๋ฌธ์„œ ๋ฉ”๋‰ด
๋ฌธ์„œ ํ™ˆ
/
MongoDB ๋งค๋‰ด์–ผ
/ / /

X.509 ํด๋Ÿฌ์Šคํ„ฐ ์ธ์ฆ์„œ ํšŒ์ „

์ด ํŽ˜์ด์ง€์˜ ๋‚ด์šฉ

  • ์ด ์ž‘์—…์— ๊ด€ํ•œ ์ •๋ณด
  • ๋‹จ๊ณ„
  • ์ž์„ธํžˆ ์•Œ์•„๋ณด๊ธฐ

๋ฒ„์ „ 7.0์— ์ถ”๊ฐ€.

ํด๋Ÿฌ์Šคํ„ฐ ๊ตฌ์„ฑ์›์€ ๊ตฌ์„ฑ์› ์ธ์ฆ ์— X.509 ์ธ์ฆ์„œ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋™์ผํ•œ ๋ฐฐํฌ์— ์žˆ๋Š” ๋‹ค๋ฅธ ์„œ๋ฒ„๋ฅผ ์‹๋ณ„ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

์„œ๋ฒ„๋Š” ์—ฐ๊ฒฐ ์š”์ฒญ์„ ์ˆ˜์‹ ํ•˜๋ฉด ์ธ์ฆ์„œ์˜ ๊ณ ์œ  ์ด๋ฆ„(DN) ๊ฐ’ ๋˜๋Š” ํ™•์žฅ ๊ฐ’ ๋ฌธ์ž์—ด์„ clusterAuthX509 ์„ค์ • ๋ฐ tlsClusterAuthX509Override ๋งค๊ฐœ๋ณ€์ˆ˜์˜ ๊ตฌ์„ฑ๋œ ๊ฐ’๊ณผ ๋น„๊ตํ•ฉ๋‹ˆ๋‹ค. ๊ฐ’์ด ์ผ์น˜ํ•˜๋ฉด ์—ฐ๊ฒฐ์„ cluster ๋ฉค๋ฒ„๋กœ ์ทจ๊ธ‰ํ•ฉ๋‹ˆ๋‹ค.

์ƒˆ ์ธ์ฆ์„œ๋ฅผ ์ฑ„ํƒํ•˜๋Š” cluster๋Š” tlsClusterAuthX509Override ๋งค๊ฐœ ๋ณ€์ˆ˜๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์ธ์ฆ์„œ ์ˆœํ™˜ ์ ˆ์ฐจ ์ค‘์— ๋‹ค๋ฅธ DN ์†์„ฑ์„ ๊ฐ€์ง„ X.509 ์ธ์ฆ์„œ๋ฅผ ์ˆ˜๋ฝํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๋ชจ๋“  ๊ตฌ์„ฑ์›์ด ์ƒˆ ๊ฐ’์œผ๋กœ ์ธ์ฆ์„œ๋ฅผ ์‚ฌ์šฉํ•˜๋ฉด ์žฌ์ •์˜๋ฅผ ์ œ๊ฑฐํ•˜์—ฌ ์ด์ œ ์˜ค๋ž˜๋œ ์ธ์ฆ์„œ ๊ฑฐ๋ถ€๋ฅผ ์‹œ์ž‘ํ•ฉ๋‹ˆ๋‹ค.

์ฐธ๊ณ 

net.tls.clusterAuthX509 ์„ค์ •์„ ์‚ฌ์šฉํ•˜์ง€ ์•Š๊ณ  ์—…๋ฐ์ดํŠธ ํ›„ ์‚ฌ์šฉํ•˜์ง€ ์•Š๋Š” ํด๋Ÿฌ์Šคํ„ฐ์—์„œ ์ธ์ฆ์„œ๋ฅผ ์ˆœํ™˜ํ•˜๊ธฐ ์œ„ํ•ด ๋กค๋ง ์—…๋ฐ์ดํŠธ๋ฅผ ์ˆ˜ํ–‰ํ•˜๋ ค๋ฉด ์ƒˆ DN์ด ํฌํ•จ๋œ x.509 ํด๋Ÿฌ์Šคํ„ฐ ์ธ์ฆ์„œ์˜ ๋กค๋ง ์—…๋ฐ์ดํŠธ๋ฅผ ์ฐธ์กฐํ•˜์„ธ์š”.

ํšŒ์› ์ธ์ฆ์„œ( clusterFile ๋ฐ certificateKeyFile ์„ค์ •์„ ์‚ฌ์šฉํ•˜์—ฌ ์„ค์ •)์— 10gen ์กฐ์ง ๋ฐ 10gen Server ์กฐ์ง ๋‹จ์œ„( attributes ์„ค์ •์„ ์‚ฌ์šฉํ•˜์—ฌ ์„ค์ •)๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ๊ณ ์œ  ์ด๋ฆ„(DN) ๊ฐ’์ด ์žˆ๋Š” ๋ณต์ œ๋ณธ ์„ธํŠธ๋ฅผ ์ƒ๊ฐํ•ด ๋ณด์„ธ์š”.

security:
clusterAuthMode: x509
net:
tls:
mode: requireTLS
certificateKeyFile: /etc/mycerts/10gen-server1.pem
CAFile: /etc/mycerts/ca.pem
clusterFile: /etc/mycerts/10gen-cluster1.pem
clusterCAFile: /etc/mycerts/ca.pem
clusterAuthX509:
attributes: O=10gen, OU=10gen Server

์ด ํŠœํ† ๋ฆฌ์–ผ์—์„œ๋Š” ์ƒˆ X.509 ์ธ์ฆ์„œ๊ฐ€ ๋ฉค๋ฒ„์‹ญ ์ธ์ฆ์„œ ๋ฐ ๊ธฐํƒ€ ๋ชจ๋“  ์š”๊ตฌ ์‚ฌํ•ญ์„ ์ถฉ์กฑํ•˜๊ณ  ํด๋Ÿฌ์Šคํ„ฐ ๊ตฌ์„ฑ์ด ๊ณ ์œ  ์ด๋ฆ„(DN) ๊ฐ’์„ ์‚ฌ์šฉํ•˜์—ฌ ํ”ผ์–ด ์ธ์ฆ์„œ๋ฅผ ์‹๋ณ„ํ•œ๋‹ค๊ณ  ๊ฐ€์ •ํ•ฉ๋‹ˆ๋‹ค.

์ž์„ธํ•œ ๋‚ด์šฉ์€ ํšŒ์› ์ธ์ฆ์„œ ์š”๊ตฌ ์‚ฌํ•ญ์„ ์ฐธ์กฐํ•˜์„ธ์š”.

์ด ๋‹จ๊ณ„์—์„œ๋Š” attributes ์„ค์ •์œผ๋กœ ๊ตฌ์„ฑ๋œ cluster์—์„œ ์ƒˆ X.509 ์ธ์ฆ์„œ๋ฅผ ์‚ฌ์šฉํ•˜๋„๋ก ๋ฉค๋ฒ„ ์ธ์ฆ์„œ๋ฅผ ์—…๋ฐ์ดํŠธํ•ฉ๋‹ˆ๋‹ค.

์ƒˆ ์ธ์ฆ์„œ์—๋Š” ์กฐ์ง(O) ์†์„ฑ์„ 10gen ์—์„œ MongoDB ๋กœ, ์กฐ์ง ๋‹จ์œ„(OU) ์†์„ฑ์„ 10gen Server ์—์„œ MongoDB Server ๋กœ ๋ณ€๊ฒฝํ•˜๋Š” ๊ณ ์œ  ์ด๋ฆ„(DN)์ด ์žˆ์Šต๋‹ˆ๋‹ค.

1

๊ฐ ์„œ๋ฒ„์˜ ๊ตฌ์„ฑ ํŒŒ์ผ์„ ์—…๋ฐ์ดํŠธํ•ฉ๋‹ˆ๋‹ค.

  • ์ƒˆ ์ธ์ฆ์„œ์˜ ๊ฐ’์„ ์‚ฌ์šฉํ•˜๋„๋ก attributes ์„ค์ •์„ ๋ณ€๊ฒฝํ•ฉ๋‹ˆ๋‹ค.

  • ์ด์ „ ์ธ์ฆ์„œ์˜ ๊ณ ์œ  ์ด๋ฆ„ ์†์„ฑ์„ ์‚ฌ์šฉํ•˜๋ ค๋ฉด tlsClusterAuthX509Override ๋งค๊ฐœ๋ณ€์ˆ˜๋ฅผ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค.

์˜ˆ๋ฅผ ๋“ค๋ฉด ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

net:
tls:
mode: requireTLS
certificateKeyFile: /etc/mycerts/mongodb-server1.pem
CAFile: /etc/mycerts/ca.pem
clusterFile: /etc/mycerts/mongodb-cluster1.pem
clusterCAFile: /etc/mycerts/ca.pem
clusterAuthX509:
attributes: O=MongoDB, OU=MongoDB Server
security:
clusterAuthMode: x509
setParameter:
tlsClusterAuthX509Override: { attributes: O=10gen, OU=10gen Server }
2

๊ฐ ์„ธ์ปจ๋”๋ฆฌ cluster ๋ฉค๋ฒ„๋ฅผ ๋‹ค์‹œ ์‹œ์ž‘ํ•ฉ๋‹ˆ๋‹ค:

  1. mongosh ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๊ฐ ์„ธ์ปจ๋”๋ฆฌ ํด๋Ÿฌ์Šคํ„ฐ ๋ฉค๋ฒ„์— ์—ฐ๊ฒฐํ•œ ๋‹ค์Œ, db.shutdownServer() ๋ฉ”์„œ๋“œ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์„œ๋ฒ„๋ฅผ ์ค‘์ง€ํ•ฉ๋‹ˆ๋‹ค.

    use admin
    db.shutdownServer()
  2. ์„œ๋ฒ„๋ฅผ ๋‹ค์‹œ ์‹œ์ž‘ํ•ฉ๋‹ˆ๋‹ค.

  3. rs.status() ๋ฉ”์„œ๋“œ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋ฉค๋ฒ„ ์ƒํƒœ๋ฅผ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.

    rs.status().members
  4. ์ด ๋ฉค๋ฒ„์˜ stateStr ํ•„๋“œ์— SECONDARY ๊ฐ’์ด ํ‘œ์‹œ๋  ๋•Œ๊นŒ์ง€ ๊ธฐ๋‹ค๋ ธ๋‹ค๊ฐ€ ๋‹ค์Œ ์„ธ์ปจ๋”๋ฆฌ๋ฅผ ๋‹ค์‹œ ์‹œ์ž‘ํ•˜์„ธ์š”.

์ด์ œ ๋ณต์ œ๋ณธ ์„ธํŠธ์˜ ์„ธ์ปจ๋”๋ฆฌ ์„œ๋ฒ„๊ฐ€ ์ƒˆ DN ์†์„ฑ์ด ์žˆ๋Š” ์ธ์ฆ์„œ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๊ตฌ์„ฑ์›์˜ ํ”ผ์–ด ์—ฐ๊ฒฐ์„ ํ—ˆ์šฉํ•ฉ๋‹ˆ๋‹ค.

3

ํ”„๋ผ์ด๋จธ๋ฆฌ ๋ฉค๋ฒ„๋ฅผ ๋‹ค์‹œ ์‹œ์ž‘ํ•ฉ๋‹ˆ๋‹ค.

  1. mongosh ์„ ์‚ฌ์šฉํ•˜์—ฌ ํ”„๋ผ์ด๋จธ๋ฆฌ์— ์—ฐ๊ฒฐํ•œ ๋‹ค์Œ rs.stepDown() ๋ฉ”์„œ๋“œ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋ฉค๋ฒ„๋ฅผ ํ”„๋ผ์ด๋จธ๋ฆฌ๋กœ ๊ฐ•๋“ฑํ•ฉ๋‹ˆ๋‹ค.

    rs.stepDown()

    cluster๋Š” ์ƒˆ ์ธ์ฆ์„œ๋กœ ๋ณด์กฐ ์ธ์ฆ์„œ๋ฅผ ์ƒˆ ํ”„๋ผ์ด๋จธ๋ฆฌ ์—ญํ• ์„ ํ•˜๋„๋ก ์Šน๊ฒฉํ•ฉ๋‹ˆ๋‹ค.

  2. db.shutdownServer() ๋ฉ”์„œ๋“œ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์„œ๋ฒ„๋ฅผ ์ข…๋ฃŒํ•ฉ๋‹ˆ๋‹ค:

    use admin
    db.shutdownServer()
  3. ์„œ๋ฒ„๋ฅผ ๋‹ค์‹œ ์‹œ์ž‘ํ•ฉ๋‹ˆ๋‹ค.

๋ณต์ œ๋ณธ ์„ธํŠธ์˜ ํ”„๋ผ์ด๋จธ๋ฆฌ ์„œ๋ฒ„๋Š” ๊ฐ•๋“ฑ๋˜๊ณ  ์ด์ œ ์ƒˆ DN ์†์„ฑ์ด ์žˆ๋Š” ์ธ์ฆ์„œ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๊ตฌ์„ฑ์›์˜ Peering ์—ฐ๊ฒฐ์„ ํ—ˆ์šฉํ•˜๋Š” ์„ธ์ปจ๋”๋ฆฌ ์„œ๋ฒ„๋กœ ๋‹ค์‹œ ์‹œ์ž‘๋ฉ๋‹ˆ๋‹ค.

4

๊ฐ ์„œ๋ฒ„์˜ ๊ตฌ์„ฑ ํŒŒ์ผ์„ ์—…๋ฐ์ดํŠธํ•ฉ๋‹ˆ๋‹ค.

  • ์ƒˆ ์ธ์ฆ์„œ๋ฅผ ์‚ฌ์šฉํ•˜๋„๋ก net.tls.certificateKeyFile ์„ค์ •์„ ๋ณ€๊ฒฝํ•ฉ๋‹ˆ๋‹ค.

  • ์ƒˆ ์ธ์ฆ์„œ๋ฅผ ์‚ฌ์šฉํ•˜๋„๋ก net.tls.clusterFile ์„ค์ •์„ ๋ณ€๊ฒฝํ•ฉ๋‹ˆ๋‹ค.

์˜ˆ๋ฅผ ๋“ค๋ฉด ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

net:
tls:
mode: requireTLS
certificateKeyFile: /etc/mycerts/mongodb-server2.pem
CAFile: /etc/mycerts/ca.pem
clusterFile: /etc/mycerts/mongodb-cluster2.pem
clusterCAFile: /etc/mycerts/ca.pem
clusterAuthX509:
attributes: O=MongoDB, OU=MongoDB Server
security:
clusterAuthMode: x509
setParameter:
tlsClusterAuthX509Override: { attributes: O=10gen, OU=10gen Server }
5

๊ฐ ์„ธ์ปจ๋”๋ฆฌ cluster ๋ฉค๋ฒ„๋ฅผ ๋‹ค์‹œ ์‹œ์ž‘ํ•ฉ๋‹ˆ๋‹ค:

  1. mongosh ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๊ฐ ์„ธ์ปจ๋”๋ฆฌ ํด๋Ÿฌ์Šคํ„ฐ ๋ฉค๋ฒ„์— ์—ฐ๊ฒฐํ•œ ๋‹ค์Œ, db.shutdownServer() ๋ฉ”์„œ๋“œ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์„œ๋ฒ„๋ฅผ ์ค‘์ง€ํ•ฉ๋‹ˆ๋‹ค.

    use admin
    db.shutdownServer()
  2. ์„œ๋ฒ„๋ฅผ ๋‹ค์‹œ ์‹œ์ž‘ํ•ฉ๋‹ˆ๋‹ค.

  3. rs.status() ๋ฉ”์„œ๋“œ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋ฉค๋ฒ„ ์ƒํƒœ๋ฅผ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.

    rs.status().members
  4. ์ด ๋ฉค๋ฒ„์˜ stateStr ํ•„๋“œ์— SECONDARY ๊ฐ’์ด ํ‘œ์‹œ๋  ๋•Œ๊นŒ์ง€ ๊ธฐ๋‹ค๋ ธ๋‹ค๊ฐ€ ๋‹ค์Œ ์„ธ์ปจ๋”๋ฆฌ๋ฅผ ๋‹ค์‹œ ์‹œ์ž‘ํ•˜์„ธ์š”.

์ด์ œ ๋ณต์ œ๋ณธ ์„ธํŠธ์˜ ์„ธ์ปจ๋”๋ฆฌ ์„œ๋ฒ„๊ฐ€ ์ƒˆ๋กœ์šด X.509 ์ธ์ฆ์„œ๋ฅผ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค.

6

ํ”„๋ผ์ด๋จธ๋ฆฌ ๋ฉค๋ฒ„๋ฅผ ๋‹ค์‹œ ์‹œ์ž‘ํ•ฉ๋‹ˆ๋‹ค.

  1. mongosh ์„ ์‚ฌ์šฉํ•˜์—ฌ ํ”„๋ผ์ด๋จธ๋ฆฌ์— ์—ฐ๊ฒฐํ•œ ๋‹ค์Œ rs.stepDown() ๋ฉ”์„œ๋“œ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋ฉค๋ฒ„๋ฅผ ํ”„๋ผ์ด๋จธ๋ฆฌ๋กœ ๊ฐ•๋“ฑํ•ฉ๋‹ˆ๋‹ค.

    rs.stepDown()

    cluster๋Š” ์ƒˆ ์ธ์ฆ์„œ๋กœ ๋ณด์กฐ ์ธ์ฆ์„œ๋ฅผ ์ƒˆ ํ”„๋ผ์ด๋จธ๋ฆฌ ์—ญํ• ์„ ํ•˜๋„๋ก ์Šน๊ฒฉํ•ฉ๋‹ˆ๋‹ค.

  2. db.shutdownServer() ๋ฉ”์„œ๋“œ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์„œ๋ฒ„๋ฅผ ์ข…๋ฃŒํ•ฉ๋‹ˆ๋‹ค:

    use admin
    db.shutdownServer()
  3. ์„œ๋ฒ„๋ฅผ ๋‹ค์‹œ ์‹œ์ž‘ํ•ฉ๋‹ˆ๋‹ค.

๋ณต์ œ๋ณธ ์„ธํŠธ์˜ ํ”„๋ผ์ด๋จธ๋ฆฌ ์„œ๋ฒ„๋Š” ๊ฐ•๋“ฑ๋˜๊ณ  ์ƒˆ X.509 ์ธ์ฆ์„œ๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ์„ธ์ปจ๋”๋ฆฌ ์„œ๋ฒ„๋กœ ๋‹ค์‹œ ์‹œ์ž‘๋ฉ๋‹ˆ๋‹ค.

7

์ด์ œ cluster์˜ ๋ชจ๋“  ๋ฉค๋ฒ„๊ฐ€ ์ƒˆ X.509 ์ธ์ฆ์„œ๋ฅผ ์‚ฌ์šฉํ•˜๋ฏ€๋กœ ๊ตฌ์„ฑ setParameter tlsClusterAuthX509Override ํŒŒ์ผ์„ ์—…๋ฐ์ดํŠธํ•˜์—ฌ ๋งค๊ฐœ ๋ณ€์ˆ˜์— ๋Œ€ํ•œ ์„ค์ •์„ ์ œ๊ฑฐํ•ฉ๋‹ˆ๋‹ค.

์˜ˆ๋ฅผ ๋“ค๋ฉด ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

net:
tls:
mode: requireTLS
certificateKeyFile: /etc/mycerts/mongodb-server1.pem
CAFile: /etc/mycerts/ca.pem
clusterFile: /etc/mycerts/mongodb-cluster1.pem
clusterCAFile: /etc/mycerts/ca.pem
clusterAuthX509:
attributes: O=MongoDB, OU=MongoDB Server
security:
clusterAuthMode: x509

์ด๋ ‡๊ฒŒ ํ•˜๋ฉด ์„œ๋ฒ„๊ฐ€ ์‹œ์ž‘ ์‹œ ์ด์ „ ์ธ์ฆ์„œ ์„ค์ •์„ ๊ตฌ์„ฑํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

8

๊ฐ ์„ธ์ปจ๋”๋ฆฌ cluster ๋ฉค๋ฒ„๋ฅผ ๋‹ค์‹œ ์‹œ์ž‘ํ•ฉ๋‹ˆ๋‹ค:

  1. mongosh ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๊ฐ ์„ธ์ปจ๋”๋ฆฌ ํด๋Ÿฌ์Šคํ„ฐ ๋ฉค๋ฒ„์— ์—ฐ๊ฒฐํ•œ ๋‹ค์Œ, db.shutdownServer() ๋ฉ”์„œ๋“œ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์„œ๋ฒ„๋ฅผ ์ค‘์ง€ํ•ฉ๋‹ˆ๋‹ค.

    use admin
    db.shutdownServer()
  2. ์„œ๋ฒ„๋ฅผ ๋‹ค์‹œ ์‹œ์ž‘ํ•ฉ๋‹ˆ๋‹ค.

  3. rs.status() ๋ฉ”์„œ๋“œ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋ฉค๋ฒ„ ์ƒํƒœ๋ฅผ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.

    rs.status().members
  4. ์ด ๋ฉค๋ฒ„์˜ stateStr ํ•„๋“œ์— SECONDARY ๊ฐ’์ด ํ‘œ์‹œ๋  ๋•Œ๊นŒ์ง€ ๊ธฐ๋‹ค๋ ธ๋‹ค๊ฐ€ ๋‹ค์Œ ์„ธ์ปจ๋”๋ฆฌ๋ฅผ ๋‹ค์‹œ ์‹œ์ž‘ํ•˜์„ธ์š”.

๋ณต์ œ๋ณธ ์„ธํŠธ์˜ ์„ธ์ปจ๋”๋ฆฌ ์„œ๋ฒ„๊ฐ€ ๋‹ค์‹œ ์‹œ์ž‘๋˜๊ณ  ๋” ์ด์ƒ ์ด์ „ X.509 ์ธ์ฆ์„œ์—์„œ์˜ ์—ฐ๊ฒฐ์„ ํ—ˆ์šฉํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

9

ํ”„๋ผ์ด๋จธ๋ฆฌ ๋ฉค๋ฒ„๋ฅผ ๋‹ค์‹œ ์‹œ์ž‘ํ•ฉ๋‹ˆ๋‹ค.

  1. mongosh ์„ ์‚ฌ์šฉํ•˜์—ฌ ํ”„๋ผ์ด๋จธ๋ฆฌ์— ์—ฐ๊ฒฐํ•œ ๋‹ค์Œ rs.stepDown() ๋ฉ”์„œ๋“œ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋ฉค๋ฒ„๋ฅผ ํ”„๋ผ์ด๋จธ๋ฆฌ๋กœ ๊ฐ•๋“ฑํ•ฉ๋‹ˆ๋‹ค.

    rs.stepDown()

    cluster๋Š” ์ƒˆ ์ธ์ฆ์„œ๋กœ ๋ณด์กฐ ์ธ์ฆ์„œ๋ฅผ ์ƒˆ ํ”„๋ผ์ด๋จธ๋ฆฌ ์—ญํ• ์„ ํ•˜๋„๋ก ์Šน๊ฒฉํ•ฉ๋‹ˆ๋‹ค.

  2. db.shutdownServer() ๋ฉ”์„œ๋“œ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์„œ๋ฒ„๋ฅผ ์ข…๋ฃŒํ•ฉ๋‹ˆ๋‹ค:

    use admin
    db.shutdownServer()
  3. ์„œ๋ฒ„๋ฅผ ๋‹ค์‹œ ์‹œ์ž‘ํ•ฉ๋‹ˆ๋‹ค.

ํ”„๋ผ์ด๋จธ๋ฆฌ ์„œ๋ฒ„๋Š” ๋” ์ด์ƒ ์ด์ „ X.509 ์ธ์ฆ์„œ์—์„œ์˜ ์—ฐ๊ฒฐ์„ ํ—ˆ์šฉํ•˜์ง€ ์•Š๋Š” ์„ธ์ปจ๋”๋ฆฌ ์„œ๋ฒ„๋กœ ๋‹ค์‹œ ์‹œ์ž‘๋ฉ๋‹ˆ๋‹ค.

๋Œ์•„๊ฐ€๊ธฐ

์ƒˆ DN์„ ํฌํ•จํ•˜๋Š” x.509 ํด๋Ÿฌ์Šคํ„ฐ ์ธ์ฆ์„œ์˜ ๋กค๋ง ์—…๋ฐ์ดํŠธ

๋‹ค์Œ

X.509 ์ธ์ฆ์„œ๋ฅผ ํšŒ์ „ํ•˜์—ฌ ํ™•์žฅ์ž ๊ฐ’ ์‚ฌ์šฉ