使用智能卡+配置文件时如何规避openconnect的“文件名过长”错误?
问题描述
尝试将OpenConnect从命令行切换为配置文件方式连接VPN,使用捷德StarSign CUT S智能卡,命令行可正常连接,但配置文件模式触发"文件名过长"错误导致连接失败。
命令行正常执行命令
$ openconnect \ --authgroup=<my_gateway> \ --protocol=gp \ --servercert <...> \ --disable-ipv6 \ --cafile <file.pem> \ <my_server_url> \ -c "pkcs11:model=XXXXXXXXXXXXXXXX;manufacturer=A.E.T.%20Europe%20B.V.;serial=XXXXXXXXXXXXXXXX;token=XXXXXXXXX;id=<...>;object=<...>;type=cert"
配置文件内容(vpn.config)
authgroup = <my_gateway> protocol = gp servercert = <...> disable-ipv6 cafile = <file.pem> server = <my_server_url> certificate = "pkcs11:model=XXXXXXXXXXXXXXXX;manufacturer=A.E.T.%20Europe%20B.V.;serial=XXXXXXXXXXXXXXXX;token=XXXXXXXXX;id=<...>;object=<...>;type=cert"
报错信息
$ openconnect --config=vpn.config Failed to open key/certificate file <...>: File name too long Loading certificate failed. Aborting. Failed to open HTTPS connection to <...> Failed to complete authentication
环境信息
- OpenConnect版本:v9.01,基于GnuTLS 3.7.7,支持PKCS#11等特性
- 所有操作以root身份执行
解决方案
这不是OpenConnect的Bug,而是配置文件的语法使用错误导致的:
命令行中给PKCS#11 URI加双引号是为了避免Shell解析特殊字符(分号、%20转义符),但OpenConnect配置文件的解析逻辑与Shell不同,引号会被当作URI的一部分处理,导致程序将带引号的字符串当作本地文件路径尝试打开,从而触发"文件名过长"的错误。
只需修改配置文件,去掉certificate参数值的双引号即可:
authgroup = <my_gateway> protocol = gp servercert = <...> disable-ipv6 cafile = <file.pem> server = <my_server_url> certificate = pkcs11:model=XXXXXXXXXXXXXXXX;manufacturer=A.E.T.%20Europe%20B.V.;serial=XXXXXXXXXXXXXXXX;token=XXXXXXXXX;id=<...>;object=<...>;type=cert
修改后重新执行命令即可正常连接:
$ openconnect --config=vpn.config
补充说明:如果PKCS#11 URI中包含真实空格(而非%20转义),此时才需要用单/双引号包裹值;但对于已用%20转义空格的URI,绝对不要额外添加引号。
内容的提问来源于Stack Exchange,提问作者Djunzu
相关产品推荐
相关产品推荐

