CentOS 7.9上配置Stunnel 5.67(OpenSSL 3.0.7)时初始化TLS上下文失败的问题求助
CentOS 7.9上配置Stunnel 5.67(OpenSSL 3.0.7)时初始化TLS上下文失败的问题求助
我目前在用CentOS Linux release v7.9.2009 (Core),系统已经更新到最新版本了。
环境搭建过程
首先我安装了最新版的OpenSSL,执行的命令如下:
cd ~ wget https://www.openssl.org/source/openssl-3.0.7.tar.gz tar -zxvf openssl-3.0.7.tar.gz yum install -y perl-IPC-Cmd cd openssl-3.0.7 ./Configure make make install ln -s /usr/local/lib64/libssl.so.3 /usr/lib64/libssl.so.3 ln -s /usr/local/lib64/libcrypto.so.3 /usr/lib64/libcrypto.so.3 sudo ldconfig reboot openssl version -d
执行openssl version -d后的输出是:
OPENSSLDIR: "/usr/local/ssl"
接下来我安装了最新版的Stunnel,命令如下:
wget ftp://ftp.stunnel.org/stunnel/archive/5.x/stunnel-5.67.tar.gz sudo yum -y install tar sudo yum -y update tar tar -xvzf stunnel-5.67.tar.gz cd stunnel-5.67 rm -rf stunnel-5.67 # 这一步是学习测试用的 groupadd -g 51 stunnel && useradd -c "stunnel Daemon" -d /var/lib/stunnel \ -g stunnel -s /bin/false -u 51 stunnel ./configure --prefix=/usr --sysconfdir=/etc --localstatedir=/var --disable-systemd --with-ssl=/usr/local make make docdir=/usr/share/doc/stunnel-5.67 install
通过这些操作,我已经把Stunnel关联到了刚安装的OpenSSL 3.0.7版本上。
之后我用make cert命令生成了一个简单的证书文件stunnel.pem。
Stunnel配置文件
我的/etc/stunnel/stunnel.conf配置内容如下:
[Server] client = no accept = 11523 connect = 127.0.0.1:11869 cert = stunnel.pem
FIPS状态检查
我检查了系统的FIPS状态:
sysctl crypto.fips_enabled
结果显示:
crypto.fips_enabled = 0
运行时错误信息
启动Stunnel后,出现了下面的错误,导致TLS上下文初始化失败:
[ ] Initializing inetd mode configuration [ ] Clients allowed=500 [.] stunnel 5.67 on x86_64-pc-linux-gnu platform [.] Compiled/running with OpenSSL 3.0.7 1 Nov 2022 [.] Threading:PTHREAD Sockets:POLL,IPv6 TLS:ENGINE,OCSP,PSK,SNI [ ] errno: (*__errno_location ()) [ ] Initializing inetd mode configuration [.] Reading configuration from file /etc/stunnel/stunnel.conf [.] UTF-8 byte order mark not detected [.] FIPS mode disabled [ ] Compression disabled [ ] No PRNG seeding was required [ ] Initializing service [Server] [ ] stunnel default security level set: 2 [ ] Ciphers: HIGH:!aNULL:!SSLv2:!DH:!kDHEPSK [ ] TLSv1.3 ciphersuites: TLS_AES_256_GCM_SHA384:TLS_AES_128_GCM_SHA256:TLS_CHACHA20_POLY1305_SHA256 [ ] TLS options: 0x2100000 (+0x0, -0x0) [ ] Session resumption enabled [ ] Loading certificate from file: stunnel.pem [!] error queue: ssl/ssl_rsa.c:448: error:0A080002:SSL routines::system lib [!] error queue: crypto/bio/bss_file.c:300: error:10080002:BIO routines::system lib [!] SSL_CTX_use_certificate_chain_file: crypto/bio/bss_file.c:297: error:80000002:system library::No such file or directory [!] Service [certificate-based Server]: Failed to initialize TLS context [!] Configuration failed [ ] Deallocating temporary section defaults [ ] Deallocating section [Server]
有没有大佬能帮我看看这个问题怎么解决呀?
备注:内容来源于stack exchange,提问作者helius.dev
相关产品推荐
相关产品推荐

