20.8. 자체 서명 인증서(Self-Signed Certificate) 생성하기

여러분은 스스로 자체 서명한 인증서를 작성하실 수 있습니다. 자체 서명 인증서는 CA-서명 인증서와 같은 보안 보증을 제공하지 않는다는 점에 유의해 주십시오. 인증서에 대한 보다 상세한 정보를 원하신다면, 20.5 절을 참조하시기 바랍니다.

자체 서명 인증서를 생성하기 위해서는 우선 20.6 절에 나온 지시에 따라 임의키를 생성하셔야 하니다. 키를 생성 후 /usr/share/ssl/certs 디렉토리로 이동하여 다음 명령을 입력해 주십시오:

make testcert

다음과 같은 출력 결과가 나타나며 암호 입력이 요청될 것입니다 (암호없이 키를 생성한 경우 제외):

umask 77 ; \
/usr/bin/openssl req -new -key /etc/httpd/conf/ssl.key/server.key 
-x509 -days 365 -out /etc/httpd/conf/ssl.crt/server.crt
Using configuration from /usr/share/ssl/openssl.cnf
Enter PEM pass phrase:

암호를 입력하신 후 (또는 암호없이 키를 생성한 경우 암호를 입력할 필요가 없이), 보다 많은 정보를 위한 일련의 질문 사항들이 나타날 것입니다. 컴퓨터의 질문 사항들과 예시 답변은 다음과 같이 나타납니다. (회사와 호스트에 대한 올바른 정보를 입력하십시오):

You are about to be asked to enter information that will be incorporated
into your certificate request.
What you are about to enter is what is called a Distinguished Name or a
DN.
There are quite a few fields but you can leave some blank
For some fields there will be a default value,
If you enter '.', the field will be left blank.
-----
Country Name (2 letter code) [GB]:US      
State or Province Name (full name) [Berkshire]:North Carolina
Locality Name (eg, city) [Newbury]:Raleigh
Organization Name (eg, company) [My Company Ltd]:My Company, Inc.
Organizational Unit Name (eg, section) []:Documentation
Common Name (your name or server's hostname) []:myhost.example.com
Email Address []:myemail@example.com

올바른 입력정보가 채워지면, 자체 서명 인증서가 생성되어 /etc/httpd/conf/ssl.crt/server.crt에 저장됩니다. 인증서를 생성하신 후 다음과 같은 명령을 사용하여 보안 서버를 재시작하셔야 합니다:

/sbin/service httpd restart