¸¶ÀÌÅ©·Î¼ÒÇÁÆ®, ±¸±Û µîÀÇ È¸»çÀÇ ºê¶ó¿ìÀú¿¡¼ SHA-1 ÀÎÁõ¿¡ ´ëÇÑ Áö¿øÀ» 2016³â 6¿ùºÎÅÍ Áß´ÜÇÒ ¿¹Á¤ÀÔ´Ï´Ù.
´Ü Windows XP SP2 ÀÌÇÏ ¹öÀü, Windows 2003 Àº SHA-2 ¸¦ Áö¿øÇÏÁö ¾Ê±â ¶§¹®¿¡ º» Á¤Ã¥¿¡ ¿µÇâÀ» ¹ÞÁö ¾Ê½À´Ï´Ù.
SHA-1 ·Î ¼¸íÇÏ¿´´õ¶óµµ 2016³â 1¿ù 1ÀÏ ÀÌÀü¿¡ »ý¼ºµÈ ÆÄÀÏÀ̶ó¸é 2020³â 1¿ù Àü±îÁö »ç¿ëÀÌ °¡´ÉÇÕ´Ï´Ù.
(µû¶ó¼ 2015³â±îÁö Àû¿ëÇϽŠ¿ÀÁî Á¦Ç°Àº 2020³â 1¿ù Àü±îÁö »ç¿ëÀÌ °¡´ÉÇϽøç
2016³âµµºÎÅÍ Àû¿ëÇϽô ¿ÀÁî Á¦Ç°À» ¾Æ·¡ ÀýÂ÷´ë·Î ¹Ý¿µÇϽñ⠹ٶø´Ï´Ù.)
ÀÌ¿¡ ¿µÇâÀ» ¹Þ´Â ºä¾î´Â OZ ActiveX ºä¾îÀ̸ç(±× ¿Ü ¿ÀÁî Á¦Ç°Àº ¿µÇâÀ» ¹ÞÁö ¾Ê½À´Ï´Ù.)
2016³â 1¿ùºÎÅÍ Á¦°øµÇ´Â ¹öÀüºÎÅÍ ÀÎÁõ ¹æ½ÄÀ» SHA-2 ·Î º¯°æÇÏ¿´½À´Ï´Ù.
¶ÇÇÑ Windows XP SP2 ÀÌÇÏ, Windows 2003 »ç¿ë °í°´À» À§ÇÑ SHA1 ÀÎÁõ ÆÄÀϵµ ¹èÆ÷°¡ µË´Ï´Ù.
SHA-2 ÀÎÁõ ¹æ½ÄÀÌ ¹Ý¿µµÈ ActiveX ºä¾î¸¦ ¾÷µ¥ÀÌÆ® Çϱâ À§Çؼ´Â ½Å±Ô ¹èÆ÷ ÆÄÀÏ ¹× idf ÆÄÀÏÀ» ¹Ý¿µÇÏ¼Å¾ß ÇÕ´Ï´Ù.
¶ÇÇÑ Windows XP, Windows 2003 »ç¿ëÀÚ¸¦ °í·ÁÇØ
À¥ÆäÀÌÁö¿¡¼ ¿ÀÁî ºä¾î¸¦ ¼³Ä¡ÇÏ´Â ºÎºÐÀÇ ¼Ò½º¸¦ ¼öÁ¤ÇÏ¼Å¾ß ÇÕ´Ï´Ù.
l ActiveX ºä¾î¿¡ º¯°æµÈ ÆÄÀÏ ±¸¼º
|
±âÁ¸ ¹èÆ÷ ÆÄÀÏ |
½Å±Ô ¹èÆ÷ ÆÄÀÏ |
|
ZTransferX_x,x,x,x.cab
ozrviewerocx.zip
ozaviewerocx.zip |
ZTransferX_x,x,x,x.cab
ozrviewerocx.zip
ozaviewerocx.zip
ZTransferX_x,x,x,x_SHA1.cab
ozrviewerocx_SHA1.zip
ozaviewerocx_SHA1.zip |
|
SHA1 ¹æ½ÄÀ¸·Î ÀÎÁõµÈ ÆÄÀϸ¸ ¹èÆ÷ |
SHA1, SHA2 ¹æ½ÄÀ¸·Î ÀÎÁõµÈ ÆÄÀÏÀ» ¸ðµÎ ¹èÆ÷
¡°SHA1¡±ÀÌ ºÙÁö ¾Ê´Â ÆÄÀÏÀº SHA2 ¹æ½ÄÀ¸·Î
ÀÎÁõµÈ ÆÄÀÏÀÓ |
l ÇØ´ç ÆÄÀÏ º¯°æ°ú °ü·ÃÇÏ¿©
ActiveX ºä¾î´Â idf¸¦ ÀÌ¿ëÇØ »ç¿ëÀÚ PCÀÇ OS¿¡ µû¶ó ºÐ¸®ÇÏ¿© ¼³Ä¡Çϵµ·Ï idf¿Í Á¦Ç°À» ÆÐÄ¡ÇÕ´Ï´Ù.
l ActiveX ºä¾îÀÇ ZTransferX¿Í ºä¾î¸¦ ¼³Ä¡ÇÏ´Â À¥ ÆäÀÌÁö¸¦ ¼öÁ¤ÇØ¾ß ÇÕ´Ï´Ù.
l ¼³Ä¡ ű×
|
l ±âÁ¸ À¥ ÆäÀÌÁö |
|
<html style='height:100%'>
<head>
<script language = "JavaScript" src = "http://127.0.0.1:8080/ztransferx_browers.js"></script>
</head>
...
<body style='height:100%'>
<div id = "InstallOZViewer">
<script language = "JavaScript">
Initialize_ZT("ZTransferX", "CLSID:C7C7225A-9476-47AC-B0B0-FF3B79D55E67", "0", "0", "http://127.0.0.1:8080/ozviewer/ZTransferX_2,2,5,1.cab#version=2,2,5,1", "application/OZTransferX_1027");
Insert_ZT_Param("download.server", "http://127.0.0.1/ozviewer/");
Insert_ZT_Param("download.port", "8080");
Insert_ZT_Param("download.instruction", "ozrviewer.idf");
Insert_ZT_Param("install.base", "<PROGRAMS>/Forcs");
Insert_ZT_Param("install.namespace", "custom_namespace");
Start_ZT();
</script>
</div></body>
</html> |
|
OS¿¡ °ü°è ¾øÀÌ ZTransferX ¼³Ä¡ |
|
½Å±Ô À¥ ÆäÀÌÁö |
|
<html style='height:100%'>
<head>
<script language = "JavaScript" src = "http://127.0.0.1:8080/ztransferx_browers.js"></script>
</head>
...
<body style='height:100%'>
<div id = "InstallOZViewer">
<script language = "JavaScript">
if(IsNeedSha1_ZT())
Initialize_ZT("ZTransferX", "CLSID:C7C7225A-9476-47AC-B0B0-FF3B79D55E67", "0", "0", "http://127.0.0.1:8080/ozviewer/ZTransferX_2,2,5,3_SHA1.cab#version=2,2,5,3", "application/OZTransferX_1027");
else
Initialize_ZT("ZTransferX", "CLSID:C7C7225A-9476-47AC-B0B0-FF3B79D55E67", "0", "0", "http://127.0.0.1:8080/ozviewer/ZTransferX_2,2,5,3.cab#version=2,2,5,3", "application/OZTransferX_1027");
Insert_ZT_Param("download.server", "http://127.0.0.1/zt/");
Insert_ZT_Param("download.port", "8080");
Insert_ZT_Param("download.instruction", "ozrviewer.idf");
Insert_ZT_Param("install.base", "<PROGRAMS>/Forcs");
Insert_ZT_Param("install.namespace", "ZT_Install_Test");
Start_ZT();
</script>
</div>
</body>
</html> |
|
OS¿¡ µû¶ó SHA1, SHA2 ¹æ½ÄÀ¸·Î ÀÎÁõµÈ ZTransferX ÆÄÀÏÀ» ±¸ºÐÇÏ¿© ¼³Ä¡Çϵµ·Ï IsNeedSha1_ZT ÇÔ¼ö Ãß°¡ |
l ½Å±Ô À¥ ÆäÀÌÁö¿¡ Ãß°¡µÈ IsNeedSha1_ZT ÇÔ¼ö¸¦ »ç¿ëÇÏ·Á¸é ztransferx_browers.js ÆÄÀÏ¿¡ ÇØ´ç ÇÔ¼ö¸¦ Ãß°¡ÇØ¾ß ÇÕ´Ï´Ù.
|
½Å±Ô ztransferx_browers.js |
|
...
function IsNeedSha1_ZT() {
var retval = false;
var uanaVigatorOs = navigator.userAgent;
var AgentUserOs= uanaVigatorOs.replace(/ /g,'');
if( AgentUserOs.indexOf("Windows95") != -1||
AgentUserOs.indexOf("Windows98") != -1||
AgentUserOs.indexOf("Win9x4.90") != -1||
AgentUserOs.indexOf("WindowsNT4.0") != -1||
AgentUserOs.indexOf("WindowsNT5.0") != -1||
AgentUserOs.indexOf("WindowsNT5.1") != -1||
AgentUserOs.indexOf("WindowsNT5.2") != -1)
{
retval = true;
}
return retval;
}
function Insert_ZT_Param(ParameterName, ParameterValue) {
... |
|
OS¿¡ µû¶ó SHA1, SHA2 ¹æ½ÄÀ¸·Î ÀÎÁõµÈ ZTransferX ÆÄÀÏÀ» ±¸ºÐÇÏ¿© ¼³Ä¡Çϵµ·Ï IsNeedSha1_ZT ÇÔ¼ö Ãß°¡ |
À§ ³»¿ëÀÌ Àû¿ëµÇ´Â Á¦Ç°Àº ¾Æ·¡¿Í °°½À´Ï´Ù.
6.0 AV(x32/x64) 2016/01/06 ÀÌÈÄ ¹öÀü
6.0 RV_ActiveX(x32/x64) 2016/01/06 ÀÌÈÄ ¹öÀü
7.0 AV(x32/x64) 2016/01/06 ÀÌÈÄ ¹öÀü
7.0 RV_ActiveX(x32/x64) 2016/01/06 ÀÌÈÄ ¹öÀü
ZT 2,2,5,3 ÀÌÈÄ ¹öÀüºÎÅÍ
±âŸ ¹®ÀÇ»çÇ×À̳ª Áö¿ø ¿äûÀÌ ÇÊ¿äÇÒ °æ¿ì ÇïÇÁµ¥½ºÅ©(1544-0181)·Î ¿¬¶ô Áֽñ⠹ٶø´Ï´Ù.
°¨»çÇÕ´Ï´Ù.
¡Ø SHA-1 °ü·Ã Æ÷½ºÆ®ÀÔ´Ï´Ù.
±¸±Û : https://googleonlinesecurity.blogspot.kr/2014/09/gradually-sunsetting-sha-1.html
MS : http://blogs.windows.com/msedgedev/2015/11/04/sha-1-deprecation-update
http://social.technet.microsoft.com/wiki/contents/articles/32288.windows-enforcement-of-authenticode-code-signing-and-timestamping.aspx
¸ðÁú¶ó : https://blog.mozilla.org/security/2015/10/20/continuing-to-phase-out-sha-1-certificates
|