<?xml version="1.0" encoding="euc-kr" ?>
<rss version="2.0">
	<channel>
	<title>½Ã½ºÅÛ°ü¸®ÀÚÀÇ ½°ÅÍ, Ä¿ÇÇ´Ð½º</title>
	<link>http://coffeenix.net</link>
	<description>½Ã½ºÅÛ°ü¸®ÀÚÀÇ ½°ÅÍ - *NIX, º¸¾È, ³×Æ®¿÷ ¿î¿µ, IT Á¤º¸</description>
	<language>ko</language>
	<item>
		<title>Æ¯Á¤ ¾Èµå·ÎÀÌµå WebView ¹öÀü¿¡¼­ SSL ¹®Á¦ (WebView ¹ö±×)</title>
		<link>http://coffeenix.net/bbs/viewtopic.php?p=10652#10652</link>
		<description><![CDATA[Android(¾Èµå·ÎÀÌµå) WebView 54 Æ¯Á¤¹öÀü¿¡¼­ https ¿äÃ»½Ã ¹®Á¦°¡ ¹ß»ýÇÑ´Ù.  SSL/TLS ÀÎÁõ¼­¸¦ ¹ß±ÞÇÏ´Â ¾÷Ã¼/±â°üÀº ¿©·¯ °÷ÀÌ´Ù. ÀÌÁß¿¡¼­ Symantec(½Ã¸¸ÅØ), GeoTrust, Thawte ÀÎÁõ¼­¸¦ »ç¿ëÇÏ´Â ¼­¹ö·Î https ¿äÃ»ÇÒ ¶§ Transparency ¿¡·¯°¡ ¹ß»ýÇÑ´Ù. WebView 54.0.2840.85 ¹öÀüÀº ¿ì¸®³ª¶ó ½Ã°£ ±âÁØÀ¸·Î 1¿ù 7ÀÏºÎÅÍ, 54.0.2840.68Àº 2016³â 12¿ù 28ÀÏºÎÅÍ ¹ß»ýÇÑ´Ù. Âü°í·Î WebView 53 ¹öÀü´ë¿¡¼­µµ ºñ½ÁÇÑ ¹ö±×°¡ ÀÖ¾ú´Ù.<br />
<br />
<img src="http://coffeenix.net/data/images/logo/webview.jpg"><br />
<br />
¿¹¸¦ µé¾î ´Ù½Ã Á¤¸®ÇØº¸ÀÚ. ´ÙÀ½ È¯°æ¿¡¼­ ¾îÇÃ -&gt; https ¿äÃ»ÇÏ¸é Transparency ¿¡·¯°¡ ¹ß»ýÇÑ´Ù.<br />
<br />
- Å¬¶óÀÌ¾ðÆ® : Android WebView 54.0.2840.68 ¶Ç´Â 54.0.2840.85 ¹öÀü<br />
- ¼­¹ö : https ¼­¹ö¿¡ Symantec ÀÎÁõ¼­ ¼³Ä¡<br />
<br />
°¶·°½Ã S6(SM-G920), S7(SM-G930), J5(SM-J500), J7(SM-J700), LG G3(LG-F400), ... µî ¿©·¯ Æù¿¡¼­ À¯ÀúÀÇ ¾÷µ¥ÀÌÆ®¿¡ µû¶ó WebView 54.0.2840.85¹öÀüÀ» »ç¿ëÇÑ´Ù. Á¦Á¶»ç´Â WebView 55 ¾÷µ¥ÀÌÆ®¸¦ Á¦°øÇÑ´Ù. ¸ðµç À¯Àú°¡ ¾÷µ¥ÀÌÆ®ÇÏÁö´Â ¾ÊÀ» °ÍÀÌ´Ù. µû¶ó¼­ Æ¯Á¤ WebView ¹öÀüÀÏ ¶§´Â ¾îÇÃ¿¡¼­ Transparency ¿¡·¯°¡ ³ª´õ¶óµµ https ¿äÃ»ÇÏµµ·Ï ¿¹¿Ü Ã³¸®ÇÑ´Ù.<br />
<br />
Âü°í·Î User agent¿¡´Â Chrome/54.0.2840.85 Çü½ÄÀ¸·Î Ç¥½ÃµÈ´Ù.<br />
<br />
ÀÌ ¹ö±×¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ Á¤º¸´Â symantec »çÀÌÆ®¿¡ ³ª¿Í ÀÖ´Ù.<br />
<br />
Warning | Certificate Transparency error with Chrome 53<br />
https://knowledge.symantec.com/support/mpki-for-ssl-support/index?page=content&amp;id=ALERT2161&amp;actp=LIST&amp;viewlocale=en_US<br />
<br />
<br>--------------- quote --<br><br />
There is a bug in Chrome version 53 that affects some Symantec, GeoTrust, and Thawte SSL/TLS certificates resulting in an error displaying when visiting affected websites.  There are no issues with the certificates used on the affected sites, and replacing these certificates will not help.  This is entirely a bug with Certificate Transparency handling that is only present in some versions of Chrome (53 and 54).<br />
<br>--------------- /quote --<br><br />
<br />
<br>--------------- quote --<br><br />
App users will need to update/download WebView/Chrome 55 from the App Store/PlayStore for the fix.<br />
<br />
Downloading WebView/Chrome 54 today will provide a temporary solution.<br />
 <br />
Build ID 54.0.2840.68 Expires 12/27/2016<br />
Build ID 54.0.2840.85 Expires 1/7/2017<br />
<br>--------------- /quote --<br>]]></description>
		<category>*NIX /  IT Á¤º¸</category>
		<pubDate>Wed, 11 Jan 2017 14:57:22 +0900</pubDate>
	</item>
	<item>
		<title>ºê¶ó¿ìÀúº° SHA1 ÅðÃâ ½ÃÁ¡</title>
		<link>http://coffeenix.net/bbs/viewtopic.php?p=10621#10621</link>
		<description><![CDATA[±â»ç¿¡ ³»¿Â ºê¶ó¿ìÀúº° SHA1 ÅðÃâ ½ÃÁ¡À» Á¤¸®ÇÏ¸é. <br />
http://media.daum.net/digital/others/newsview?newsid=20151221111207351<br />
<br />
- MS : MSIE, 6°³¿ù ¾Õ´ç°Ü 2016.6~<br />
- ¸ðÁú¶ó : Firefox, ¾Õ´ç°Ü 2016.7.1~<br />
- ±¸±Û : Å©·Ò, 2017.1.1~ <br />
<br />
±¸±ÛÀº SHA1 ÅðÃâÀ» À§ÇØ 2´Ü°è Á¶Ä¡¸¦ ÃëÇÒ ¿¹Á¤.<br />
1´Ü°è : Å©·Ò48ÀÌ Á¤½Ä ¹èÆ÷µÇ´Â 2016³â 1¿ù ¸»ºÎÅÍ ÇØ´ç ºê¶ó¿ìÀú¿¡¼­´Â »õ·Î ¹ß±ÞµÇ´Â SHA1 ÀÎÁõ¼­¸¦ Â÷´Ü.<br />
2´Ü°è : 2017³â 1¿ù1ÀÏºÎÅÍ´Â »õ·Î ¹ß±ÞµÈ SHA1 ÀÎÁõ¼­ ¿Ü¿¡ ±âÁ¸¿¡ ¹ß±ÞµÈ ÀÎÁõ¼­µé¿¡ ´ëÇØ¼­µµ ¿ÏÀüÈ÷ Áö¿ø Áß´Ü.<br />
<br />
--------------------------------------------<br />
<br />
ÀÎÁõ¼­ ¹ß±Þ¾÷Ã¼¸¶´Ù ´Ù¸¦Áö ¸ð¸£Áö¸¸, »õ·Î SSLÀÎÁõ¼­ ¹ß±Þ¹ÞÀ¸¸é SHA2 ÀÎÁõ¼­·Î ¹ß±ÞµÉ °Å¿¡¿ä. º»ÀÎÀÇ ÀÎÁõ¼­°¡ SHA1ÀÎÁö SHA2ÀÎÁö È®ÀÎÇÏ·Á¸é openssl ¸í·ÉÀ¸·Î È®ÀÎÇÒ ¼ö ÀÖ½À´Ï´Ù. °á°ú°ª¿¡ 'Signature Algorithm: sha1WithRSAEncryption'ÀÌ Æ÷ÇÔµÇ¸é SHA1ÀÔ´Ï´Ù. sha256WithRSAEncryption ´Â SHA2ÀÔ´Ï´Ù.<br />
<br />
<br>--------------- quote --<br><br />
$ <b>echo ""|openssl s_client -connect &lt;¼­¹ö&gt;:443 |openssl x509 -noout -text </b><br />
<br>--------------- /quote --<br><br />
<br />
¡Ø Âü°í : <a href="http://coffeenix.net/board_view.php?cata_code=0&amp;bd_code=1661">openssl·Î ÀÎÁõ¼­ Á¤º¸ »ìÆìº¸±â</a> (±Û ÁÁÀºÁøÈ£, 2008.12)]]></description>
		<category>*NIX /  IT Á¤º¸</category>
		<pubDate>Mon, 21 Dec 2015 18:05:42 +0900</pubDate>
	</item>
	<item>
		<title>¶Ç ´Ù¸¥ ¹«·á SSL ÀÎÁõ¼­, Let's Encrypt</title>
		<link>http://coffeenix.net/bbs/viewtopic.php?p=10326#10326</link>
		<description><![CDATA[¹«·á SSL ÀÎÁõ¼­¸¦ ¹ß±ÞÇØÁÖ´Â Let's Encrypt°¡ °ð Á¤½Ä ¼­ºñ½º¸¦ ÇÒ °Å¶ó°í ÇÕ´Ï´Ù.<br />
EFF, ¸ðÁú¶ó, ½Ã½ºÄÚ, ¾ÆÄ«¸¶ÀÌ, IdenTrust, ¹Ì½Ã°£´ë µîÀÌ Âü¿©ÇÕ´Ï´Ù.<br />
<br />
<img src="http://coffeenix.net/data/images/logo/lets_encrypt_logo.png"><br />
<br />
¸î ³â ÀüºÎÅÍ ¹«·á·Î ¹ß±ÞÇØÁÖ°í ÀÖ´Â StartSSLÀº pay, shop, bank, credit, finance µîÀÌ µµ¸ÞÀÎ¿¡ Æ÷ÇÔµÇ¸é ¹ß±ÞÀ» ¾ÈÇØÁá´Âµ¥, ÀÌ SSL ÀÎÁõ¼­´Â Á¦¾àÀÌ<br />
ÀÖ´ÂÁö ¸ð¸£°Ú±º¿ä.<br />
StartSSL°ú Let's Encrypt 2°³ÀÇ ¹«·á ±Þ½Ä¼Ò¿¡¼­ °ñ¶ó¸Ô´Â Àç¹Ì¸¦ ´À³¥ ³¯ÀÌ ¸î´Þ ³²Áö ¾Ê¾Ò½À´Ï´Ù. 9¿ùÀÌ¸é Á¤½ÄÀ¸·Î »ç¿ëÇÒ ¼ö ÀÖÀ» °Í °°³×¿ä.<br />
<br />
First certificate: Week of July 27, 2015<br />
General availability: Week of September 14, 2015<br />
<br />
http://thehackernews.com/2015/06/free-ssl-certificate.html<br />
https://letsencrypt.org/<br />
<br />
±×¸®°í, ºê¶ó¿ìÀú Áö¿ø °ü·ÃÇØ¼­ Let's Encrypt  »çÀÌÆ®ÀÇ FAQ¿¡ ´ÙÀ½°ú °°Àº ³»¿ëÀÌ ÀÖ½À´Ï´Ù.<br />
<br />
<br>--------------- quote --<br><br />
Will certificates from Let¡¯s Encrypt be trusted by my browser?<br />
The short answer is ¡°yes¡±.<br />
<br />
The long answer is that our issuing intermediates will be cross-signed by a widely trusted IdenTrust root (DST Root CA X3). This will allow our certificates to be trusted while we work on propagating our own root.<br />
<br>--------------- /quote --<br><br />
<br />
Let's EncryptÀÇ intermediate ÀÎÁõ¼­°¡ IdenTrust root ÀÎÁõ¼­(DST Root CA X3)¿¡ ÀÇÇØ cross-signedµÇ¾ú´Ù°í ÀûÈù°É º¸¸é, ¸ðµç ºê¶ó¿ìÀú¿¡¼­ ¹Ù·Î µÈ´Ù´Â ÀÇ¹Ì°°½À´Ï´Ù. ¿Ö³Ä¸é DST Root CA X3´Â ºê¶ó¿ìÀú¿¡ ±âº»ÀûÀ¸·Î µé¾î°¡ ÀÖÀ¸´Ï±ñ¿ä. (Âü°í·Î ÇöÀç Let's»çÀÌÆ® ÀÎÁõ¼­µµ ÃÖ»óÀ§ root´Â DST Root CA X3)<br />
100% È®½ÇÇÏÁö´Â ¾Ê½À´Ï´Ù. Let's EncryptÀÇ ±ÛÀ» Á¤È®È÷ ÀÌÇØÇÏÁö ¸øÇÑ »óÅÂ¿¡¼­ ÆÇ´ÜÇÑ°Å¶ó¼­.]]></description>
		<category>*NIX /  IT Á¤º¸</category>
		<pubDate>Mon, 29 Jun 2015 13:07:18 +0900</pubDate>
	</item>
	<item>
		<title>FreeBSD¿¡¼­ Leap Second(À±ÃÊ)´Â? ¹®Á¦ ¾ø´Ù.</title>
		<link>http://coffeenix.net/bbs/viewtopic.php?p=10325#10325</link>
		<description><![CDATA[¿Ö FreeBSD´Â 2015³â 7¿ùÀÇ À±ÃÊ(Leap Second)¿¡ ´ëÇÑ ¾ê±â°¡ ¾øÀ»±î ½ÍÀ» °Ì´Ï´Ù. ¾ó¸¶Àü¿¡ ¾´ '<a href="http://coffeenix.net/bbs/viewtopic.php?p=10319#10319">2015³â À±ÃÊ(Leap second) »ðÀÔ °ü·Ã ¼­¹ö Á¡°Ë»çÇ×</a>'(2015.6.22.) ¿¡¼­µµ ¸®´ª½º(Linux)¸¸ ¾ð±ÞÇßÁÒ. ¾ê±â°¡ ¾ø´Â °Ç ¹®Á¦°¡ ¾ø±â ¶§¹®ÀÔ´Ï´Ù.<br />
<br />
<img src="http://coffeenix.net/data/images/logo/freebsd.png"><br />
<br />
<b>2012³â À±ÃÊ »ðÀÔ ¶§, Àú´Â FreeBSD¼­¹ö¿¡¼­ ¾Æ¹« °Íµµ ÇÑ °ÍÀÌ ¾ø½À´Ï´Ù.</b><br />
À±ÃÊ·Î ¹ß»ýÇÏ´Â ¹®Á¦°¡ ¾ø±â ¶§¹®¿¡ ¼­¹ö´Â ´ÜÁö 1ÃÊÀÇ ½Ã°£Â÷¸¸ ¸ÂÃçÁÖ¸é µË´Ï´Ù.<br />
ÀÌ¹Ì ¼­¹öµéÀº ½Ã°£µ¿±âÈ­°¡ ¼ÂÆÃµÇ¾î ÀÖ±â ¶§¹®¿¡ 1ÃÊ´Â ÀÚµ¿À¸·Î ¸ÂÃçÁý´Ï´Ù. µû·Î ÇÒ °ÍÀÌ ¾ø´Â °ÅÁÒ.<br />
<br />
<br>--------------- code --<br><br />
&#40;1&#41; »óÀ§ NTP ¼­¹öµé&#40;´ç½ÅÀÇ ¼­¹ö ¾Æ´Ô&#41; &lt;-&gt; &#40;2&#41; ³»ºÎ NTP¼­¹ö &#40;´ç½ÅÀÌ °ü¸®ÇÏ´Â ¼­¹ö&#41; &lt;-&gt; &#40;3&#41; ntpdate¸¦ ½ÇÇàÇÏ´Â ´Ù¼öÀÇ ¼­¹öµé<br />
<br>--------------- /code --<br><br />
À§¿¡¼­ ³ª¿Í °ü·ÃµÈ ¼­¹ö´Â 2¹ø°ú 3¹øÀÔ´Ï´Ù.<br />
<br />
(2) ntpd µ¥¸óÀ» µ¹¸®´Â ¼­¹ö´Â ÀÚµ¿À¸·Î »óÀ§ NTP ¼­¹ö·Î ºÎÅÍ À±ÃÊ »ðÀÔÀÌ µÇ¾î ½Ã°£µ¿±âÈ­µË´Ï´Ù.<br />
(3) ³ª¸ÓÁö ¼­¹öµéÀº ³»ºÎ NTP¼­¹ö¸¦ ÅëÇØ ÀÚµ¿ µ¿±âÈ­µË´Ï´Ù. (ntpdate ¸í·É)<br />
<br />
<b>FreeBSD¿¡¼­ À±ÃÊ´Â ½Å°æ¾²Áö ¸¶½Ã°í, ÆíÈ÷ ¿î¿µÇÏ¼¼¿ä.</b><br />
FreeBSD ¹®¼­¿¡ À±ÃÊ¸¦ ´Ù·é '<a href="http://www.freebsd.org/doc/en_US.ISO8859-1/articles/leap-seconds/index.html">FreeBSD Support for Leap Seconds</a>'  ±ÛÀÌ ÇÏ³ª ÀÖ´Âµ¥ Âü°í·Î ÀÐ¾îº¸¼¼¿ä.<br />
<br />
<br>--------------- quote --<br><br />
We believe and expect that FreeBSD, if provided correct and stable NTP service, will work as designed during this leap second, as it did during the previous ones.<br />
... »ý·« ...<br />
<b>In practice, leap seconds are usually not a problem on FreeBSD</b>. We hope that this overview helps clarify what to expect and how to make the leap second event proceed more smoothly.<br />
<br>--------------- /quote --<br>]]></description>
		<category>*NIX /  IT Á¤º¸</category>
		<pubDate>Mon, 29 Jun 2015 13:03:52 +0900</pubDate>
	</item>
	<item>
		<title>2015.7.1. À±ÃÊ(Leap second) »ðÀÔ °ü·Ã ¼­¹ö Á¡°Ë»çÇ×</title>
		<link>http://coffeenix.net/bbs/viewtopic.php?p=10319#10319</link>
		<description><![CDATA[7¿ù 1ÀÏ À±ÃÊ°¡ »ðÀÔ(1ÃÊ Ãß°¡)µË´Ï´Ù. ÀÌ À±ÃÊ°¡ ¼­¹ö¿¡ ¿µÇâÀ» ¹ÌÃÄ ¹®Á¦°¡ ¹ß»ýÇÒ ¼ö ÀÖ½À´Ï´Ù.<br />
<br />
<br>--------------- code --<br><br />
2015.06.30 23&#58;59&#58;58<br />
2015.06.30 23&#58;59&#58;59<br />
2015.06.30 23&#58;59&#58;60     &lt;-- À±ÃÊ »ðÀÔ<br />
2015.07.01 00&#58;00&#58;00<br />
<br>--------------- /code --<br><br />
À§ ½Ã°£Àº  UTC±âÁØÀÌ¹Ç·Î, ¿ì¸® ³ª¶ó ½Ã°£(KST)À¸·Î´Â 08:59:60 -&gt; 09:00:00ÀÔ´Ï´Ù.<br />
<br />
¹Ì¸£´Ô 3°¡Áö ÁÖÀÇÁ¡¿¡ ´ëÇØ ±ò²ûÇÏ°Ô Á¤¸®Çß¿ä. <a href="http://seblog.mirr4u.com/842">The Leap second</a> (2015.6.20.)<br />
<br />
1. ¸®´ª½º Ä¿³Î ¹öÀü ÆÐÄ¡<br />
2. NTPµ¥¸óÀº slew ¸ðµå·Î µ¿ÀÛÇÏ°Ô.<br />
3. NTPµ¥¸ó ¾Èµ¹¸®´Â ¼­¹ö´Â tzdate¸¦ tzdata-2015a-1 ÀÌ»óÀ¸·Î ¾÷±×·¹ÀÌµå<br />
<br />
¹Ì¸£´Ô ±Û Áß¿¡ ÆÐÄ¡¾ÈµÈ ³·Àº Ä¿³ÎÀÌ¸é '100% È®·ü·Î Freeze ¶Ç´Â ¸®ºÎÆÃÀÌ ¹ß»ýÇÒ ¼ö ÀÖ´Ù'°í Çß½À´Ï´Ù¸¸, ÀÌ ºÎºÐ¿¡ ´ëÇØ¼­´Â Á¦°¡ ¾ËÁö ¸øÇÕ´Ï´Ù. freeze³ª rebootµÉ °¡´É¼ºÀº ÀÖ´Âµ¥ 100%ÀÎÁö´Â ¸ð¸£°Ú¾î¿ä. ¿©·¯ ¹®¼­¿¡¼­ 100%¶ó´Â ±ÛÀ» º»ÀûÀÌ ¾ø°í, ¹ß»ýÇÒ ¼ö ÀÖ´Ù´Â ±Û¸¸ ÀÖ¾î¼­.<br />
<br />
------------------------------------------------------------------------------------<br />
<br />
´öºÐ¿¡ Àúµµ Á» Ãß°¡·Î Á¤¸®ÇØº¾´Ï´Ù. ¹Ì¸£´ÔÀÇ ±ÛÀ» ÀÐ°í ÀÌ ±ÛÀ» ÀÐ´Â°Ô ³ªÀ»°Ì´Ï´Ù.<br />
°á·ÐÀûÀ¸·Î º¸¸é, ²ÙÁØÈ÷ Ä¿³Î°ú ÆÐÅ°Áö¸¦ ¾÷µ¥ÀÌÆ®ÇßÀ¸¸é Å©°Ô ½Å°æ¾µ °Ç ¾øÀ» °Í °°½À´Ï´Ù.<br />
<br />
<br />
<b>1. ¹®Á¦°¡ ÇØ°áµÈ Ä¿³ÎÀÌ ¾ðÁ¦ ³ª¿Ô´ÂÁö Ã£¾ÆºÃ½À´Ï´Ù.</b> (¹öÀüÀº ¹Ì¸£´Ô ±Û¿¡¼­)<br />
<br />
<br>--------------- code --<br><br />
RHEL 6 &#58; 2.6.32-279.5.2, 2012.8.<br />
RHEL 5 &#58; 2.6.18-164, 2009.9.<br />
RHEL 4 &#58; 2.6.9-89, 2009.5.<br />
<br>--------------- /code --<br><br />
<br />
¿À·¡µÆÁÒ? ²ÙÁØÈ÷ ¾÷µ¥ÀÌÆ®Çß´Ù¸é Ä¿³Î ¹®Á¦´Â ¾ø½À´Ï´Ù.<br />
RHEL, CentOS¸¦ Á¦¿ÜÇÑ ´Ù¸¥ ¸®´ª½º ¹èÆ÷ÆÇÀº Á÷Á¢ È®ÀÎÇØº¸¼¼¿ä.<br />
<br />
¡Ø Ä¿³Î ¹öÀü¿¡ ´ëÇØ¼­´Â Ãß°¡·Î È®ÀÎÇØº¸°í Àû½À´Ï´Ù. (2015.6.23.(È­) AM 11½Ã Ãß°¡)<br />
<br>--------------- quote --<br><br />
'<a href="https://access.redhat.com/articles/15145">Resolve Leap Second Issues in Red Hat Enterprise Linux</a>'À» Åä´ë·Î ÀÏºÎ ´õ Ã£¾Æº¸°í.<br />
<br />
1) <b>RHEL 7</b> : Ä¿³Î ¹öÀü ¹®Á¦ ¾øÀ½<br />
<br />
2) <b>RHEL 6</b> : Æ¯Á¤ Ä¿³Î ¹öÀüÀÌÇÏ¿¡¼­ hang¹ß»ýÇÒ ¼ö<br />
   kernel-2.6.32-279.5.2, 2012.8.<br />
   840950 - livelock in leapsecond insertion [rhel-6.3.z] ( https://rhn.redhat.com/errata/RHBA-2012-1199.html )<br />
   À±ÃÊ »ðÀÔ ÈÄ CPU½Ã°£À» 100% ¼Ò¸ðÇÒ ¼ö ÀÖ´Â ¹ö±× ¼öÁ¤<br />
 <br />
   <b>RHEL 6</b>Àº  ÀÌÈÄ¿¡ ³ª¿Â ¹öÀüÁß À±ÃÊ°ü·ÃµÈ°Ô ÇÏ³ª ´õ ÀÖ±º¿ä.<br />
   kernel-2.6.32-358, 2013.2.<br />
   836803 - RHEL6: Potential fix for leapsecond caused futex related load spikes ( https://rhn.redhat.com/errata/RHSA-2013-0496.html )<br />
   À±ÃÊ¸¦ À§ÇÑ futex °ü·ÃÇÏ¿© load spike¸¦ ¹ß»ýÇÒ ¼ö ÀÖ´Â ÀáÀçÀûÀÎ ¹ö±× ¼öÁ¤. º¸´Ù ¾ÈÁ¤ÀûÀ¸·Î °¡·Á¸é kernel-2.6.32-358 ÀÌ»óÀÌ¾î¾ß ÇÒ µí.<br />
<br />
3) <b>RHEL 5</b> : Æ¯Á¤ Ä¿³Î ¹öÀüÀÌÇÏ¿¡¼­ crashµÉ ¼ö <br />
   kernel-2.6.18-164 ÀÌÀü ¹öÀü ¹®Á¦.<br />
   479765 - Leap second message can hang the kernel ( https://rhn.redhat.com/errata/RHSA-2009-1243.html )<br />
   hang ¹ß»ýµÉ ¼ö ÀÖ´Â ¹ö±× ¼öÁ¤<br />
<br />
4) <b>RHEL 4</b> : Æ¯Á¤ Ä¿³Î ¹öÀüÀÌÇÏ¿¡¼­ crashµÉ ¼ö<br />
   kernel-2.6.9-89 ÀÌÀü ¹öÀü ¹®Á¦.<br />
   https://access.redhat.com/solutions/1325313<br />
<br>--------------- /quote --<br><br />
<br />
<br />
<b>2. NTP µ¥¸óÀÇ slew ¸ðµå</b><br />
<br />
½Ã½ºÅÛ ±Ô¸ð°¡ Á¶±ÝµÇ¸é NTP¼­¹ö ¿î¿µÇÏ½ÇÅÙµ¥, NTP¼­¹ö´Â ½Ã°£º¸Á¤ÇÏ´Â ¹æ¹ýÀÌ step ¸ðµå¿Í slew ¸ðµå 2°¡Áö°¡ ÀÖ½À´Ï´Ù.<br />
<br />
- step ¸ðµå´Â Áï½Ã ½Ã°£À» º¸Á¤ÇÕ´Ï´Ù.<br />
- slew ¸ðµå´Â ¾ÆÁÖ ¾ÆÁÖ ÃµÃµÈ÷ ½Ã°£À» º¸Á¤ÇÕ´Ï´Ù. 1ÃÊ´ç 0.5ms·Î º¸Á¤ÇØÁÝ´Ï´Ù.<br />
  ±×·¯´Ï±ñ 1ÃÊ¶ó´Â ½Ã°£À» º¸Á¤ÇÏ´Âµ¥ 2000ÃÊ(1000/0.5 = 2000)¶ó´Â ½Ã°£À» ³ª´²¼­ ¾ÆÁÖ Á¶±Ý¾¿ º¸Á¤ÇØÁÖ´Â°ÅÁÒ.<br />
  ½Ã°£¿¡ ¹Î°¨ÇÑ °æ¿ì ÀÌ·¸°Ô ÇÏ´Â°Ô ÁÁ½À´Ï´Ù.<br />
<br />
°³ÀÎÀûÀ¸·Î º¸±â¿£ ¹Î°¨¼ºÀÌ Áß¿äÇÏÁö ¾Ê´Â °÷¿¡¼­´Â step¸ðµå(¿É¼Ç¾ø´Ù¸é default)·Î ÇØµµ »ó°ü¾øÀ» °Í °°½À´Ï´Ù. À¥¼­ºñ½º¸¦ ÁÖ·ÎÇÏ´Â °÷¿¡¼­ ¼­¹ö°¡ 1ÃÊ º¯°æµÇ´Âµ¥ ¹Î°¨ÇÒ Á¤µµ°¡ ¾Æ´Ï´Ï±ñ¿ä. ntpdate¸¦ ½ÇÇàÇÏ´Â Å¬¶óÀÌ¾ðÆ®¿¡¼­µµ ÀÚÃ¼ NTP¼­¹ö¿Í ¸îºÐ°£°ÝÀ¸·Î µ¿±âÈ­½ÃÅ°´Â °æ¿ì´Â µå¹°ÀÝ¾Æ¿ä? ¸î½ÊºÐ¿¡¼­ ¸î½Ã°£°£°ÝÀ¸·Î °¡Á®¿ÃÅ×´Ï, ±×¸¸Å­ ½Ã°£ ¹Î°¨µµ´Â ³·´Ù´Â ÀÇ¹ÌÁÒ.<br />
<br />
º»ÀÎµéÀÌ ¿î¿µÇÏ´Â ¼­ºñ½º Æ¯¼ºÀ» Àß ÆÇ´ÜÇØ¼­ step¸ðµå·Î ³öµÑÁö slew¸ðµå·Î º¯°æÇÒÁö °í¹ÎÇÏ¸é µÉ °Í °°½À´Ï´Ù.<br />
NTP¼­¹öÀÇ slew¸ðµå·Î º¯°æÀº ¹Ì¸£´ÔÀÌ ÀÛ¼ºÇÏ½Å ±ÛÃ³·³ ntdpµ¥¸ó¿¡ -x ¿É¼ÇÀ» Ãß°¡ÇØ¼­ ½ÇÇàÇÏ¸é µË´Ï´Ù.<br />
<br />
È¤½Ã³ª ½Í¾î ´Ù½Ã ¾ê±âÇÏ´Âµ¥, step, slew¸ðµå ¼³Á¤Àº ntpd µ¥¸óÀÌ µ¹¾Æ°¡´Â ¼­¹ö¿¡ ´ëÇÑ °ÍÀÔ´Ï´Ù. ntpdate¸¦ ½ÇÇàÇÏ´Â ´Ù¼öÀÇ ¼­¹ö¸¦ ¸»ÇÏ´Â°Ô ¾Æ´Õ´Ï´Ù. ¾Æ·¡¿¡¼­ 2¹ø ¼­¹ö¿¡¸¸ ÇØ´çµË´Ï´Ù.<br />
<br>--------------- code --<br><br />
&#40;1&#41; ¿ÜºÎ °ø½Ä NTP ¼­¹öµé&#40;´ç½ÅÀÇ ¼­¹ö ¾Æ´Ô&#41; &lt;-&gt; &#40;2&#41; ³»ºÎ NTP¼­¹ö &#40;´ç½ÅÀÌ °ü¸®ÇÏ´Â ¼­¹ö&#41; &lt;-&gt; &#40;3&#41; ntpdate¸¦ ½ÇÇàÇÏ´Â ´Ù¼öÀÇ ¼­¹öµé<br>--------------- /code --<br><br />
<br />
<br />
<b>3. ÃÖ±Ù¿¡ À±ÃÊ°¡ ¾ðÁ¦ ¹ß»ýÇß´ÂÁö Ã£¾ÆºÃ´õ´Ï °ÅÀÇ 2006³â ºÎÅÍ´Â °ÅÀÇ 3³â¸¶´Ù ÇÑ¹ø¾¿ ÀÖ¾ú³×¿ä.</b><br />
±× ÀÌÀü¿¡´Â ´õ ÀÚÁÖ ÀÖ¾ú±¸¿ä. 2012³â¿¡ ¹®Á¦°¡ ¹ß»ýÇß´Ù¸é ±× ¶§ ¹¹°¡ ¹®Á¦¿´´ÂÁö Àß ±â¾ïÇÏ½Ã°í Á¶Ä¡¸¦ ÃëÇÏ¼¼¿ä.<br />
<br />
<br>--------------- code --<br><br />
2006.1.1.<br />
2009.1.1.<br />
2012.7.1.<br />
2015.7.1.<br />
<br>--------------- /code --<br><br />
<br />
<br />
<b>4. tzdata°¡ ÀÌ¹ø À±ÃÊ±îÁö Æ÷ÇÔµÈ °æ¿ì ´ÙÀ½°ú °°ÀÌ ³ª¿Â´Ù.</b><br />
<br />
<br>--------------- quote --<br><br />
$ <b>zdump -v right/Asia/Seoul</b><br />
... »ý·« ...<br />
right/Asia/Seoul  Tue Jun 30 23:59:60 2015 UTC = Wed Jul  1 08:59:60 2015 KST isdst=0 gmtoff=32400<br />
right/Asia/Seoul  Wed Jul  1 00:00:00 2015 UTC = Wed Jul  1 09:00:00 2015 KST isdst=0 gmtoff=32400<br />
... »ý·« ...<br />
<br>--------------- /quote --<br><br />
¡Ø KDT¶ó°í ÀûÈù °ÍÀº ½æ¸ÓÅ¸ÀÓ Àû¿ëÀÌ´Ù. KST -&gt; KDT´Â ½æ¸ÓÅ¸ÀÓ ½ÃÀÛ, KDT -&gt; KST´Â ½æ¸ÓÅ¸ÀÓ Á¾·á]]></description>
		<category>*NIX /  IT Á¤º¸</category>
		<pubDate>Mon, 22 Jun 2015 17:58:58 +0900</pubDate>
	</item>
	<item>
		<title>OpenSSL Ãë¾àÁ¡ Á¤¸®, Logjam(·Î±×Àë)¿¡¼­ Heartbleed±îÁö</title>
		<link>http://coffeenix.net/bbs/viewtopic.php?p=10318#10318</link>
		<description><![CDATA[OpenSSLÃë¾àÁ¡ÀÌ ÀÛ³âºÎÅÍ ¹«´õ±â·Î ½ñ¾ÆÁö°í ÀÖ½À´Ï´Ù. Â¡±×·¯¿ï Á¤µµÁÒ. Ã³À½¿¡ ÇÑµÎ°³ ³ª¿Ã ¶§´Â Ãë¾àÁ¡¸í°ú ±× Ãë¾àÁ¡ÀÌ ¾î¶² °ÍÀÎÁö ¿¬°áÀÌ µÇ¾î¾ú´Âµ¥, Á¡Á¡ ´Ã¾î³ª´Ùº¸´Ï Çò°¥¸³´Ï´Ù. <b>±×·¡¼­ Heartbleed Ãë¾àÁ¡, POODLE Ãë¾àÁ¡, FREAK Ãë¾àÁ¡ ¾ó¸¶Àü¿¡ ³ª¿Â Logjam Ãë¾àÁ¡</b>±îÁö °£´ÜÈ÷ Á¤¸®ÇØºÃ½À´Ï´Ù.<br />
Ãë¾àÁ¡ ¿©ºÎ¸¦ Ã¼Å©ÇÒ ¼ö ÀÖ´Â ¹æ¹ýÀ» º°µµ·Î Àû¾ú½À´Ï´Ù.<br />
<br />
<img src="http://coffeenix.net/data/images/logo/openssl.jpg"><br />
<br />
<font color="darkblue"><b>1. OpenSSL Logjam Ãë¾àÁ¡ (2015.5.)</b></font><br />
<br />
<br />
TLSÇÁ·ÎÅäÄÝÀÇ Ãë¾àÁ¡À¸·Î °ø°ÝÀÚ°¡ ÀÓ½Ã Diffie-Hellman Å° ±³È¯(Diffie-Hellman key exchange)À» »ç¿ëÇÏ¿© TLS¿¬°áÀ» 512ºñÆ® ¼öÃâµî±Þ ¾ÏÈ£È­·Î ´Ù¿î±×·¹ÀÌµåÇÒ ¼ö ÀÖ´Ù.<br />
<br />
OpenSSL 1.0.2 : ÆÐÄ¡µÈ ¹öÀü 1.0.2bÀÌ»ó<br />
OpenSSL 1.0.1 : ÆÐÄ¡µÈ ¹öÀü 1.0.1nÀÌ»ó<br />
<br />
OpenSSL 1.0.1°ú 1.0.2´ëÀÇ ¹öÀüº° ÇØ°áÃ¥À» º¸¸é.<br />
- 1.0.1°ú 1.0.2 : DH ÆÄ¶ó¹ÌÅÍ°¡ 768ºñÆ®º¸´Ù Âª´Ù¸é handshake¸¦ °ÅºÎÇÏµµ·Ï TLSÅ¬¶óÀÌ¾ðÆ®¿¡ ´ëÇÑ º¸È£ ±â´ÉÀ» Ãß°¡Çß´Ù.<br />
- 1.0.2bÀÌ»ó, 1.0.1nÀÌ»ó : À§ Á¦ÇÑÀ» 1024ºñÆ®±îÁö Áõ°¡Çß´Ù.<br />
- 1.0.1mÀÌ»ó, 1.0.2aÀÌ»ó : EXPORT cipher suite(Áï, ¼öÃâµî±Þ ¾ÏÈ£)¸¦ ±âº»ÀûÀ¸·Î disableÇß´Ù.<br />
<br />
<br>--------------- quote --<br><br />
<b>1) Ãë¾àÁ¡ ¿©ºÎ È®ÀÎÇÏ±â</b><br />
   ¹Ýµå½Ã openssl 1.0.2 client¸¦ »ç¿ëÇØ¾ß Server Temp Key: °ªÀ» º¼ ¼ö ÀÖ´Ù. Server Temp Key: °ªÀÌ 1024ºñÆ®°Å³ª ÀÌÇÏÀÌ¸é 2048ºñÆ® DH parameter¸¦ »ý¼ºÇÑ´Ù. (1024ºñÆ®°¡ ¹Ýµå½Ã Ãë¾àÇÏ´Ù´Â °ÍÀº ¾Æ´Ï°í, ¹Ý´ë·Î ¾ÈÀüÇÑ °Íµµ ¾Æ´Ï´Ù. ¿À´Ã³¯ °°ÀÌ PC ¿¬»ê±â´ÉÀÌ ÁÁÀº °æ¿ì 1024ºñÆ® ¾ÏÈ£¸¦ ºü¸¥ ½Ã°£³»¿¡ Ç® ¼ö ÀÖ´Ù´Â °ÍÀÓ. ±×·¡¼­ 2048ºñÆ®¸¦ ±ÇÀå)<br />
<br />
   $ openssl s_client -connect ¼­¹ö:433 - cipher EDH<br />
<br />
<b>2) apache ¼³Á¤</b><br />
   $ openssl dhparam -out dhparam.pem 2048<br />
<br />
   »ý¼ºµÈ DH parameter¸¦ SSLCertificateFile ¿¡ ÀûÈù ÆÄÀÏ ¸ÇµÚ¿¡ ºÙÀÎ´Ù.<br />
   cat dhparam.pem &gt;&gt; /path/to/sslcertfile<br />
<br />
   ±×·±µ¥, apache 2.4.7ÀÌÀü ¹öÀüÀº DH parameter°¡ Ç×»ó 1024ºñÆ®·Î ¼ÂÆÃµÇ¾î ÀÖ°í, »ç¿ëÀÚ°¡ ÀÌ¸¦ ¹Ù²Ü ¼ö ¾ø´Ù.<br />
   RHEL 6(CentOS 6)ÀÇ apache 2.2¹öÀüÀº 2.4.7°ÍÀ» ¹éÆ÷ÆÃÇØ¼­ ¼ÂÆÃÀÌ °¡´ÉÇÏ´Ù.<br />
<br />
<b>3) nginx ¼³Á¤</b><br />
   $ openssl dhparam -out dhparam.pem 2048<br />
<br />
   nginx.conf¿¡ ´ÙÀ½ Ãß°¡<br />
   ssl_dhparam /path/to/dhparam.pem;<br />
<br>--------------- /quote --<br><br />
<br />
ÀÚ¼¼ÇÑ Á¤º¸´Â ´ÙÀ½ ±ÛÀ».<br />
https://www.openssl.org/blog/blog/2015/05/20/logjam-freak-upcoming-changes/<br />
http://www.openssl.org/news/secadv_20150611.txt<br />
https://access.redhat.com/ko/articles/1480443 (ÇÑ±Û)<br />
<br />
À¥¼­¹ö ¼³Á¤°ú °ü·Ã¿¡¼­´Â Guide to Deploying Diffie-Hellman for TLS ( https://weakdh.org/sysadmin.html )±ÛÀÌ °¡Àå Á¤¸®°¡ Àß µÈ °Í °°´Ù.<br />
<br />
<br />
<font color="darkblue"><b>2. OpenSSL FREAK Ãë¾àÁ¡ (2015.3.)</b></font><br />
<br />
°ú°Å ¹Ì±¹Àº ¾ÏÈ£È­ ±â¼ú¿¡ ´ëÇØ ÇØ¿Ü ¼öÃâÀ» Á¦ÇÑÇß´Ù. ±×·¡¼­ ÇØ¿Ü¿¡ ¾ÏÈ£È­ ±â¼úÀ» ¼öÃâÇÏ·Á¸é ³·Àº ¼öÁØÀÎ 512ºñÆ® ¾ÏÈ£È­(RSA EXPORT)¸¸ »ç¿ëÇÒ ¼ö ÀÖ¾ú´Ù. ÀÌÈÄ 2000³â¿¡ ¹Ì±¹Àº ÀÌ ¼öÃâÁ¦ÇÑÀ» ¾ø¾Ý´Ù.<br />
<br />
ÇöÀç´Â 2048ºñÆ® ÀÌ»óÀÇ ¾ÏÈ£È­ Å°¸¦ ¸¹ÀÌ »ç¿ëÇÑ´Ù. ±×·±µ¥, ¼öÃâÁ¦ÇÑÀÌ ¾ø¾îÁøÁö 10¿©³âÀÌ Áö³µ´Âµ¥µµ OpenSSL¿¡ ¼öÃâµî±Þ ¾ÏÈ£È­ ±â´ÉÀÌ ±×´ë·Î ³²¾ÆÀÖ¾ú´Ù. FREAK(Factoring attack on RSA-EXPORT Keys)¶ó°í ºÒ¸®´Â Ãë¾àÁ¡Àº °ø°ÝÀÚ°¡ 512ºñÆ®ÀÇ ³·Àº ¼öÁØÀÇ ¼öÃâµî±Þ ¾ÏÈ£¸¦ ¿äÃ»ÇÒ ¼ö°¡ ÀÖ´Ù.<br />
<br />
OpenSSL 1.0.1 : ÆÐÄ¡µÈ ¹öÀü 1.0.1k<br />
OpenSSL 1.0.0 : ÆÐÄ¡µÈ ¹öÀü 1.0.0p<br />
OpenSSL 0.9.8 : ÆÐÄ¡µÈ ¹öÀü 0.9.8zd<br />
<br />
<br>--------------- quote --<br><br />
<b>1) Ãë¾àÁ¡ ¿©ºÎ È®ÀÎÇÏ±â</b><br />
   $ openssl s_client -connect ¼­¹ö:433 - cipher EXPORT<br />
<br />
<b>2) apache ¼³Á¤ : SSLCipherSuite ¿¡ !EXP ¶Ç´Â !EXPORT¸¦ Ãß°¡ÇÑ´Ù.</b><br />
   (¿¹) SSLCipherSuite HIGH:!aNULL:!MD5:!EXP<br />
<br />
<b>3) nginx ¼³Á¤ : !EXPORT¸¦ Ãß°¡ÇÑ´Ù.</b><br />
   (¿¹) ssl_ciphers HIGH:!aNULL:!MD5:!EXPORT;<br />
<br>--------------- /quote --<br><br />
<br />
<br />
<font color="darkblue"><b>3. OpenSSL POODLE Ãë¾àÁ¡ (SSLv3 Ãë¾àÁ¡, 2014.10.)</b></font><br />
<br />
POODLE(Padding Oracle On Downgraded Legacy Encryption)ÀÌ¶ó°í ºÒ¸®´Â Ãë¾àÁ¡Àº SSL 3.0 ¹öÀü¿¡ Á¸ÀçÇÏ´Â Ãë¾àÁ¡ÀÌ´Ù. °ø°ÝÀÚ°¡ ÆÐµù ¿À¶óÅ¬ °ø°Ý(ÀÌ°Ô ¹ºÁö ¸ð¸§)À» ÇÏ¿© ¾ÏÈ£È­ Åë½ÅÀ» ÇØµ¶ÇÒ ¼ö ÀÖ´Ù.<br />
<br />
Poodle Ãë¾àÁ¡Àº ÇÁ·ÎÅäÄÝ ÀÚÃ¼ °áÇÔÀÌ ¾Æ´Ï¶ó ±¸Çö»óÀÇ ¹®Á¦¿©¼­ ÆÐÄ¡°¡ ¾Æ´Ñ ¼³Á¤ º¯°æÀ¸·Î ÇØ°áÇÑ´Ù. SSL v3¸¸ ÇØ´çµÇ°í TLSÀº Ãë¾àÇÏÁö ¾Ê´Ù. µû¶ó¼­ SSL v3¸¦ »ç¿ëÇÏÁö ¾Êµµ·Ï ¼³Á¤ÇØÁÖ¸é µÈ´Ù.<br />
<br />
<br>--------------- quote --<br><br />
<b>1) Ãë¾àÁ¡ ¿©ºÎ È®ÀÎÇÏ±â</b><br />
   $ openssl s_client -connect ¼­¹ö:443 -ssl2 (-ssl2 ¿É¼ÇÀº Áö¿øÇÏÁö ¾ÊÀ» ¼ö ÀÖÀ½)<br />
   $ openssl s_client -connect ¼­¹ö:443 -ssl3<br />
<br />
<b>2) apache ¼³Á¤ : SSLProtocol¿¡¼­ -SSLv3¸¦ Ãß°¡ÇÑ´Ù.</b><br />
   (¿¹) SSLProtocol all -SSLv2 -SSLv3<br />
<br />
<b>3) nginx ¼³Á¤  : TLS¸¸ Çã¿ë</b><br />
   (¿¹) ssl_protocols TLSv1.2 TLSv1.1 TLSv1;<br />
<br>--------------- /quote --<br><br />
<br />
ÀÚ¼¼ÇÑ Á¤º¸´Â ´ÙÀ½ ±ÛÀ».<br />
https://access.redhat.com/ko/node/1256013 (ÇÑ±Û)<br />
<br />
<br />
<font color="darkblue"><b>4. OpenSSL Heartbleed Ãë¾àÁ¡ (2014.4.)</b></font><br />
<br />
OpenSSL 1.0.1¹öÀü¿¡ TLS heartbeat Ãë¾àÁ¡(ÀÏ¸í Heartbleed Bug¶ó°í ºÎ¸§. CVE-2014-0160, openssl: information disclosure in handling of TLS heartbeat extension packets)ÀÌ ÀÖ´Ù. °ø°ÝÀÚ°¡ https¼­¹öÀÇ ¸Þ¸ð¸® 64KB µ¥ÀÌÅÍ¸¦ º¼ ¼ö ÀÖ´Ù. ¸Þ¸ð¸®¿¡´Â https¼­¹ö¿Í À¯Àú°£¿¡ ÁÖ°í ¹ÞÀº µ¥ÀÌÅÍµé(ID/PW, ... µîÀÇ Á¤º¸)ÀÌ ÀÖ´Âµ¥, °ø°ÝÀÚ´Â plain textÇüÅÂ·Î º¼ ¼ö ÀÖ´Ù. ±×¸®°í,SSL °³ÀÎÅ°¸¦ ¾òÀ» ¼ö.<br />
<br />
ÀÚ¼¼ÇÑ Á¤º¸´Â ´ÙÀ½ ±ÛÀ».<br />
http://coffeenix.net/bbs/viewtopic.php?t=8239<br />
<br />
<br />
------------------------------------------------------------------------------------------------------------<br />
<font color="darkblue"><b>5. openssl ¸í·ÉÀ¸·Î °£´ÜÈ÷ Ãë¾àÁ¡ ¿©ºÎ Ã¼Å©</b></font><br />
<br />
¡Ø Âü°í : <a href="http://coffeenix.net/board_view.php?cata_code=0&amp;bd_code=1661">openssl·Î ÀÎÁõ¼­ Á¤º¸ »ìÆìº¸±â</a> (2008.12.)<br />
<br />
<b>1-1) SSLv3°¡ Çã¿ëµÈ °æ¿ì</b><br />
<br />
<br>--------------- code --<br><br />
$ openssl s_client -connect ¼­¹ö&#58;443 -ssl3<br />
CONNECTED&#40;00000003&#41;<br />
depth=1 C = IL, O = StartCom Ltd., OU = Secure Digital Certificate Signing, CN = StartCom Class 1 Primary Intermediate Server CA<br />
verify error&#58;num=20&#58;unable to get local issuer certificate<br />
verify return&#58;0<br />
---<br />
Certificate chain<br />
...»ý·«...<br />
SSL-Session&#58;<br />
    Protocol  &#58; SSLv3<br />
    Cipher    &#58; DHE-RSA-AES256-SHA &lt;-- SSLv3 Áö¿øÇÏ´Â °æ¿ì.<br />
<br>--------------- /code --<br><br />
<br />
<b>1-2) SSLv3°¡ Çã¿ëµÇÁö ¾ÊÀº °æ¿ì (¾ÈÀü)</b><br />
<br />
<br>--------------- code --<br><br />
$ openssl s_client -connect ¼­¹ö&#58;443 -ssl3<br />
CONNECTED&#40;00000003&#41;<br />
140289569347264&#58;error&#58;14094410&#58;SSL routines&#58;SSL3_READ_BYTES&#58;sslv3 alert handshake failure&#58;s3_pkt.c&#58;1256&#58;SSL alert number 40<br />
140289569347264&#58;error&#58;1409E0E5&#58;SSL routines&#58;SSL3_WRITE_BYTES&#58;ssl handshake failure&#58;s3_pkt.c&#58;596&#58;<br />
---<br />
no peer certificate available<br />
---<br />
No client certificate CA names sent<br />
---<br />
SSL handshake has read 7 bytes and written 0 bytes<br />
---<br />
New, &#40;NONE&#41;, Cipher is &#40;NONE&#41;<br />
Secure Renegotiation IS NOT supported<br />
Compression&#58; NONE<br />
Expansion&#58; NONE<br />
SSL-Session&#58;<br />
    Protocol  &#58; SSLv3<br />
    Cipher    &#58; 0000 &lt;-- SSLv3 Áö¿øÇÏÁö ¾ÊÀ½.<br />
<br>--------------- /code --<br><br />
<br />
<b>2-1) ¼öÃâ¿ë ¾ÏÈ£È­°¡ Çã¿ëµÈ °æ¿ì (ÀÎÁõ¼­ Á¤º¸°¡ Ç¥½ÃµÊ. º¸¾È»ó Ãë¾à)</b><br />
<br />
<br>--------------- code --<br><br />
$ openssl s_client -connect ¼­¹ö&#58;443 -cipher EXPORT<br />
CONNECTED&#40;00000003&#41;<br />
depth=2 C = US, O = &quot;VeriSign, Inc.&quot;, OU = VeriSign Trust Network, ... »ý·« ...<br />
verify error&#58;num=20&#58;unable to get local issuer certificate<br />
verify return&#58;0<br />
---<br />
Certificate chain<br />
...»ý·«...<br />
SSL handshake has read 4798 bytes and written 201 bytes<br />
<br>--------------- /code --<br><br />
<br />
<b>2-3) ¼öÃâ¿ë ¾ÏÈ£È­°¡ Çã¿ëµÇÁö ¾Ê´Â °æ¿ì (¾ÈÀü)</b><br />
<br />
<br>--------------- code --<br><br />
$ openssl s_client -connect ¼­¹ö&#58;443 -cipher EXPORT<br />
CONNECTED&#40;00000003&#41;<br />
139768004437696&#58;error&#58;14077410&#58;SSL routines&#58;SSL23_GET_SERVER_HELLO&#58;sslv3 alert handshake failure&#58;s23_clnt.c&#58;741&#58;<br />
---<br />
no peer certificate available<br />
---<br />
No client certificate CA names sent<br />
---<br />
SSL handshake has read 7 bytes and written 75 bytes<br />
---<br />
New, &#40;NONE&#41;, Cipher is &#40;NONE&#41;<br />
Secure Renegotiation IS NOT supported<br />
Compression&#58; NONE<br />
Expansion&#58; NONE<br />
---<br />
<br>--------------- /code --<br><br />
<br />
<b>3-1) logjam¿¡ Ãë¾àÇÑ °æ¿ì</b> (¹Ýµå½Ã openssl 1.0.2 client·Î Å×½ºÆ®ÇØ¾ß Server Temp Key: °ªÀ» È®ÀÎÇÒ ¼ö ÀÖ´Ù)<br />
<br />
<br>--------------- code --<br><br />
$ openssl s_client -connect ¼­¹ö&#58;443 -cipher EDH<br />
... »ý·« ...<br />
Server Temp Key&#58; DH, 1024 bits &lt;--- 1024ºñÆ®ÀÌ°Å³ª ³·´Ù¸é 2048ºñÆ® DH parameter¸¦ »ç¿ëÇÏµµ·Ï ¼ÂÆÃÇÑ´Ù.<br />
<br />
SSL-Session&#58;<br />
    Protocol  &#58; TLSv1<br />
    Cipher    &#58; DHE-RSA-AES256-SHA<br />
... »ý·« ...<br />
<br>--------------- /code --<br><br />
<br />
<b>3-2) logjam Ãë¾àÁ¡¿¡ ¾ÈÀüÇÑ °æ¿ì</b><br />
<br />
<br>--------------- code --<br><br />
$ openssl s_client -connect ¼­¹ö&#58;443 -cipher EDH<br />
CONNECTED&#40;00000003&#41;<br />
139828320765632&#58;error&#58;14077410&#58;SSL routines&#58;SSL23_GET_SERVER_HELLO&#58;sslv3 alert handshake failure&#58;s23_clnt.c&#58;769&#58;<br />
---<br />
no peer certificate available<br />
---<br />
No client certificate CA names sent<br />
---<br />
SSL handshake has read 7 bytes and written 145 bytes<br />
---<br />
New, &#40;NONE&#41;, Cipher is &#40;NONE&#41;<br />
Secure Renegotiation IS NOT supported<br />
Compression&#58; NONE<br />
Expansion&#58; NONE<br />
No ALPN negotiated<br />
---<br />
<br>--------------- /code --<br>]]></description>
		<category>*NIX /  IT Á¤º¸</category>
		<pubDate>Tue, 16 Jun 2015 16:40:33 +0900</pubDate>
	</item>
	<item>
		<title>¸®´ª½º glibc Ãë¾àÁ¡, &quot;GHOST&quot;</title>
		<link>http://coffeenix.net/bbs/viewtopic.php?p=10120#10120</link>
		<description><![CDATA[glibc¿¡ ÀÏ¸í "GHOST"¶ó°í ºÒ¸®´Â ½É°¢ÇÑ Ãë¾àÁ¡(CVE-2015-0235)ÀÌ ¹ß°ßµÇ¾ú´Ù. gblic 2.17ÀÌÇÏ(2013.5.21 ÀÌÀü ¹öÀü)´Â gethostbyname(), gethostbyname2() ÄÝÀÇ ¹ö±×·Î ·ÎÄÃ°ú ¿ø°ÝÁö¿¡¼­ ±ÇÇÑÀ» È¹µæÇÒ ¼ö ÀÖ´Ù. Exim ¸ÞÀÏ¼­¹ö´Â À©°ÝÁö¿¡¼­ Ãë¾àÇÑ °ÍÀ¸·Î È®ÀÎµÇ¾ú°í, gethostbyname ÄÝÀ» »ç¿ëÇÏ´Â ¿©·¯ µ¥¸óµéÀÌ ¹®Á¦°¡ ÀÖÀ» ¼ö ÀÖ´Ù.<br />
<br />
* Linux "GHOST" Vulnerability Hits Glibc Systems<br />
  http://www.phoronix.com/scan.php?page=news_item&amp;px=Linux-GHOST-Glibc-Security<br />
<br />
* GHOST: glibc gethostbyname buffer overflow<br />
  http://www.openwall.com/lists/oss-security/2015/01/27/9<br />
<br />
<br>--------------- quote --<br>we discovered that it was fixed on May 21, 2013 (between the releases of glibc-2.17 and glibc-2.18 ).<br />
Unfortunately, it was not recognized as a security threat; as a result, most stable and long-term-support distributions were left exposed (and still are):<br />
  Debian 7 (wheezy), Red Hat Enterprise Linux 6 &amp; 7, CentOS 6 &amp; 7, Ubuntu 12.04, for example.<br />
<br>--------------- /quote --<br><br />
<br />
<b><u>´ÙÇàÀÎ °ÍÀº apache, nginx, lighttpd µî ´ëÇ¥ÀûÀÎ À¥¼­¹ö¿Í proftpd, vsftpd, pure-ftpd µî ´Ù¼ö FTP ¼­¹ö, openssh´Â Ãë¾àÇÏÁö ¾Ê´Â °ÍÀ¸·Î ¹àÇôÁ³´Ù.</u></b><br />
Qualys Security Advisory teamÀÌ OSS Security ¸ÞÀÏ¸µ¸®½ºÆ®¿¡ º¸³½ ³»¿ë¿¡ µû¸£¸é, ´ÙÀ½ µ¥¸óµéÀº ¹®Á¦ ¾ø´Ù°í ÇÑ´Ù.<br />
http://www.openwall.com/lists/oss-security/2015/01/27/18<br />
<br />
<br>--------------- quote --<br><br />
apache, cups, dovecot, gnupg, isc-dhcp, lighttpd, mariadb/mysql, nfs-utils, nginx, nodejs, openldap, openssh, postfix, proftpd, pure-ftpd, rsyslog, samba, sendmail, sysklogd, syslog-ng, tcp_wrappers, vsftpd, xinetd.<br />
<br>--------------- /quote --<br><br />
<br />
RHEL(CentOS)Àº ÆÐÄ¡¸¦ Á¦°øÇÏ°í ÀÖ´Ù.<br />
<br />
* RHEL5, CentOS 5 (ÆÐÄ¡µÈ ÆÐÅ°Áö¸í : glibc-2.5-123.el5_11.1)<br />
  https://rhn.redhat.com/errata/RHSA-2015-0090.html<br />
* RHEL6 &amp; 7, CentOS 6 &amp; 7 (RHEL6 ÆÐÄ¡µÈ ÆÐÅ°Áö¸í :  glibc-2.12-1.149.el6_6.5, RHEL 7 : glibc-2.17-55.el7_0.5)<br />
  https://rhn.redhat.com/errata/RHSA-2015-0092.html<br />
<br />
<br>--------------- code --<br><br />
# yum -y update    &#40; -y´Â ¾÷µ¥ÀÌÆ® ÇÒ °ÍÀÎÁö ¹¯Áö ¾Ê°í ¹Ù·Î update&#41;<br />
... »ý·« ...<br />
 glibc            x86_64    2.12-1.149.el6_6.5    updates      3.8 M<br />
 glibc-common     x86_64    2.12-1.149.el6_6.5    updates       14 M<br />
 glibc-devel      x86_64    2.12-1.149.el6_6.5    updates      983 k<br />
 glibc-headers    x86_64    2.12-1.149.el6_6.5    updates      612 k<br />
<br>--------------- /code --<br>]]></description>
		<category>*NIX /  IT Á¤º¸</category>
		<pubDate>Wed, 28 Jan 2015 14:02:09 +0900</pubDate>
	</item>
	<item>
		<title>OpenSSL 1.0.1 Heartbleed Ãë¾àÁ¡ (¹Ýµå½Ã ÆÐÄ¡ ÇÊ¿ä)</title>
		<link>http://coffeenix.net/bbs/viewtopic.php?p=10078#10078</link>
		<description><![CDATA[OpenSSL 1.0.1¹öÀü¿¡ TLS heartbeat Ãë¾àÁ¡(ÀÏ¸í Heartbleed Bug¶ó°í ºÎ¸§. CVE-2014-0160, openssl: information disclosure in handling of TLS heartbeat extension packets)ÀÌ ÀÖ½À´Ï´Ù. <br />
°ø°ÝÀÚ°¡ https¼­¹öÀÇ ¸Þ¸ð¸® 64KB µ¥ÀÌÅÍ¸¦ º¼ ¼ö ÀÖ½À´Ï´Ù. ¸Þ¸ð¸®¿¡´Â https¼­¹ö¿Í À¯Àú°£¿¡ ÁÖ°í ¹ÞÀº µ¥ÀÌÅÍµé(ID/PW, ... µîÀÇ Á¤º¸)ÀÌ ÀÖ´Âµ¥, °ø°ÝÀÚ´Â plain textÇüÅÂ·Î º¼ ¼ö ÀÖ½À´Ï´Ù. ±×¸®°í,SSL °³ÀÎÅ°¸¦ ¾òÀ» ¼ö ÀÖ½À´Ï´Ù. ¹Ýµå½Ã ¾÷µ¥ÀÌÆ®ÇÏ¼¼¿ä.<br />
<br />
http://a4.aurynj.net/post/82075898166/heartbleed (Heartbleed ÀÌ½´¿¡ °üÇØ Á¤¸®)<br />
http://yisangwook.tumblr.com/post/82056087918/openssl-heartbeat-heartbleed (OpenSSL Ãë¾àÁ¡ ¹ß°ß. Heartbleed)<br />
http://heartbleed.com/<br />
<br />
1. Ãë¾àÇÑ ¹öÀü<br />
<br />
OpenSSL 1.0.0°ú 0.9.8 ¹öÀüÀº Ãë¾àÇÏÁö ¾ÊÀ¸¸ç,<br />
<b>1.0.1Àº 1.0.1f±îÁö Ãë¾àÇÕ´Ï´Ù. 1.0.1g¿¡¼­ ÆÐÄ¡µÇ¾ú±¸¿ä.</b><br />
<br />
http://www.openssl.org/news/secadv_20140407.txt<br />
<br />
2. RHEL, CentOS<br />
<br />
- CentOS 5 : 0.9.8<br />
- CentOS 6 : 1.0.1ÀÔ´Ï´Ù. CentOS 6Àº ¾÷µ¥ÀÌÆ®ÇÏ¼¼¿ä. yumÀ¸·Î ÇöÀç Áö¿øÇÕ´Ï´Ù. ÆÐÄ¡µÈ rpm : 1.0.1e-16.el6_5.7 ( https://rhn.redhat.com/errata/RHSA-2014-0376.html )<br />
<br />
<br>--------------- code --<br><br />
# yum update openssl*<br />
... »ý·« ...<br />
=============================================================================<br />
 Package              Arch      Version               Repository        Size<br />
=============================================================================<br />
Updating&#58;<br />
 openssl              x86_64    1.0.1e-16.el6_5.7     updates          1.5 M<br />
 openssl-devel        x86_64    1.0.1e-16.el6_5.7     updates          1.2 M<br />
<br>--------------- /code --<br><br />
<br />
<br />
3. FreeBSD<br />
<br />
- FreeBSD 8.x, 9.x : 0.9.8 ÀÔ´Ï´Ù. ports·Î º°µµ ¼³Ä¡ÇÏÁö ¾Ê¾Ò´Ù¸é ¾÷µ¥ÀÌÆ®ÇÏÁö ¾ÈÇØµµ µÇ¿ä.<br />
- FreeBSD 10.0 : 1.0.1e. ÆÐÄ¡ ³ª¿Ô½À´Ï´Ù. ( http://www.freebsd.org/security/advisories/FreeBSD-SA-14:06.openssl.asc )<br />
<br />
<br>--------------- code --<br><br />
# freebsd-update fetch<br />
# freebsd-update install<br />
# ls -la /usr/lib*/libssl*<br />
-r--r--r--  1 root  wheel  685846 Apr  9 12&#58;28 /usr/lib/libssl.a<br />
lrwxr-xr-x  1 root  wheel      11 Feb 25 09&#58;24 /usr/lib/libssl.so -&gt; libssl.so.7<br />
-r--r--r--  1 root  wheel  430352 Apr  9 12&#58;28 /usr/lib/libssl.so.7<br />
-r--r--r--  1 root  wheel  713782 Apr  9 12&#58;28 /usr/lib/libssl_p.a<br />
-r--r--r--  1 root  wheel  470850 Apr  9 12&#58;28 /usr/lib32/libssl.a<br />
lrwxr-xr-x  1 root  wheel      11 Feb 25 09&#58;26 /usr/lib32/libssl.so -&gt; libssl.so.7<br />
-r--r--r--  1 root  wheel  363552 Apr  9 12&#58;28 /usr/lib32/libssl.so.7<br />
-r--r--r--  1 root  wheel  480306 Apr  9 12&#58;28 /usr/lib32/libssl_p.a<br />
# <br />
<br>--------------- /code --<br><br />
<br />
3. Ubuntu<br />
<br />
- Ubuntu 13.10, 12.10, 12.04 LTS<br />
- apt-get À¸·Î Áö¿ø µË´Ï´Ù. (http://www.ubuntu.com/usn/usn-2165-1/)<br />
<br />
<br>--------------- code --<br><br />
# apt-get update<br />
# apt-get upgarde<br />
<br />
or <br />
<br />
# apt-get update<br />
# apt-get install libssl1.0.0 openssl<br />
<br />
»ý·«<br />
<br>--------------- /code --<br><br />
<br />
- ÆÐÄ¡ È®ÀÎÀº<br />
<br />
<br>--------------- code --<br><br />
# dpkg -l | grep ssl<br />
ii  openssl  1.0.1e-3ubuntu1.2   &lt;-- ubuntu 13.10<br />
ii  libssl1.0.0   1.0.1e-3ubuntu1.2<br />
<br />
ii  openssl  1.0.1c-3ubuntu2.7   &lt;-- ubuntu 12.10<br />
ii  libssl1.0.0   1.0.1c-3ubuntu2.7<br />
<br />
ii  openssl  1.0.1-4ubuntu5.12   &lt;-- ubuntu 12.04 LTS<br />
ii  libssl1.0.0   1.0.1-4ubuntu5.12<br />
<br>--------------- /code --<br><br />
<br />
- Âü°í·Î <br />
<br />
<br>--------------- code --<br><br />
# openssl version <br />
OpenSSL 1.0.1 14 Mar 2012<br />
<br />
Ã³·³ ³ª¿Íµµ ÆÐÄ¡ µÈ °ÍÀÔ´Ï´Ù. ÇØ´ç Version Á¤º¸´Â °»½ÅµÇÁö ¾Ê¾Ò´õ±º¿ä.<br />
¸î¸î Æ÷½ºÆ®¿¡¼­ openssl version À¸·Î ¾÷µ¥ÀÌÆ® È®ÀÎÇÏ¶ó´Â ºÎºÐÀÌ ÀÖ´Âµ¥ ÀÌ ºÎºÐ Á¶½É ÇÏ½Ê½Ã¿À. dpkg ·Î È®ÀÎ ÇÏ½Ê½Ã¿À.<br />
<br>--------------- /code --<br><br />
<br />
<br />
4.  AWS - ELB(Elastic Load Balancing)<br />
<br />
- 04/07ÀÏ ÆÐÄ¡ÀüÀÌ¾úÀ¸³ª ÇöÀç´Â ¸ðµÎ ÆÐÄ¡°¡ ¿Ï·á µÇ¾ú´Ù. <br />
(https://aws.amazon.com/security/security-bulletins/aws-services-updated-to-address-openssl-vulnerability/)<br />
<br />
<br />
¾÷µ¥ÀÌÆ® ÈÄ openssl»ç¿ëÇÏ´Â µ¥¸óÀº Àç½ÇÇàÇØÁÖ¼¼¿ä.<br />
<br />
¡Ø 4.9(¼ö) 15:00 ±Û ¼öÁ¤<br />
¡Ø 4.9(¼ö) 15:40 ±Û ¼öÁ¤(ubuntu Ãß°¡) - ¹ü³ÃÀÌ]]></description>
		<category>*NIX /  IT Á¤º¸</category>
		<pubDate>Wed, 09 Apr 2014 11:48:13 +0900</pubDate>
	</item>
	<item>
		<title>FreeBSD 10.0ÀÌ ³ª¿Ô½À´Ï´Ù.</title>
		<link>http://coffeenix.net/bbs/viewtopic.php?p=10074#10074</link>
		<description><![CDATA[FreeBSD 10.0ÀÌ ¹ßÇ¥µÇ¾ú½À´Ï´Ù.<br />
¸¹Àº °ÍÀÌ ¹Ù²î¾î¼­ ÀûÀÀÇÏ´Âµ¥ ½Ã°£ÀÌ °É¸± °Í °°¾Æ¿ä.<br />
<br />
<img src="http://coffeenix.net/data/images/logo/freebsd.png"><br />
<br />
- GCC´Â ¾ø°í clangÀÌ ±âº»ÀÌ°í,<br />
- make´Â NetBSDÀÇ bmake("Portable" BSD make)·Î ´ëÃ¼µÇ¾ú½À´Ï´Ù.<br />
- BIND¼­¹ö´Â ¼³Ä¡µÇÁö ¾Ê½À´Ï´Ù. BINDÇÊ¿ä½Ã ports³ª pkg·Î ¼³Ä¡ÇØ¾ß ÇÕ´Ï´Ù.<br />
- cvsµµ »ç¶óÁ³½À´Ï´Ù. ±×¸® ¾µÀÏÀº ¾øÀ¸´Ï.<br />
- pkg_info, pkg_add µî ±âÁ¸ pkg_ ÅøÀÌ ¿ÏÀüÈ÷ »ç¶óÁ³½À´Ï´Ù. ÀÌÁ¦ ¿ÀÁ÷ pkg¸¸ »ç¿ëÇÒ ¼ö ÀÖ½À´Ï´Ù. 8.4°ú 9.2¹öÀü¿¡¼­´Â pkg_ Åø°ú pkg°¡ °øÁ¸ÇßÁÒ.<br />
- °¡»óÈ­ °³¼±<br />
- ZFS(ZFS version 5, zpool version 28 ) °³¼±. SSD TRIMÁö¿øÇÏ°í LZ4 Áö¿øÇÑ´Ù°í ÇÏ´Âµ¥, FreeBSD 9.2µµ °°Àº ZFS, zpool ¹öÀüÀ¸·Î Áö¿øÁßÀÎµ¥, Ãß°¡·Î ´Þ<br />
¶óÁø°Ô ÀÖ³ª...<br />
<br />
ÀÚ¼¼ÇÑ °ÍÀº ¸±¸®Áî ³ëÆ®¸¦.<br />
<br />
http://www.freebsd.org/releases/10.0R/announce.html<br />
http://www.freebsd.org/releases/10.0R/relnotes.html]]></description>
		<category>*NIX /  IT Á¤º¸</category>
		<pubDate>Tue, 21 Jan 2014 10:27:28 +0900</pubDate>
	</item>
	<item>
		<title>MSIE 11ÀÇ useragent¸í</title>
		<link>http://coffeenix.net/bbs/viewtopic.php?p=9990#9990</link>
		<description><![CDATA[MSIE 11 (ÀÍ½ºÇÃ·Î·¯ 11)ÀÇ useragent¸íÀÌ ¹Ù²î¾ú´Ù.<br />
useragent¸í¿¡ Æ÷ÇÔµÇ¾ú´ø 'MSIE 10.0'°ú °°Àº °ÍÀÌ »ç¶óÁö°í, 'rv:11.0'ÀÌ µîÀåÇß´Ù.<br />
<br />
* MSIE 10 ¹öÀü<br />
<br>--------------- code --<br>Mozilla/5.0 &#40;compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0&#41;<br>--------------- /code --<br><br />
<br />
* MSIE 11 ¹öÀü<br />
<br>--------------- code --<br>Mozilla/5.0 &#40;Windows NT 6.1; Trident/7.0; rv&#58;11.0&#41; like Gecko &lt;-- Win 7<br />
Mozilla/5.0 &#40;Windows NT 6.3; Trident/7.0; rv&#58;11.0&#41; like Gecko &lt;-- Win 8.1<br>--------------- /code --<br><br />
<br />
±×¸®°í, useragent³»ÀÇ Trident¸¦ È®ÀÎÇØºÃ´õ´Ï ´ÙÀ½°ú °°´Ù.<br />
<br />
<br>--------------- code --<br><br />
Trident/4.0 -&gt; MSIE 8<br />
Trident/5.0 -&gt; MSIE 9<br />
Trident/6.0 -&gt; MSIE 10<br />
Trident/7.0 -&gt; MSIE 11<br />
<br>--------------- /code --<br><br />
<br />
* Âü°í »çÀÌÆ® :<br />
http://blogs.msdn.com/b/ieinternals/archive/2013/09/21/internet-explorer-11-user-agent-string-ua-string-sniffing-compatibility-with-gecko-webkit.aspx]]></description>
		<category>*NIX /  IT Á¤º¸</category>
		<pubDate>Wed, 23 Oct 2013 08:24:44 +0900</pubDate>
	</item>
	</channel>
</rss>
