TLS ๋ฐ ์ธ์ฆ์„œ

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ

์ด ์„น์…˜์€ X.509 ํŒŒ์‹ฑ, ํฌ๋งท, ๋ณ€ํ™˜ ๋ฐ ์ผ๋ฐ˜์ ์ธ ์‹ค์ˆ˜์— ๊ด€ํ•œ ๊ฒƒ์ž…๋‹ˆ๋‹ค.

X.509: ํŒŒ์‹ฑ, ํฌ๋งท ๋ฐ ์ผ๋ฐ˜์ ์ธ ์‹ค์ˆ˜

๋น ๋ฅธ ํŒŒ์‹ฑ

openssl x509 -in cert.pem -noout -text
openssl asn1parse -in cert.pem

ํ™•์ธํ•  ์œ ์šฉํ•œ ํ•„๋“œ:

  • Subject / Issuer / SAN
  • Key Usage / EKU
  • Basic Constraints (CA์ธ๊ฐ€?)
  • Validity window (NotBefore/NotAfter)
  • Signature algorithm (MD5? SHA1?)

ํ˜•์‹ ๋ฐ ๋ณ€ํ™˜

  • PEM (Base64, BEGIN/END ํ—ค๋” ํฌํ•จ)
  • DER (๋ฐ”์ด๋„ˆ๋ฆฌ)
  • PKCS#7 (.p7b) (์ธ์ฆ์„œ ์ฒด์ธ, ๊ฐœ์ธ ํ‚ค ์—†์Œ)
  • PKCS#12 (.pfx/.p12) (์ธ์ฆ์„œ + ๊ฐœ์ธ ํ‚ค + ์ฒด์ธ)

๋ณ€ํ™˜:

openssl x509 -in cert.cer -outform PEM -out cert.pem
openssl x509 -in cert.pem -outform der -out cert.der
openssl pkcs12 -in file.pfx -out out.pem

์ผ๋ฐ˜์ ์ธ ๊ณต๊ฒฉ ๋ฒกํ„ฐ

  • ์‚ฌ์šฉ์ž ์ œ๊ณต ๋ฃจํŠธ ์‹ ๋ขฐ / ์ฒด์ธ ๊ฒ€์ฆ ๋ˆ„๋ฝ
  • ์•ฝํ•œ ์„œ๋ช… ์•Œ๊ณ ๋ฆฌ์ฆ˜(๋ ˆ๊ฑฐ์‹œ)
  • ์ด๋ฆ„ ์ œ์•ฝ / SAN ํŒŒ์‹ฑ ๋ฒ„๊ทธ(๊ตฌํ˜„๋ณ„)
  • Confused deputy issues with client-certificate authentication misbinding

CT logs

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ