You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用智能卡+配置文件时如何规避openconnect的“文件名过长”错误?

问题描述

尝试将OpenConnect从命令行切换为配置文件方式连接VPN,使用捷德StarSign CUT S智能卡,命令行可正常连接,但配置文件模式触发"文件名过长"错误导致连接失败。

命令行正常执行命令

$ openconnect \
--authgroup=<my_gateway> \
--protocol=gp \
--servercert <...> \
--disable-ipv6 \
--cafile <file.pem> \
<my_server_url> \
-c "pkcs11:model=XXXXXXXXXXXXXXXX;manufacturer=A.E.T.%20Europe%20B.V.;serial=XXXXXXXXXXXXXXXX;token=XXXXXXXXX;id=<...>;object=<...>;type=cert"

配置文件内容(vpn.config)

authgroup = <my_gateway>
protocol = gp
servercert = <...>
disable-ipv6
cafile = <file.pem>
server = <my_server_url>
certificate = "pkcs11:model=XXXXXXXXXXXXXXXX;manufacturer=A.E.T.%20Europe%20B.V.;serial=XXXXXXXXXXXXXXXX;token=XXXXXXXXX;id=<...>;object=<...>;type=cert"

报错信息

$ openconnect --config=vpn.config
Failed to open key/certificate file <...>: File name too long
Loading certificate failed. Aborting.
Failed to open HTTPS connection to <...>
Failed to complete authentication

环境信息

  • OpenConnect版本:v9.01,基于GnuTLS 3.7.7,支持PKCS#11等特性
  • 所有操作以root身份执行

解决方案

这不是OpenConnect的Bug,而是配置文件的语法使用错误导致的:

命令行中给PKCS#11 URI加双引号是为了避免Shell解析特殊字符(分号、%20转义符),但OpenConnect配置文件的解析逻辑与Shell不同,引号会被当作URI的一部分处理,导致程序将带引号的字符串当作本地文件路径尝试打开,从而触发"文件名过长"的错误。

只需修改配置文件,去掉certificate参数值的双引号即可:

authgroup = <my_gateway>
protocol = gp
servercert = <...>
disable-ipv6
cafile = <file.pem>
server = <my_server_url>
certificate = pkcs11:model=XXXXXXXXXXXXXXXX;manufacturer=A.E.T.%20Europe%20B.V.;serial=XXXXXXXXXXXXXXXX;token=XXXXXXXXX;id=<...>;object=<...>;type=cert

修改后重新执行命令即可正常连接:

$ openconnect --config=vpn.config

补充说明:如果PKCS#11 URI中包含真实空格(而非%20转义),此时才需要用单/双引号包裹值;但对于已用%20转义空格的URI,绝对不要额外添加引号。


内容的提问来源于Stack Exchange,提问作者Djunzu

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.16 14:05:21