/
OpenSSL ์ž์ฃผ ์“ฐ๋Š” ๋ช…๋ น์–ด(command) ๋ฐ ์‚ฌ์šฉ๋ฒ•, tip ์ •๋ฆฌ

OpenSSL ์ž์ฃผ ์“ฐ๋Š” ๋ช…๋ น์–ด(command) ๋ฐ ์‚ฌ์šฉ๋ฒ•, tip ์ •๋ฆฌ

HTTPS ์„ค์ •, ๋ฐ์ดํƒ€ ์•”๋ณตํ˜ธ๋“ฑ OpenSSL ์„ ํ™œ์šฉํ•  ์ผ์ด ๋งŽ์œผ๋ฏ€๋กœ ์‚ฌ๋ก€๋ณ„๋กœ ์ž์ฃผ ์‚ฌ์šฉํ•˜๋Š” ๋ช…๋ น์–ด๋ฅผ ์ •๋ฆฌํ–ˆ์Šต๋‹ˆ๋‹ค.

์•”ํ˜ธ์— ๋Œ€ํ•œ ๋Œ€๋žต์ ์ธ ์†Œ๊ฐœ๋Š” slideshare ์— ๊ณต๊ฐœํ•œ "์•”ํ˜ธํ™” ์ด๊ฒƒ๋งŒ ์•Œ๋ฉด ๋œ๋‹ค" ๋ฅผ ์ฐธ๊ณ ํ•˜์„ธ์š”


์„ค์น˜

RHEL/CentOS Linux ๋Š” ๊ธฐ๋ณธ ํŒจํ‚ค์ง€์— ํฌํ•จ๋˜์–ด ์žˆ์œผ๋ฏ€๋กœ ๋ณ„๋„ ์„ค์น˜๋ฅผ ์•ˆํ•ด๋„ ๋ฉ๋‹ˆ๋‹ค. Windows ๋‚˜ ๊ธฐํƒ€ Unix ์—์„œ ์„ค์น˜๋Š” OpenSSL ์ปดํŒŒ์ผ(compile) & ๋นŒ๋“œ(build) ์ฐธ๊ณ ํ•˜์„ธ์š”


์„ค์น˜๋œ openssl  ์˜ version ์€ ๋‹ค์Œ ๋ช…๋ น์–ด๋กœ ํ™•์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

$ openssl version


OpenSSL 1.0.2o  27 Mar 2018


์ธ์ฆ์„œ ์ •๋ณด ๋ณด๊ธฐ

openssl ๋กœ x509 ์ธ์ฆ์„œ ํŒŒ์‹ฑ( certificate parsing )ํ•˜๊ธฐ ์ฐธ๊ณ 


๊ฐœ์ธํ‚ค(PrivateKey)

RSA 2048 ํ‚ค ์ƒ์„ฑ ๋ฐ ๊ฐœ์ธํ‚ค๋ฅผ AES256 ์œผ๋กœ  ์•”ํ˜ธํ™”

  • ์•”ํ˜ธ( pass phrase)๋Š” asdfasdf ์ด๋ฉฐ ์ž…๋ ฅ์ฐฝ์„ ๋„์šฐ์ง€ ์•Š๊ณ  ์ปค๋งจ๋“œ์—์„œ ๋ฐ”๋กœ ์„ค์ •( -passout ์˜ต์…˜)
openssl genrsa -aes256 -passout pass:asdfasdf -out aes-pri.pem 2048


์œ„์—์„œ ์ƒ์„ฑํ•œ ๊ฐœ์ธํ‚ค ๋ณตํ˜ธํ™”ํ•˜์—ฌ RSA Private Key ์ถ”์ถœ

openssl rsa -outform der -in aes-pri.pem -passin pass:asdfasdf -out aes-pri.key

pass phrase ์™€ ์•”ํ˜ธํ™” ์•Œ๊ณ ๋ฆฌ์ฆ˜ ๋ณ€๊ฒฝ

  • ์•Œ๊ณ ๋ฆฌ์ฆ˜:  Triple DES → AES256
  •  Pass phrase : asdfasdf -> new-password
openssl rsa -aes256 -in aes-pri.pem -passin pass:asdfasdf  -passout pass:new-password  -out aes-pri.key



๊ฐœ์ธํ‚ค(PrivateKey) pass phrase ํ•ด๋…

OpenSSL ๋กœ ๊ฐœ์ธ ํ‚ค(Private Key) ๋น„๋ฐ€ ๊ตฌ์ ˆ(Pass Phrase) ํ•ด๋… ๋ฐ ์•”ํ˜ธํ™” ์ฐธ๊ณ ํ•˜์„ธ์š”.

๊ฐœ์ธํ‚ค(PrivateKey) pass phrase ์„ค์ •

OpenSSL ๋กœ ๊ฐœ์ธ ํ‚ค(Private Key) ๋น„๋ฐ€ ๊ตฌ์ ˆ(Pass Phrase) ํ•ด๋… ๋ฐ ์•”ํ˜ธํ™” ์ฐธ๊ณ ํ•˜์„ธ์š”.


pkcs#8 ๋ฐฉ์‹์˜ ๊ฐœ์ธํ‚ค ํ•ด๋…

Private-Key Information Syntax Specification ๋ฐฉ์‹์œผ๋กœ ์•”ํ˜ธํ™”๋œ RSA PrivateKey ๋ฅผ ํ•ด๋…ํ•˜๋ ค๋ฉด ์•„๋ž˜ ๋ช…๋ น์„ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค.

openssl pkcs8 -inform der -in pkcs8-pri.key -out rsa-pri.key

PKCS#8 ํŒŒ์ผ์€ binary ํ˜•์‹(DER) ๊ณผ text ํ˜•์‹(PEM) ์ด ์žˆ์„ ์ˆ˜ ์žˆ์œผ๋ฉฐ ์—๋””ํ„ฐ๋กœ ์—ด์—ˆ์„ ๋•Œ -----BEGIN ENCRYPTED PRIVATE KEY----- ๋กœ ์‹œ์ž‘ํ•˜๋Š” ๊ฒฝ์šฐ PEM ์ด๋ฉฐ ๊นจ์ง€๋Š” ๋ฌธ์ž๊ฐ€ ์žˆ์„ ๊ฒฝ์šฐ DER ์ž…๋‹ˆ๋‹ค.

PKCS8 PEM ์˜ˆ์ œ

-----BEGIN ENCRYPTED PRIVATE KEY-----
MIIFHzBJBgkqhkiG9w0BBQ0wPDAbBgkqhkiG9w0BBQwwDgQITJWLw/UHoM0CAggA


PEM ํ˜•์‹์ผ ๊ฒฝ์šฐ -inform der ๊ตฌ๋ฌธ๋Œ€์‹  -inform pem ์„ ์‚ฌ์šฉํ•˜๋ฉด ๋ฉ๋‹ˆ๋‹ค.


pkcs#8 ๋กœ ๋ณ€ํ™˜

๊ฐœ์ธํ‚ค์˜ pass phrase ๋ฅผ PKCS#8 ํ˜•์‹์œผ๋กœ ๋ณ€ํ™˜

openssl pkcs8 -topk8 -v2 aes128 -in aes-pri.pem -out aes-strong.key -outform der -passout pass:asdfasdf
  • -topk8 : output PKCS8 file
  • -v2 aes128 : PKCS#5 Ver 2.0 ์‚ฌ์šฉ ๋ฐ aes128 ์‚ฌ์šฉ


HTTPS ์—ฐ๊ฒฐ์˜ ์ธ์ฆ์„œ ๋””๋ฒ„๊น…

HTTPS ๋””๋ฒ„๊น…(httpd ์˜ SSLCertificateChainFile, SSLCACertificateFile ์ •์ƒ ์„ค์ • ์—ฌ๋ถ€ ํ™•์ธ๋“ฑ)์ด๋‚˜ curl ๋“ฑ์˜ ca bundle ์— ๋“ฑ๋กํ•˜๊ธฐ ์œ„ํ•œ ๋ชฉ์ ์œผ๋กœ ์„œ๋ฒ„๊ฐ€ ์‚ฌ์šฉํ•˜๋Š” SSL ์ธ์ฆ์„œ๋ฅผ ์ถ”์ถœํ•  ๊ฒฝ์šฐ ์•„๋ž˜ ๋ช…๋ น์–ด ์‚ฌ์šฉ

openssl s_client -debug -connect ssl.example.com:443

CMS (PKCS#7, S/MIME)  

cms(Cryptographic Message Syntax) ๋ช…๋ น์–ด๋Š” S/MIME v3.1 mail ์ด๋‚˜ PKCS#7 ํ˜•์‹์˜ ๋ฐ์ดํƒ€๋ฅผ ์ฒ˜๋ฆฌํ•˜๋Š” ๋ช…๋ น์–ด๋กœ ์ฃผ์š” ์˜ต์…˜์€ ๋‹ค์Œ๊ณผ ๊ฐ™๋‹ค.

  • -verify : ์ „์ž์„œ๋ช… ๊ฒ€์ฆ ์ˆ˜ํ–‰
  • -in : ๊ฒ€์ฆํ•  ์ „์ž์„œ๋ช… ๋ฐ์ดํƒ€ ํŒŒ์ผ
  • -certfile : ๊ฒ€์ฆ์— ์‚ฌ์šฉํ•  ์ธ์ฆ์„œ ํŒŒ์ผ(์ „์ž ์„œ๋ช… ๋ฐ์ดํƒ€๋‚ด์— ์ธ์ฆ์„œ๊ฐ€ ์—†์„ ๊ฒฝ์šฐ ํ•„์š” - ์ƒ์„ฑ์‹œ -nocerts ์œผ๋กœ ์ƒ์„ฑํ–ˆ์„ ๊ฒฝ์šฐ)
  • -out : ๊ฒ€์ฆํ›„ ์›๋ณธ์„ ์ €์žฅํ•  ํŒŒ์ผ๋ช…
  • -content : ๊ฒ€์ฆ์— ์‚ฌ์šฉํ•  ์›๋ณธ ํŒŒ์ผ
  • -CAfile : ์ธ์ฆ์„œ ๋ฐœ๊ธ‰ ์ฒด์ธ(CA ์ธ์ฆ์„œ ๋ฌถ์Œ. PEM ํ˜•์‹์œผ๋กœ ์—ฐ์ ‘ํ•ด์„œ ์ž‘์„ฑํ•ด ์ฃผ๋ฉด ๋˜๋ฉฐ ์˜ˆ์ œ๋Š” curl ์— ํฌํ•จ๋œ ca์ธ์ฆ์„œ ๋ฒˆ๋“ค ํŒŒ์ผ ์ฐธ๊ณ  - /etc/pki/tls/certs/ca-bundle.crt)

signeddata ๊ฒ€์ฆ

DER ๋กœ ์ธ์ฝ”๋”ฉ๋œ cms signed-data ํ˜•์‹์ธ inputfile ์„ ๊ฒ€์ฆํ•˜๊ณ  ์›๋ณธ์„ content ๋ผ๋Š” ํŒŒ์ผ๋กœ ์ €์žฅ. 

openssl cms -verify -in signedData.ber -inform DER  -out content


์ธ์ฆ์„œ ์ฒด์ธ ์ง€์ •

signed-data ์•ˆ์— ์ธ์ฆ์„œ ์ฒด์ธ์ด ์—†์„ ๊ฒฝ์šฐ ๋‹ค์Œ๊ณผ ๊ฐ™์€ ์—๋Ÿฌ๊ฐ€ ๋ฐœ์ƒํ•œ๋‹ค.

certificate verify error:cms_smime.c:304:Verify error:unable to get local issuer certificate

CA ์ธ์ฆ์„œ๋ฅผ PEM ํ˜•์‹์˜ ํŒŒ์ผ(Ex: ca-file) ์œผ๋กœ ๋งŒ๋“  ํ›„์—  -CAfile file ์˜ต์…˜์„ ์ถ”๊ฐ€ํ•˜๋ฉด ๊ฒ€์ฆ์‹œ ์‚ฌ์šฉํ•  CA ์ธ์ฆ์„œ๋ฅผ ์ง€์ •ํ•ด ์ค„ ์ˆ˜ ์žˆ๋‹ค.

openssl cms -verify -in signedData.ber -inform DER  -out content -CAfile ca-file


detached signeddata ๊ฒ€์ฆ

์„œ๋ช…์— ์‚ฌ์šฉ๋œ ์ปจํ…์ธ ๊ฐ€ CMS Signed Data ๋‚ด์— ์—†๊ฑฐ๋‚˜ ๋˜๋Š” ์žˆ์–ด๋„ ๊ฐ•์ œ๋กœ ์™ธ๋ถ€ ํŒŒ์ผ์„ ์‚ฌ์šฉํ•  ๊ฒฝ์šฐ -content file ์˜ต์…˜์œผ๋กœ ํŒŒ์ผ์„ ์ง€์ •ํ•˜๋ฉด ๋œ๋‹ค.

openssl cms -verify -in signedData.ber -inform DER  -out content -CAfile ca-file -content origFile


signeddata ์ƒ์„ฑ

PEM ํ˜•์‹์œผ๋กœ ๋œ ์ธ์ฆ์„œ์™€ ๊ฐœ์ธํ‚ค๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์ „์ž ์„œ๋ช… ๋ฐ์ดํƒ€ ์ƒ์„ฑ

openssl cms  -sign -in contents.pdf -aes128 -nosmimecap -signer sign-cert.pem -inkey sign-key.pem -outform DER -nodetach  -out signed-data.ber
  • -sign : ์ „์ž ์„œ๋ช… ๋ฐ์ดํƒ€ ์ƒ์„ฑ
  • -in : ์ „์ž์„œ๋ช…ํ•  ์›๋ณธ ๋ฐ์ดํƒ€
  • -nodetach:  ์ „์ž์„œ๋ช… ๋ฐ์ดํƒ€์— ์›๋ณธ ์ฒจ๋ถ€
  • -nosmimecap:
  • -noattr: ์ „์ž์„œ๋ช… ๋ฐ์ดํƒ€์— ์–ด๋–ค signed attributes ๋„ ํฌํ•จํ•˜์ง€ ์•Š์Œ.


envelop  data ์ƒ์„ฑ

CMS envelopedData data ์ƒ์„ฑ(๋Œ€์นญํ‚ค๋ฅผ ์ƒ์„ฑํ›„ ์›๋ณธ์„ ์•”ํ˜ธํ™”ํ•œ ํ›„์— ์ƒ๋Œ€๋ฐฉ ์ธ์ฆ์„œ์˜ ๊ณต๊ฐœํ‚ค๋กœ ๋Œ€์นญํ‚ค๋ฅผ ์•”ํ˜ธํ•œ ๋ฐ์ดํƒ€ ํ˜•์‹)

openssl cms -encrypt -in contents.pdf -aes256 -recip sign-cert.pem -outform DER -out enveloped-data.ber
  • -encrypt: encrypt ๋ฐ์ดํƒ€ ์ƒ์„ฑ
  • -in : ์•”ํ˜ธํ™”ํ•  ์›๋ณธ ๋ฐ์ดํƒ€

  • -aes256 : AES256 ์œผ๋กœ ์•”ํ˜ธํ™”(-aes128, -seed, -camellia128 ๋“ฑ์˜ ์•Œ๊ณ ๋ฆฌ์ฆ˜ ์‚ฌ์šฉ ๊ฐ€๋Šฅ)
  • -recip: ๋ฐ์ดํƒ€๋ฅผ ์ˆ˜์‹ ํ•  ์ƒ๋Œ€๋ฐฉ์˜ ์ธ์ฆ์„œ(์ด ์•ˆ์— ์žˆ๋Š” ๊ณต๊ฐœํ‚ค๋กœ ์•”ํ˜ธํ™”ํ•˜๋ฏ€๋กœ ์ƒ๋Œ€๋ฐฉ ์ธ์ฆ์„œ๋ฅผ ์ •ํ™•ํžˆ ๋„ฃ์–ด์ฃผ์–ด์•ผ ํ•จ)

envelop  data ํ•ด๋…

openssl cms -decrypt -in enveloped-data.ber -inform der -inkey kmpri.pem
  • -decrypt : 1123
  • -in : ํ•ด๋…ํ•  enveloped data ํŒŒ์ผ
  • -inform : ํŒŒ์ผ์˜ ํฌ๋งท. ๊ธฐ๋ณธ๊ฐ’์€ PEM ์ด๋ฉฐ der ์ธ์ฝ”๋”ฉ๋˜์—ˆ์„ ๊ฒฝ์šฐ der ์ถ”๊ฐ€
  • -inkey: ๋ณตํ˜ธํ™”ํ•  ๊ฐœ์ธํ‚ค

-decrypt ์‹œ -out ์˜ต์…˜์ด ํ†ตํ•˜์ง€ ์•Š์œผ๋ฏ€๋กœ > ๋กœ ์›๋ณธ ํŒŒ์ผ์„ ์ €์žฅํ•ด์•ผ ํ•จ

openssl cms -decrypt -in enveloped-data.ber -inform der -inkey kmpri.pem > contents

PKCS#12

Check a Certificate Signing Request (CSR) - PKCS#10

openssl req -text -noout -verify -in CSR.csr

pkcs12 ์ƒ์„ฑ

p12 ํŒŒ์ผ ์ƒ์„ฑ

openssl pkcs12 -export -in cert.pem -inkey pri-key.pem -out file.p12 -name "My Certificate"
  • -export : PKCS#12 ํŒŒ์ผ ์ƒ์„ฑ
  • -in : p12 ์— ๋“ค์–ด๊ฐˆ ์ธ์ฆ์„œ
  • -inkey: ํฌํ•จ์‹œํ‚ฌ ๊ฐœ์ธํ‚ค
  • -out : ์ƒ์„ฑ๋  p12 ํŒŒ์ผ๋ช…
  • -name: ์ฒจ๋ถ€ ๊ทธ๋ฆผ์ฒ˜๋Ÿผ friendlyName ์— ๋“ค์–ด๊ฐˆ ์ด๋ฆ„์ด๋ฉฐ Java ์—์„œ KeyStore ๋กœ ์ ‘๊ทผ์‹œ alias ํ•ญ๋ชฉ์ด ๋˜๋ฏ€๋กœ ํ•„์ˆ˜๋กœ ์ž…๋ ฅํ•ด์•ผ ํ•œ๋‹ค. openssl ์€ ์ž…๋ ฅ๋˜์ง€ ์•Š์•˜์„ ๊ฒฝ์šฐ ์ธ์ฆ์„œ์˜ ํ•ด์‹œ๊ฐ’์„ ์„ค์ •ํ•˜๋Š” ๊ฒƒ ๊ฐ™๋‹ค.
     
  • -descert :  p12 ๋‚ด ์ธ์ฆ์„œ ํ•ญ๋ชฉ์„ Triple DES ๋กœ ์•”ํ˜ธํ™”(๊ธฐ๋ณธ๊ฐ’ RC2-40) - ์ธ์ฆ์„œ๋Š” ๊ณต๊ฐœํ•˜๋Š” ์šฉ๋„์ด๋ฏ€๋กœ ํฌ๊ฒŒ ์˜๋ฏธ ์—†๋Š” ์˜ต์…˜
  • -des3 : encrypt private keys with triple DES (default)
  • -aes128 : ๊ฐœ์ธํ‚ค๋ฅผ AES128 ๋กœ ์•”ํ˜ธํ™”(๊ถŒ์žฅ)
  • -keypbe alg: specify private key PBE algorithm (default 3DES)


๊ธฐํƒ€ ์ธ์ฆ์„œ๋ฅผ ํฌํ•จํ•˜์—ฌ p12 ์ƒ์„ฑ

openssl pkcs12 -export -in cert.pem -inkey pri-key.pem -out file.p12 -name "My Certificate" \
  -certfile othercerts.pem
  • -certfile : ํฌํ•จ์‹œํ‚ฌ ์ถ”๊ฐ€ ์ธ์ฆ์„œ

Check a PKCS#12 file (.pfx or .p12)

PKCS#12 ์ •๋ณด ์ถœ๋ ฅ

openssl pkcs12 -info -in keyStore.p12


PKCS#12 ๋‚ด ์ธ์ฆ์„œ๋ฅผ ํŒŒ์ผ๋กœ ์ €์žฅ(-clcerts -nokeys)

openssl pkcs12 -in file.p12 -clcerts -nokeys -out file.crt


PKCS#12 ๋‚ด ๊ฐœ์ธํ‚ค๋ฅผ ํŒŒ์ผ๋กœ ์ €์žฅ

openssl pkcs12 -in file.p12 -nocerts -out file.key


PKCS#12 ๋‚ด ๊ฐœ์ธํ‚ค์— pass phrase ๋ฅผ ์ ์šฉํ•˜์ง€ ์•Š๊ณ  ํŒŒ์ผ๋กœ ์ €์žฅ

openssl pkcs12 -in file.p12 -out file.pem -nodes


OCSP

์ธ์ฆ์„œ๋Š” PEM ํ˜•์‹์ด์–ด์•ผ ํ•จ.

OCSPRequest ์ƒ์„ฑ

lesstif.cer ์ธ์ฆ์„œ๋ฅผ ๊ฒ€์ฆํ•˜๊ธฐ ์œ„ํ•œ OCSPRequest ๋ฅผ ์ƒ์„ฑํ•˜์—ฌ ํŒŒ์ผ(ocsp-req.ber)๋กœ ์ €์žฅ. -issuer ์˜ต์…˜์—๋Š” ์ธ์ฆ๊ธฐ๊ด€ ์ธ์ฆ์„œ๋ฅผ ์ž…๋ ฅ

openssl ocsp -issuer myca.cer -cert lesstif.cer -reqout ocsp-req.ber 

ocsp ๋กœ ์ธ์ฆ์„œ ๊ฒ€์ฆ

์œ„์—์„œ ์ƒ์„ฑํ•œ OCSPRequest ๋ฅผ ์ฝ์–ด์„œ -url ๋กœ ์ง€์ •๋œ OCSP ์„œ๋ฒ„์—์„œ ์ธ์ฆ์„œ ๊ฒ€์ฆ ์š”์ฒญ

openssl ocsp -reqin ocsp-req.ber -text -url http://myocsp.server.com:8080/ocsp


๊ฒ€์ฆํ•  ์ธ์ฆ์„œ๋ฅผ ์ฝ์–ด์„œ ๊ฒ€์ฆ ์š”์ฒญ

openssl ocsp -issuer myca.cer -cert lesstif.cer  -text -url http://myocsp.server.com:8080/ocsp


ocsp asn ํŒŒ์‹ฑ

-reqin ์œผ๋กœ ์ง€์ •๋œ ํŒŒ์ผ๋กœ๋ถ€ํ„ฐ OCSPRequest ํ˜•์‹์˜ ๋ฐ์ดํƒ€๋ฅผ ์ฝ์–ด์„œ ์ถœ๋ ฅ

$ openssl ocsp -reqin ocsp-req.ber -text
 
OCSP Request Data:
    Version: 1 (0x0)
    Requestor List:
        Certificate ID:
          Hash Algorithm: sha1
          Issuer Name Hash: D530654290FA7C42771A7566518BB1420AB04CE0
          Issuer Key Hash: 4D5D560A0703DF83CAF3D56D8F19FC12AC90A28A
          Serial Number: 598E19F6
    Request Extensions:
        OCSP Nonce: 
            0410D8F5A2A55605873CBEBB043FCA79022A

TSA(Time Stamp Authority)

ts ์ƒ์„ฑ

openssl ts -query -data mydata.txt -no_nonce -sha1 -out design1.tsq  


print

openssl ts -query -in design1.tsq -text

ASN1Parse

UTF8String ์ƒ์„ฑ

UTF8String ์„ ์ƒ์„ฑํ•ด์„œ utf8string.der ํŒŒ์ผ๋กœ ์ €์žฅ


openssl asn1parse -genstr "UTF8:ํ—ฌ๋กœ World" -out utf8string.der


UTF8String file ๋กœ ๋ถ€ํ„ฐ ํŒŒ์‹ฑ

์ƒ์„ฑ๋œ ASN1 ํŒŒ์ผ๋กœ ๋ถ€ํ„ฐ ํŒŒ์‹ฑ

openssl asn1parse -inform DER -in utf8string.der


UTCTime ์ƒ์„ฑ

openssl asn1parse -genstr "UTCTIME:970909034126Z" -out utctime.der

UTCTime  ํŒŒ์‹ฑ

openssl asn1parse -inform DER -in utctime.der


OctetString ์ƒ์„ฑ

ํ™•์ธ ํ•„์š”


"Hello World" ๋ผ๋Š” ๋ฌธ์ž์—ด์„ Octet string ์œผ๋กœ ์ƒ์„ฑํ•ด์„œ octetstring.der ๋กœ ์ €์žฅ

openssl asn1parse -genstr "OCTETSTRING:Hello World"   -out octetstring.der

contents ๋ผ๋Š” ํŒŒ์ผ์„ octet string ์œผ๋กœ ์ƒ์„ฑํ•˜์—ฌ octetstring.der ๋กœ ์ €์žฅ
openssl asn1parse -genstr "OCTETSTRING" -in contents  -out octetstring.der

์•Œ๊ณ ๋ฆฌ์ฆ˜ ์†๋„ ์ธก์ •

openssl speed ๋ช…๋ น์–ด๋กœ ์ธก์ • ๊ฐ€๋Šฅ

$ openssl speed -h




๋‹ค์Œ์€ aes-128-cbc ์™€ rsa 2014 ๋ฅผ ๋น„๊ตํ•˜๋Š” ๋ช…๋ น

$ openssl speed aes-128-cbc rsa1024


Doing aes-128 cbc for 3s on 16 size blocks: 22920078 aes-128 cbc's in 3.00s
Doing aes-128 cbc for 3s on 64 size blocks: 6343026 aes-128 cbc's in 3.00s
Doing aes-128 cbc for 3s on 256 size blocks: 1621301 aes-128 cbc's in 3.00s
Doing aes-128 cbc for 3s on 1024 size blocks: 408313 aes-128 cbc's in 3.00s
Doing aes-128 cbc for 3s on 8192 size blocks: 51219 aes-128 cbc's in 3.00s

Doing 1024 bit private rsa's for 10s: 52898 1024 bit private RSA's in 10.00s
Doing 1024 bit public rsa's for 10s: 907416 1024 bit public RSA's in 9.99s

OpenSSL 1.0.1e-fips 11 Feb 2013



๊ฐ™์ด ๋ณด๊ธฐ


Ref



Related content

OpenSSL ์ปดํŒŒ์ผ(compile) & ๋นŒ๋“œ(build)
OpenSSL ์ปดํŒŒ์ผ(compile) & ๋นŒ๋“œ(build)
More like this
OpenSSL ๋กœ SSL/TLS ์šฉ ์ธ์ฆ์„œ ์š”์ฒญ ๋ฐ ๋ฐœ๊ธ‰๋ฐ›๊ธฐ
OpenSSL ๋กœ SSL/TLS ์šฉ ์ธ์ฆ์„œ ์š”์ฒญ ๋ฐ ๋ฐœ๊ธ‰๋ฐ›๊ธฐ
More like this
SSL/TLS implementation Library list
SSL/TLS implementation Library list
More like this
RHEL/CentOS 7 ์— TLS 1.3 ์ ์šฉํ•˜๊ธฐ(OpenSSL 1.1 & Nginx compile)
RHEL/CentOS 7 ์— TLS 1.3 ์ ์šฉํ•˜๊ธฐ(OpenSSL 1.1 & Nginx compile)
More like this
OpenSSL ๋กœ ROOT CA ์ƒ์„ฑ ๋ฐ SSL ์ธ์ฆ์„œ ๋ฐœ๊ธ‰
OpenSSL ๋กœ ROOT CA ์ƒ์„ฑ ๋ฐ SSL ์ธ์ฆ์„œ ๋ฐœ๊ธ‰
More like this
Windows ์— OpenSSH ์„ค์น˜
Windows ์— OpenSSH ์„ค์น˜
More like this