You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何让Puppet 4中8140端口兼容TLS 1.2?

Puppet Server 8140端口TLS 1.2配置位置说明

你的Puppet Server使用Jetty作为Web服务器,8140端口的TLS配置主要集中在以下几个位置:

  • 核心配置目录:/etc/puppetlabs/puppetserver/conf.d/
    重点查看webserver.conf文件,其中的ssl-settings区块包含TLS协议和加密套件的配置:

    ssl-settings: {
      ssl-protocols: ["TLSv1.2"]  # 确保包含TLSv1.2,可按需添加其他兼容版本
      cipher-suites: [
        "TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384",
        "TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256",
        # 其他TLS 1.2支持的加密套件
      ]
    }
    

    部分版本可能存在单独的jetty-ssl.conf文件,配置逻辑类似。

  • Jetty XML配置文件(旧版本Puppet Server)
    若使用较旧版本的Puppet Server,配置可能在/etc/puppetlabs/puppetserver/jetty/etc/jetty-ssl.xml中,找到<Set name="sslContextFactory">节点,添加或修改TLS协议设置:

    <Set name="sslContextFactory">
      <New class="org.eclipse.jetty.util.ssl.SslContextFactory">
        <Set name="excludeProtocols">
          <Array type="java.lang.String">
            <Item>SSLv3</Item>
            <Item>TLSv1</Item>
            <Item>TLSv1.1</Item>
          </Array>
        </Set>
        <Set name="includeProtocols">
          <Array type="java.lang.String">
            <Item>TLSv1.2</Item>
          </Array>
        </Set>
      </New>
    </Set>
    
  • JVM层面的TLS参数
    检查/etc/puppetlabs/puppetserver/puppetserver.conf中的jvm-config区块,确认是否有强制指定TLS版本的Java参数:

    jvm-config: {
      java_args: [
        # 其他参数...
        "-Djdk.tls.client.protocols=TLSv1.2",
        "-Djdk.tls.server.protocols=TLSv1.2"
      ]
    }
    

修改配置后,重启Puppet Server服务生效:

systemctl restart puppetserver

再次运行你的nmap命令验证TLS 1.2是否已启用。

内容的提问来源于stack exchange,提问作者Somethingwhatever

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.20 02:34:57