Windows环境下ejabberd配置ZeroSSL生成的SSL证书方法问询
Got it, let's walk through getting your ZeroSSL certificate up and running with ejabberd on Windows step by step. I've tackled this exact setup before, so here's what you need to do:
1. Prepare Your Certificate Files
First, let's narrow down the files you actually need for ejabberd:
- You only require domain-key.txt (your private key) and domain-crt.txt (your signed SSL certificate). The other files (
account-key.txt,domain-csr.txt) are safe to store for backup but aren't needed for the running config. - Move these two files to a secure, accessible directory (avoid the default
Program Filesfolder if possible—permissions can get tricky there. I usually use something likeC:\ejabberd-certificates\). - Optional: Rename them to more intuitive names like
privkey.pemandfullchain.pemif you want, but just make sure you reference the correct filenames later in the config.
2. Edit the ejabberd Configuration File
Locate your ejabberd.yml config file. On Windows, this is typically found at C:\Program Files\ejabberd-[version]\conf\ejabberd.yml (replace [version] with your installed ejabberd version).
Open it with a YAML-friendly editor (Notepad++, VS Code works great) and find the listen section. You’ll need to update or add entries for SSL-enabled ports:
Example Config for Key Ports
Here’s how to set up the most commonly used SSL ports:
listen: # XMPP Client SSL/TLS (port 5223) - port: 5223 module: ejabberd_c2s tls: true tls_certfile: "C:/ejabberd-certificates/domain-crt.txt" tls_keyfile: "C:/ejabberd-certificates/domain-key.txt" allow_multiple_connections: true max_stanza_size: 65536 shaper: c2s_shaper access: c2s # Server-to-Server SSL/TLS (port 5269) - port: 5269 module: ejabberd_s2s_in tls: true tls_certfile: "C:/ejabberd-certificates/domain-crt.txt" tls_keyfile: "C:/ejabberd-certificates/domain-key.txt" shaper: s2s_shaper access: s2s # HTTPS for ejabberd Web Admin (port 5443) - port: 5443 module: ejabberd_http tls: true tls_certfile: "C:/ejabberd-certificates/domain-crt.txt" tls_keyfile: "C:/ejabberd-certificates/domain-key.txt" request_handlers: "/admin": ejabberd_web_admin "/api": mod_http_api "/bosh": mod_bosh "/captcha": ejabberd_captcha "/upload": mod_http_upload "/ws": ejabberd_http_ws
- Critical note: Use forward slashes (
/) in file paths, or double backslashes (\\) if you prefer (YAML requires escaping backslashes). - If your
domain-crt.txtdoesn’t include the full certificate chain (some ZeroSSL downloads split this into a separate file), append the ZeroSSL intermediate certificate to the end ofdomain-crt.txt(just copy-paste the intermediate cert text below your server certificate). This ensures clients trust your SSL cert.
3. Set File Permissions
On Windows, the ejabberd service runs under a dedicated user (usually LOCAL SERVICE). Make sure this user can read your certificate files:
- Right-click your certificate directory > Properties > Security tab.
- Click Edit > Add > Type
LOCAL SERVICE> Click Check Names > OK. - Grant the
LOCAL SERVICEuser Read & execute permissions. - Click Apply > OK.
4. Restart the ejabberd Service
To apply your config changes, restart the ejabberd service:
- Press
Win + R> Typeservices.msc> Hit Enter. - Find the
ejabberdservice in the list. - Right-click it > Restart.
5. Verify the SSL Setup
To confirm everything works:
- Use an XMPP client (like Pidgin or Gajim) to connect to your server on port 5223 with SSL enabled.
- Or run this command in Command Prompt (if you have OpenSSL installed):
Look for the lineopenssl s_client -connect yourdomain.com:5223Verify return code: 0 (ok)—this means your certificate is trusted.
If you hit issues, check the ejabberd log file (usually C:\Program Files\ejabberd-[version]\logs\ejabberd.log) for error messages. Common problems include incorrect file paths or missing read permissions.
内容的提问来源于stack exchange,提问作者Luiz Alves

