Microsoft º¸¾È °øÁö: ÃÖ¼Ò ÀÎÁõ¼­ Ű ±æÀÌ ¾÷µ¥ÀÌÆ®

±â¼ú ÀÚ·á: 2661254 - ÀÌ ¹®¼­°¡ Àû¿ëµÇ´Â Á¦Ç° º¸±â.
¸ðµÎ È®´ë | ¸ðµÎ Ãà¼Ò

ÀÌ ÆäÀÌÁö¿¡¼­

¼Ò°³

Microsoft´Â IT Àü¹®°¡¸¦ À§ÇÑ Microsoft º¸¾È °øÁö¸¦ ¹ßÇ¥Çß½À´Ï´Ù. ÀÌ °øÁö¿¡ µû¶ó, 1024ºñÆ®º¸´Ù ªÀº ۸¦ °®´Â RSA ÀÎÁõ¼­ÀÇ »ç¿ëÀÌ Â÷´ÜµÉ ¿¹Á¤ÀÔ´Ï´Ù. ÀÌ º¸¾È °øÁö¸¦ º¸·Á¸é ´ÙÀ½ Microsoft À¥ »çÀÌÆ®·Î À̵¿ÇϽʽÿÀ.
http://technet.microsoft.com/ko-kr/security/advisory/2661254
Áß¿äÇÑ Á¤º¸¿¡ ´ëÇÑ ¹«´Ü °ø°³ À§ÇèÀ» ÁÙÀ̱â À§ÇØ Microsoft´Â Áö¿øµÇ´Â ¸ðµç Microsoft Windows ¹öÀü¿¡ ´ëÇÑ ºñº¸¾È ¾÷µ¥ÀÌÆ®(KB 2661254)¸¦ ¹ßÇ¥Çß½À´Ï´Ù. ÀÌ ¾÷µ¥ÀÌÆ®´Â 1024ºñÆ®º¸´Ù ±æÀ̰¡ ªÀº ¾Ïȣȭ ۸¦ Â÷´ÜÇÕ´Ï´Ù. ÀÌ ¾÷µ¥ÀÌÆ®´Â Windows 8 Release Preview ¶Ç´Â Windows Server 2012 ¸±¸®½º Èĺ¸¿¡´Â Àû¿ëµÇÁö ¾Ê½À´Ï´Ù. ÀÌ·¯ÇÑ ¿î¿µ üÁ¦¿¡´Â 1024ºñÆ®º¸´Ù ±æÀ̰¡ ªÀº ¾àÇÑ RSA ŰÀÇ »ç¿ëÀ» Â÷´ÜÇÏ´Â ±â´ÉÀÌ ÀÌ¹Ì Æ÷ÇԵǾî Àֱ⠶§¹®ÀÔ´Ï´Ù.

Ãß°¡ Á¤º¸

°ø°³ Ű ±â¹Ý ¾Ïȣȭ ¾Ë°í¸®ÁòÀÇ °­µµ´Â ¹«Â÷º° ¾ÏÈ£ ´ëÀÔ °ø°Ý(brute force attack) ¹æ¹ýÀ» »ç¿ëÇÏ¿© °³ÀΠ۸¦ ¾Ë¾Æ³»´Â µ¥ °É¸®´Â ½Ã°£¿¡ µû¶ó ´Ù¸¨´Ï´Ù. °³ÀΠ۸¦ ¾Ë¾Æ³»±â Àü¿¡ ÄÄÇ»ÆÃ ±â´ÉÀ» »ç¿ëÇÏ¿© ÀÌ·¯ÇÑ À§ÇèÀ» ¹æÁöÇÒ ¼ö ÀÖÀ¸¸é ÀÌ ¾Ë°í¸®ÁòÀÌ °­·ÂÇÑ °ÍÀ¸·Î °£Áֵ˴ϴÙ. À§Çù ¹üÀ§°¡ °è¼Ó È®»êµÇ°í ÀÖ½À´Ï´Ù. µû¶ó¼­ Microsoft´Â Ű ±æÀ̰¡ 1024ºñÆ®º¸´Ù ªÀº RSA ¾Ë°í¸®Áò ±âÁØÀ» °­È­Çϰí ÀÖ½À´Ï´Ù.

ÀÌ ¾÷µ¥ÀÌÆ®¸¦ Àû¿ëÇϸé CertGetCertificateChain ÇÔ¼ö¸¦ »ç¿ëÇÏ¿© ÀÛ¼ºÇÑ ÀÎÁõ¼­ üÀθ¸ ¿µÇâÀ» ¹Þ½À´Ï´Ù. CryptoAPI´Â ÀÎÁõ¼­ ½Å·Ú üÀÎÀ» ¸¸µé°í ½Ã°£ À¯È¿¼º, ÀÎÁõ¼­ ÇØÁö ¹× ÀÎÁõ¼­ Á¤Ã¥(¿¹: ¿ëµµ)¿¡ µû¶ó ÇØ´ç üÀÎÀÌ À¯È¿ÇÑÁö °Ë»çÇÕ´Ï´Ù. ÀÌ ¾÷µ¥ÀÌÆ®´Â üÀÎÀÇ ¾î¶² ÀÎÁõ¼­µµ 1024ºñÆ®º¸´Ù ±æÀ̰¡ ªÀº RSA ۸¦ °®Áö ¾Êµµ·Ï Çϱâ À§ÇØ Ãß°¡ÀûÀÎ °Ë»çµµ ÁøÇàÇÕ´Ï´Ù.

¾÷µ¥ÀÌÆ® ´ëü Á¤º¸

ÀÌ ¾÷µ¥ÀÌÆ®´Â ´ÙÀ½ ¾÷µ¥ÀÌÆ®¸¦ ´ëüÇÕ´Ï´Ù.
2677070 Windows Vista, Windows Server 2008, Windows 7 ¹× Windows Server 2008 R2¿¡ ´ëÇØ ÇØÁöµÈ ÀÎÁõ¼­ÀÇ ÀÚµ¿ ¾÷µ¥ÀÌÆ® ÇÁ·Î±×·¥ÀÌ Ãâ½ÃµÇ¾ú½À´Ï´Ù.

ÀÌ º¸¾È ¾÷µ¥ÀÌÆ®ÀÇ ¾Ë·ÁÁø ¹®Á¦Á¡

¾÷µ¥ÀÌÆ®°¡ ¿Ï·áµÇ¸é
  • ÄÄÇ»Å͸¦ ´Ù½Ã ½ÃÀÛÇØ¾ß ÇÕ´Ï´Ù.
  • CA(ÀÎÁõ ±â°ü)¿¡¼­ Ű ±æÀ̰¡ 1024ºñÆ®º¸´Ù ªÀº RSA ÀÎÁõ¼­¸¦ ¹ß±ÞÇÒ ¼ö ¾ø½À´Ï´Ù.
  • CA¿¡¼­ 1024ºñÆ®º¸´Ù Ű ±æÀ̰¡ ªÀº RSA ÀÎÁõ¼­¸¦ »ç¿ëÇϰí ÀÖÀ» ¶§´Â CA ¼­ºñ½º(certsvc)¸¦ ½ÃÀÛÇÒ ¼ö ¾ø½À´Ï´Ù.
  • Internet Explorer¿¡¼­ Ű ±æÀ̰¡ 1024ºñÆ®º¸´Ù ªÀº RSA ÀÎÁõ¼­·Î º¸¾ÈÀÌ À¯ÁöµÇ´Â À¥ »çÀÌÆ®¿¡ ¾×¼¼½ºÇÒ ¼ö ¾ø½À´Ï´Ù.
  • Ű ±æÀ̰¡ 1024ºñÆ®º¸´Ù ªÀº RSA ÀÎÁõ¼­¸¦ »ç¿ëÇϰí ÀÖ´Â °æ¿ì Outlook 2010¿¡¼­ ÀüÀÚ ¸ÞÀÏÀ» ¾ÏȣȭÇÒ ¼ö ¾ø½À´Ï´Ù. ±×·¯³ª Ű ±æÀ̰¡ 1024ºñÆ®º¸´Ù ªÀº RSA ÀÎÁõ¼­¸¦ »ç¿ëÇÏ¿© ÀÌ¹Ì ¾ÏȣȭµÈ ÀüÀÚ ¸ÞÀÏÀº ÀÌ ¾÷µ¥ÀÌÆ®¸¦ ¼³Ä¡ÇÑ ÈÄ¿¡µµ ¾ÏÈ£¸¦ ÇØµ¶ÇÒ ¼ö ÀÖ½À´Ï´Ù.
  • Ű ±æÀ̰¡ 1024ºñÆ®º¸´Ù ªÀº RSA ÀÎÁõ¼­¸¦ »ç¿ëÇϰí ÀÖ´Â °æ¿ì Outlook 2010¿¡¼­ ÀüÀÚ ¸ÞÀÏ¿¡ µðÁöÅÐ ¼­¸íÇÒ ¼ö ¾ø½À´Ï´Ù.
  • Ű ±æÀ̰¡ 1024ºñÆ®º¸´Ù ªÀº RSA ÀÎÁõ¼­¸¦ »ç¿ëÇÏ¿© ¾ÏȣȭµÇ°Å³ª µðÁöÅÐ ¼­¸íµÈ ÀüÀÚ ¸ÞÀÏÀ» Outlook 2010¿¡¼­ ¼ö½ÅÇϸé ÇØ´ç ÀÎÁõ¼­¸¦ ½Å·ÚÇÒ ¼ö ¾ø´Ù´Â ¿À·ù°¡ ³ªÅ¸³³´Ï´Ù. »ç¿ëÀÚ´Â ¿©ÀüÈ÷ ¾ÏȣȭµÇ¾î Àְųª ¼­¸íµÈ ÀüÀÚ ¸ÞÀÏÀ» º¼ ¼ö ÀÖ½À´Ï´Ù.
  • Outlook 2010¿¡¼­ SSL/TLS¿¡ ´ëÇØ Ű ±æÀ̰¡ 1024ºñÆ®º¸´Ù ªÀº RSA ÀÎÁõ¼­¸¦ »ç¿ëÇÏ´Â Microsoft Exchange Server¿¡ ¿¬°áÇÒ ¼ö ¾ø½À´Ï´Ù. ´ÙÀ½ ¿À·ù°¡ Ç¥½ÃµË´Ï´Ù. "ÀÌ »çÀÌÆ®¿Í ±³È¯ÇÑ Á¤º¸´Â ´Ù¸¥ »ç¶÷ÀÌ º¸°Å³ª º¯°æÇÒ ¼ö ¾ø½À´Ï´Ù. ±×·¯³ª »çÀÌÆ® º¸¾È ÀÎÁõ¼­¿¡ ¹®Á¦°¡ ÀÖ½À´Ï´Ù. º¸¾È ÀÎÁõ¼­°¡ À¯È¿ÇÏÁö ¾Ê½À´Ï´Ù. ÀÌ »çÀÌÆ®´Â ½Å·ÚÇÒ ¼ö ¾ø½À´Ï´Ù."
  • "¾Ë ¼ö ¾ø´Â °Ô½ÃÀÚ"¶ó´Â º¸¾È °æ°í°¡ º¸°íµÇÁö¸¸ ´ÙÀ½ °æ¿ì¿¡´Â ¼³Ä¡¸¦ °è¼Ó ÁøÇàÇÒ ¼ö ÀÖ½À´Ï´Ù.
    • 2010³â 1¿ù 1ÀÏ ÀÌÈÄ ³¯Â¥°¡ ÂïÇô ÀÖ°í Ű ±æÀ̰¡ 1024ºñÆ®º¸´Ù ªÀº RSA ÀÎÁõ¼­¸¦ »ç¿ëÇÏ¿© ¼­¸íµÈ Authenticode ¼­¸íÀÌ ¹ß°ßµÇ¾ú½À´Ï´Ù.
    • ¼­¸íµÈ ¼³Ä¡ °ü¸®ÀÚ°¡ Ű ±æÀ̰¡ 1024ºñÆ®º¸´Ù ªÀº RSA ÀÎÁõ¼­¸¦ »ç¿ëÇÏ¿© ¼­¸íµÇ¾ú½À´Ï´Ù.
    • ActiveX ÄÁÆ®·ÑÀÌ Å° ±æÀ̰¡ 1024ºñÆ®º¸´Ù ªÀº RSA ÀÎÁõ¼­¸¦ »ç¿ëÇÏ¿© ¼­¸íµÇ¾ú½À´Ï´Ù. ÀÌ ¾÷µ¥ÀÌÆ®¸¦ ¼³Ä¡Çϱâ Àü¿¡ ÀÌ¹Ì ¼³Ä¡µÈ ActiveX ÄÁÆ®·ÑÀº ¿µÇâÀ» ¹ÞÁö ¾Ê½À´Ï´Ù.
  • Ű ±æÀ̰¡ 512ºñÆ®ÀÎ RSA ÀÎÁõ¼­¸¦ »ç¿ëÇÏ´Â System Center HP-UX PA-RISC ÄÄÇ»ÅͰ¡ ÇÏÆ®ºñÆ® °æ°í¸¦ »ý¼ºÇϸç ÄÄÇ»ÅÍ¿¡ ´ëÇÑ ¸ðµç Operations Manager ¸ð´ÏÅ͸µÀÌ ½ÇÆÐÇÕ´Ï´Ù. "¼­¸íµÈ ÀÎÁõ¼­ È®ÀÎ"À̶ó°í ¼³¸íµÈ "SSL ÀÎÁõ¼­ ¿À·ù"µµ »ý¼ºµË´Ï´Ù. ¶ÇÇÑ Operations Manager´Â "¼­¸íµÈ ÀÎÁõ¼­ È®ÀÎ" ¿À·ù ¶§¹®¿¡ »õ·Î¿î HP-UX PA-RISC ÄÄÇ»Å͸¦ °Ë»öÇÏÁö ¸øÇÕ´Ï´Ù. HP-UX PA-RISC ÄÄÇ»Å͸¦ »ç¿ëÇÏ´Â System Center °í°´Àº Ű ±æÀ̰¡ 1024ºñÆ® ÀÌ»óÀÎ RSA ÀÎÁõ¼­¸¦ ´Ù½Ã ¹ß±Þ¹Þ´Â °ÍÀÌ ÁÁ½À´Ï´Ù. ÀÚ¼¼ÇÑ ³»¿ëÀº ´ÙÀ½ TechNet À¥ ÆäÀÌÁö·Î À̵¿ÇϽʽÿÀ.
    Áß¿ä: Operations Manager¿¡ ÀÇÇØ ¸ð´ÏÅ͸µµÇ´Â HP-UX PA-RISC ÄÄÇ»ÅÍ¿¡¼­ ÇâÈÄ Windows ¾÷µ¥ÀÌÆ® ÈÄ¿¡ ÇÏÆ®ºñÆ® ¹× ¸ð´ÏÅ͸µÀÌ ½ÇÆÐÇÔ
Âü°í EFS ¾Ïȣȭ´Â ÀÌ ¾÷µ¥ÀÌÆ®ÀÇ ¿µÇâÀ» ¹ÞÁö ¾Ê½À´Ï´Ù.

Ű ±æÀ̰¡ 1024ºñÆ®º¸´Ù ªÀº RSA ÀÎÁõ¼­ °Ë»ö

Ű ±æÀ̰¡ 1024ºñÆ®º¸´Ù ªÀº RSA ÀÎÁõ¼­°¡ »ç¿ë ÁßÀÎÁö È®ÀÎÇÏ´Â ¹æ¹ý¿¡´Â ´ÙÀ½ ³× °¡Áö°¡ ÀÖ½À´Ï´Ù.
  • ÀÎÁõ¼­¿Í ÀÎÁõ °æ·Î¸¦ ¼öµ¿À¸·Î È®ÀÎ
  • CAPI2 ·Î±ë »ç¿ë
  • ÀÎÁõ¼­ ÅÛÇø´ È®ÀÎ
  • ¾÷µ¥ÀÌÆ®°¡ ¼³Ä¡µÈ ÄÄÇ»ÅÍ¿¡¼­ ·Î±ëÀ» »ç¿ëÇϵµ·Ï ¼³Á¤

ÀÎÁõ¼­¿Í ÀÎÁõ °æ·Î¸¦ ¼öµ¿À¸·Î È®ÀÎ

ÀÎÁõ¼­¸¦ ¿­°í Çü½Ä, Ű ±æÀÌ ¹× ÀÎÁõ °æ·Î¸¦ ¼öµ¿À¸·Î È®ÀÎÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ·¸°Ô ÇÏ·Á¸é ³»ºÎÀûÀ¸·Î ¹ß±ÞµÈ ÀÎÁõ¼­¸¦ È®ÀÎ(ÀϹÝÀûÀ¸·Î µÎ ¹ø Ŭ¸¯)ÇÏ¸é µË´Ï´Ù. ÀÎÁõ °æ·Î ÅÇ¿¡¼­ üÀÎÀÇ °¢ ÀÎÁõ¼­¿¡ ´ëÇÑ ÀÎÁõ¼­ º¸±â¸¦ Ŭ¸¯ÇÏ°í ¸ðµç RSA ÀÎÁõ¼­ÀÇ Å° ±æÀ̰¡ Àû¾îµµ 1024ºñÆ® ÀÌ»óÀÎÁö È®ÀÎÇÕ´Ï´Ù.

¿¹¸¦ µé¾î ´ÙÀ½ ±×¸²ÀÇ ÀÎÁõ¼­´Â ¿£ÅÍÇÁ¶óÀÌÁî ·çÆ® CAÀÎ AdatumRootCA¿¡¼­ µµ¸ÞÀÎ ÄÁÆ®·Ñ·¯(2003DC.adatum.com)·Î ¹ß±ÞµÇ¾ú½À´Ï´Ù. ÀÎÁõ °æ·Î ÅÇ¿¡¼­ AdatumRootCA ÀÎÁõ¼­¸¦ ¼±ÅÃÇÒ ¼ö ÀÖ½À´Ï´Ù.

±×¸² Ãà¼Ò±×¸² È®´ë


AdatumRootCA ÀÎÁõ¼­¸¦ º¸·Á¸é ÀÎÁõ¼­ º¸±â¸¦ Ŭ¸¯ÇÕ´Ï´Ù. ´ÙÀ½ ±×¸²°ú °°ÀÌ ¼¼ºÎ Á¤º¸ â¿¡¼­ °ø°³ ۸¦ ¼±ÅÃÇÏ¿© Ű Å©±â¸¦ È®ÀÎÇÕ´Ï´Ù.

±×¸² Ãà¼Ò±×¸² È®´ë


ÀÌ ¿¹Á¦¿¡¼­ AdatumRootCA¿¡ ´ëÇÑ RSA ÀÎÁõ¼­´Â 2048ºñÆ®ÀÔ´Ï´Ù.

CAPI2 ·Î±ë »ç¿ë

Windows Vista ¶Ç´Â Windows Server 2008À̳ª ÀÌÈÄ ¹öÀüÀÇ Windows°¡ ½ÇÇàµÇ´Â ÄÄÇ»ÅÍ¿¡¼­´Â CAPI2 ·Î±ëÀ» »ç¿ëÇÏ¿© ±æÀ̰¡ 1024ºñÆ®º¸´Ù ªÀº ۸¦ ½Äº°ÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ·¸°Ô ÇÏ¸é ½Ã½ºÅÛ¿¡¼­ ÀϹÝÀûÀÎ ÀÛ¾÷À» ¼öÇàÇÒ ¼ö ÀÖÀ¸¸ç ³ªÁß¿¡ ÀÌ ·Î±×¸¦ È®ÀÎÇÏ¿© ±æÀ̰¡ 1024ºñÆ®º¸´Ù ªÀº ۸¦ ½Äº°ÇÒ ¼ö ÀÖ½À´Ï´Ù. ±×·± ´ÙÀ½ ÀÌ Á¤º¸¸¦ »ç¿ëÇÏ¿© ÀÎÁõ¼­ Ãâó¸¦ ÃßÀûÇϰí ÇÊ¿äÇÑ ¾÷µ¥ÀÌÆ®¸¦ ¼öÇàÇÒ ¼ö ÀÖ½À´Ï´Ù.

ÀÌ·¸°Ô ÇÏ·Á¸é ¸ÕÀú ÀÚ¼¼ÇÑ Áø´Ü ·Î±ëÀ» »ç¿ëÇϵµ·Ï ¼³Á¤ÇØ¾ß ÇÕ´Ï´Ù. ÀÚ¼¼ÇÑ ·Î±ë ¸ðµå¸¦ ¼³Á¤ÇÏ·Á¸é ´ÙÀ½°ú °°ÀÌ ÇϽʽÿÀ.

1. ·¹Áö½ºÆ®¸® ÆíÁý±â(Regedit.exe)¸¦ ¿±´Ï´Ù.

2. ´ÙÀ½ ·¹Áö½ºÆ®¸® Ű·Î À̵¿ÇÕ´Ï´Ù.

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\crypt32


3. DWORD(32ºñÆ®) °ª DiagLevelÀ» Ãß°¡Çϰí 0x00000005 °ªÀ» ÁöÁ¤ÇÕ´Ï´Ù.

4. QWORD(64ºñÆ®) °ª DiagMatchAnyMask¸¦ Ãß°¡Çϰí 0x00ffffff °ªÀ» ÁöÁ¤ÇÕ´Ï´Ù.

±×¸² Ãà¼Ò±×¸² È®´ë


ÀÌ ÀÛ¾÷À» ¼öÇàÇÑ ÈÄ¿¡ À̺¥Æ® ºä¾î¿¡¼­ CAPI2 ÀÛµ¿ ·Î±ëÀ» »ç¿ëÇϵµ·Ï ¼³Á¤ÇÒ ¼ö ÀÖ½À´Ï´Ù. CAPI2 ÀÛµ¿ ·Î±×´Â À̺¥Æ® ºä¾îÀÇ ÀÀ¿ë ÇÁ·Î±×·¥ ¹× ¼­ºñ½º ·Î±×, Microsoft, Windows ¹× CAPI2¿¡ ÀÖ½À´Ï´Ù. ·Î±ëÀ» »ç¿ëÇϵµ·Ï ¼³Á¤ÇÏ·Á¸é ÀÛµ¿ ·Î±×¸¦ ¸¶¿ì½º ¿À¸¥ÂÊ ´ÜÃ߷ΠŬ¸¯ÇÏ°í ·Î±× »ç¿ëÀ» Ŭ¸¯ÇÑ ´ÙÀ½ ÇöÀç ·Î±× ÇÊÅ͸µÀ» Ŭ¸¯ÇÕ´Ï´Ù. XML ÅÇÀ» Ŭ¸¯ÇÑ ´ÙÀ½ ¼öµ¿À¸·Î Äõ¸® ÆíÁý È®ÀζõÀ» ¼±ÅÃÇÕ´Ï´Ù.
±×¸² Ãà¼Ò±×¸² È®´ë


ÀÌ ·Î±×¸¦ ¼öÁýÇÑ ÈÄ¿¡ ´ÙÀ½ ÇÊÅ͸¦ »ç¿ëÇÏ¿© Ű ±æÀ̰¡ 1024ºñÆ®º¸´Ù ªÀº ÀÎÁõ ÀÛ¾÷À» ã±â À§ÇØ °Ë»öÇØ¾ß ÇÏ´Â Ç׸ñ ¼ö¸¦ ÁÙÀÏ ¼ö ÀÖ½À´Ï´Ù. ´ÙÀ½ ÇÊÅ͸¦ ÁöÁ¤Çϸé 512ºñÆ® ±æÀÌÀÇ Å°¸¦ ã½À´Ï´Ù.

<QueryList>

<Query Id="0" Path="Microsoft-Windows-CAPI2/Operational">

<Select Path="Microsoft-Windows-CAPI2/Operational">Event[UserData[CertGetCertificateChain[CertificateChain[ChainElement[PublicKeyAlgorithm[@publicKeyLength='512']]]]] and UserData[CertGetCertificateChain[CertificateChain[ChainElement[PublicKeyAlgorithm[@publicKeyName='RSA']]]]]]</Select>

</Query>

</QueryList>

±×¸² Ãà¼Ò±×¸² È®´ë


´ÜÀÏ Äõ¸®¸¦ »ç¿ëÇÏ¿© ¿©·¯ °³ÀÇ Å° ±æÀ̸¦ Äõ¸®ÇÒ ¼öµµ ÀÖ½À´Ï´Ù. ¿¹¸¦ µé¾î ´ÙÀ½ ÇÊÅ͸¦ Àû¿ëÇÏ¸é ±æÀ̰¡ 384ºñÆ®¿Í 512ºñÆ®ÀΠ۸¦ ¸ðµÎ Äõ¸®ÇÕ´Ï´Ù.

<QueryList>

<Query Id="0" Path="Microsoft-Windows-CAPI2/Operational">

<Select Path="Microsoft-Windows-CAPI2/Operational">Event[UserData[CertGetCertificateChain[CertificateChain[ChainElement[PublicKeyAlgorithm[@publicKeyLength='384']]]]] and UserData[CertGetCertificateChain[CertificateChain[ChainElement[PublicKeyAlgorithm[@publicKeyName='RSA']]]]]] or Event[UserData[CertGetCertificateChain[CertificateChain[ChainElement[PublicKeyAlgorithm[@publicKeyLength='512']]]]] and UserData[CertGetCertificateChain[CertificateChain[ChainElement[PublicKeyAlgorithm[@publicKeyName='RSA']]]]]]</Select>

</Query>

</QueryList>

ÀÎÁõ¼­ ÅÛÇø´ È®ÀÎ

CA(ÀÎÁõ ±â°ü)¿¡ ´ëÇØ ´ÙÀ½ Äõ¸®¸¦ ½ÇÇàÇÏ¿© Ű ±æÀ̰¡ 1024ºñÆ®º¸´Ù ªÀº ÀÎÁõ¼­ ÅÛÇø´À» °Ë»öÇÒ ¼ö ÀÖ½À´Ï´Ù.

certutil -dstemplate | findstr "[ msPKI-Minimal-Key-Size" | findstr /v "1024 2048 4096"

Âü°í Á¶Á÷ÀÇ °¢ Æ÷¸®½ºÆ®¿¡¼­ ÀÌ ¸í·ÉÀ» ½ÇÇàÇØ¾ß ÇÕ´Ï´Ù.

ÀÌ Äõ¸®¸¦ ½ÇÇàÇÏ´Â °æ¿ì 1024ºñÆ®º¸´Ù ªÀº ۸¦ »ç¿ëÇÏ´Â ÅÛÇø´ÀÌ Å° Å©±â¿Í ÇÔ²² Ç¥½ÃµË´Ï´Ù. ´ÙÀ½ ±×¸²¿¡¼­´Â µÎ °³ÀÇ ±âº» Á¦°ø ÅÛÇø´ÀÎ SmartcardLogon°ú SmartcardUser°¡ ±âº» Ű ±æÀ̸¦ °¡Áö¸ç ÃÖ¼Ò Å° Å©±â 512ºñÆ®ÀÓÀ» º¸¿© ÁÝ´Ï´Ù. ÃÖ¼Ò Å° ±æÀ̰¡ 1024ºñÆ®º¸´Ù ªÀº Áߺ¹µÈ ´Ù¸¥ ÅÛÇø´ÀÌ ¹ß°ßµÉ ¼öµµ ÀÖ½À´Ï´Ù.

°Ë»öµÈ ÅÛÇø´ Áß¿¡¼­ 1024ºñÆ® ÀÌÇÏÀÇ Å°¸¦ Çã¿ëÇÏ´Â °¢ ÅÛÇø´¿¡ ´ëÇØ ÀÎÁõ ±â°ü ÄܼÖÀÇ ÀÎÁõ¼­ ÅÛÇø´ ¼½¼Ç¿¡ Ç¥½ÃµÈ ´ë·Î ÀÎÁõ¼­¸¦ ¹ß±ÞÇÒ ¼ö ÀÖ´ÂÁö È®ÀÎÇØ¾ß ÇÕ´Ï´Ù.

±×¸² Ãà¼Ò±×¸² È®´ë


¾÷µ¥ÀÌÆ®°¡ ¼³Ä¡µÈ ÄÄÇ»ÅÍ¿¡¼­ ·Î±ë »ç¿ë

·¹Áö½ºÆ®¸® ¼³Á¤À» »ç¿ëÇÏ¿© ÀÌ ¾÷µ¥ÀÌÆ®°¡ Àû¿ëµÈ ÄÄÇ»ÅÍ¿¡¼­ Ű ±æÀ̰¡ 1024ºñÆ®º¸´Ù ÀÛÀº RSA ÀÎÁõ¼­¸¦ ãµµ·Ï ÇÒ ¼ö ÀÖ½À´Ï´Ù. ·Î±ëÀ» ±¸ÇöÇϱâ À§ÇÑ ¿É¼ÇÀº 1024ºñÆ® ÀÌÇÏÀÇ Å° ±æÀ̸¦ Çã¿ëÇÏ´Â µ¥ »ç¿ëÇÒ ¼ö ÀÖ´Â ·¹Áö½ºÆ®¸® ¼³Á¤°ú ¹ÐÁ¢ÇÏ°Ô ¿¬°áµÇ¾î ÀÖÀ¸¹Ç·Î "ÇØ°á ¹æ¹ý" Àý¿¡ ¼³¸íµÇ¾î ÀÖ½À´Ï´Ù. ·Î±ëÀ» »ç¿ëÇϵµ·Ï ¼³Á¤ÇÏ´Â ¹æ¹ý¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ ³»¿ëÀº ÀÌ ¹®¼­ µÞºÎºÐ¿¡ ³ª¿À´Â "·¹Áö½ºÆ®¸® ¼³Á¤À» »ç¿ëÇÏ¿© 1024ºñÆ® ÀÌÇÏÀÇ Å° ±æÀÌ Çã¿ë" ÀýÀ» ÂüÁ¶ÇϽʽÿÀ.

ÇØ°á ¹æ¹ý

Ű ±æÀ̰¡ 1024ºñÆ®º¸´Ù ÀÛÀº ÀÎÁõ¼­ÀÇ Â÷´Ü°ú °ü·ÃµÈ ¹®Á¦ÀÇ ±âº»ÀûÀÎ ÇØ°á ¹æ¹ýÀº ´õ Å«(1024ºñÆ® ÀÌ»ó) ÀÎÁõ¼­¸¦ ±¸ÇöÇÏ´Â °ÍÀÔ´Ï´Ù. µû¶ó¼­ »ç¿ëÀڴ Ű ±æÀ̰¡ 2048ºñÆ® ÀÌ»óÀÎ ÀÎÁõ¼­¸¦ ±¸ÇöÇÏ´Â °ÍÀÌ ÁÁ½À´Ï´Ù.

ÀÎÁõ¼­ ÀÚµ¿ µî·ÏÀ» ÅëÇØ ¹ß±ÞµÈ ÀÎÁõ¼­ÀÇ Å° Å©±â ´Ã¸®±â

Ű ±æÀ̰¡ 1024ºñÆ®º¸´Ù ÀÛÀº RSA ÀÎÁõ¼­¸¦ ¹ß±ÞÇÑ ÅÛÇø´ÀÇ °æ¿ì ÃÖ¼Ò Å° Å©±â ¼³Á¤À» 1024ºñÆ® ÀÌ»óÀ¸·Î ´Ã¸®´Â °ÍÀ» °í·ÁÇØ¾ß ÇÕ´Ï´Ù. ¿©±â¼­´Â ÀÌ·¯ÇÑ ÀÎÁõ¼­°¡ ¹ß±ÞµÈ ÀåÄ¡°¡ ´õ Å« Ű Å©±â¸¦ Áö¿øÇÑ´Ù°í °¡Á¤ÇÕ´Ï´Ù.

ÃÖ¼Ò Å° Å©±â¸¦ ´Ã¸° ÈÄ¿¡ ÀÎÁõ¼­ ÅÛÇø´ ÄܼÖÀÇ ¸ðµç ÀÎÁõ¼­ ¼ÒÀ¯ÀÚ ´Ù½Ã µî·Ï ¿É¼ÇÀ» »ç¿ëÇÏ¿© Ŭ¶óÀÌ¾ðÆ® ÄÄÇ»ÅͰ¡ ´Ù½Ã µî·ÏÇÏ°í ´õ Å« Ű Å©±â¸¦ ¿äûÇϵµ·Ï ÇÕ´Ï´Ù.

±×¸² Ãà¼Ò±×¸² È®´ë


±âº» Á¦°øµÈ ½º¸¶Æ® Ä«µå ·Î±×¿Â ¶Ç´Â ½º¸¶Æ® Ä«µå »ç¿ëÀÚ ÅÛÇø´À» »ç¿ëÇÏ¿© ÀÎÁõ¼­¸¦ ¹ß±ÞÇÑ °æ¿ì ÅÛÇø´ÀÇ ÃÖ¼Ò Å° Å©±â¸¦ Á÷Á¢ Á¶Á¤ÇÒ ¼ö ¾ø½À´Ï´Ù. ´ë½Å ÀÌ ÅÛÇø´À» º¹Á¦ÇÑ ´ÙÀ½ º¹Á¦µÈ ÅÛÇø´¿¡¼­ Ű Å©±â¸¦ ´Ã¸®°í ¿øº» ÅÛÇø´À» º¹Á¦ÇÑ ÅÛÇø´À¸·Î ¹Ù²ß´Ï´Ù.

±×¸² Ãà¼Ò±×¸² È®´ë


ÅÛÇø´À» ¹Ù²Û ÈÄ¿¡´Â ¸ðµç ÀÎÁõ¼­ ¼ÒÀ¯ÀÚ ´Ù½Ã µî·Ï ¿É¼ÇÀ» »ç¿ëÇÏ¿© Ŭ¶óÀÌ¾ðÆ® ÄÄÇ»ÅͰ¡ ´Ù½Ã µî·ÏÇÏ°í ´õ Å« Ű Å©±â¸¦ ¿äûÇϵµ·Ï ÇÕ´Ï´Ù.

±×¸² Ãà¼Ò±×¸² È®´ë


·¹Áö½ºÆ®¸® ¼³Á¤À» »ç¿ëÇÏ¿© 1024ºñÆ® ÀÌÇÏÀÇ Å° ±æÀÌ Çã¿ë

Microsoft´Â 1024ºñÆ®º¸´Ù ªÀº ÀÎÁõ¼­¸¦ »ç¿ëÇÏ´Â °ÍÀ» ±ÇÀåÇÏÁö ¾Ê½À´Ï´Ù. ±×·¸Áö¸¸ °í°´µéÀº Ű ±æÀ̰¡ 1024ºñÆ®º¸´Ù ªÀº RSA ÀÎÁõ¼­¸¦ ±³Ã¼Çϱâ À§ÇÑ Àå±âÀûÀÎ ÇØ°á ¹æ¹ýÀÌ °³¹ßµÇ´Â µ¿¾È ÀÓ½Ã ÇØ°á ¹æ¹ýÀÌ ÇÊ¿äÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ·¯ÇÑ °æ¿ì¸¦ À§ÇØ Microsoft´Â ¾÷µ¥ÀÌÆ® ÀÛµ¿ ¹æ½ÄÀ» º¯°æÇÏ´Â ±â´ÉÀ» Á¦°øÇϰí ÀÖ½À´Ï´Ù. ÀÌ·¯ÇÑ ¼³Á¤À» ±¸¼ºÇÏ¸é °ø°ÝÀÚ°¡ ÀÎÁõ¼­¸¦ ÇØµ¶Çϰí À̸¦ ¾Ç¿ëÇÏ¿© ÄÜÅÙÃ÷¸¦ ½ºÇªÇÎÇϰųª, ÇÇ½Ì °ø°ÝÀ» °¨ÇàÇϰųª, ¸Þ½ÃÁö °¡·Îä±â(man-in-the-middle) °ø°ÝÀ» ÇÒ ¼öµµ ÀÖ½À´Ï´Ù.

Áß¿ä ÀÌ Àý, ¹æ¹ý ¶Ç´Â ÀÛ¾÷¿¡´Â ·¹Áö½ºÆ®¸®¸¦ ¼öÁ¤ÇÏ´Â ¹æ¹ý¿¡ ´ëÇÑ ´Ü°è°¡ Æ÷ÇԵǾî ÀÖ½À´Ï´Ù. ±×·¯³ª ·¹Áö½ºÆ®¸®¸¦ À߸ø ¼öÁ¤ÇÏ¸é ½É°¢ÇÑ ¹®Á¦°¡ ¹ß»ýÇÒ ¼ö ÀÖ½À´Ï´Ù. µû¶ó¼­ ´ÙÀ½ ´Ü°è¸¦ ÁÖÀÇÇÏ¿© ¼öÇàÇØ¾ß ÇÕ´Ï´Ù. Ãß°¡ º¸È£ Á¶Ä¡·Î ·¹Áö½ºÆ®¸®¸¦ ¼öÁ¤Çϱâ Àü¿¡ ÇØ´ç ·¹Áö½ºÆ®¸®¸¦ ¹é¾÷ÇÏ´Â °ÍÀÌ ÁÁ½À´Ï´Ù. ÀÌ·¸°Ô ÇÏ¸é ¹®Á¦°¡ ¹ß»ýÇÏ´Â °æ¿ì ·¹Áö½ºÆ®¸®¸¦ º¹¿øÇÒ ¼ö ÀÖ½À´Ï´Ù. ·¹Áö½ºÆ®¸® ¹é¾÷ ¹× º¹¿ø ¹æ¹ý¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ ³»¿ëÀº ´ÙÀ½ ¹®¼­ ¹øÈ£¸¦ Ŭ¸¯ÇÏ¿© Microsoft ±â¼ú ÀÚ·á ¹®¼­¸¦ ÂüÁ¶ÇϽʽÿÀ.
322756 Windows¿¡¼­ ·¹Áö½ºÆ®¸®¸¦ ¹é¾÷ ¹× º¹¿øÇÏ´Â ¹æ¹ý
ÀÌ ¾÷µ¥ÀÌÆ®°¡ Àû¿ëµÈ Windows 8 ¶Ç´Â Windows Server 2012 ±â¹Ý ÄÄÇ»ÅÍ¿¡¼­ ´ÙÀ½ ·¹Áö½ºÆ®¸® °æ·Î¿Í ¼³Á¤À» »ç¿ëÇÏ¿© Ű ±æÀ̰¡ 1024ºñÆ®º¸´Ù ªÀº RSA ÀÎÁõ¼­ÀÇ °Ë»ö°ú Â÷´ÜÀ» Á¦¾îÇÒ ¼ö ÀÖ½À´Ï´Ù.

HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CertDLLCreateCertificateChainEngine\Config

1024ºñÆ® ÀÌÇÏÀÇ Å° Â÷´Ü ±â´ÉÀÌ ÀÛµ¿ÇÏ´Â ¹æ½ÄÀ» Á¦¾îÇÏ´Â °ª¿¡´Â ´ÙÀ½ ³× °¡Áö°¡ ÀÖ½À´Ï´Ù.
  • MinRsaPubKeyBitLength
  • EnableWeakSignatureFlags
  • WeakSignatureLogDir
  • WeakRsaPubKeyTime
ÀÌ·¯ÇÑ °¢ °ª°ú ÀÌ·¯ÇÑ °ªÀ¸·Î Á¦¾îµÇ´Â ´ë»óÀº ´ÙÀ½ Àý¿¡ ¼³¸íµÇ¾î ÀÖ½À´Ï´Ù.

Windows Vista ¹× Windows Server 2008 ÀÌ»ó ¿î¿µ üÁ¦¿¡¼­´Â certutil ¸í·ÉÀ» »ç¿ëÇÏ¿© ÀÌ·¯ÇÑ ·¹Áö½ºÆ®¸® ¼³Á¤À» º¯°æÇÒ ¼ö ÀÖ½À´Ï´Ù. Windows XP, Windows Server 2003 ¹× Windows Server 2003 R2¿¡¼­´Â certutil ¸í·ÉÀ» »ç¿ëÇÏ¿© ÀÌ·¯ÇÑ ·¹Áö½ºÆ®¸® ¼³Á¤À» º¯°æÇÒ ¼ö ¾ø½À´Ï´Ù. ±×·¯³ª ·¹Áö½ºÆ®¸® ÆíÁý±â, reg ¸í·É ¶Ç´Â reg ÆÄÀÏÀº »ç¿ë °¡´ÉÇÕ´Ï´Ù.

MinRsaPubKeyBitLength

MinRsaPubKeyBitLength´Â Çã¿ëµÇ´Â ÃÖ¼Ò RSA Ű ±æÀ̸¦ Á¤ÀÇÇÏ´Â DWORD °ªÀÔ´Ï´Ù. ±âº»ÀûÀ¸·Î ÀÌ °ªÀº Á¸ÀçÇÏÁö ¾ÊÀ¸¸ç Çã¿ëµÇ´Â ÃÖ¼Ò RSA Ű ±æÀÌ´Â 1024ÀÔ´Ï´Ù. ´ÙÀ½ ¸í·ÉÀ» ½ÇÇàÇÏ¿© certutilÀ» »ç¿ëÇϸé ÀÌ °ªÀ» 512·Î ¼³Á¤ÇÒ ¼ö ÀÖ½À´Ï´Ù.

certutil -setreg chain\minRSAPubKeyBitLength 512

Âü°íÀÌ ¹®¼­¿¡ Ç¥½ÃµÇ´Â ¸ðµç certutil ¸í·ÉÀº ·¹Áö½ºÆ®¸®¸¦ º¯°æÇÏ°Ô µÇ¹Ç·Î ·ÎÄà °ü¸®ÀÚ ±ÇÇÑÀÌ ÇÊ¿äÇÕ´Ï´Ù. "º¯°æ »çÇ×ÀÌ Àû¿ëµÇ·Á¸é CertSvc ¼­ºñ½º°¡ ´Ù½Ã ½ÃÀ۵Ǿî¾ß ÇÒ ¼öµµ ÀÖ½À´Ï´Ù." ¸Þ½ÃÁö´Â ¹«½ÃÇØµµ µË´Ï´Ù. ÀÌ·¯ÇÑ ¸í·ÉÀº ÀÎÁõ¼­ ¼­ºñ½º(CertSvc)¿¡ ¿µÇâÀ» ¹ÌÄ¡Áö ¾ÊÀ¸¹Ç·Î ´Ù½Ã ½ÃÀÛÇÒ Çʿ䰡 ¾ø½À´Ï´Ù.?

ÀÌ °ªÀ» Á¦°ÅÇÏ¿© ±æÀ̰¡ 1024ºñÆ®º¸´Ù ªÀº ۸¦ Â÷´ÜÇÏ´Â ¹æ½ÄÀ¸·Î º¹±ÍÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ·¸°Ô ÇÏ·Á¸é ´ÙÀ½ certutil ¸í·ÉÀ» ½ÇÇàÇÕ´Ï´Ù.

certutil -delreg chain\MinRsaPubKeyBitLength

EnableWeakSignatureFlags

EnableWeakSignatureFlags DWORD °ªÀº 2, 4, 6 ¹× 8ÀÇ ¼¼ °¡Áö °ªÀ» °¡Áú ¼ö ÀÖ½À´Ï´Ù. ÀÌ·¯ÇÑ ¼³Á¤¿¡ µû¶ó 1024ºñÆ® ¹Ì¸¸ÀÇ Å° °Ë»ö ¹× Â÷´Ü ±â´É ÀÛµ¿ ¹æ½ÄÀÌ ´Þ¶óÁý´Ï´Ù. ÀÌ·¯ÇÑ ¼³Á¤Àº ´ÙÀ½ Ç¥¿¡ ¼³¸íµÇ¾î ÀÖ½À´Ï´Ù.
Ç¥ Ãà¼ÒÇ¥ È®´ë
10Áø¼ö °ª¼³¸í
2»ç¿ëÇϵµ·Ï ¼³Á¤µÇ¸é ·çÆ® ÀÎÁõ¼­(üÀÎ ÀÛ¼º Áß¿¡)´Â Ű ±æÀ̰¡ 1024ºñÆ®º¸´Ù ªÀº RSA ÀÎÁõ¼­¸¦ Æ÷ÇÔÇÒ ¼ö ÀÖ½À´Ï´Ù. üÀÎ ¾Æ·¡ÂÊ¿¡¼­ 1024ºñÆ® ¹Ì¸¸ÀÇ RSA ÀÎÁõ¼­¸¦ Â÷´ÜÇÏ´Â ¹æ½ÄÀº ¿©ÀüÈ÷ Àû¿ëµË´Ï´Ù. ÀÌ °ªÀÌ ¼³Á¤µÇ¾úÀ» ¶§ »ç¿ëÇϵµ·Ï ¼³Á¤µÈ Ç÷¡±×´Â CERT_CHAIN_ENABLE_WEAK_RSA_ROOT_FLAG·Î ¼³Á¤µË´Ï´Ù.
4·Î±ëÀÌ »ç¿ëµÇÁö¸¸ Ű ±æÀ̰¡ 1024ºñÆ®º¸´Ù ÀÛÀº RSA ÀÎÁõ¼­ÀÇ Â÷´ÜÀº ¿©ÀüÈ÷ Àû¿ëµË´Ï´Ù. »ç¿ëÇϵµ·Ï ¼³Á¤µÉ °æ¿ì WeakSignatureLogDirÀÌ ÇÊ¿äÇÕ´Ï´Ù. ±æÀ̰¡ 1024ºñÆ® ¹Ì¸¸ÀÎ ¸ðµç Ű´Â ½ÇÁ¦ WeakSignatureLogDir Æú´õ·Î º¹»çµË´Ï´Ù. ÀÌ °ªÀÌ ¼³Á¤µÇ¾úÀ» ¶§ »ç¿ëÇϵµ·Ï ¼³Á¤µÈ Ç÷¡±×´Â CERT_CHAIN_ENABLE_WEAK_LOGGING_FLAG·Î ¼³Á¤µË´Ï´Ù.
6»ç¿ëÇϵµ·Ï ¼³Á¤µÇ¸é ·çÆ® ÀÎÁõ¼­´Â Ű ±æÀ̰¡ 1024ºñÆ®º¸´Ù ÀÛÀº RSA ÀÎÁõ¼­¸¦ Æ÷ÇÔÇÒ ¼ö ÀÖÀ¸¸ç WeakSignatureLogDirÀÌ ÇÊ¿äÇÕ´Ï´Ù. Ű ±æÀ̰¡ 1024ºñÆ®º¸´Ù ÀÛÀº ·çÆ® ÀÎÁõ¼­ ¾Æ·¡ÀÇ ¸ðµç Ű´Â Â÷´ÜµÇ°í WeakSignatureLogDir·Î ÁöÁ¤µÈ Æú´õ¿¡ ·Î±ëµË´Ï´Ù.
8·Î±ëÀÌ »ç¿ëµÇ¸ç ±æÀ̰¡ 1024ºñÆ®º¸´Ù ÀÛÀº ŰÀÇ Â÷´ÜÀÌ Àû¿ëµË´Ï´Ù. »ç¿ëÇϵµ·Ï ¼³Á¤µÉ °æ¿ì WeakSignatureLogDirÀÌ ÇÊ¿äÇÕ´Ï´Ù. ±æÀ̰¡ 1024ºñÆ® ¹Ì¸¸ÀÎ ¸ðµç Ű´Â ½ÇÁ¦ WeakSignatureLogDir Æú´õ·Î º¹»çµË´Ï´Ù. ÀÌ °ªÀÌ ¼³Á¤µÇ¾úÀ» ¶§ »ç¿ëÇϵµ·Ï ¼³Á¤µÈ Ç÷¡±×´Â CERT_CHAIN_ENABLE_ONLY_WEAK_LOGGING_FLAG·Î ¼³Á¤µË´Ï´Ù.

¿¹Á¦

Ű ±æÀ̰¡ 1024ºñÆ®º¸´Ù ÀÛÀº RSA ·çÆ® ÀÎÁõ¼­¸¦ »ç¿ëÇϵµ·Ï ¼³Á¤ÇÏ·Á¸é ´ÙÀ½ certutil ¸í·ÉÀ» »ç¿ëÇÕ´Ï´Ù.

certutil -setreg chain\EnableWeakSignatureFlags 2

Ű ±æÀ̰¡ 1024ºñÆ®º¸´Ù ÀÛÀº ÀÎÁõ¼­¸¦ °è¼Ó Â÷´ÜÇϸ鼭 ·Î±ëÀ» »ç¿ëÇϵµ·Ï ¼³Á¤ÇÏ·Á¸é ´ÙÀ½ certutil ¸í·ÉÀ» »ç¿ëÇÕ´Ï´Ù.

certutil -setreg chain\EnableWeakSignatureFlags 4

·çÆ® ÀÎÁõ¼­ ¾Æ·¡¿¡¼­ Ű ±æÀ̰¡ 1024ºñÆ®º¸´Ù ÀÛÀº RSA ÀÎÁõ¼­ÀÇ ·Î±ëÀ» »ç¿ëÇϵµ·Ï ¼³Á¤ÇÏ·Á¸é ´ÙÀ½ certutil ¸í·ÉÀ» »ç¿ëÇÕ´Ï´Ù.

certutil -setreg chain\EnableWeakSignatureFlags 6

·Î±ë¸¸ »ç¿ëÇϵµ·Ï ¼³Á¤ÇÏ°í ±æÀ̰¡ 1024ºñÆ®º¸´Ù ÀÛÀº ۸¦ Â÷´ÜÇÏÁö ¾ÊÀ¸·Á¸é ´ÙÀ½ certutil ¸í·ÉÀ» »ç¿ëÇÕ´Ï´Ù.

certutil -setreg chain\EnableWeakSignatureFlags 8

Âü°í ·Î±ëÀ» »ç¿ëÇϵµ·Ï ¼³Á¤Çϸé(10Áø¼ö ¼³Á¤ 4, 6 ¶Ç´Â 8) ´ÙÀ½ Àý¿¡ ¼³¸íµÈ °Íó·³ ·Î±× µð·ºÅ͸®µµ ±¸¼ºÇØ¾ß ÇÕ´Ï´Ù.

WeakSignatureLogDir

Á¤ÀÇµÉ °æ¿ì Ű ±æÀ̰¡ 1024ºñÆ®º¸´Ù ªÀº ÀÎÁõ¼­°¡ ÁöÁ¤µÈ Æú´õ¿¡ ±â·ÏµË´Ï´Ù. ¿¹¸¦ µé¾î C:\Under1024KeyLog°¡ ÀÌ °ªÀÇ µ¥ÀÌÅͰ¡ µÉ ¼ö ÀÖ½À´Ï´Ù. ÀÌ ¿É¼ÇÀº EnableWeakSignatureFlags°¡ 4 ¶Ç´Â 8·Î ¼³Á¤µÇ¾î ÀÖÀ» ¶§ ÇÊ¿äÇÕ´Ï´Ù. ÀÎÁõµÈ »ç¿ëÀÚ¿Í ·Î±× ±×·ì ¸ðµç ÀÀ¿ë ÇÁ·Î±×·¥ ÆÐŰÁö µÑ ´Ù ¼öÁ¤ ¾×¼¼½º ±ÇÇÑÀ» °¡Áöµµ·Ï ÁöÁ¤µÈ Æú´õ¿¡ ´ëÇÑ º¸¾ÈÀ» ±¸¼ºÇØ¾ß ÇÕ´Ï´Ù. C:\Under1024KeyLog¿¡ ´ëÇØ ÀÌ °ªÀ» ¼³Á¤ÇÏ·Á¸é ´ÙÀ½ certutil ¸í·ÉÀ» »ç¿ëÇÕ´Ï´Ù.

Certutil -setreg chain\WeakSignatureLogDir "c:\Under1024KeyLog"

¶ÇÇÑ ³×Æ®¿öÅ© °øÀ¯ Æú´õ¿¡ ¾²µµ·Ï WeakSignatureLogDirÀ» ±¸¼ºÇÒ ¼öµµ ÀÖ½À´Ï´Ù. ±¸¼ºµÈ ¸ðµç »ç¿ëÀÚ°¡ °øÀ¯ Æú´õ¿¡ ¾µ ¼ö ÀÖµµ·Ï ³×Æ®¿öÅ© À§Ä¡¿¡ ´ëÇØ ÇØ´ç »ç¿ë ±ÇÇÑÀÌ ±¸¼ºµÇ¾î¾ß ÇÕ´Ï´Ù. ´ÙÀ½ ¸í·ÉÀº Server1¿¡¼­ ³×Æ®¿öÅ© °øÀ¯ Æú´õ RSA¿¡ ÀÖ´Â Keys Æú´õ¿¡ ¾µ ¼ö ÀÖµµ·Ï WeakSignatureLogDirÀ» ±¸¼ºÇÏ´Â ¹æ¹ýÀÇ ¿¹ÀÔ´Ï´Ù.

Certutil -setreg chain\WeakSignatureLogDir "\\server1\rsa\keys"

WeakRsaPubKeyTime

WeakRsaPubKeyTimeÀº UTC/GMT·Î ÀúÀåµÈ Windows FILETIME µ¥ÀÌÅÍ Çü½ÄÀ» Æ÷ÇÔÇÏ´Â 8¹ÙÀÌÆ® REG_BINARY °ªÀÔ´Ï´Ù. ÀÌ °ªÀº Authenticode ¼­¸í¿¡ ´ëÇØ ±æÀ̰¡ 1024ºñÆ®º¸´Ù ªÀº ۸¦ Â÷´ÜÇÏ¿© ÀáÀçÀûÀÎ ¹®Á¦¸¦ ÁÙÀÌ´Â µ¥ ÁÖ·Î »ç¿ëµË´Ï´Ù. ±¸¼ºµÈ ³¯Â¥ ¹× ½Ã°£ Àü¿¡ Äڵ忡 ¼³¸íÇÏ´Â µ¥ »ç¿ëµÈ ÀÎÁõ¼­´Â Ű ±æÀ̰¡ 1024ºñÆ®º¸´Ù ªÀºÁö È®ÀεÇÁö ¾Ê½À´Ï´Ù. ±âº»ÀûÀ¸·Î ÀÌ ·¹Áö½ºÆ®¸® °ªÀº ¾øÀ¸¸ç ÀÚÁ¤ UTC/GMT¿¡ 2010³â 1¿ù 1ÀÏ ¾ÆÄ§ ÀÏÂïÀ¸·Î Ãë±ÞµË´Ï´Ù.

Âü°íÀÌ ¼³Á¤Àº ÀÎÁõ¼­°¡ ŸÀÓ½ºÅÆÇÁ ÆÄÀÏ¿¡ Authenticode ¼³¸íÀ» ÇÏ´Â µ¥ »ç¿ëµÇ¾úÀ» ¶§¸¸ Àû¿ë °¡´ÉÇÕ´Ï´Ù. ÀÌ Äڵ忡 ½Ã°£ÀÌ ÂïÈ÷Áö ¾ÊÀº °æ¿ì ÇöÀç ½Ã°£ÀÌ »ç¿ëµÇ°í WeakRsaPubKeyTime ¼³Á¤Àº »ç¿ëµÇÁö ¾Ê½À´Ï´Ù.

WeakRsaPubKeyTime ¼³Á¤Àº ÀÌÀü ¼­¸íÀÌ À¯È¿ÇÏ´Ù°í °£ÁÖµÉ ³¯Â¥¸¦ ±¸¼ºÇÒ ¼ö ÀÖµµ·Ï ÇÕ´Ï´Ù. WeakRsaPubKeyTime¿¡ ´ëÇØ ´Ù¸¥ ³¯Â¥¿Í ½Ã°£À» ¼³Á¤ÇØ¾ß ÇÒ °æ¿ì certutilÀ» »ç¿ëÇÏ¿© ´Ù¸¥ ³¯Â¥¸¦ ¼³Á¤ÇÒ ¼ö ÀÖ½À´Ï´Ù. ¿¹¸¦ µé¾î ³¯Â¥¸¦ 2010³â 8¿ù 29ÀÏ·Î ¼³Á¤ÇÏ·Á¸é ´ÙÀ½ ¸í·ÉÀ» »ç¿ëÇÒ ¼ö ÀÖÀ» °ÍÀÔ´Ï´Ù.

certutil -setreg chain\WeakRsaPubKeyTime @08/29/2010

ƯÁ¤ ³¯Â¥(¿¹: 2011³â 7¿ù 4ÀÏ 6:00 PM)¸¦ ¼³Á¤ÇØ¾ß ÇÒ °æ¿ì ÀÏ ¹× ½Ã°£À» +[dd:hh] Çü½ÄÀ¸·Î ÀÌ ¸í·É¿¡ Ãß°¡ÇÕ´Ï´Ù. 6:00 PMÀº 2011³â 7¿ù 4ÀÏ ÀÚÁ¤ºÎÅÍ 18½Ã°£ÀÌ °æ°úÇÑ °ÍÀ̹ǷΠ´ÙÀ½ ¸í·ÉÀ» ½ÇÇàÇÒ ¼ö ÀÖ½À´Ï´Ù.

certutil -setreg chain\WeakRsaPubKeyTime @01/15/2011+00:18

IIS(ÀÎÅÍ³Ý Á¤º¸ ¼­ºñ½º)¿¡¼­ ÀÎÁõ¼­ ±¸¼º

1024ºñÆ® ÀÌ»óÀÇ »õ ÀÎÁõ¼­¸¦ ¹ß±ÞÇØ¾ß ÇÏ´Â IIS °í°´ÀÎ °æ¿ì ´ÙÀ½ ¹®¼­¸¦ ÂüÁ¶ÇϽʽÿÀ.
IIS 7¿¡¼­ SSLÀ» ¼³Á¤ÇÏ´Â ¹æ¹ý
IIS 6ÀÇ SSL ¹× ÀÎÁõ¼­

ÇØ°á ¹æ¹ý

Microsoft ´Ù¿î·Îµå ¼¾ÅÍ¿¡¼­ ´ÙÀ½ ÆÄÀÏÀ» ´Ù¿î·ÎµåÇÒ ¼ö ÀÖ½À´Ï´Ù.


Áö¿øµÇ´Â ¸ðµç x86 ±â¹Ý ¹öÀüÀÇ Windows XP

±×¸² Ãà¼Ò±×¸² È®´ë
´Ù¿î·Îµå
ÀÌ ÆÐŰÁö¸¦ Áö±Ý ´Ù¿î·ÎµåÇÕ´Ï´Ù.

Áö¿øµÇ´Â ¸ðµç x64 ±â¹Ý ¹öÀüÀÇ Windows XP Professional x64 ¹öÀü

±×¸² Ãà¼Ò±×¸² È®´ë
´Ù¿î·Îµå
ÀÌ ÆÐŰÁö¸¦ Áö±Ý ´Ù¿î·ÎµåÇÕ´Ï´Ù.

Áö¿øµÇ´Â ¸ðµç x86 ±â¹Ý ¹öÀüÀÇ Windows Server 2003

±×¸² Ãà¼Ò±×¸² È®´ë
´Ù¿î·Îµå
ÀÌ ÆÐŰÁö¸¦ Áö±Ý ´Ù¿î·ÎµåÇÕ´Ï´Ù.

Áö¿øµÇ´Â ¸ðµç x64 ±â¹Ý ¹öÀüÀÇ Windows Server 2003

±×¸² Ãà¼Ò±×¸² È®´ë
´Ù¿î·Îµå
ÀÌ ÆÐŰÁö¸¦ Áö±Ý ´Ù¿î·ÎµåÇÕ´Ï´Ù.

Áö¿øµÇ´Â ¸ðµç IA-64 ±â¹Ý ¹öÀüÀÇ Windows Server 2003

±×¸² Ãà¼Ò±×¸² È®´ë
´Ù¿î·Îµå
ÀÌ ÆÐŰÁö¸¦ Áö±Ý ´Ù¿î·ÎµåÇÕ´Ï´Ù.

Áö¿øµÇ´Â ¸ðµç x86 ±â¹Ý ¹öÀüÀÇ Windows Vista

±×¸² Ãà¼Ò±×¸² È®´ë
´Ù¿î·Îµå
ÀÌ ÆÐŰÁö¸¦ Áö±Ý ´Ù¿î·ÎµåÇÕ´Ï´Ù.

Áö¿øµÇ´Â ¸ðµç x64 ±â¹Ý ¹öÀüÀÇ Windows Vista

±×¸² Ãà¼Ò±×¸² È®´ë
´Ù¿î·Îµå
ÀÌ ÆÐŰÁö¸¦ Áö±Ý ´Ù¿î·ÎµåÇÕ´Ï´Ù.

Áö¿øµÇ´Â ¸ðµç x86 ±â¹Ý ¹öÀüÀÇ Windows Server 2008

±×¸² Ãà¼Ò±×¸² È®´ë
´Ù¿î·Îµå
ÀÌ ÆÐŰÁö¸¦ Áö±Ý ´Ù¿î·ÎµåÇÕ´Ï´Ù.

Áö¿øµÇ´Â ¸ðµç x64 ±â¹Ý ¹öÀüÀÇ Windows Server 2008

±×¸² Ãà¼Ò±×¸² È®´ë
´Ù¿î·Îµå
ÀÌ ÆÐŰÁö¸¦ Áö±Ý ´Ù¿î·ÎµåÇÕ´Ï´Ù.

Áö¿øµÇ´Â ¸ðµç IA-64 ±â¹Ý ¹öÀüÀÇ Windows Server 2008

±×¸² Ãà¼Ò±×¸² È®´ë
´Ù¿î·Îµå
ÀÌ ÆÐŰÁö¸¦ Áö±Ý ´Ù¿î·ÎµåÇÕ´Ï´Ù.

Áö¿øµÇ´Â ¸ðµç x86 ±â¹Ý ¹öÀüÀÇ Windows 7

±×¸² Ãà¼Ò±×¸² È®´ë
´Ù¿î·Îµå
ÀÌ ÆÐŰÁö¸¦ Áö±Ý ´Ù¿î·ÎµåÇÕ´Ï´Ù.

Áö¿øµÇ´Â ¸ðµç x64 ±â¹Ý ¹öÀüÀÇ Windows 7

±×¸² Ãà¼Ò±×¸² È®´ë
´Ù¿î·Îµå
ÀÌ ÆÐŰÁö¸¦ Áö±Ý ´Ù¿î·ÎµåÇÕ´Ï´Ù.

Áö¿øµÇ´Â ¸ðµç x64 ±â¹Ý ¹öÀüÀÇ Windows Server 2008 R2

±×¸² Ãà¼Ò±×¸² È®´ë
´Ù¿î·Îµå
ÀÌ ÆÐŰÁö¸¦ Áö±Ý ´Ù¿î·ÎµåÇÕ´Ï´Ù.

Áö¿øµÇ´Â ¸ðµç IA-64 ±â¹Ý ¹öÀüÀÇ Windows Server 2008 R2

±×¸² Ãà¼Ò±×¸² È®´ë
´Ù¿î·Îµå
ÀÌ ÆÐŰÁö¸¦ Áö±Ý ´Ù¿î·ÎµåÇÕ´Ï´Ù.

Áö¿øµÇ´Â ¸ðµç x86 ±â¹Ý ¹öÀüÀÇ Windows Embedded Standard 7

±×¸² Ãà¼Ò±×¸² È®´ë
´Ù¿î·Îµå
ÀÌ ÆÐŰÁö¸¦ Áö±Ý ´Ù¿î·ÎµåÇÕ´Ï´Ù.

Áö¿øµÇ´Â ¸ðµç x64 ±â¹Ý ¹öÀüÀÇ Windows Embedded Standard 7

±×¸² Ãà¼Ò±×¸² È®´ë
´Ù¿î·Îµå
ÀÌ ÆÐŰÁö¸¦ Áö±Ý ´Ù¿î·ÎµåÇÕ´Ï´Ù.

Ãâ½ÃµÈ ³¯Â¥: 2012³â 8¿ù 14ÀÏ

Microsoft Áö¿ø ÆÄÀÏÀ» ´Ù¿î·ÎµåÇÏ´Â ¹æ¹ý¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ ³»¿ëÀº ´ÙÀ½ ¹®¼­ ¹øÈ£¸¦ Ŭ¸¯ÇÏ¿© Microsoft ±â¼ú ÀÚ·á ¹®¼­¸¦ ÂüÁ¶ÇϽʽÿÀ.
119591 ¿Â¶óÀÎ ¼­ºñ½º·ÎºÎÅÍ Microsoft Áö¿ø ÆÄÀÏÀ» ±¸ÇÏ´Â ¹æ¹ý
Microsoft´Â ÆÄÀÏÀ» °Ô½ÃÇÑ ³¯Â¥¿¡ »ç¿ëÇÒ ¼ö ÀÖ´Â ÃֽйÙÀÌ·¯½º ¿¹¹æ ÇÁ·Î±×·¥À¸·Î ÀÌ ÆÄÀÏÀ» °Ë»çÇß½À´Ï´Ù. ÀÌ ÆÄÀÏÀº ÇØ´ç ÆÄÀÏÀ» ¹«´ÜÀ¸·Î º¯°æÇÒ ¼ö ¾øµµ·Ï º¸¾ÈÀÌ °­È­µÈ ¼­¹ö¿¡ º¸°üµË´Ï´Ù.

ÆÄÀÏ Á¤º¸

ÀÌ·¯ÇÑ ÆÐŰÁö¿¡ Á¦°øµÇ´Â ÆÄÀÏ ¸ñ·ÏÀ» º¸·Á¸é ´ÙÀ½ ¸µÅ©¸¦ Ŭ¸¯ÇϽʽÿÀ.
File attributes tables for security update 2661254.csv

¼Ó¼º

±â¼ú ÀÚ·á: 2661254 - ¸¶Áö¸· °ËÅä: 2012³â 12¿ù 26ÀÏ ¼ö¿äÀÏ - ¼öÁ¤: 6.0
º» ¹®¼­ÀÇ Á¤º¸´Â ´ÙÀ½ÀÇ Á¦Ç°¿¡ Àû¿ëµË´Ï´Ù.
  • Windows 7 Service Pack 1?À»(¸¦) ´ÙÀ½°ú ÇÔ²² »ç¿ëÇßÀ» ¶§
    • Windows 7 Enterprise
    • Windows 7 Professional
    • Windows 7 Ultimate
    • Windows 7 Home Premium
    • Windows 7 Home Basic
  • Windows 7 Enterprise
  • Windows 7 Professional
  • Windows 7 Ultimate
  • Windows 7 Home Premium
  • Windows 7 Home Basic
  • Windows Server 2008 R2 Service Pack 1?À»(¸¦) ´ÙÀ½°ú ÇÔ²² »ç¿ëÇßÀ» ¶§
    • Windows Server 2008 R2 Standard
    • Windows Server 2008 R2 Enterprise
    • Windows Server 2008 R2 Datacenter
  • Windows Server 2008 R2 Standard
  • Windows Server 2008 R2 Enterprise
  • Windows Server 2008 R2 Datacenter
  • Windows Server 2008 Service Pack 2?À»(¸¦) ´ÙÀ½°ú ÇÔ²² »ç¿ëÇßÀ» ¶§
    • Windows Server 2008 for Itanium-Based Systems
    • Windows Server 2008 Datacenter
    • Windows Server 2008 Enterprise
    • Windows Server 2008 Standard
    • Windows Web Server 2008
  • Windows Server 2008 for Itanium-Based Systems
  • Windows Server 2008 Datacenter
  • Windows Server 2008 Enterprise
  • Windows Server 2008 Standard
  • Windows Web Server 2008
  • Windows Vista Service Pack 2?À»(¸¦) ´ÙÀ½°ú ÇÔ²² »ç¿ëÇßÀ» ¶§
    • Windows Vista Business
    • Windows Vista Enterprise
    • Windows Vista Home Basic
    • Windows Vista Home Premium
    • Windows Vista Starter
    • Windows Vista Ultimate
    • Windows Vista Enterprise 64-bit edition
    • Windows Vista Home Basic 64-bit edition
    • Windows Vista Home Premium 64-bit edition
    • Windows Vista Ultimate 64-bit edition
    • Windows Vista Business 64-bit edition
  • Windows Vista Service Pack 1?À»(¸¦) ´ÙÀ½°ú ÇÔ²² »ç¿ëÇßÀ» ¶§
    • Windows Vista Business
    • Windows Vista Enterprise
    • Windows Vista Home Basic
    • Windows Vista Home Premium
    • Windows Vista Starter
    • Windows Vista Ultimate
    • Windows Vista Enterprise 64-bit edition
    • Windows Vista Home Basic 64-bit edition
    • Windows Vista Home Premium 64-bit edition
    • Windows Vista Ultimate 64-bit edition
    • Windows Vista Business 64-bit edition
  • Microsoft Windows Server 2003 Service Pack 2?À»(¸¦) ´ÙÀ½°ú ÇÔ²² »ç¿ëÇßÀ» ¶§
    • Microsoft Windows Server 2003, Standard Edition (32-bit x86)
    • Microsoft Windows Server 2003, Enterprise Edition (32-bit x86)
    • Microsoft Windows Server 2003, Datacenter Edition (32-bit x86)
    • Microsoft Windows Server 2003, Web Edition
    • Microsoft Windows Server 2003, Datacenter x64 Edition
    • Microsoft Windows Server 2003, Enterprise x64 Edition
    • Microsoft Windows Server 2003, Standard x64 Edition
    • Microsoft Windows XP Professional x64 Edition
    • Microsoft Windows Server 2003, Datacenter Edition for Itanium-Based Systems
    • Microsoft Windows Server 2003, Enterprise Edition for Itanium-based Systems
  • Microsoft Windows XP Service Pack 3?À»(¸¦) ´ÙÀ½°ú ÇÔ²² »ç¿ëÇßÀ» ¶§
    • Microsoft Windows XP Home Edition
    • Microsoft Windows XP Professional
Ű¿öµå:?
kbSecAdvisory atdownload kbbug kbExpertiseInter kbfix kbsecurity kbsecvulnerability KB2661254

Çǵå¹é º¸³»±â