Áú»¢¶Ä²©

3 §±§â§à§Ò§Ý§Ö§Þ§í §ã PSK

PSK §ã§à§Õ§Ö§â§Ø§Ú§ä §ß§Ö§é§Ö§ä§ß§à§Ö §Ü§à§Ý§Ú§é§Ö§ã§ä§Ó§à hex-§è§Ú§æ§â

§±§â§à§Ü§ã§Ú §Ú§Ý§Ú §Ñ§Ô§Ö§ß§ä §ß§Ö §Ù§Ñ§á§å§ã§Ü§Ñ§ð§ä§ã§ñ, §ã§à§à§Ò§ë§Ö§ß§Ú§Ö §Ó §Ø§å§â§ß§Ñ§Ý§Ö §á§â§à§Ü§ã§Ú §Ú§Ý§Ú §Ñ§Ô§Ö§ß§ä§Ñ:

invalid PSK in file "/home/zabbix/zabbix_proxy.psk"

§£ GnuTLS §á§Ö§â§Ö§Õ§Ñ§ß§Ñ §ã§ä§â§à§Ü§Ñ §Ú§Õ§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§ä§à§â PSK §Õ§Ý§Ú§ß§ß§Ö§Ö 128 §Ò§Ñ§Û§ä

§£ §Ø§å§â§ß§Ñ§Ý§Ö §ß§Ñ §ã§ä§à§â§à§ß§Ö TLS §Ü§Ý§Ú§Ö§ß§ä§Ñ:

gnutls_handshake() failed: -110 The TLS connection was non-properly terminated.

§£ §Ø§å§â§ß§Ñ§Ý§Ö §ß§Ñ §ã§ä§à§â§à§ß§Ö TLS §ã§Ö§â§Ó§Ö§â§Ñ.

gnutls_handshake() failed: -90 The SRP username supplied is illegal.

§£ mbed TLS (PolarSSL) §á§Ö§â§Ö§Õ§Ñ§ß PSK §Õ§Ý§Ú§ß§ß§Ö§Ö 32 §Ò§Ñ§Û§ä

§£ §Ý§ð§Ò§à§Þ §Ø§å§â§ß§Ñ§Ý§Ö Áú»¢¶Ä²©:

ssl_set_psk(): SSL - Bad input parameters to function

§ª§ã§á§à§Ý§î§Ù§å§Ö§ä§ã§ñ §à§Õ§Ú§ß§Ñ§Ü§à§Ó§Ñ§ñ §ã§ä§â§à§Ü§Ñ §Ú§Õ§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§Ú PSK, §ß§à §â§Ñ§Ù§ß§í§Ö §Ù§ß§Ñ§é§Ö§ß§Ú§ñ PSK §Õ§Ý§ñ §ã§Ó§ñ§Ù§Ú §Þ§Ö§Ø§Õ§å §Ü§à§Þ§á§à§ß§Ö§ß§ä§Ñ§Þ§Ú (§ß§Ñ§á§â§Ú§Þ§Ö§â §ã OpenSSL)

§£ §Ø§å§â§ß§Ñ§Ý§Ö §ß§Ñ §ã§ä§à§â§à§ß§Ö §Ú§ß§Ú§è§Ú§Ñ§ä§à§â§Ñ §á§à§Õ§Ü§Ý§ð§é§Ö§ß§Ú§ñ:

...[connect] TCP successful, cannot establish TLS to [[xx.xx.xx.xx]:xxx]: SSL_connect() returned SSL_ERROR_SSL: file s3_pkt.c line 1472: error:140943FC:SSL routines:ssl3_read_bytes:sslv3 alert bad record mac: SSL alert number 20: TLS read fatal alert "bad record mac"

§£ §Ø§å§â§ß§Ñ§Ý§Ö §ß§Ñ §á§â§Ú§ß§Ú§Þ§Ñ§ð§ë§Ö§Û §ã§ä§à§â§à§ß§Ö:

...failed to accept an incoming connection: from xx.xx.xx.xx: TLS handshake returned error code 1: file s3_pkt.c line 532: error:1408F119:SSL routines:SSL3_GET_RECORD:decryption failed or bad record mac: TLS write fatal alert "bad record mac"