내부망 개발 클러스터라 공인 인증서 대신 자체 Root CA 를 만들고 그 CA 로 Trino 서버 인증서를 서명한다. 결과물은 Trino 설정 의 http-server.https.keystore.path 에 넣는 PEM 하나다. 일반적인 자체 서명 절차는 CA 인증서 생성 에도 있다.
| 산출물 | 용도 |
|---|---|
rootca/rootca.key · rootca.crt |
내부 Root CA. 클라이언트 truststore 에 rootca.crt 를 넣는다 |
trino/trino.key · trino.crt |
Trino coordinator 서버 인증서 |
trino/trino.pem |
키 + 인증서. Trino 가 읽는 파일 |
mkdir -p ~/certs/rootca ~/certs/trino
cd ~/certs/rootca
openssl genrsa -aes256 -out rootca.key 4096
rootca_openssl.conf
[ req ]
default_bits = 4096
default_md = sha256
default_keyfile = rootca.key
distinguished_name = req_distinguished_name
extensions = v3_ca
req_extensions = v3_ca
[ v3_ca ]
basicConstraints = critical, CA:TRUE, pathlen:0
subjectKeyIdentifier = hash
keyUsage = keyCertSign, cRLSign
[ req_distinguished_name ]
countryName = Country Name (2 letter code)
countryName_default = KR
organizationName = Organization Name (eg, company)
organizationName_default = example
commonName = Common Name (eg, your name or your server's hostname)
commonName_default = example Internal Root CA
commonName_max = 64
openssl req -new -key rootca.key -out rootca.csr -config rootca_openssl.conf
openssl x509 -req -days 3650 -extensions v3_ca -set_serial 1 \
-in rootca.csr -signkey rootca.key -out rootca.crt -extfile rootca_openssl.conf
openssl x509 -in rootca.crt -noout -subject -dates
default_md 는 sha256 이다. sha1 서명은 현행 자바와 브라우저가 거부한다.
Trino 가 기동할 때 암호를 물을 수 없으므로 서버 키에는 암호를 두지 않는다.
cd ~/certs/trino
openssl genrsa -out trino.key 2048
trino_openssl.conf — subjectAltName 에 클라이언트가 접속할 호스트명을 전부 적는다. 내부 TLS 를 켜면 IP 도 IP.1 = ... 으로 넣는다.
[ req ]
default_bits = 2048
default_md = sha256
distinguished_name = req_distinguished_name
req_extensions = v3_user
[ v3_user ]
basicConstraints = CA:FALSE
authorityKeyIdentifier = keyid,issuer
subjectKeyIdentifier = hash
keyUsage = nonRepudiation, digitalSignature, keyEncipherment
extendedKeyUsage = serverAuth, clientAuth
subjectAltName = @alt_names
[ alt_names ]
DNS.1 = trino.example.net
DNS.2 = trino
DNS.3 = *.example.net
IP.1 = 192.168.1.41
[ req_distinguished_name ]
countryName = Country Name (2 letter code)
countryName_default = KR
organizationName = Organization Name (eg, company)
organizationName_default = example
organizationalUnitName = Organizational Unit Name (eg, section)
organizationalUnitName_default = data
commonName = Common Name (eg, your name or your server's hostname)
commonName_default = trino.example.net
commonName_max = 64
openssl req -new -key trino.key -out trino.csr -config trino_openssl.conf
openssl x509 -req -days 365 -extensions v3_user -extfile trino_openssl.conf \
-in trino.csr -CA ../rootca/rootca.crt -CAkey ../rootca/rootca.key -CAcreateserial \
-out trino.crt
openssl x509 -in trino.crt -noout -text | grep -A1 'Subject Alternative Name'
Root CA 키의 암호를 묻는다. SAN 에 적은 이름이 그대로 보이면 된다.
Trino 는 키와 인증서를 이어 붙인 PEM 을 그대로 읽는다. PKCS#12 로 바꿀 필요가 없다.
cat trino.key trino.crt > trino.pem
chmod 600 trino.pem
sudo install -o trino -g trino -m 600 trino.pem /opt/trino/etc/certs/trino.pem
config.properties
http-server.https.enabled=true
http-server.https.port=8443
http-server.https.keystore.path=etc/certs/trino.pem
Root CA 를 클라이언트 쪽에 넣어야 SSLVerification=FULL 로 붙는다.
# 자바 클라이언트 (DBeaver · JDBC)
keytool -importcert -alias example-rootca -file rootca.crt \
-keystore truststore.jks -storepass ${TRUSTSTORE_PASSWORD} -noprompt
# Trino CLI
trino --server https://trino.example.net:8443 --truststore-path truststore.jks --truststore-password ${TRUSTSTORE_PASSWORD}
같은 절차를 default_md = sha1 · Root CA 2048비트 · 서버 키에 암호를 걸었다가 openssl rsa 로 푸는 방식으로 했다. 지금은 위와 같이 처음부터 sha256 과 암호 없는 서버 키로 만든다.