서버.보안
아파치 SSL인증서 비번묻지않기
landzz
2011. 3. 2. 11:12
http://lamia.kr/entertainment/?mid=computer&category=1579&document_srl=1616
1. 아래와 같이 명령을 내리면 패스워드를 물어볼 것이다. 최초 개인키를 생성했을때 패스워드를 넣어준다.openssl rsa -in /usr/local/apache/conf/ssl.key/abc.com.key -out /usr/local/apache/conf/abc.com.key.insecure
2. 기존 파일 이름을 변경해준다.
mv /usr/local/apache/conf/ssl.key/abc.com.key /usr/local/apache/conf/ssl.key/abc.com.key.secure
3. 위 1번에서 새로 생성한 개인키로 교체해준다.
mv /usr/local/apache/conf/ssl.key/abc.com.insecure /usr/local/apache/conf/ssl.key/abc.com.key
4. 아파치 SSL 모드로 시작해보면 패스워드를 물어보지 않을 것이다.
################################################################
참고 ssl.conf
--------------------
SSLRandomSeed startup builtin
SSLRandomSeed connect builtin
#SSLRandomSeed startup file:/dev/random 512
#SSLRandomSeed startup file:/dev/urandom 512
#SSLRandomSeed connect file:/dev/random 512
#SSLRandomSeed connect file:/dev/urandom 512
#SSLPassPhraseDialog builtin
##SSLPassPhraseDialog exec:/home/workpixel/SSL/password.sh
~~~~~
Listen 443
~~~~~
SSLEngine on
SSLCipherSuite ALL:!ADH:!EXPORT56:RC4+RSA:+HIGH:+MEDIUM:+LOW:+SSLv2:+EXP:+eNULL
################################################
### ssl 인증서
SSLCertificateFile /home/workpixel/SSL/www.designpixel.co.kr.crt
##SSLCertificateKeyFile /home/workpixel/SSL/www.designpixel.co.kr.key
SSLCertificateKeyFile /home/workpixel/SSL/www.designpixel.co.kr.nopwd.key
########################################################