmNoZXN0ZXIxEDAOBgNVBAcTB1NhbGZvcmQxGDAWBgNVBAoT
D1NlY3RpZ28gTGltaXRlZDE3MDUGA1UEAxMuU2VjdGlnbyBFQ0MgRG9tYWluIFZh
bGlkYXRpb24gU2VjdXJlIFNlcnZlciBDQTBZMBMGByqGSM49AgEGCCqGSM49AwEH
A0IABHkYk8qfbZ5sVwAjBTcLXw9YWsTef1Wj6R7W2SUKiKAgSh16TwUwimNJE4xk
IQeV/To14UrOkPAY9z2vaKb71EijggFuMIIBajAfBgNVHSMEGDAWgBQ64QmG1M8Z
wpZ2dEl23OA1xmNjmjAdBgNVHQ4EFgQU9oUKOxGG4QR9DqoLLNLuzGR7e64wDgYD
VR0PAQH/BAQDAgGGMBIGA1UdEwEB/wQIMAYBAf8CAQAwHQYDVR0lBBYwFAYIKwYB
BQUHAwEGCCsGAQUFBwMCMBsGA1UdIAQUMBIwBgYEVR0gADAIBgZngQwBAgEwUAYD
VR0fBEkwRzBFoEOgQYY/aHR0cDovL2NybC51c2VydHJ1c3QuY29tL1VTRVJUcnVz
dEVDQ0NlcnRpZmljYXRpb25BdXRob3JpdHkuY3JsMHYGCCsGAQUFBwEBBGowaDA/
BggrBgEFBQcwAoYzaHR0cDovL2NydC51c2VydHJ1c3QuY29tL1VTRVJUcnVzdEVD
Q0FkZFRydXN0Q0EuY3J0MCUGCCsGAQUFBzABhhlodHRwOi8vb2NzcC51c2VydHJ1
c3QuY29tMAoGCCqGSM49BAMDA2gAMGUCMEvnx3FcsVwJbZpCYF9z6fDWJtS1UVRs
cS0chWBNKPFNpvDKdrdKRe+oAkr2jU+ubgIxAODheSr2XhcA7oz9HmedGdMhlrd9
4ToKFbZl+/OnFFzqnvOhcjHvClECEQcKmc8fmA==
-----END CERTIFICATE-----

# Subject: /C=US/ST=New Jersey/L=Jersey City/O=The USERTRUST Network/CN=USERTrust ECC Certification Authority
# Algo: EC secp384r1, key size: 384
# Issuer: /C=GB/ST=Greater Manchester/L=Salford/O=Comodo CA Limited/CN=AAA Certificate Services
# Not valid before: 2019-03-12T00:00:00Z
# Not valid after: 2028-12-31T23:59:59Z
# SHA-1 Fingerprint: CA:77:88:C3:2D:A1:E4:B7:86:3A:4F:B5:7D:00:B5:5D:DA:CB:C7:F9
# SHA-256 Fingerprint: A6:CF:64:DB:B4:C8:D5:FD:19:CE:48:89:60:68:DB:03:B5:33:A8:D1:33:6C:62:56:A8:7D:00:CB:B3:DE:F3:EA
-----BEGIN CERTIFICATE-----
MIID0zCCArugAwIBAgIQVmcdBOpPmUxvEIFHWdJ1lDANBgkqhkiG9w0BAQwFADB7
MQswCQYDVQQGEwJHQjEbMBkGA1UECAwSR3JlYXRlciBNYW5jaGVzdGVyMRAwDgYD
VQQHDAdTYWxmb3JkMRowGAYDVQQKDBFDb21vZG8gQ0EgTGltaXRlZDEhMB8GA1UE
AwwYQUFBIENlcnRpZmljYXRlIFNlcnZpY2VzMB4XDTE5MDMxMjAwMDAwMFoXDTI4
MTIzMTIzNTk1OVowgYgxCzAJBgNVBAYTAlVTMRMwEQYDVQQIEwpOZXcgSmVyc2V5
MRQwEgYDVQQHEwtKZXJzZXkgQ2l0eTEeMBwGA1UEChMVVGhlIFVTRVJUUlVTVCBO
ZXR3b3JrMS4wLAYDVQQDEyVVU0VSVHJ1c3QgRUNDIENlcnRpZmljYXRpb24gQXV0
aG9yaXR5MHYwEAYHKoZIzj0CAQYFK4EEACIDYgAEGqxUWqn5aCPnetUkb1PGWthL
q8bVttHmc3Gu3ZzWDGH926CJA7gFFOxXzu5dP+Ihs8731Ip54KODfi2X0GHE8Znc
JZFjq38wo7Rw4sehM5zzvy5cU7Ffs30yf4o043l5o4HyMIHvMB8GA1UdIwQYMBaA
FKARCiM+lvEH7OKvKe+CpX/QMKS0MB0GA1UdDgQWBBQ64QmG1M8ZwpZ2dEl23OA1
xmNjmjAOBgNVHQ8BAf8EBAMCAYYwDwYDVR0TAQH/BAUwAwEB/zARBgNVHSAECjAI
MAYGBFUdIAAwQwYDVR0fBDwwOjA4oDagNIYyaHR0cDovL2NybC5jb21vZG9jYS5j
b20vQUFBQ2VydGlmaWNhdGVTZXJ2aWNlcy5jcmwwNAYIKwYBBQUHAQEEKDAmMCQG
CCsGAQUFBzABhhhodHRwOi8vb2NzcC5jb21vZG9jYS5jb20wDQYJKoZIhvcNAQEM
BQADggEBABns652JLCALBIAdGN5CmXKZFjK9Dpx1WywV4ilAbe7/ctvbq5AfjJXy
ij0IckKJUAfiORVsAYfZFhr1wHUrxeZWEQff2Ji8fJ8ZOd+LygBkc7xGEJuTI42+
FsMuCIKchjN0djsoTI0DQoWz4rIjQtUfenVqGtF8qmchxDM6OW1TyaLtYiKou+JV
bJlsQ2uRl9EMC5MCHdK8aXdJ5htN978UeAOwproLtOGFfy/cQjutdAFI3tZs4RmY
CV4Ks2dH/hzg1cEo70qLRDEmBDeNiXQ2Lu+lIg+DdEmSx/cQwgwp+7e9un/jX9Wf
8qn0dNW44bOwgeThpWOjzOoEeJBuv/c=
-----END CERTIFICATE-----

๊ทธ๊ฒŒ ๋‹ค์•ผ. ๊ด€์‹ฌ์„ ๊ฐ€์ ธ ์ฃผ์…”์„œ ๊ฐ์‚ฌํ•ฉ๋‹ˆ๋‹ค.

์ถœ์ฒ˜ : habr.com