ÃֽŠ°Ô½Ã±Û(OS/WAS)
2020.04.23 / 14:53

aws¿¡¼­ ¶Ç´Â ¿ìºÐÅõ ubuntoo tomcat ¼­¹ö ½ÃÀÛ ½Ã°£ÀÌ ³Ê¹« ´À¸®´Ù¸é...

Äڷγª
Ãßõ ¼ö 212

¾î´À ¼ø°£ºÎÅÍÀÎÁö ¸ð¸£°Ú´Ù. óÀ½¿¡´Â ¹Ù·Î ¹Ù·Î ½ÃÀÛÇÏ´ø tomcat ¼­¹ö°¡ ¾î´À ¼ø°£ºÎÅÍ °©Àڱ⠴À·ÁÁ³´Ù. µµÀúÈ÷ ¿øÀÎÀ» ãÀ» ¼ö ¾ø¾ú´Âµ¥ ÀÌ·¯ Àú¸® ã´Ù°¡ ÇØ°á¹æ¹ýÀ» ã¾Ò´Ù.

¿ìºÐÅõÀÇ °æ¿ì

sudo apt-get install haveged

À§¿Í °°ÀÌ haveged¸¦ ¼³Ä¡ÇÑ ÈÄ ½ÃÀÛÇÏ´Ï Á¤¸» »¡¶óÁ³´Ù. ±× µ¿¾È ¸Å¹ø ½ÃÀÛÇÏ°í Å×½ºÆ®ÇÒ ¶§¸¶´Ù Á¤¸» Â¥Áõ³µ´Âµ¥...

ÇØ°á ¹æ¹ýÀº Fresh Tomcat takes loong time to start up ¿¡¼­ ã¾Ò´Ù.

Á¤È®ÇÑ ¿øÀÎÀº entropy poolÀ̶ó´Â ³ð°ú °ü·ÃÀÌ ÀÖ´Â µí Çѵ¥ ¿î¿µÃ¼Á¦¿¡ ´ëÇÑ Áö½ÄÀÌ ±íÁö ¾Ê¾Æ entropy poolÀÌ ¹«¾ùÀ» ÇÏ´Â ³ðÀÎÁö Àß ¸ð¸£°Ú´Ù.


¾ó¸¶ Àü °­ÀÇ Áß¿¡ ´Ù¸¥ °³¹ßÀÚÀÇ µµ¿òÀ» ¹Þ¾Æ ´Ù¸¥ ÇØ°á ¹æ¹ýÀ» ã¾Ò³×¿ä. ¾Æ¸¶µµ ÀÌ ¹æ¹ýÀÌ ¸ðµç ¹æ¹ýÀÇ ÇØ°áÃ¥À¸·Î º¸¿©Áý´Ï´Ù.

tomcat ±¸µ¿ ½Ã /dev/random ºí·ÎÅ· À̽´ ¹®¼­ Âü°íÇØ º¸¸é ¿øÀÎ, ÇØ°áÃ¥ÀÌ ³ª¿À³×¿ä.

ÇØ°áÃ¥¸¸ °øÀ¯ÇÏ¸é ´ÙÀ½°ú °°¾Æ¿ä. tomcat ¼­¹ö ½ÃÀÛÇÒ ¶§ ´ÙÀ½°ú °°ÀÌ ¼³Á¤ Ãß°¡ÇÏ¸é µË´Ï´Ù.

JAVA_OPTS="$JAVA_OPTS -Djava.security.egd=file:/dev/./urandom"

À§ ¼³Á¤µµ entropy pool°ú °ü·ÃÇÑ ¼³Á¤À̱º¿ä.



¶ÇÇϳªÀÇ ¹æ¹ýÀº java.security ÆÄÀÏ¿¡ ¾Æ·¡¿Í °°ÀÌ À̸¦ ¸í½ÃÇÏ´Â °ÍÀÔ´Ï´Ù. (ȸ»ç¿¡¼­´Â ÀÌ ¹æ¹ýÀ» ÁÖ·Î ¾²°í ÀÖ¾î¿ä)

securerandom.source=file:/dev/./urandom

java.security ÆÄÀÏÀÇ À§Ä¡´Â

  • JDK 8 ÀÌÇÏ : {JAVA_HOME}/jre/lib/security/java.security
  • JDK 9 ÀÌ»ó : {JAVA_HOME}/conf/security/java.security

TomcatÃֽŠ¹öÀü¿¡¼­´Â ÇØ´ç ¿É¼ÇÀÌ ¾ø¾îµµ µÈ´Ù´Âµ¥ ¾ÆÁ÷ Á¤È®È÷ ¾î´À ¹öÀüºÎÅÍÀÎÁö´Â ãÁö´Â ¸øÇß¾î¿ä.

( https://spring.io/guides/gs/spring-boot-docker/ ¿¡¼­

To reduce Tomcat startup time we added a system property pointing to "/dev/urandom" as a source of entropy. This is not necessary with more recent versions of Spring Boot, if you use the "standard" version of Tomcat (or any other web server). )