You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Secure Global Desktop(SGD)本地更新自签名证书有效期未生效问题咨询

Secure Global Desktop(SGD) 自签名证书更新不生效排查方案
  • 首先清理SGD服务端证书缓存
    SGD默认会主动缓存证书链数据,仅替换pem文件不会自动刷新缓存,执行以下操作:
    1. 停止SGD服务:tarantella stop
    2. 清空两个缓存目录下的旧证书文件:/opt/tarantella/var/tsp/certs/、/opt/tarantella/var/info/certs/
    3. 重启SGD服务:tarantella start
  • 检查证书文件权限
    SGD服务默认以tarantella用户运行,若替换的pem文件权限配置错误会导致服务无法读取新证书,自动回退到旧证书,执行以下命令修正:
    chown tarantella:tarantella /opt/tarantella/var/tsp/certs/host.pem
    chmod 600 /opt/tarantella/var/tsp/certs/host.pem
    
  • 同步更新全链路证书
    很多场景下仅替换SGD核心服务的pem文件无法覆盖所有访问入口,需要同步更新Web层证书:
    1. Apache SSL证书:替换/opt/tarantella/webserver/apache/conf/ssl.crt/目录下的crt和key文件
    2. Tomcat keystore更新:
      • 先将pem证书+私钥转为pkcs12格式:openssl pkcs12 -export -in 你的新证书.pem -inkey 你的私钥.key -out sgd_cert.p12 -name sgd_host
      • 导入到Tomcat默认keystore:keytool -importkeystore -srckeystore sgd_cert.p12 -srcstoretype pkcs12 -destkeystore /opt/tarantella/webserver/tomcat/conf/keystore -deststoretype JKS
      • 默认keystore密码为changeit,未自定义配置可直接使用
  • 验证服务端证书有效性
    避免客户端缓存干扰判断,直接用openssl命令检测服务端返回的证书有效期:
    openssl s_client -connect 你的SGD域名/IP:443 | openssl x509 -noout -dates
    若输出的notAfter字段显示为2024年,说明服务端配置已生效,清理本地浏览器SSL缓存、SGD客户端缓存后重新访问即可。

内容的提问来源于stack exchange,提问作者Dain L

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.26 08:15:00