Enterprise NTAuth ÀúÀå¼Ò·Î Ÿ»ç CA(ÀÎÁõ ±â°ü) ÀÎÁõ¼­¸¦ °¡Á®¿À´Â ¹æ¹ý

±â¼ú ÀÚ·á: 295663 - ÀÌ ¹®¼­°¡ Àû¿ëµÇ´Â Á¦Ç° º¸±â.
¸ðµÎ È®´ë | ¸ðµÎ Ãà¼Ò

ÀÌ ÆäÀÌÁö¿¡¼­

¿ä¾à

ÀÌ ¹®¼­¿¡¼­´Â Enterprise NTAuth ÀúÀå¼Ò·Î Ÿ»ç CA(ÀÎÁõ ±â°ü) ÀÎÁõ¼­¸¦ °¡Á®¿À´Â µ¥ »ç¿ëÇÒ ¼ö ÀÖ´Â µÎ °¡Áö ¹æ¹ýÀ» ¼³¸íÇÕ´Ï´Ù. Ÿ»ç CA¸¦ »ç¿ëÇÏ¿© ½º¸¶Æ® Ä«µå ·Î±×¿Â ¶Ç´Â µµ¸ÞÀÎ ÄÁÆ®·Ñ·¯ ÀÎÁõ¼­¸¦ ¹ß±ÞÇÏ´Â °æ¿ì Enterprise NTAuth ÀúÀå¼Ò·Î Ÿ»ç CA ÀÎÁõ¼­¸¦ °¡Á®¿Í¾ß ÇÕ´Ï´Ù. °ü¸®ÀÚ´Â Enterprise NTAuth ÀúÀå¼Ò¿¡ CA ÀÎÁõ¼­¸¦ °Ô½ÃÇÏ¿© ÇØ´ç CA°¡ ÀÌ·¯ÇÑ Á¾·ùÀÇ ÀÎÁõ¼­¸¦ ¹ß±ÞÇÒ ¼ö ÀÖµµ·Ï ½Å·ÚµÇ¾úÀ½À» ³ªÅ¸³À´Ï´Ù. Windows CA´Â ÀÚµ¿À¸·Î ÇØ´ç CA ÀÎÁõ¼­¸¦ ÀÌ ÀúÀå¼Ò¿¡ °Ô½ÃÇÕ´Ï´Ù.

NTAuth ÀúÀå¼Ò´Â Æ÷¸®½ºÆ®ÀÇ ±¸¼º ÄÁÅ×À̳ʿ¡ ÀÖ´Â Active Directory µð·ºÅ͸® ¼­ºñ½º °³Ã¼ÀÔ´Ï´Ù. LDAP(Lightweight Directory Access Protocol) °íÀ¯ À̸§Àº ´ÙÀ½°ú À¯»çÇÕ´Ï´Ù.
CN=NTAuthCertificates,CN=Public Key Services,CN=Services,CN=Configuration,DC=MyDomain,DC=com
NTAuth ÀúÀå¼Ò¿¡ °Ô½ÃµÇ´Â ÀÎÁõ¼­´Â cACertificate ´ÙÁß °ª Ư¼º¿¡ ±â·ÏµË´Ï´Ù. ÀÌ Æ¯¼º¿¡ ÀÎÁõ¼­¸¦ Ãß°¡ÇÏ´Â µ¥ »ç¿ëÇÒ ¼ö ÀÖ´Â ¹æ¹ýÀº µÎ °¡Áö°¡ ÀÖ½À´Ï´Ù.

¹æ¹ý 1: PKI »óÅ µµ±¸¸¦ »ç¿ëÇÏ¿© ÀÎÁõ¼­ °¡Á®¿À±â

PKI »óÅ µµ±¸(PKIView)´Â °ø°³ Ű ÀÎÇÁ¶ó¸¦ ±¸¼ºÇÏ´Â Çϳª ÀÌ»óÀÇ Microsoft Windows ÀÎÁõ ±â°ü »óŸ¦ Ç¥½ÃÇÏ´Â MMC ½º³ÀÀÎ ±¸¼º ¿ä¼ÒÀÔ´Ï´Ù. ÀÌ µµ±¸´Â Windows Server 2003 Resource Kit µµ±¸ÀÇ ÀϺηΠÁ¦°øµË´Ï´Ù. ÀÌ µµ±¸¸¦ ´Ù¿î·ÎµåÇÏ·Á¸é ´ÙÀ½ Microsoft À¥ »çÀÌÆ®¸¦ ¹æ¹®ÇϽʽÿÀ.
http://www.microsoft.com/downloads/details.aspx?familyid=9d467a69-57ff-4ae7-96ee-b18c4790cffd&displaylang=en(¿µ¹®)
PKIView´Â ¿£ÅÍÇÁ¶óÀÌÁî¿¡ ÀÖ´Â °¢ CA¿¡¼­ CA ÀÎÁõ¼­¿Í CRL(ÀÎÁõ¼­ ÇØÁö ¸ñ·Ï)¿¡ ´ëÇÑ Á¤º¸¸¦ ¼öÁýÇÑ ´ÙÀ½ ÀÌ ÀÎÁõ¼­¿Í CRLÀÌ ¿Ã¹Ù·Î ÀÛµ¿ÇÏ´ÂÁö È®ÀÎÇϱâ À§ÇØ À¯È¿¼ºÀ» °Ë»çÇÕ´Ï´Ù. ÀÌ ÀÎÁõ¼­¿Í CRLÀÌ ¿Ã¹Ù·Î ÀÛµ¿ÇÏÁö ¾Ê°Å³ª ÀÌ ÀÎÁõ¼­¿Í CRL¿¡¼­ ¿À·ù°¡ ¹ß»ýÇÏ·Á°í Çϸé PKIView´Â ÀÚ¼¼ÇÑ °æ°í³ª ¸î °¡Áö ¿À·ù Á¤º¸¸¦ Á¦°øÇÕ´Ï´Ù.

PKIView´Â Active Directory Æ÷¸®½ºÆ®¿¡ ¼³Ä¡µÈ Windows Server 2003 ÀÎÁõ ±â°üÀÇ »óŸ¦ Ç¥½ÃÇÕ´Ï´Ù. PKIView¸¦ »ç¿ëÇÏ¸é ¿£ÅÍÇÁ¶óÀÌÁî CA¿Í ¿¬°áµÈ ÇÏÀ§ ¹× ·çÆ® CA¸¦ Æ÷ÇÔÇÏ¿© ¸ðµç PKI ±¸¼º ¿ä¼Ò¸¦ °Ë»öÇÒ ¼ö ÀÖ°í ·çÆ® CA Æ®·¯½ºÆ® ¹× NTAuth ÀúÀå¼Ò °°Àº Áß¿äÇÑ PKI ÄÁÅ×À̳ʸ¦ °ü¸®ÇÒ ¼öµµ ÀÖ½À´Ï´Ù. ÀÌ ÄÁÅ×À̳ʴ Active Directory Æ÷¸®½ºÆ®ÀÇ ±¸¼º ÆÄƼ¼Ç¿¡µµ ÀÖ½À´Ï´Ù. ÀÌ ¹®¼­¿¡¼­´Â ¾Õ¿¡¼­ µÎ ¹øÂ°·Î ¼³¸íÇÑ ±â´É¿¡ ´ëÇØ ¼³¸íÇÕ´Ï´Ù. PKIView¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ ³»¿ëÀº Microsoft Windows Server 2003 Resource Kit µµ±¸ ¼³¸í¼­¸¦ ÂüÁ¶ÇϽʽÿÀ.

Âü°í PKIView¸¦ »ç¿ëÇÏ¿© Windows 2000 CA¿Í Windows Server 2003 CA¸¦ µÑ ´Ù °ü¸®ÇÒ ¼ö ÀÖ½À´Ï´Ù. Windows Server 2003 Resource Kit µµ±¸¸¦ ¼³Ä¡ÇÏ·Á¸é ÄÄÇ»ÅÍ¿¡¼­ Windows XP ÀÌ»óÀ» ½ÇÇàÇØ¾ß ÇÕ´Ï´Ù.

Enterprise NTAuth ÀúÀå¼Ò·Î CA ÀÎÁõ¼­¸¦ °¡Á®¿À·Á¸é ´ÙÀ½°ú °°ÀÌ ÇϽʽÿÀ.
  1. CA ÀÎÁõ¼­¸¦ .cer ÆÄÀÏ·Î ³»º¸³À´Ï´Ù. ´ÙÀ½°ú °°Àº ÆÄÀÏ Çü½ÄÀÌ Áö¿øµË´Ï´Ù.
    • DER·Î ÀÎÄÚµùµÈ ÀÌÁø X.509(.cer)
    • Base 64·Î ÀÎÄÚµùµÈ X.509(.cer)
  2. Windows Server 2003 Resource Kit µµ±¸¸¦ ¼³Ä¡ÇÕ´Ï´Ù. ÀÌ µµ±¸ ÆÐŰÁö¿¡´Â Windows XP ÀÌ»óÀÌ ÇÊ¿äÇÕ´Ï´Ù.
  3. Microsoft Management Console(Mmc.exe)À» ½ÃÀÛÇÏ°í ´ÙÀ½°ú °°ÀÌ PKI »óÅ ½º³ÀÀÎÀ» Ãß°¡ÇÕ´Ï´Ù.
    1. ÄÜ¼Ö ¸Þ´º¿¡¼­ ½º³ÀÀÎ Ãß°¡/Á¦°Å¸¦ ´©¸¨´Ï´Ù.
    2. µ¶¸³ ½ÇÇàÇü ÅÇÀ» ´©¸¥ ´ÙÀ½ Ãß°¡ ´ÜÃ߸¦ ´©¸¨´Ï´Ù.
    3. ½º³ÀÀÎ ¸ñ·Ï¿¡¼­ Enterprise PKI¸¦ ´©¸¨´Ï´Ù.
    4. Ãß°¡¸¦ ´©¸¥ ´ÙÀ½ ´Ý±â¸¦ ´©¸¨´Ï´Ù.
    5. È®ÀÎÀ» ´©¸¨´Ï´Ù.
  4. Enterprise PKI¸¦ ¸¶¿ì½º ¿À¸¥ÂÊ ´ÜÃß·Î ´©¸¥ ´ÙÀ½ Manage AD Containers¸¦ ´©¸¨´Ï´Ù.
  5. NTAuthCertificates ÅÇÀ» ´©¸¥ ´ÙÀ½ Ãß°¡¸¦ ´©¸¨´Ï´Ù.
  6. ÆÄÀÏ ¸Þ´º¿¡¼­ ¿­±â¸¦ ´©¸¨´Ï´Ù.
  7. CA ÀÎÁõ¼­¸¦ ã¾Æ¼­ ´©¸¥ ´ÙÀ½ È®ÀÎÀ» ´­·¯ °¡Á®¿À±â¸¦ ¿Ï·áÇÕ´Ï´Ù.

¹æ¹ý 2: Certutil.exe¸¦ »ç¿ëÇÏ¿© ÀÎÁõ¼­ °¡Á®¿À±â

Certutil.exe´Â Windows CA¸¦ °ü¸®Çϱâ À§ÇÑ ¸í·ÉÁÙ À¯Æ¿¸®Æ¼ÀÔ´Ï´Ù. Windows Server 2003¿¡¼­´Â Certutil.exe¸¦ »ç¿ëÇÏ¿© Active Directory¿¡ ÀÎÁõ¼­¸¦ °Ô½ÃÇÒ ¼ö ÀÖ½À´Ï´Ù. Certutil.exe´Â Windows Server 2003°ú ÇÔ²² ¼³Ä¡µË´Ï´Ù. ÀÌ µµ±¸´Â Windows Server 2003 °ü¸® µµ±¸ ÆÑÀÇ ÀϺηεµ Á¦°øµË´Ï´Ù. ÀÌ µµ±¸ ÆÑÀ» ´Ù¿î·ÎµåÇÏ·Á¸é ´ÙÀ½ Microsoft À¥ »çÀÌÆ®¸¦ ¹æ¹®ÇϽʽÿÀ.
http://www.microsoft.com/downloads/details.aspx?FamilyID=c16ae515-c8f4-47ef-a1e4-a8dcbacff8e3&DisplayLang=en(¿µ¹®)
Enterprise NTAuth ÀúÀå¼Ò·Î CA ÀÎÁõ¼­¸¦ °¡Á®¿À·Á¸é ´ÙÀ½°ú °°ÀÌ ÇϽʽÿÀ.
  1. CA ÀÎÁõ¼­¸¦ .cer ÆÄÀÏ·Î ³»º¸³À´Ï´Ù. ´ÙÀ½°ú °°Àº ÆÄÀÏ Çü½ÄÀÌ Áö¿øµË´Ï´Ù.
    • DER·Î ÀÎÄÚµùµÈ ÀÌÁø X.509(.cer)
    • Base 64·Î ÀÎÄÚµùµÈ X.509(.cer)
  2. ¸í·É ÇÁ·ÒÇÁÆ®¿¡¼­ ´ÙÀ½ ¸í·ÉÀ» ÀÔ·ÂÇÑ ´ÙÀ½ Enter ۸¦ ´©¸¨´Ï´Ù.
    certutil -dspublish -f filename NTAuthCA




Microsoft Á¦Ç° °ü·Ã ±â¼ú Àü¹®°¡µé°ú ¿Â¶óÀÎÀ¸·Î Á¤º¸¸¦ ±³È¯ÇϽ÷Á¸é Microsoft ´º½º ±×·ì¿¡ Âü¿©ÇϽñ⠹ٶø´Ï´Ù.

¼Ó¼º

±â¼ú ÀÚ·á: 295663 - ¸¶Áö¸· °ËÅä: 2006³â 5¿ù 15ÀÏ ¿ù¿äÀÏ - ¼öÁ¤: 2.1
º» ¹®¼­ÀÇ Á¤º¸´Â ´ÙÀ½ÀÇ Á¦Ç°¿¡ Àû¿ëµË´Ï´Ù.
  • Microsoft Windows Server 2003, Enterprise Edition (32-bit x86)
  • Microsoft Windows Server 2003, Standard Edition (32-bit x86)
  • Microsoft Windows 2000 Advanced Server
  • Microsoft Windows 2000 Server
Ű¿öµå:?
kbhowtomaster kbenv KB295663

Çǵå¹é º¸³»±â