<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
  <channel>
    <title>KENSEI IT BLOG</title>
    <link>https://kensei.tistory.com/</link>
    <description>겐세이 IT 블로그</description>
    <language>ko</language>
    <pubDate>Sun, 31 May 2026 14:18:22 +0900</pubDate>
    <generator>TISTORY</generator>
    <ttl>100</ttl>
    <managingEditor>CHOMAN</managingEditor>
    <item>
      <title>imgburn</title>
      <link>https://kensei.tistory.com/1229</link>
      <description>&lt;p&gt;&lt;figure class=&quot;fileblock&quot; data-ke-align=&quot;alignCenter&quot;&gt;&lt;a href=&quot;https://blog.kakaocdn.net/dn/de82aF/dJMcac9JNsH/1ULopn51J8LAB8yIjhobsk/SetupImgBurn_2.5.8.0.exe?attach=1&amp;amp;knm=tfile.exe&quot; class=&quot;&quot;&gt;
    &lt;div class=&quot;image&quot;&gt;&lt;/div&gt;
    &lt;div class=&quot;desc&quot;&gt;&lt;div class=&quot;filename&quot;&gt;&lt;span class=&quot;name&quot;&gt;SetupImgBurn_2.5.8.0.exe&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;size&quot;&gt;2.96MB&lt;/div&gt;
&lt;/div&gt;
  &lt;/a&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;</description>
      <author>CHOMAN</author>
      <guid isPermaLink="true">https://kensei.tistory.com/1229</guid>
      <comments>https://kensei.tistory.com/1229#entry1229comment</comments>
      <pubDate>Fri, 30 Jan 2026 17:57:54 +0900</pubDate>
    </item>
    <item>
      <title>nc 네트워크 파일복사</title>
      <link>https://kensei.tistory.com/1218</link>
      <description>&lt;h1&gt;scp rsync ftp 등을 이용하여 복사하기 어려울때&lt;/h1&gt;
&lt;h1&gt;보내는 서버&lt;/h1&gt;
&lt;pre class=&quot;nginx&quot;&gt;&lt;code&gt;nc 받는서버아이피 받는서버포트 &amp;lt; 파일명&lt;/code&gt;&lt;/pre&gt;
&lt;h1&gt;받는 서버&lt;/h1&gt;
&lt;pre class=&quot;nginx&quot;&gt;&lt;code&gt;nc -l -p 포트번호 &amp;gt; 파일명&lt;/code&gt;&lt;/pre&gt;
&lt;blockquote data-ke-style=&quot;style1&quot;&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;방화벽 확인, md5sum, sha2sum 등 파일 검증 필요함&lt;/p&gt;
&lt;/blockquote&gt;</description>
      <category>Linux</category>
      <category>NC</category>
      <category>파일복사</category>
      <author>CHOMAN</author>
      <guid isPermaLink="true">https://kensei.tistory.com/1218</guid>
      <comments>https://kensei.tistory.com/1218#entry1218comment</comments>
      <pubDate>Fri, 22 Aug 2025 17:24:20 +0900</pubDate>
    </item>
    <item>
      <title>윈도우 정품 인증 초기화</title>
      <link>https://kensei.tistory.com/1210</link>
      <description>&lt;h3&gt;cmd 관리자 권한으로 실행&lt;/h3&gt;
&lt;pre&gt;&lt;code&gt;slmgr.vbs -rearm&lt;/code&gt;&lt;/pre&gt;&lt;blockquote data-ke-style=&quot;style1&quot;&gt;&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&lt;p&gt;리부팅&lt;/p&gt;
&lt;/span&gt;&lt;/p&gt;&lt;/blockquote&gt;</description>
      <category>windows</category>
      <category>윈도우</category>
      <category>윈도우 정품 인증</category>
      <category>인증</category>
      <category>정품</category>
      <author>CHOMAN</author>
      <guid isPermaLink="true">https://kensei.tistory.com/1210</guid>
      <comments>https://kensei.tistory.com/1210#entry1210comment</comments>
      <pubDate>Wed, 7 May 2025 17:36:21 +0900</pubDate>
    </item>
    <item>
      <title>BPFDoorChecker (리눅스 백신)</title>
      <link>https://kensei.tistory.com/1209</link>
      <description>&lt;h1&gt;SKT 유심 정보 유출사건 관련 공격자가 사용한 악성코드라고 알려짐&lt;/h1&gt;
&lt;p&gt;BPFDoor&lt;/p&gt;
&lt;h1&gt;원본 및 자료출처 (INCA INTERNET)&lt;/h1&gt;
&lt;pre&gt;&lt;code&gt;https://tachyonlab.com/kr/popup/BPFDoorVaccine&lt;/code&gt;&lt;/pre&gt;&lt;blockquote data-ke-style=&quot;style1&quot;&gt;&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&lt;p&gt;BPFDoor 를 탐지하기 위한 전용 백신인듯 함&lt;/p&gt;
&lt;/span&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;h1&gt;리눅스에 설치&lt;/h1&gt;
&lt;pre&gt;&lt;code&gt;# yum install wget -y
# wget https://tachyonlab.com/exe/BPFDoorChecker
# chmod +x BPFDoorChecker
# ./BPFDoorChecker&lt;/code&gt;&lt;/pre&gt;&lt;h1&gt;검사해보기&lt;/h1&gt;
&lt;pre&gt;&lt;code&gt;./BPFDoorChecker : 프로세스와 기본 경로만 검사 (빠름)
./BPFDoorChecker --target_path=/ (오래걸림)
--disinfect= true : 자동치료 (프로세스를 죽일수 있다고 함, 주의해서 사용)&lt;/code&gt;&lt;/pre&gt;&lt;h1&gt;풀스캔&lt;/h1&gt;
&lt;pre&gt;&lt;code&gt;[root@localhost ~]# ./BPFDoorChecker --target_path=/
 _______         _
|__   __|       | |
   | | __ _  ___| |__  _   _  ___  _ __
   | |/ _` |/ __| &amp;#39;_ \| | | |/ _ \| &amp;#39;_ \
   | | (_| | (__| | | | |_| | (_) | | | |
__ |_|\__,_|\___|_| |_|\__, |\___/|_| |_|     _               _
|  _ \       / _|  | |  __/ |                | |             | |
| |_) |_ __ | |_ __| | |___/ ___  _ __    ___| |__   ___  ___| | _____ _ __
|  _ &amp;lt;| &amp;#39;_ \|  _/ _` |/ _ \ / _ \| &amp;#39;__|  / __| &amp;#39;_ \ / _ \/ __| |/ / _ \ &amp;#39;__|
| |_) | |_) | || (_| | (_) | (_) | |    | (__| | | |  __/ (__|   &amp;lt;  __/ |
|____/| .__/|_| \__,_|\___/ \___/|_|     \___|_| |_|\___|\___|_|\_\___|_|
      | |
      |_|

Version 1.0
Copyright (c) 2025-2026 by INCA Internet Co, Ltd.

Process Scan Started!
Process Scan End!
File Scan Started!
File Scan End!
===============================================================
+statistics+
-File : 0 / 144420
-Process : 0 / 110
===============================================================
[root@localhost ~]#&lt;/code&gt;&lt;/pre&gt;&lt;blockquote data-ke-style=&quot;style1&quot;&gt;&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&lt;p&gt;centos6 에서 풀스캔시 리부팅 되는 증상 발견&lt;/p&gt;
&lt;/span&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;h1&gt;OS 호환&lt;/h1&gt;
&lt;p&gt;아래 OS 에서 돌려봤다&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;Centos 6,7,8, rocky9 , debian&lt;/code&gt;&lt;/pre&gt;&lt;blockquote data-ke-style=&quot;style1&quot;&gt;&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&lt;p&gt;FREEBSD, redhat9 에서는 실행되지 않았음&lt;/p&gt;
&lt;/span&gt;&lt;/p&gt;&lt;/blockquote&gt;</description>
      <category>Security</category>
      <category>bpfdoor</category>
      <category>bpfdoorchecker</category>
      <category>SKT</category>
      <category>usim</category>
      <category>유심</category>
      <author>CHOMAN</author>
      <guid isPermaLink="true">https://kensei.tistory.com/1209</guid>
      <comments>https://kensei.tistory.com/1209#entry1209comment</comments>
      <pubDate>Fri, 2 May 2025 17:03:00 +0900</pubDate>
    </item>
    <item>
      <title>lvs ldirectord FTP 분배 설정</title>
      <link>https://kensei.tistory.com/1207</link>
      <description>&lt;p data-ke-size=&quot;size16&quot;&gt;LVS 는 CENTOS7, FTP 서버는 rocky9&lt;/p&gt;
&lt;h1&gt;/etc/ha.d/ldirectord.cf&lt;/h1&gt;
&lt;pre class=&quot;routeros&quot;&gt;&lt;code&gt;#  PASSIVE
virtual=12.34.56.165:21
    real=12.34.56.122:21 gate 20
    real=12.34.56.123:21 gate 20
    service=ftp
    scheduler=wlc
    netmask=255.255.255.255
    protocol=tcp
    checkport=21
    checktype=connect
    persistent=15&lt;/code&gt;&lt;/pre&gt;
&lt;blockquote data-ke-style=&quot;style1&quot;&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;연결 유지 설정 15초, persistent=15 FTP 연결의 문제가 있으면 초를 더 늘리거나 한다&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h1&gt;파일 전송 및 다운로드 가능하나 100%에서 세션이 멈춤&lt;/h1&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;firewalld logging&lt;/p&gt;
&lt;pre class=&quot;makefile&quot;&gt;&lt;code&gt;/etc/firewalld/firewalld.conf

# Default: off
#LogDenied=off
LogDenied=all&lt;/code&gt;&lt;/pre&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;/var/log/messages&lt;/p&gt;
&lt;pre class=&quot;angelscript&quot;&gt;&lt;code&gt;Apr 23 20:22:03 LVS1 kernel: STATE_INVALID_DROP: IN=em1 OUT= MAC=6c:3c:8c:7b:f0:a3:6c:3c:8c:7b:f0:03:08:00 SRC=12.34.56.210 DST=12.34.56.165 LEN=52 TOS=0x10 PREC=0x00 TTL=64 ID=14539 DF PROTO=TCP SPT=48602 DPT=21 WINDOW=251 RES=0x00 ACK FIN URGP=0
Apr 23 20:22:04 LVS1 kernel: STATE_INVALID_DROP: IN=em1 OUT= MAC=6c:3c:8c:7b:f0:a3:6c:3c:8c:7b:f0:03:08:00 SRC=12.34.56.210 DST=12.34.56.165 LEN=52 TOS=0x10 PREC=0x00 TTL=64 ID=14540 DF PROTO=TCP SPT=48602 DPT=21 WINDOW=251 RES=0x00 ACK FIN URGP=0
Apr 23 20:22:04 LVS1 kernel: STATE_INVALID_DROP: IN=em1 OUT= MAC=6c:3c:8c:7b:f0:a3:6c:3c:8c:7b:f0:03:08:00 SRC=12.34.56.210 DST=12.34.56.165 LEN=52 TOS=0x10 PREC=0x00 TTL=64 ID=14542 DF PROTO=TCP SPT=48602 DPT=21 WINDOW=251 RES=0x00 ACK FIN URGP=0
Apr 23 20:22:04 LVS1 kernel: STATE_INVALID_DROP: IN=em1 OUT= MAC=6c:3c:8c:7b:f0:a3:6c:3c:8c:7b:f0:03:08:00 SRC=12.34.56.210 DST=12.34.56.165 LEN=52 TOS=0x10 PREC=0x00 TTL=64 ID=14543 DF PROTO=TCP SPT=48602 DPT=21 WINDOW=251 RES=0x00 ACK FIN URGP=0
Apr 23 20:22:05 LVS1 kernel: STATE_INVALID_DROP: IN=em1 OUT= MAC=6c:3c:8c:7b:f0:a3:6c:3c:8c:7b:f0:03:08:00 SRC=12.34.56.210 DST=12.34.56.165 LEN=52 TOS=0x10 PREC=0x00 TTL=64 ID=14544 DF PROTO=TCP SPT=48602 DPT=21 WINDOW=251 RES=0x00 ACK FIN URGP=0
Apr 23 20:22:07 LVS1 kernel: STATE_INVALID_DROP: IN=em1 OUT= MAC=6c:3c:8c:7b:f0:a3:6c:3c:8c:7b:f0:03:08:00 SRC=12.34.56.210 DST=12.34.56.165 LEN=52 TOS=0x10 PREC=0x00 TTL=64 ID=14545 DF PROTO=TCP SPT=48602 DPT=21 WINDOW=251 RES=0x00 ACK FIN URGP=0
Apr 23 20:22:10 LVS1 kernel: STATE_INVALID_DROP: IN=em1 OUT= MAC=6c:3c:8c:7b:f0:a3:6c:3c:8c:7b:f0:03:08:00 SRC=12.34.56.210 DST=12.34.56.165 LEN=52 TOS=0x10 PREC=0x00 TTL=64 ID=14546 DF PROTO=TCP SPT=48602 DPT=21 WINDOW=251 RES=0x00 ACK FIN URGP=0
Apr 23 20:22:17 LVS1 kernel: STATE_INVALID_DROP: IN=em1 OUT= MAC=6c:3c:8c:7b:f0:a3:6c:3c:8c:7b:f0:03:08:00 SRC=12.34.56.210 DST=12.34.56.165 LEN=52 TOS=0x10 PREC=0x00 TTL=64 ID=14547 DF PROTO=TCP SPT=48602 DPT=21 WINDOW=251 RES=0x00 ACK FIN URGP=0
Apr 23 20:22:30 LVS1 kernel: STATE_INVALID_DROP: IN=em1 OUT= MAC=6c:3c:8c:7b:f0:a3:6c:3c:8c:7b:f0:03:08:00 SRC=12.34.56.210 DST=12.34.56.165 LEN=52 TOS=0x10 PREC=0x00 TTL=64 ID=14548 DF PROTO=TCP SPT=48602 DPT=21 WINDOW=251 RES=0x00 ACK FIN URGP=0
Apr 23 20:22:56 LVS1 kernel: STATE_INVALID_DROP: IN=em1 OUT= MAC=6c:3c:8c:7b:f0:a3:6c:3c:8c:7b:f0:03:08:00 SRC=12.34.56.210 DST=12.34.56.165 LEN=52 TOS=0x10 PREC=0x00 TTL=64 ID=14549 DF PROTO=TCP SPT=48602 DPT=21 WINDOW=251 RES=0x00 ACK FIN URGP=0&lt;/code&gt;&lt;/pre&gt;
&lt;h1&gt;해결책&lt;/h1&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;conntrack 모듈에서 STATE INVALID PACKET 으로 간주하여 패킷이 드롭됨&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;LVS firewalld 설정&lt;/p&gt;
&lt;pre class=&quot;routeros&quot;&gt;&lt;code&gt;firewall-cmd --permanent --direct --add-rule ipv4 filter INPUT 0 -p tcp --dport 30000:31000 -m conntrack --ctstate INVALID -j ACCEPT
firewall-cmd --reload&lt;/code&gt;&lt;/pre&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;각 FTP 서버 설정 vsftpd.conf&lt;/p&gt;
&lt;pre class=&quot;ini&quot;&gt;&lt;code&gt;pasv_enable=YES
pasv_min_port=30000
pasv_max_port=31000&lt;/code&gt;&lt;/pre&gt;</description>
      <category>Linux</category>
      <category>ftp</category>
      <category>ldirectord</category>
      <category>LVS</category>
      <category>Passive</category>
      <author>CHOMAN</author>
      <guid isPermaLink="true">https://kensei.tistory.com/1207</guid>
      <comments>https://kensei.tistory.com/1207#entry1207comment</comments>
      <pubDate>Fri, 25 Apr 2025 17:34:46 +0900</pubDate>
    </item>
    <item>
      <title>윈도우11 랜카드가 여러개인 경우 모두 활성화</title>
      <link>https://kensei.tistory.com/1177</link>
      <description>&lt;h1&gt;실행창 gpedit.msc 입력&lt;/h1&gt;
&lt;pre&gt;&lt;code&gt;컴퓨터 구성 - 관리 템플릿 - 네트워크 - Windows 연결 관리자 (이동)
인터넷 또는 Windows 도메인에 대한 동시 연결 수 최소화 (더블클릭)&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-ke-mobileStyle=&quot;widthOrigin&quot; data-origin-width=&quot;686&quot; data-origin-height=&quot;636&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/cJ6TR4/btsEBZVLHHX/Ko5kLK69z4aojyxO9uLVL1/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/cJ6TR4/btsEBZVLHHX/Ko5kLK69z4aojyxO9uLVL1/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/cJ6TR4/btsEBZVLHHX/Ko5kLK69z4aojyxO9uLVL1/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FcJ6TR4%2FbtsEBZVLHHX%2FKo5kLK69z4aojyxO9uLVL1%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot; loading=&quot;lazy&quot; width=&quot;686&quot; height=&quot;636&quot; data-origin-width=&quot;686&quot; data-origin-height=&quot;636&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;h1&gt;네트워크 인터페이스 아이피 주소를 수동으로 다 적용해야 함 (자동설정 X)&lt;/h1&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-ke-mobileStyle=&quot;widthOrigin&quot; data-origin-width=&quot;465&quot; data-origin-height=&quot;518&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/q7S1s/btsFfu7FeD0/4gGNKmQLOX8bFKVJsSXXx0/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/q7S1s/btsFfu7FeD0/4gGNKmQLOX8bFKVJsSXXx0/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/q7S1s/btsFfu7FeD0/4gGNKmQLOX8bFKVJsSXXx0/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2Fq7S1s%2FbtsFfu7FeD0%2F4gGNKmQLOX8bFKVJsSXXx0%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot; loading=&quot;lazy&quot; width=&quot;465&quot; height=&quot;518&quot; data-origin-width=&quot;465&quot; data-origin-height=&quot;518&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;h1&gt;게이트 웨이 자동메트릭 해제&lt;/h1&gt;
&lt;pre&gt;&lt;code&gt;그냥 놔두면 나중에 연결된 랜인터페이스가 기본 게이트웨이로 동작하게 됨

위의 화면에서 &amp;quot;고급&amp;quot; 을 클릭하여 메트릭 설정을 하면 된다
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-ke-mobileStyle=&quot;widthOrigin&quot; data-origin-width=&quot;465&quot; data-origin-height=&quot;555&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/BDvTf/btsEEJxnnK4/Wi0syueA95QLIZNUlc4Pyk/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/BDvTf/btsEEJxnnK4/Wi0syueA95QLIZNUlc4Pyk/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/BDvTf/btsEEJxnnK4/Wi0syueA95QLIZNUlc4Pyk/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FBDvTf%2FbtsEEJxnnK4%2FWi0syueA95QLIZNUlc4Pyk%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot; loading=&quot;lazy&quot; width=&quot;465&quot; height=&quot;555&quot; data-origin-width=&quot;465&quot; data-origin-height=&quot;555&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p&gt;자동 메트릭 해제후에 인터페이스 메트릭에 번호 입력 낮은 번호가 우선권을 가짐&lt;/p&gt;</description>
      <category>windows</category>
      <category>WIFI2개</category>
      <category>랜카드</category>
      <category>랜카드2개</category>
      <category>윈도우11</category>
      <author>CHOMAN</author>
      <guid isPermaLink="true">https://kensei.tistory.com/1177</guid>
      <comments>https://kensei.tistory.com/1177#entry1177comment</comments>
      <pubDate>Thu, 8 Feb 2024 14:15:31 +0900</pubDate>
    </item>
    <item>
      <title>ERR_SSL_PROTOCOL_ERROR</title>
      <link>https://kensei.tistory.com/1154</link>
      <description>&lt;h1&gt;원문사이트&lt;/h1&gt;
&lt;pre&gt;&lt;code&gt;https://serverfault.com/questions/1144894/https-compatibility-issue-with-chrome-116-117-err-ssl-protocol-error&lt;/code&gt;&lt;/pre&gt;&lt;h1&gt;브라우저 (chrome) 업데이트 이후 특정 사이트 접속시 발생 (ERR_SSL_PROTOCOL_ERROR)&lt;/h1&gt;
&lt;h1&gt;브라우저 관련 옵션 SSL HANDSHAKE 옵션 조정&lt;/h1&gt;
&lt;pre&gt;&lt;code&gt;chrome://flags/#use-sha1-server-handshakes&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-ke-mobileStyle=&quot;widthOrigin&quot; data-origin-width=&quot;1202&quot; data-origin-height=&quot;219&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/KLRAH/btsxh8kMIjk/rztaf2yNpw6Sl7nMk9Mh6k/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/KLRAH/btsxh8kMIjk/rztaf2yNpw6Sl7nMk9Mh6k/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/KLRAH/btsxh8kMIjk/rztaf2yNpw6Sl7nMk9Mh6k/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FKLRAH%2Fbtsxh8kMIjk%2Frztaf2yNpw6Sl7nMk9Mh6k%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot; loading=&quot;lazy&quot; width=&quot;1202&quot; height=&quot;219&quot; data-origin-width=&quot;1202&quot; data-origin-height=&quot;219&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;h1&gt;해당 웹서버 openssl 업데이트&lt;/h1&gt;
&lt;pre&gt;&lt;code&gt;yum update openssl&lt;/code&gt;&lt;/pre&gt;&lt;h1&gt;발생한 클라이언트 환경&lt;/h1&gt;
&lt;pre&gt;&lt;code&gt;윈도우10
크롬 버전 117.0.5938.150(공식 빌드) (64비트) 업데이트 직후&lt;/code&gt;&lt;/pre&gt;&lt;h1&gt;발생한 웹 서버 환경&lt;/h1&gt;
&lt;pre&gt;&lt;code&gt;CentOS release 6.4 (Final)
Linux RM.Dev 2.6.32-642.11.1.el6.x86_64 #1 SMP Fri Nov 18 19:25:05 UTC 2016 x86_64 x86_64 x86_64 GNU/Linux
openssl-devel-1.0.1e-16.el6_5.15.x86_64
openssl-1.0.1e-16.el6_5.15.x86_64&lt;/code&gt;&lt;/pre&gt;&lt;blockquote data-ke-style=&quot;style1&quot;&gt;&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&lt;p&gt;이번 경우는 웹서버의 openssl 업데이트 이후 해결되었음&lt;/p&gt;
&lt;/span&gt;&lt;/p&gt;&lt;/blockquote&gt;</description>
      <category>Linux</category>
      <category>ERR_SSL_PROTOCOL_ERROR</category>
      <author>CHOMAN</author>
      <guid isPermaLink="true">https://kensei.tistory.com/1154</guid>
      <comments>https://kensei.tistory.com/1154#entry1154comment</comments>
      <pubDate>Fri, 6 Oct 2023 13:38:21 +0900</pubDate>
    </item>
    <item>
      <title>virt-*tools</title>
      <link>https://kensei.tistory.com/1142</link>
      <description>&lt;h1&gt;virt-edit (파일수정)&lt;/h1&gt;
&lt;pre class=&quot;awk&quot;&gt;&lt;code&gt;virt-edit 파일이름.qcow2_bak /etc/sysconfig/network-scripts/ifcfg-eth0&lt;/code&gt;&lt;/pre&gt;
&lt;h1&gt;virt-df (남은 공간 확인)&lt;/h1&gt;
&lt;pre class=&quot;css&quot;&gt;&lt;code&gt;virt-df 파일이름.qcow2_bak&lt;/code&gt;&lt;/pre&gt;
&lt;h1&gt;virt-resize&lt;/h1&gt;
&lt;h1&gt;virt-sysprep for preparing an image for distribution (for example, delete SSH host keys, remove MAC address info, or remove user accounts).&lt;/h1&gt;
&lt;h1&gt;virt-sparsify for making an image sparse.&lt;/h1&gt;
&lt;h1&gt;virt-p2v for converting a physical machine to an image that runs on KVM.&lt;/h1&gt;
&lt;h1&gt;참고 링크&lt;/h1&gt;
&lt;pre class=&quot;awk&quot;&gt;&lt;code&gt;https://docs.openstack.org/image-guide/modify-images.html#mount-a-qcow2-image-without-lvm&lt;/code&gt;&lt;/pre&gt;</description>
      <category>VIRT</category>
      <category>virt-tools</category>
      <author>CHOMAN</author>
      <guid isPermaLink="true">https://kensei.tistory.com/1142</guid>
      <comments>https://kensei.tistory.com/1142#entry1142comment</comments>
      <pubDate>Tue, 7 Mar 2023 16:55:11 +0900</pubDate>
    </item>
    <item>
      <title>openssl</title>
      <link>https://kensei.tistory.com/1141</link>
      <description>&lt;h1&gt;openssl 에서는 공개키를 파일로 저장 or 읽을때 PEM (Privacy Enhanced Mail) 또는 DER (Distinguished Encoding Rules) 형식을 사용&lt;/h1&gt;
&lt;h1&gt;PEM&lt;/h1&gt;
&lt;pre&gt;&lt;code&gt;개인키 (RSA, DSA), 공개키 (RSA, DSA) 및 (X509) 인증서 포함가능
ascii 헤더로 묶인 데이터를 base64로 인코드 DER 형식으로 데이터 저장 (시스템간 텍스트모드 전송 적합)&lt;/code&gt;&lt;/pre&gt;&lt;h1&gt;DER&lt;/h1&gt;
&lt;pre&gt;&lt;code&gt;모든 개인키, 공개키 및 인증서 포항가능
대부분 브라우저에서 기본형식 
ASN1 DER 형식에 따라 저장, 헤더 없음 &lt;/code&gt;&lt;/pre&gt;&lt;h1&gt;PKCS#12&lt;/h1&gt;
&lt;pre&gt;&lt;code&gt;모든 개인키, 공개키, 인증서 포함가능
바이너리 형식으로 저장 PFX 파일이라고도 함&lt;/code&gt;&lt;/pre&gt;&lt;h1&gt;ssl 생성 방법 (서버)&lt;/h1&gt;
&lt;pre&gt;&lt;code&gt;랜덤넘버생성

openssl md5 * &amp;gt; rand.dat

키쌍 생성

openssl genrsa -rand rand.dat -des3 1024 &amp;gt; key.pem

생성된 키쌍을 이용하여 CSR 생성

openssl req -new -key key.pem &amp;gt; csr.pem
(Enter PEM pass phrase : key 비밀번호설정)

CSR 확인

openssl req -new -key key.pem &amp;gt; cer.pem

임시 crt 생성

openssl req -x509 -days 365 -key /usr/local/apache/conf/ssl/key1.pem -in /usr/local/apache/conf/ssl/csr1.pem
&amp;gt; /usr/local/apache/conf/ssl/crt1.pem&lt;/code&gt;&lt;/pre&gt;&lt;h1&gt;키 포맷 변경&lt;/h1&gt;
&lt;pre&gt;&lt;code&gt;CRT → DER 변경
openssl x509 -in 도메인.co.kr.crt -out 도메인.co.kr.der -outform DER

DER → PEM 변경
openssl x509 -in 도메인.co.kr.der -inform DER -out 도메인.co.kr.pem -outform PEM&lt;/code&gt;&lt;/pre&gt;&lt;h1&gt;인증서 확인&lt;/h1&gt;
&lt;pre&gt;&lt;code&gt;openssl x509 -noout -text -in 도메인.co.kr.crt (PEM 포맷)
openssl x509 -noout -inform DER -text -in 도메인.co.kr.crt (DER 포맷)&lt;/code&gt;&lt;/pre&gt;&lt;h1&gt;개인키 (비밀키) 보기&lt;/h1&gt;
&lt;pre&gt;&lt;code&gt;openssl rsa -noout -text -in 도메인.co.kr.key
openssl x509 -in 도메인_co_kr_crt.pem -noout -text&lt;/code&gt;&lt;/pre&gt;&lt;blockquote data-ke-style=&quot;style1&quot;&gt;&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&lt;p&gt;패스워드가 걸려져 있으면 패스워드를 물어봄&lt;/p&gt;
&lt;/span&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;h1&gt;개인키 (비밀키) 패스워드 삭제&lt;/h1&gt;
&lt;pre&gt;&lt;code&gt;openssl rsa -in proxykey.pem -out proxykey1.pem
openssl rsa -in Private.key -out PrivateKey_nopass.key

Enter pass phrase for proxykey.pem: (패스워드 정확히 입력)
writing RSA key&lt;/code&gt;&lt;/pre&gt;</description>
      <category>openssl</category>
      <author>CHOMAN</author>
      <guid isPermaLink="true">https://kensei.tistory.com/1141</guid>
      <comments>https://kensei.tistory.com/1141#entry1141comment</comments>
      <pubDate>Tue, 7 Mar 2023 15:28:41 +0900</pubDate>
    </item>
    <item>
      <title>guestfish</title>
      <link>https://kensei.tistory.com/1140</link>
      <description>&lt;h1&gt;실행&lt;/h1&gt;
&lt;pre&gt;&lt;code&gt;guestfish --rw -a 도메인.qcow2&lt;/code&gt;&lt;/pre&gt;&lt;pre&gt;&lt;code&gt;&amp;gt;&amp;lt;fs&amp;gt; run
&amp;gt;&amp;lt;fs&amp;gt; mount /dev/sda3 /
&amp;gt;&amp;lt;fs&amp;gt; ls /
bin
boot
dev
etc
home
lib
lib64
media
mnt
opt
proc
root
run
sbin
srv
sys
tmp
usr
var

&amp;gt;&amp;lt;fs&amp;gt; vi /etc/rc.d/rc.local
&amp;gt;&amp;lt;fs&amp;gt; quit&lt;/code&gt;&lt;/pre&gt;&lt;blockquote data-ke-style=&quot;style1&quot;&gt;&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;span style=&quot;font-family: 'Noto Serif KR';&quot;&gt;&lt;p&gt;단일성으로 간단하게 이미지 파일 내용 수정할때 이용하는듯 함&lt;br&gt;가상머신이 active 상태에서는 수정되지 않음&lt;/p&gt;
&lt;/span&gt;&lt;/p&gt;&lt;/blockquote&gt;</description>
      <category>Cloud</category>
      <category>guestfish</category>
      <author>CHOMAN</author>
      <guid isPermaLink="true">https://kensei.tistory.com/1140</guid>
      <comments>https://kensei.tistory.com/1140#entry1140comment</comments>
      <pubDate>Mon, 6 Mar 2023 16:08:44 +0900</pubDate>
    </item>
  </channel>
</rss>