yessign Version 3.1 (yessign). ccopyright 2009 yessign ALL RIGHTS RESERVED
- - 2000. 8.29. 2000. 8.29. 2001. 7. 5. 2001. 7. 5. 2001.12.17. 2001.12.17. 2002. 3.12. 2002. 3.12. 2002. 8.21. 2002. 9. 5. 2002.12.27. 2003. 1.13. 2004. 3.31. 2004. 6.12. 2004. 9.16. 2004.10. 1. 2005. 2.21. 2005. 3. 8. 2005.11.17. 2005.12. 2. 2005.12.29. 2006. 1.13. 2006. 6.14. 2006. 7. 1. 2006. 6.30. 2006. 8. 1. 2007. 5.21. 2007. 8. 1. 2009.10. 7. 2009.10.22.
- - 1. 1 1.1 1 1.1.1 yessign 1 1.1.2 1 1.1.3 1 1.1.4 2 1.2 2 1.3 3 1.3.1 3 1.3.2 () 3 1.3.3 4 1.3.4 4 1.3.5 4 1.3.6 5 1.3.7 5 1.3.8 6 1.3.9 7 1.3.10 8 1.4 9 1.4.1 9 1.4.2 9 1.4.3 10 1.4.4 10 1.4.5 10 1.5 10 1.5.1 10 1.5.2 11
2. 12 2.1 12 2.2 12 2.2.1 13 2.2.2 13 2.2.3 (CRL) 13 2.2.4 13 2.3 13 3. 15 3.1 15 3.1.1 15 3.1.2 15 3.1.3 15 3.2 15 3.2.1 16 3.2.2 17 3.3 19 3.3.1 19 3.3.2 19 3.4 20 3.4.1 20 3.4.2 21 3.5 21 3.5.1 21 3.5.2 21 3.6 21 3.6.1 22 3.6.2 22 3.6.3 22
3.6.4 (CRL) 23 3.6.5 23 3.6.6 23 3.6.7 23 3.6.8 23 3.6.9 23 3.7 (OCSP) 24 3.8 24 3.9 25 3.10 (CRL) 27 3.11 (OCSP) 29 3.12 31 3.13 31 3.13.1 31 3.13.2 31 3.14 31 4. 33 4.1 33 4.2 33 4.2.1 33 4.2.2 33 5. 34 5.1 34 5.1.1 34 5.1.2 34 5.1.3 35 5.1.4 35 5.1.5 35
5.1.6 35 5.1.7, 36 5.1.8 36 5.1.9 36 5.1.10 36 5.1.11 36 5.2 36 5.2.1 37 5.2.2 37 5.2.3 37 5.3 37 5.3.1 38 5.3.2 38 5.3.3 38 5.3.4 38 5.3.5 38 5.3.6 38 5.3.7 39 5.3.8 S/W 39 5.3.9 39 5.3.10 40 5.4 40 5.4.1, 40 5.4.2, 41 5.4.3 41 5.5 41 5.5.1 41 5.5.2 42 5.5.3 42 5.6 42 5.6.1 42
5.6.2 42 5.6.3 43 5.7 43 5.7.1 43 5.7.2 43 5.7.3 44 5.7.4 44 5.7.5 45 6. 46 6.1 46 6.1.1 46 6.1.2 46 6.2 46 6.2.1 46 6.2.2 46 6.2.3 47 6.3 47 6.3.1 47 6.3.2 47 6.3.3 47 6.4 47 6.5 48 6.5.1 48 6.5.2 48 6.6 49 6.7 50
1. 1.1 1.1.1 yessign ( ). ( ) ( ), ( ), ( ), ( ),. 1.1.2,, 5.,. 1.1.3 32 ( ) 1986 6 2,,, 2000 4 12 4 ( )
. 1.1.4 1.1.4.1 15,.,.,,. 1.1.4.2 16 ( ),. 1.1.4.3... 1.2 yessign.
1.3. 1.3.1 (PKI, Public Key Infrastructure). - -,,, - - 1.3.2 () 25 (). - 4-141 - 183-192 - - - - -
1.3.3 4 ( ) 8 ( ). - - -,,,,,, -, CRL - - - 1.3.4,,,,. ( ),, 4.2.1 -. 1.3.5.,. ().
,. 1.3.6. 1.3.7 1.3.7.1 222( ) yessign (http://www.yessign.or.kr). - - - - - - CRL - 1.3.7.2 21 ( ). 1.3.7.3
8 ( ). 1.3.7.4 21 ( ),. yessign(http://www.yessign.or.kr), CRL, CRL,. 1.3.7.5,,,. 1.3.7.6 15 ( ),. 1.3.8 1.3.8.1 7 ( ),,,,,. 3 ( )
. 1.3.8.2 15 ( ),. 1.3.9 1.3.9.1 15 ( ).. - - - -, - 1.3.9.2 ( ).,. 1.3.9.3 21 ( ).
.. 1.3.9.4 21 ( ). 1.3.9.5. ( ) 10. - - - (,, ) 1.3.9.6. 1.3.10 1.3.10.1 ( )..
1.3.10.2. - - - - 3 1.3.10.3. 1.4 1.4.1 : (http://www.yessign.or.kr) : yessign@kftc.or.kr : 10-3 : 1577-5500 FAX : (02)531-3379 1.4.2 6 ( ).
.. - - - 1.4.3 6 ( ) 15. 1.4.4 yessign(http://www.yessign.or.kr) 4.2.1 -. 1.4.5 30 ( ) ( ). 1.5 1.5.1 1.5.1.1
6.6. 1.5.1.2. - :, CRL ITU-T X.500. 1.5.2. - CRL : Certificate Revocation List, - DN : Ditinguished Name,
2. 2.1 / ( ),. 1.. ( 2006-17, 2006.4.27) 2006 6 30. 2006 7 31 /, /. 2.2 28 ( ).
. 2.2.1. ( : /, ) CTR 4,000 2.2.2. 2.2.3 (CRL) CRL. 2.2.4. 2.3 7, 7,.. yessign
,.
3. 3.1 3.1.1 ( ), /. 3.1.2 -. -. - yessign(http://www.yessign.or.kr). -. -. 3.1.3. - - - 3.2
3.2.1.,. 3.2.1.1 132( ) 133().,,.,. -, ( ) -, ( )
,,. 3.2.1.2 132( ) 4 //.. - (ID) - - ( ) 3.2.2 3.2.2.1 7 ( ),,.., 7 ( ) 7.
3.2.2.2. -,, - - -,.. - - - - - - - DN. DN ID. ID,,., CRL.. 3.2.2.3,
,. 3.2.2.4.. 3.3 3.3.1 1. 1. 3.3.2 3.3.2.1.. - - - -,
.. 3.3.2.2. - - -.. DN DN. 3.3.2.3 "3.2.2.3 ". 3.3.2.4 "3.2.2.4 ". 3.4 3.4.1,.
. 3.4.2 3.2.2. 3.5 3.5.1 (,, ). 3.5.2,. 3.2.2.4. 3.6,,..,,
. 3.6.1. - - 3.6.2 18 ( ) "1.3.7 ". - -, - - - - 6 - - 3.6.3 "3.2.1 ".
3.6.4 (CRL) CRL yessign(http://www.yessign.or.kr). 3.6.5 "3.6.1 " "3.6.2 ". 3.6.6 "3.2.1 ". 3.6.7,. 3.6.8 CRL CRL. 3.6.9 17 ( ) 6.
3.7 (OCSP) (OCSP) OCSP(Online Certificate Status Protocol),, yessign.. S/W.. 3.8 20 ( ).
3.9. 1) # ASN.1 Note 1 Version INTEGER m m 0x02 ( 3) 2 Serial Number INTEGER m m 3 Signature OID m m 4 5 Issuer m m [KCAC.TS.DN] type OID m m C(Country) printablestring, printablestring value m m utf8string utf8string Validity m m notbefore UTCTime m m [1] notafter UTCTime m m 6 7 Subject m m [KCAC.TS.DN] type OID m m C(Country) printablestring, printablestring value m m utf8string utf8string Subject Public Key Info m m algorithm OID m m subjectpublickey BIT STRING m m 8 Extensions Extensions m m [2] [1] "2.1 ", "3.3 ", "3.4 " [2] 2)
2) # ASN.1 C Note 1 Authority Key Identifier keyidentifier OCTET STRING m m KeyID n authoritycertissuer GeneralNames m m authoritycertserialnumber INTEGER m m 2 Subject Key Identifier OCTET STRING n m m m m subjectpublickey 160 3 Key Usage BIT STRING c m m, 4 Certificate Policy policyidentifier OID m m [1] policyqualifiers m m PolicyQualifierId OID m m CPS, UserNotice Qualifier c m m CPSuri IA5String m m URI UserNotice m m NoticeReference SEQUENCE - - ExplicitText BMPString m m 5 Policy Mappings - - - 6 Subject Alternative Names othername n m m m m rfc822name o m 7 Issuer Alternative Names othername n o m id-kisa-identifydata VID id-kisa-identifydata 8 Extended Key Usage OID n o o id-kisa-hsm [2] 9 Basic Constraints - x x 10 Policy Constraints - - - 11 Name Constraints - - - 12 13 CRL DistributionPoint distributionpoint DistributionPoint Name reasons ReasonFlags - - n m m m m CRL crlissuer GeneralNames o m CRL Authority Information Access accessmethod OID n m m id-ad-ocsp accesslocation GeneralNames m m OCSP URI [1] 2.1 [2] [KCAC.TS.HSM] (id-kisa-hsm) m m
3.10 (CRL) CRL. 1) # ASN.1 Note 1 Version INTEGER m m 0x01 ( 3) 2 Signature OID m m Issuer m m [KCAC.TS.DN] type OID m m 3 C(Country) printablestring, printablestring value m m utf8string utf8string 4 This Update UTCTime m m CRL 5 Next Update UTCTime m m CRL Revoked Certificates m m [1] 6 usercertificate INTEGER m m revocationdata UTCTime m m crlentryextensions Extensions m m [2] 7 CRL Extensions Extensions m m [3] [1] Revoked Certificates [2] 3) CRL [3] 2) CRL
2) CRL # ASN.1 C Note 1 Authority Key Identifier keyidentifier OCTET STRING m m KeyID n authoritycertissuer GeneralNames m m authoritycertserialnumber INTEGER m m 2 Issuer Alternative Names othername n o m 3 CRL Number INTEGER n m m m m id-kisa-identifydata Issuing DistributionPoint m m DistributionPointName IA5String m m CRL [1] 4 onlycontainsusercerts BOOLEAN c - - onlycontainscacerts BOOLEAN - - onlysomereasons BIT STRING - - IndirectCRL BOOLEAN o m [2] [1] CRLDP ([KCAC.TS.DSCP] ) [2] IndirectCRL TRUE 3) CRL # ASN.1 C Note 1 Reason Code ENUMERATED n m m 2 Hold Instruction Code OID n o m 3 Invalidity Date UTCTime n o m 4 Certificate Issuer GeneralNames c o m
3.11 (OCSP). 1) 3.9, 1).
2) # ASN.1 C Note 1 Authority Key Identifier keyidentifier OCTET STRING m m n authoritycertissuer GeneralNames m m authoritycertserialnumber INTEGER m m 2 Subject Key Identifier OCTET STRING n m m m m subjectpublickey 160 3 Key Usage BIT STRING c m m, 4 Certificate Policy policyidentifier OID m m policyqualifiers m m PolicyQualifierId OID m m CPS, UserNotice Qualifier m m c CPSuri IA5String m m UserNotice m m NoticeReference SEQUENCE - - m m OCSP URI ExplicitText BMPString m m 5 Policy Mappings - - - 6 Subject Alternative Names othername n m m 7 Issuer Alternative Names othername n o m 8 Extended Key Usage OID c m m 9 Basic Constraints - x x 10 Policy Constraints - - - 11 Name Constraints - - - 12 13 CRL DistributionPoint distributionpoint DistributionPoint Name reasons ReasonFlags o m n m m m m CRL URI id-kisa-identifydata VID id-kisa-identifydata crlissuer GeneralNames o m CRL Authority Information Access accessmethod OID n o m id-ad-ocsp [1] accesslocation GeneralNames 14 OCSP No Check OID n o m id-pkix-ocsp-nocheck [2] [1] [2] shortlived
3.12.. 3.13 3.13.1 30. 10 ( ) 6. 3.13.2 60. ( " " ).,.. 3.14 6
.,. - 4 - - 4 6 6-64 - 11 3.13.2.
4. 4.1 CRL yessign(http://www.yessign.or.kr). 4.2 4.2.1 : http://www.yessign.or.kr/cps.htm : ldap://ds.yessign.or.kr/ CRL : ldap://ds.yessign.or.kr/ : http://www.yessign.or.kr/ra.htm : http://www.rootca.or.kr/cert.htm : ldap://ds.yessign.or.kr/ 4.2.2, CRL 24., yessign(http://www.yessign.or.kr).
5. 5.1,,,, ( " " ). 5.1.1. -,, - -, 5.1.2. - -,, - -
- - CCTV - 2 5.1.3 30cm. 5.1.4,,. 5.1.5,. 5.1.6. -, 3T -, -
- 5.1.7,,. 5.1.8. -, - - 5.1.9. 5.1.10,,. 5.1.11 22 ( ), CRL 10. 5.2
5.2.1. -,, - -, ( 2 ) 1-2 - 2-2 5.2.2,,. 5.2.3. - 3-2 - 5.3
5.3.1 -. -. 5.3.2. - RSA KCDSA : 2048 - HAS-160 SHA-1 : 160 5.3.3,. 5.3.4. 5.3.5. 5.3.6.
5.3.7-2. -. -. -. -. -. -,. -. - //(, ). - //. -. -. 5.3.8 S/W S/W. - S/W - 5.3.9 -,.
-. -. -. -,. -,. -. - //. - //. 5.3.10. 5.4. 5.4.1, 12. -
- 2 -, 5.4.2, -. -, 1. -. -,. -. 5.4.3 -. 5.5 5.5.1 10. - -
- - - - - - - (login) (logoff) - 5.5.2.,. 5.5.3. 5.6 5.6.1 22 ( ) 10. - - 5.6.2.
-. -.,. 5.6.1 10Km 1. 5.6.3. 5.7,. 5.7.1. 5.7.2. - -, -, Dos. - ( )
- - -. - - - 5.7.3 -. -,. -,. 5.7.4 -, Dos IP,. -. -, Dos,, S/W, ID, PASSWORD S/W,. -. -. - IP, S/W
. 5.7.5 -. -. -.
6. 6.1 6.1.1. - -,,, - CRL 6.1.2,, 6.1.1,,. 6.2 6.2.1,, 26 (). 6.2.2., 26 ().
6.2.3 25. 398 ( ).,. 6.3 6.3.1. 6.3.2. 6.3.3,,.. 6.4
24 ( ),. 3. - ( ) - - - - 6.5 6.5.1..,,, 7. 6.5.2.. - -
- - - - - - - - 6.6 1.3. - - - -. - - - (yessign) - - CRL
. 6.7. 2009 10 22.