/
vsftpd + SSL/TLS ๋กœ ๊ฒฌ๊ณ ํ•œ ftp ์„œ๋น„์Šค ๊ตฌ์„ฑ

vsftpd + SSL/TLS ๋กœ ๊ฒฌ๊ณ ํ•œ ftp ์„œ๋น„์Šค ๊ตฌ์„ฑ


์™ธ๋ถ€์—์„œ ๋Œ€์šฉ๋Ÿ‰ ํŒŒ์ผ์„ ์—…๋กœ๋“œํ•  ์ผ์ด ์ƒ๊ฒจ์„œ ์–ด๋–ค ๋ฐฉ๋ฒ•์„ ์‚ฌ์šฉํ• ๊นŒ ๊ถ๋ฆฌํ•˜๋‹ค๊ฐ€ SCP ๋ฅผ ์‚ฌ์šฉํ•˜๊ธฐ๋กœ ํ–ˆ์Šต๋‹ˆ๋‹ค.

์ ‘์†์ž๊ฐ€ ssh ๋กœ ์—ฐ๊ฒฐํ•ด์„œ ์‹œ์Šคํ…œ์„ ์ด๋ฆฌ ์ €๋ฆฌ ๋‘˜๋Ÿฌ ๋ณด๋Š” ๊ฒƒ์€ ๋ณด์•ˆ์ƒ ๋ฌธ์ œ๊ฐ€ ์žˆ์œผ๋‹ˆ ๊ถŒํ•œ์ด ์ œํ•œ๋œ restricted shell(rbash) ์„ ๋กœ๊ทธ์ธ ์…ธ๋กœ ์„ค์ •ํ•˜๊ธฐ๋กœ ํ–ˆ์Šต๋‹ˆ๋‹ค.


๊ทธ๋Ÿฐ๋ฐ rbash ๋Š” scp ๊ฐ€ ๋™์ž‘ํ•˜์ง€ ์•Š๋Š” ๋ฌธ์ œ๊ฐ€ ์žˆ์–ด์„œ ๋‹ค๋ฅธ ๋ฐฉ๋ฒ•์„ ์ฐพ๋‹ค๊ฐ€ FTP ๋กœ ํŒŒ์ผ์„ ๋ฐ›๊ธฐ๋กœ ์ •ํ–ˆ์Šต๋‹ˆ๋‹ค.

FTP ๋Š” ์˜ค๋ž˜๋œ ์„œ๋น„์Šค์ง€๋งŒ IT ์— ์ต์ˆ™ํ•˜์ง€ ์•Š์€ ์ด๋„ ์–ด๋ ต์ง€ ์•Š๊ฒŒ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๊ณ  ๊ฒ€์ฆ๋œ ์„œ๋น„์Šค๋‹ˆ๊นŒ์š”.


ํ•˜์ง€๋งŒ FTP ๋Š” ์•”ํ˜ธํ™”๊ฐ€ ๋˜์ง€ ์•Š์€ ํŒจํ‚ท์ด ์˜ค๊ฐ€๋Š” ๋“ฑ์˜ ๋ณด์•ˆ ๋ฌธ์ œ๊ฐ€ ์žˆ์œผ๋ฏ€๋กœ ์–ด๋–ป๊ฒŒ ๊ฒฌ๊ณ ํ•˜๊ฒŒ ํ• ๊นŒ ๊ณ ๋ฏผํ•˜๋‹ค ๋ณด๋‹ˆ FTP ์„œ๋ฒ„์ธ vsftpd ๊ฐ€ SSL/TLS ๋ฅผ ์ง€์›ํ•˜๋Š” ๊ฒƒ์„ ์•Œ๊ฒŒ ๋˜์–ด FTP + SSL/TLS ๋กœ ์„œ๋น„์Šค๋ฅผ ๊ตฌ์„ฑํ–ˆใ„ฑใ…Ž ๊ทธ ๊ณผ์ •์„ ๊ธฐ๋กํ•ด ๋ด…๋‹ˆ๋‹ค.

์„ค์น˜

๋จผ์ € ํŒจํ‚ค์ง€ ๋งค๋‹ˆ์ €๋ฅผ ํ†ตํ•ด์„œ vsftpd ๋ฅผ ์„ค์น˜ํ•˜๊ณ  ์ž๋™์œผ๋กœ ๊ตฌ๋™๋˜๋„๋ก ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค.

sudo yum install vsftpd
systemctl enable vsftpd
systemctl restart vsftpd


์„ค์ •

/etc/vsftpd/vsftpd.conf  ๋ฅผ ์—ด์–ด์„œ ๋‹ค์Œ ๋‚ด์šฉ์„ ์ถ”๊ฐ€ํ•ฉ๋‹ˆ๋‹ค.

 Click here to expand...


์ด์ œ TLS ์—ฐ๊ฒฐ์— ์‚ฌ์šฉํ•  ์ธ์ฆ์„œ๋ฅผ ์ €์žฅํ•  ํด๋”๋ฅผ ์ƒ์„ฑํ•ฉ๋‹ˆ๋‹ค.

sudo mkdir /etc/ssl/private


TLS ์—ฐ๊ฒฐ์— ์‚ฌ์šฉํ•  RSA ์ธ์ฆ์„œ๋ฅผ ์ƒ์„ฑํ•ฉ๋‹ˆ๋‹ค.

openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout /etc/ssl/private/vsftpd.pem -out /etc/ssl/private/vsftpd.pem


์ƒ์„ฑํ•  ๋•Œ Common name ์—๋Š” ์—ฐ๊ฒฐํ•  ์„œ๋ฒ„์˜ IP ๋‚˜ Domain name ์„ ์ ์–ด์ค๋‹ˆ๋‹ค.


firewalld ๋ฅผ ์‚ฌ์šฉํ•œ๋‹ค๋ฉด ๋ฐฉํ™”๋ฒฝ์— ํฌํŠธ๋ฅผ ์ถ”๊ฐ€ํ•ด ์ค๋‹ˆ๋‹ค.

sudo firewall-cmd --permanent --zone=dmz --add-port=2120-2142/tcp   

zone ์ด๋ฆ„์€ ์‚ฌ์šฉ์ž ํ™˜๊ฒฝ์— ๋”ฐ๋ผ ๋‹ค๋ฅผ ์ˆ˜ ์žˆ์œผ๋ฉฐ firewall-cmd --get-active-zone ๋ช…๋ น์–ด๋กœ ํ™œ์„ฑํ™”๋œ ์กด์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.


๋ฐฉํ™”๋ฒฝ ์„ค์ •์ด ๋๋‚ฌ์œผ๋ฉด ์„ค์ •์„ ๋ฐ˜์˜ํ•ฉ๋‹ˆ๋‹ค.

sudo firewall-cmd --reload


๋งŒ์•ฝ ์‚ฌ์šฉ์ž๊ฐ€ home ๋””๋ ‰ํ„ฐ๋ฆฌ ์ด์™ธ์˜ ํด๋”๋ฅผ ์ฝ์–ด์•ผ ํ•œ๋‹ค๋ฉด FTP ์ ‘์†์‹œ ํ™ˆ ์ด์™ธ ํด๋”๋ฅผ ์ฝ๊ธฐ ์œ„ํ•œ Linux bind mount ์‚ฌ์šฉ๋ฒ• ๋ฅผ ์ฐธ๊ณ ํ•ด์„œ ๋Œ€์ƒ ํด๋”๋ฅผ bind ๋งˆ์šด๋“œ ํ•ด์ค๋‹ˆ๋‹ค.

FileZilla ์„ค์ •


ํŒŒ์ผ์งˆ๋ผ์˜ Site Manager ์— ๋‹ค์Œ๊ณผ ๊ฐ™์ด ์„ค์ •ํ•ด ์ค๋‹ˆ๋‹ค. Port ๋Š” listen_port ์ด๋ฉฐ Protocol ์€ FTP, Encryption ์€ Use explicit FTP over TLS ๋ฅผ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.


์—ฐ๊ฒฐ์— ์„ฑ๊ณตํ•˜๋ฉด ์•„๋ž˜์™€ ๊ฐ™์ด ์ธ์ฆ์„œ๋ฅผ ์‹ ๋ขฐํ•˜๊ฒ ๋ƒ๋Š” ์ฐฝ์ด ๋œจ๋ฉฐ Always trust ๋ฅผ ์ฒดํฌํ•ฉ๋‹ˆ๋‹ค.


๊ฐ™์ด ๋ณด๊ธฐ

Ref

Related content

์›Œ๋“œํ”„๋ ˆ์Šค ํ”Œ๋Ÿฌ๊ทธ์ธ ์—…๋ฐ์ดํŠธ๋ฅผ FTP ๋Œ€์‹  SSH/SCP ๋กœ ํ•˜๊ธฐ
์›Œ๋“œํ”„๋ ˆ์Šค ํ”Œ๋Ÿฌ๊ทธ์ธ ์—…๋ฐ์ดํŠธ๋ฅผ FTP ๋Œ€์‹  SSH/SCP ๋กœ ํ•˜๊ธฐ
More like this
linux ์—์„œ scp ๋กœ ์›๊ฒฉ์ง€์— ํŒŒ์ผ ์ „์†กํ•˜๊ธฐ
linux ์—์„œ scp ๋กœ ์›๊ฒฉ์ง€์— ํŒŒ์ผ ์ „์†กํ•˜๊ธฐ
More like this
SecureCRT SSH Port forwarding ์œผ๋กœ ์›๊ฒฉ ์„œ๋ฒ„ ์—ฐ๊ฒฐํ•˜๊ธฐ
SecureCRT SSH Port forwarding ์œผ๋กœ ์›๊ฒฉ ์„œ๋ฒ„ ์—ฐ๊ฒฐํ•˜๊ธฐ
More like this
ssh ๋กœ ํฌํŠธ ํฌ์›Œ๋”ฉ(port forwarding)ํ•ด์„œ Proxy ์„œ๋ฒ„๋กœ ์‚ฌ์šฉํ•˜๊ธฐ
ssh ๋กœ ํฌํŠธ ํฌ์›Œ๋”ฉ(port forwarding)ํ•ด์„œ Proxy ์„œ๋ฒ„๋กœ ์‚ฌ์šฉํ•˜๊ธฐ
More like this
ssh ๋ฅผ 22๋ฒˆ์ด ์•„๋‹Œ ๋‹ค๋ฅธ ํฌํŠธ ์‚ฌ์šฉ
ssh ๋ฅผ 22๋ฒˆ์ด ์•„๋‹Œ ๋‹ค๋ฅธ ํฌํŠธ ์‚ฌ์šฉ
More like this
Windows ์—์„œ SSH Client๋ฅผ ์„ค์น˜ํ•ด์„œ ์›๊ฒฉ ์„œ๋ฒ„ ์ ‘์†ํ•˜๊ธฐ
Windows ์—์„œ SSH Client๋ฅผ ์„ค์น˜ํ•ด์„œ ์›๊ฒฉ ์„œ๋ฒ„ ์ ‘์†ํ•˜๊ธฐ
More like this