AWS CloudHSM 클라이언트 SDK 3용 OpenSSL Dynamic Engine 설치 - AWS CloudHSM

AWS CloudHSM 클라이언트 SDK 3용 OpenSSL Dynamic Engine 설치

다음 단계에서는 클라이언트 SDK 3를 사용하는 OpenSSL용 AWS CloudHSM Dynamic Engine을 설치하고 구성하는 방법에 대해 설명합니다. 업그레이드에 대한 자세한 내용은 클라이언트 SDK 3 업그레이드을 참조하십시오.

OpenSSL 엔진을 설치 및 구성하려면
  1. 다음 명령을 사용하여 OpenSSL 엔진을 다운로드하고 설치합니다.

    Amazon Linux
    $ wget https://s3.amazonaws.com/cloudhsmv2-software/CloudHsmClient/EL6/cloudhsm-client-dyn-latest.el6.x86_64.rpm
    $ sudo yum install ./cloudhsm-client-dyn-latest.el6.x86_64.rpm
    Amazon Linux 2
    $ wget https://s3.amazonaws.com/cloudhsmv2-software/CloudHsmClient/EL7/cloudhsm-client-dyn-latest.el7.x86_64.rpm
    $ sudo yum install ./cloudhsm-client-dyn-latest.el7.x86_64.rpm
    CentOS 6
    $ wget https://s3.amazonaws.com/cloudhsmv2-software/CloudHsmClient/EL6/cloudhsm-client-dyn-latest.el6.x86_64.rpm
    $ sudo yum install ./cloudhsm-client-dyn-latest.el6.x86_64.rpm
    CentOS 7
    $ wget https://s3.amazonaws.com/cloudhsmv2-software/CloudHsmClient/EL7/cloudhsm-client-dyn-latest.el7.x86_64.rpm
    $ sudo yum install ./cloudhsm-client-dyn-latest.el7.x86_64.rpm
    RHEL 6
    $ wget https://s3.amazonaws.com/cloudhsmv2-software/CloudHsmClient/EL6/cloudhsm-client-dyn-latest.el6.x86_64.rpm
    $ sudo yum install ./cloudhsm-client-dyn-latest.el6.x86_64.rpm
    RHEL 7
    $ wget https://s3.amazonaws.com/cloudhsmv2-software/CloudHsmClient/EL7/cloudhsm-client-dyn-latest.el7.x86_64.rpm
    $ sudo yum install ./cloudhsm-client-dyn-latest.el7.x86_64.rpm
    Ubuntu 16.04 LTS
    $ wget https://s3.amazonaws.com/cloudhsmv2-software/CloudHsmClient/Xenial/cloudhsm-client-dyn_latest_amd64.deb
    $ sudo apt install ./cloudhsm-client-dyn_latest_amd64.deb

    /opt/cloudhsm/lib/libcloudhsm_openssl.so에 OpenSSL 엔진이 설치되어 있습니다.

  2. 다음 명령을 사용하여 CU(Crypto User)의 인증서가 포함된 n3fips_password라는 환경 변수를 설정합니다.

    $ export n3fips_password=<HSM user name>:<password>