설명
클라이언트 인증서는 내부 API나 B2B 연동에서 호출자 검증에 사용할 수 있습니다. 모든 앱에 필수인 것은 아니지만, 인증서 인증을 요구하는 서비스에서 요청하지 않거나 검증하지 않으면 의도한 보호가 빠집니다. App Service가 전달한 인증서의 유효성과 신뢰 여부는 애플리케이션에서 검증해야 합니다.
잠재적 영향
인증서의 제출과 신뢰 검증이 불완전하면, 허가받지 않은 호출자가 민감한 기능에 접근할 수 있습니다.
해결 방법
필요한 앱에서 클라이언트 인증서를 활성화하고 HTTPS와 Required 모드를 적용하세요. 예외 경로를 검토하고 앱에서 인증서 체인, 유효 기간과 허용된 신원을 검증하세요. HTTP/2나 TLS 1.3을 쓴다면 TLS 재협상을 요구하는 모드와 제외 경로를 사용하지 않도록 구성하세요.
예시
AzureRM 3.x의 기존 azurerm_app_service 예시입니다. 현재 리소스에서는 client_certificate_enabled와 client_certificate_mode를 사용하며, 인증서 검증 코드는 별도입니다.
변경 전
hcl
resource "azurerm_app_service" "example" {
name = "example-app-service"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
app_service_plan_id = azurerm_app_service_plan.example.id
}
변경 후
hcl
resource "azurerm_app_service" "example" {
name = "example-app-service"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
app_service_plan_id = azurerm_app_service_plan.example.id
client_cert_enabled = true
}
변경 후에는 클라이언트 인증서를 활성화합니다. 이 설정만으로 인증서의 발급자나 호출 권한까지 검증되는 것은 아닙니다.