Áú»¢¶Ä²©

Table of Contents

1 §ª§ã§á§à§Ý§î§Ù§à§Ó§Ñ§ß§Ú§Ö §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§à§Ó

§°§Ò§Ù§à§â

Áú»¢¶Ä²© §Þ§à§Ø§Ö§ä §Ú§ã§á§à§Ý§î§Ù§à§Ó§Ñ§ä§î RSA §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§í §Ó §æ§à§â§Þ§Ñ§ä§Ö PEM, §á§à§Õ§á§Ú§ã§Ñ§ß§ß§í§Ö §á§å§Ò§Ý§Ú§é§ß§í§Þ §Ú§Ý§Ú §Ó§ß§å§ä§â§Ö§ß§ß§Ú§Þ §è§Ö§ß§ä§â§à§Þ §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§Ú (CA). §±§â§à§Ó§Ö§â§Ü§Ñ §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ §Ó§í§á§à§Ý§ß§ñ§Ö§ä§ã§ñ §Ó §à§ä§ß§à§ê§Ö§ß§Ú§Ú §ã §Ù§Ñ§â§Ñ§ß§Ö§Ö §á§à§Õ§Ô§à§ä§à§Ó§Ý§Ö§ß§ß§í§Þ CA §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§à§Þ. §³§Ñ§Þ§à§á§à§Õ§á§Ú§ã§Ñ§ß§ß§í§Ö §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§í §ß§Ö §á§à§Õ§Õ§Ö§â§Ø§Ú§Ó§Ñ§ð§ä§ã§ñ. §°§á§è§Ú§à§ß§Ñ§Ý§î§ß§à §Þ§à§Ø§ß§à §Ú§ã§á§à§Ý§î§Ù§à§Ó§Ñ§ä§î §ã§á§Ú§ã§Ü§Ú §à§ä§Ù§í§Ó§à§Ó §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§à§Ó (CRL). §¬§Ñ§Ø§Õ§í§Û §Ü§à§Þ§á§à§ß§Ö§ß§ä Áú»¢¶Ä²© §Þ§à§Ø§Ö§ä §Ú§Þ§Ö§ä§î §ä§à§Ý§î§Ü§à §à§Õ§Ú§ß §ß§Ñ§ã§ä§â§à§Ö§ß§ß§í§Û §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä.

§¥§Ý§ñ §á§à§Ý§å§é§Ö§ß§Ú§ñ §Ò§à§Ý§Ö§Ö §á§à§Õ§â§à§Ò§ß§à§Û §Ú§ß§æ§à§â§Þ§Ñ§è§Ú§Ú §à §ä§à§Þ §Ü§Ñ§Ü §ß§Ñ§ã§ä§â§à§Ú§ä§î §Ú §å§á§â§Ñ§Ó§Ý§ñ§ä§î §Ó§ß§å§ä§â§Ö§ß§ß§Ú§Þ CA, §Ü§Ñ§Ü §Ô§Ö§ß§Ö§â§Ú§â§à§Ó§Ñ§ä§î §Ù§Ñ§á§â§à§ã§í §ß§Ñ §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§í §Ú §á§à§Õ§á§Ú§ã§í§Ó§Ñ§ä§î §Ú§ç, §Ü§Ñ§Ü §à§ä§Ù§í§Ó§Ñ§ä§î §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§í, §Ó§ã§× §ï§ä§à §Ó§í §Þ§à§Ø§Ö§ä§Ö §ß§Ñ§Û§ä§Ú §Ó §Ò§à§Ý§î§ê§à§Þ §Ü§à§Ý§Ú§é§Ö§ã§ä§Ó§Ö §â§Ñ§Ù§Ý§Ú§é§ß§í§ç §â§å§Ü§à§Ó§à§Õ§ã§ä§Ó §Ó §ã§Ö§ä§Ú, §ß§Ñ§á§â§Ú§Þ§Ö§â, .

§´§ë§Ñ§ä§Ö§Ý§î§ß§à §á§â§à§Õ§å§Þ§í§Ó§Ñ§Û§ä§Ö §Ú §ä§Ö§ã§ä§Ú§â§å§Û§ä§Ö §Ó§Ñ§ê§Ú §â§Ñ§ã§ê§Ú§â§Ö§ß§Ú§ñ §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§à§Ó - §ã§Þ§à§ä§â§Ú §°§Ô§â§Ñ§ß§Ú§é§Ö§ß§Ú§ñ §á§â§Ú §Ú§ã§á§à§Ý§î§Ù§à§Ó§Ñ§ß§Ú§Ú §â§Ñ§ã§ê§Ú§â§Ö§ß§Ú§Û X.509 v3 §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§à§Ó.

§±§Ñ§â§Ñ§Þ§Ö§ä§â§í §ß§Ñ§ã§ä§â§à§Û§Ü§Ú §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§à§Ó

§±§Ñ§â§Ñ§Þ§Ö§ä§â §°§Ò§ñ§Ù§Ñ§ä§Ö§Ý§Ö§ß §°§á§Ú§ã§Ñ§ß§Ú§Ö
TLSCAFile * §¡§Ò§ã§à§Ý§ð§ä§ß§í§Û §á§å§ä§î §Ü §æ§Ñ§Û§Ý§å, §Ü§à§ä§à§â§í§Û §ã§à§Õ§Ö§â§Ø§Ú§ä §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§í §Ó§Ö§â§ç§ß§Ö§Ô§à §å§â§à§Ó§ß§ñ CA(§Ú) §Õ§Ý§ñ §Ó§Ö§â§Ú§æ§Ú§Ü§Ñ§è§Ú§Ú §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ §å§Ù§Ý§Ñ. §±§â§Ú §ß§Ñ§Ý§Ú§é§Ú§Ú §è§Ö§á§à§é§Ü§Ú §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§à§Ó §ã §ß§Ö§ã§Ü§à§Ý§î§Ü§Ú§Þ§Ú §é§Ý§Ö§ß§Ñ§Þ§Ú, §à§ß§Ú §Õ§à§Ý§Ø§ß§í §Ò§í§ä§î §à§ä§ã§à§â§ä§Ú§â§à§Ó§Ñ§ß§í: §ã§ß§Ñ§é§Ñ§Ý§Ñ §ã§Ý§Ö§Õ§å§ð§ä §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§í CA §ß§Ú§Ù§Ü§à§Ô§à §å§â§à§Ó§ß§ñ §Ù§Ñ §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ§Þ§Ú §Ò§à§Ý§Ö§Ö §Ó§í§ã§à§Ü§à§Ô§à §å§â§à§Ó§ß§ñ CA(§Ú). §³§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§í §Ú§Ù §ß§Ö§ã§Ü§à§Ý§î§Ü§Ú§ç CA(§Ú) §Þ§à§Ø§ß§à §Ó§Ü§Ý§ð§é§Ñ§ä§î §Ó §à§Õ§Ú§ß §æ§Ñ§Û§Ý.
TLSCRLFile §¡§Ò§ã§à§Ý§ð§ä§ß§í§Û §á§å§ä§î §Ü §æ§Ñ§Û§Ý§å, §Ü§à§ä§à§â§í§Û §ã§à§Õ§Ö§â§Ø§Ú§ä §ã§á§Ú§ã§Ü§Ú §à§ä§à§Ù§Ó§Ñ§ß§ß§í§ç §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§à§Ó. §³§Þ§à§ä§â§Ú§ä§Ö §Ù§Ñ§Þ§Ö§ä§Ü§Ú §Ó §³§á§Ú§ã§Ü§Ú §à§ä§à§Ù§Ó§Ñ§ß§ß§í§ç §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§à§Ó (CRL).
TLSCertFile * §¡§Ò§ã§à§Ý§ð§ä§ß§í§Û §á§å§ä§î §Ü §æ§Ñ§Û§Ý§å, §Ü§à§ä§à§â§í§Û §ã§à§Õ§Ö§â§Ø§Ú§ä §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä (§è§Ö§á§à§é§Ü§å §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§à§Ó).
§£ §ã§Ý§å§é§Ñ§Ö §è§Ö§á§à§é§Ü§Ú §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§à§Ó §ã §ß§Ö§ã§Ü§à§Ý§î§Ü§Ú§Þ§Ú §é§Ý§Ö§ß§Ñ§Þ§Ú §à§ß§Ú §Õ§à§Ý§Ø§ß§í §Ò§í§ä§î §à§ä§ã§à§â§ä§Ú§â§à§Ó§Ñ§ß§í: §ã§ß§Ñ§é§Ñ§Ý§Ñ §ã§Ö§â§Ó§Ö§â, §á§â§à§Ü§ã§Ú §Ú§Ý§Ú §Ñ§Ô§Ö§ß§ä, §ã §á§à§ã§Ý§Ö§Õ§å§ð§ë§Ú§Þ§Ú CA §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ§Þ§Ú §ß§Ú§Ù§Ü§à§Ô§à §å§â§à§Ó§ß§ñ §Ú §Ù§Ñ§ä§Ö§Þ CA §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§í §Ò§à§Ý§Ö§Ö §Ó§í§ã§à§Ü§à§Ô§à §å§â§à§Ó§ß§ñ.
TLSKeyFile * §¡§Ò§ã§à§Ý§ð§ä§ß§í§Û §á§å§ä§î §Ü §æ§Ñ§Û§Ý§å, §Ü§à§ä§à§â§í§Û §ã§à§Õ§Ö§â§Ø§Ú§ä §á§â§Ú§Ó§Ñ§ä§ß§í§Û §Ü§Ý§ð§é. §©§Ñ§Õ§Ñ§Û§ä§Ö §á§â§Ñ§Ó§Ñ §Õ§à§ã§ä§å§á§Ñ §Ü §ï§ä§à§Þ§å §æ§Ñ§Û§Ý§å - §à§ß §Õ§à§Ý§Ø§Ö§ß §Ò§í§ä§î §Õ§à§ã§ä§å§á§Ö§ß §Õ§Ý§ñ §é§ä§Ö§ß§Ú§ñ §ä§à§Ý§î§Ü§à §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§ð Áú»¢¶Ä²©.
TLSServerCertIssuer §²§Ñ§Ù§â§Ö§ê§Ö§ß§ß§í§Û §ï§Þ§Ú§ä§Ö§ß§ä §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ §ã§Ö§â§Ó§Ö§â§Ñ.
TLSServerCertSubject §²§Ñ§Ù§â§Ö§ê§Ö§ß§ß§í§Û §ã§å§Ò§ì§Ö§Ü§ä §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ §ã§Ö§â§Ó§Ö§â§Ñ.

Configuration examples

After setting up the necessary certificates, configure Áú»¢¶Ä²© components to use certificate-based encryption.

Below are detailed steps for configuring:

§¯§Ñ§ã§ä§â§à§Û§Ü§Ñ §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ §ß§Ñ Áú»¢¶Ä²© §ã§Ö§â§Ó§Ö§â§Ö

1. §¥§Ý§ñ §ä§à§Ô§à, §é§ä§à§Ò§í §á§â§à§Ó§Ö§â§ñ§ä§î §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§í §ç§à§ã§ä§à§Ó, Áú»¢¶Ä²© §ã§Ö§â§Ó§Ö§â §Õ§à§Ý§Ø§Ö§ß §Ú§Þ§Ö§ä§î §Õ§à§ã§ä§å§á §Ü §æ§Ñ§Û§Ý§å §ã §Ú§ç §Ü§à§â§ß§Ö§Ó§í§Þ§Ú §Ó§Ö§â§ç§ß§Ö§Ô§à §å§â§à§Ó§ß§ñ §ã§Ñ§Þ§à§á§à§Õ§á§Ú§ã§ß§í§Þ§Ú CA §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ§Þ§Ú. §¯§Ñ§á§â§Ú§Þ§Ö§â, §Ö§ã§Ý§Ú §Þ§í §à§Ø§Ú§Õ§Ñ§Ö§Þ §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§í §à§ä §Õ§Ó§å§ç §ß§Ö§Ù§Ñ§Ó§Ú§ã§Ú§Þ§í§ç §Ü§à§â§ß§Ö§Ó§í§ç CA, §Þ§í §Þ§à§Ø§Ö§Þ §á§à§Þ§Ö§ã§ä§Ú§ä§î §Ú§ç §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§í §Ó §æ§Ñ§Û§Ý /home/zabbix/zabbix_ca_file, §á§â§Ú§Þ§Ö§â§ß§à §ã§Ý§Ö§Õ§å§ð§ë§Ú§Þ §à§Ò§â§Ñ§Ù§à§Þ:

Certificate:
           Data:
               Version: 3 (0x2)
               Serial Number: 1 (0x1)
           Signature Algorithm: sha1WithRSAEncryption
               Issuer: DC=com, DC=zabbix, O=Áú»¢¶Ä²© SIA, OU=Development group, CN=Root1 CA
                   ...
               Subject: DC=com, DC=zabbix, O=Áú»¢¶Ä²© SIA, OU=Development group, CN=Root1 CA
               Subject Public Key Info:
                   Public Key Algorithm: rsaEncryption
                       Public-Key: (2048 bit)
                   ...
               X509v3 extensions:
                   X509v3 Key Usage: critical
                       Certificate Sign, CRL Sign
                   X509v3 Basic Constraints: critical
                       CA:TRUE
                   ...
       -----BEGIN CERTIFICATE-----
       MIID2jCCAsKgAwIBAgIBATANBgkqhkiG9w0BAQUFADB+MRMwEQYKCZImiZPyLGQB
       ....
       9wEzdN8uTrqoyU78gi12npLj08LegRKjb5hFTVmO
       -----END CERTIFICATE-----
       Certificate:
           Data:
               Version: 3 (0x2)
               Serial Number: 1 (0x1)
           Signature Algorithm: sha1WithRSAEncryption
               Issuer: DC=com, DC=zabbix, O=Áú»¢¶Ä²© SIA, OU=Development group, CN=Root2 CA
                   ...
               Subject: DC=com, DC=zabbix, O=Áú»¢¶Ä²© SIA, OU=Development group, CN=Root2 CA
               Subject Public Key Info:
                   Public Key Algorithm: rsaEncryption
                       Public-Key: (2048 bit)
                   ....
               X509v3 extensions:
                   X509v3 Key Usage: critical
                       Certificate Sign, CRL Sign
                   X509v3 Basic Constraints: critical
                       CA:TRUE
                   ....       
       -----BEGIN CERTIFICATE-----
       MIID3DCCAsSgAwIBAgIBATANBgkqhkiG9w0BAQUFADB/MRMwEQYKCZImiZPyLGQB
       ...
       vdGNYoSfvu41GQAR5Vj5FnRJRzv5XQOZ3B6894GY1zY=
       -----END CERTIFICATE-----

2. §±§à§Þ§Ö§ã§ä§Ú§ä§Ö §è§Ö§á§à§é§Ü§å §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§à§Ó Áú»¢¶Ä²© §ã§Ö§â§Ó§Ö§â§Ñ §Ó §æ§Ñ§Û§Ý, §ß§Ñ§á§â§Ú§Þ§Ö§â, /home/zabbix/zabbix_server.crt:

Certificate:
           Data:
               Version: 3 (0x2)
               Serial Number: 1 (0x1)
           Signature Algorithm: sha1WithRSAEncryption
               Issuer: DC=com, DC=zabbix, O=Áú»¢¶Ä²© SIA, OU=Development group, CN=Signing CA
               ...
               Subject: DC=com, DC=zabbix, O=Áú»¢¶Ä²© SIA, OU=Development group, CN=Áú»¢¶Ä²© server
               Subject Public Key Info:
                   Public Key Algorithm: rsaEncryption
                       Public-Key: (2048 bit)
                       ...
               X509v3 extensions:
                   X509v3 Key Usage: critical
                       Digital Signature, Key Encipherment
                   X509v3 Basic Constraints: 
                       CA:FALSE
                   ...
       -----BEGIN CERTIFICATE-----
       MIIECDCCAvCgAwIBAgIBATANBgkqhkiG9w0BAQUFADCBgTETMBEGCgmSJomT8ixk
       ...
       h02u1GHiy46GI+xfR3LsPwFKlkTaaLaL/6aaoQ==
       -----END CERTIFICATE-----
       Certificate:
           Data:
               Version: 3 (0x2)
               Serial Number: 2 (0x2)
           Signature Algorithm: sha1WithRSAEncryption
               Issuer: DC=com, DC=zabbix, O=Áú»¢¶Ä²© SIA, OU=Development group, CN=Root1 CA
               ...
               Subject: DC=com, DC=zabbix, O=Áú»¢¶Ä²© SIA, OU=Development group, CN=Signing CA
               Subject Public Key Info:
                   Public Key Algorithm: rsaEncryption
                       Public-Key: (2048 bit)
                   ...
               X509v3 extensions:
                   X509v3 Key Usage: critical
                       Certificate Sign, CRL Sign
                   X509v3 Basic Constraints: critical
                       CA:TRUE, pathlen:0
               ...
       -----BEGIN CERTIFICATE-----
       MIID4TCCAsmgAwIBAgIBAjANBgkqhkiG9w0BAQUFADB+MRMwEQYKCZImiZPyLGQB
       ...
       dyCeWnvL7u5sd6ffo8iRny0QzbHKmQt/wUtcVIvWXdMIFJM0Hw==
       -----END CERTIFICATE-----

§©§Õ§Ö§ã§î §á§Ö§â§Ó§í§Þ §ñ§Ó§Ý§ñ§Ö§ä§ã§ñ §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä Áú»¢¶Ä²© §ã§Ö§â§Ó§Ö§â§Ñ, §Ù§Ñ §ß§Ú§Þ §á§â§à§Þ§Ö§Ø§å§ä§à§é§ß§í§Ö CA §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä.

3. §±§à§Þ§Ö§ã§ä§Ú§ä§Ö §á§â§Ú§Ó§Ñ§ä§ß§í§Û §Ü§Ý§ð§é Áú»¢¶Ä²© §ã§Ö§â§Ó§Ö§â§Ñ §Ó §æ§Ñ§Û§Ý, §ß§Ñ§á§â§Ú§Þ§Ö§â, /home/zabbix/zabbix_server.key:

-----BEGIN PRIVATE KEY-----
       MIIEwAIBADANBgkqhkiG9w0BAQEFAASCBKowggSmAgEAAoIBAQC9tIXIJoVnNXDl
       ...
       IJLkhbybBYEf47MLhffWa7XvZTY=
       -----END PRIVATE KEY-----

4. §ª§Ù§Þ§Ö§ß§Ú§ä§Ö §á§Ñ§â§Ñ§Þ§Ö§ä§â§í TLS §Ó §æ§Ñ§Û§Ý§Ö §Ü§à§ß§æ§Ú§Ô§å§â§Ñ§è§Ú§Ú Áú»¢¶Ä²© §ã§Ö§â§Ó§Ö§â§Ñ, §á§â§Ú§Þ§Ö§â§ß§à §ä§Ñ§Ü:

TLSCAFile=/home/zabbix/zabbix_ca_file
       TLSCertFile=/home/zabbix/zabbix_server.crt
       TLSKeyFile=/home/zabbix/zabbix_server.key

§¯§Ñ§ã§ä§â§à§Û§Ü§Ñ §ê§Ú§æ§â§à§Ó§Ñ§ß§Ú§ñ §Õ§Ý§ñ Áú»¢¶Ä²© §á§â§à§Ü§ã§Ú §ß§Ñ §à§ã§ß§à§Ó§Ö §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ

1. §±§à§Õ§Ô§à§ä§à§Ó§î§ä§Ö §æ§Ñ§Û§Ý§í §ã CA §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ§Þ§Ú §Ó§Ö§â§ç§ß§Ö§Ô§à §å§â§à§Ó§ß§ñ, §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§à§Þ (§è§Ö§á§à§é§Ü§à§Û) §á§â§à§Ü§ã§Ú §Ú §á§â§Ú§Ó§Ñ§ä§ß§í§Þ §Ü§Ý§ð§é§Ö§Þ, §Ü§Ñ§Ü §à§á§Ú§ã§Ñ§ß§à §Ó §¯§Ñ§ã§ä§â§à§Û§Ü§Ö §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ §ß§Ñ Áú»¢¶Ä²© §ã§Ö§â§Ó§Ö§â§Ö. §ª§Ù§Þ§Ö§ß§Ú§ä§Ö §á§Ñ§â§Ñ§Þ§Ö§ä§â§í TLSCAFile, TLSCertFile, TLSKeyFile §Ó §æ§Ñ§Û§Ý§Ö §Ü§à§ß§æ§Ú§Ô§å§â§Ñ§è§Ú§Ú §á§â§à§Ü§ã§Ú §ã§à§à§ä§Ó§Ö§ä§ã§ä§Ó§Ö§ß§ß§à.

2. §±§â§Ú §Ñ§Ü§ä§Ú§Ó§ß§à§Þ §á§â§à§Ü§ã§Ú §Ú§Ù§Þ§Ö§ß§Ú§ä§Ö TLSConnect §á§Ñ§â§Ñ§Þ§Ö§ä§â:

TLSConnect=cert

§±§â§Ú §á§Ñ§ã§ã§Ú§Ó§ß§à§Þ §á§â§à§Ü§ã§Ú §Ú§Ù§Þ§Ö§ß§Ú§ä§Ö TLSAccept §á§Ñ§â§Ñ§Þ§Ö§ä§â:

TLSAccept=cert

3. §´§Ö§á§Ö§â§î §å §Ó§Ñ§ã §Ö§ã§ä§î §Þ§Ú§ß§Ú§Þ§Ñ§Ý§î§ß§Ñ§ñ §ß§Ñ§ã§ä§â§à§Û§Ü§Ñ §á§â§à§Ü§ã§Ú §ß§Ñ §à§ã§ß§à§Ó§Ö §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ. §£§í §Ó§à§Ù§Þ§à§Ø§ß§à §Ù§Ñ§ç§à§ä§Ú§ä§Ö §å§Ý§å§é§ê§Ú§ä§î §Ò§Ö§Ù§à§á§Ñ§ã§ß§à§ã§ä§î §á§â§à§Ü§ã§Ú, §å§Ü§Ñ§Ù§Ñ§Ó §á§Ñ§â§Ñ§Þ§Ö§ä§â§í TLSServerCertIssuer §Ú TLSServerCertSubject (§ã§Þ§à§ä§â§Ú §°§Ô§â§Ñ§ß§Ú§é§Ö§ß§Ú§Ö §â§Ñ§Ù§â§Ö§ê§Ö§ß§ß§í§ç §¿§Þ§Ú§ä§Ö§ß§ä§Ñ §Ú §³§å§Ò§ì§Ö§Ü§ä§Ñ §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ).

4. §£ §Ü§à§ß§Ö§é§ß§à§Þ §Ú§ä§à§Ô§Ö §á§Ñ§â§Ñ§Þ§Ö§ä§â§í TLS §Ó §æ§Ñ§Û§Ý§Ö §Ü§à§ß§æ§Ú§Ô§å§â§Ñ§è§Ú§Ú §á§â§à§Ü§ã§Ú §Þ§à§Ô§å§ä §Ó§í§Ô§Ý§ñ§Õ§Ö§ä§î §ã§Ý§Ö§Õ§å§ð§ë§Ú§Þ §à§Ò§â§Ñ§Ù§à§Þ:

TLSConnect=cert
       TLSAccept=cert
       TLSCAFile=/home/zabbix/zabbix_ca_file
       TLSServerCertIssuer=CN=Signing CA,OU=Development group,O=Áú»¢¶Ä²© SIA,DC=zabbix,DC=com
       TLSServerCertSubject=CN=Áú»¢¶Ä²© server,OU=Development group,O=Áú»¢¶Ä²© SIA,DC=zabbix,DC=com
       TLSCertFile=/home/zabbix/zabbix_proxy.crt
       TLSKeyFile=/home/zabbix/zabbix_proxy.key

5. §¯§Ñ§ã§ä§â§à§Û§ä§Ö §ê§Ú§æ§â§à§Ó§Ñ§ß§Ú§Ö §ï§ä§à§Þ§å §á§â§à§Ü§ã§Ú §Ó §Ó§Ö§Ò-§Ú§ß§ä§Ö§â§æ§Ö§Û§ã§Ö Áú»¢¶Ä²©:

  • §±§Ö§â§Ö§Û§Õ§Ú§ä§Ö §Ó: §¡§Õ§Þ§Ú§ß§Ú§ã§ä§â§Ú§â§à§Ó§Ñ§ß§Ú§Ö ¡ú §±§â§à§Ü§ã§Ú
  • §£§í§Ò§Ö§â§Ú§ä§Ö §á§â§à§Ü§ã§Ú §Ú §ß§Ñ§Ø§Þ§Ú§ä§Ö §ß§Ñ §Ó§Ü§Ý§Ñ§Õ§Ü§å §º§Ú§æ§â§à§Ó§Ñ§ß§Ú§Ö

§£ §á§â§Ú§Þ§Ö§â§Ö §ß§Ú§Ø§Ö §á§à§Ý§ñ §¿§Þ§Ú§ä§Ö§ß§ä §Ú §³§å§Ò§ì§Ö§Ü§ä §Ù§Ñ§á§à§Ý§ß§Ö§ß§í - §ã§Þ§à§ä§â§Ú§ä§Ö §°§Ô§â§Ñ§ß§Ú§é§Ö§ß§Ú§Ö §â§Ñ§Ù§â§Ö§ê§Ö§ß§ß§í§ç §¿§Þ§Ú§ä§Ö§ß§ä§Ñ §Ú §³§å§Ò§ì§Ö§Ü§ä§Ñ §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ §à §ä§à§Þ, §Ü§Ñ§Ü §Ú§ã§á§à§Ý§î§Ù§à§Ó§Ñ§ä§î §ï§ä§Ú §á§à§Ý§ñ.

§±§â§Ú §Ñ§Ü§ä§Ú§Ó§ß§à§Þ §á§â§à§Ü§ã§Ú

proxy_active_cert.png

§±§â§Ú §á§Ñ§ã§ã§Ú§Ó§ß§à§Þ §á§â§à§Ü§ã§Ú

proxy_passive_cert.png

§¯§Ñ§ã§ä§â§à§Û§Ü§Ñ §ê§Ú§æ§â§à§Ó§Ñ§ß§Ú§ñ §Õ§Ý§ñ Áú»¢¶Ä²© §Ñ§Ô§Ö§ß§ä§Ñ §ß§Ñ §à§ã§ß§à§Ó§Ö §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ

1. §±§à§Õ§Ô§à§ä§à§Ó§î§ä§Ö §æ§Ñ§Û§Ý§í §ã CA §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ§Þ§Ú §Ó§Ö§â§ç§ß§Ö§Ô§à §å§â§à§Ó§ß§ñ, §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§à§Þ (§è§Ö§á§à§é§Ü§à§Û) §Ñ§Ô§Ö§ß§ä§Ñ §Ú §á§â§Ú§Ó§Ñ§ä§ß§í§Þ §Ü§Ý§ð§é§Ö§Þ, §Ü§Ñ§Ü §à§á§Ú§ã§Ñ§ß§à §Ó §¯§Ñ§ã§ä§â§à§Û§Ü§Ö §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ §ß§Ñ Áú»¢¶Ä²© §ã§Ö§â§Ó§Ö§â§Ö. §ª§Ù§Þ§Ö§ß§Ú§ä§Ö §á§Ñ§â§Ñ§Þ§Ö§ä§â§í TLSCAFile, TLSCertFile, TLSKeyFile §Ó §æ§Ñ§Û§Ý§Ö §Ü§à§ß§æ§Ú§Ô§å§â§Ñ§è§Ú§Ú §Ñ§Ô§Ö§ß§ä§Ñ §ã§à§à§ä§Ó§Ö§ä§ã§ä§Ó§Ö§ß§ß§à.

2. §±§â§Ú §Ñ§Ü§ä§Ú§Ó§ß§í§ç §á§â§à§Ó§Ö§â§Ü§Ñ§ç §Ú§Ù§Þ§Ö§ß§Ú§ä§Ö TLSConnect §á§Ñ§â§Ñ§Þ§Ö§ä§â:

TLSConnect=cert

§±§â§Ú §á§Ñ§ã§ã§Ú§Ó§ß§í§ç §á§â§à§Ó§Ö§â§Ü§Ñ§ç §Ú§Ù§Þ§Ö§ß§Ú§ä§Ö TLSAccept §á§Ñ§â§Ñ§Þ§Ö§ä§â:

TLSAccept=cert

3. §´§Ö§á§Ö§â§î §å §Ó§Ñ§ã §Ö§ã§ä§î §Þ§Ú§ß§Ú§Þ§Ñ§Ý§î§ß§Ñ§ñ §ß§Ñ§ã§ä§â§à§Û§Ü§Ñ §Ñ§Ô§Ö§ß§ä§Ñ §ß§Ñ §à§ã§ß§à§Ó§Ö §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ. §£§í §Ó§à§Ù§Þ§à§Ø§ß§à §Ù§Ñ§ç§à§ä§Ú§ä§Ö §å§Ý§å§é§ê§Ú§ä§î §Ò§Ö§Ù§à§á§Ñ§ã§ß§à§ã§ä§î §Ñ§Ô§Ö§ß§ä§Ñ, §å§Ü§Ñ§Ù§Ñ§Ó §á§Ñ§â§Ñ§Þ§Ö§ä§â§í TLSServerCertIssuer §Ú TLSServerCertSubject.(§ã§Þ§à§ä§â§Ú §°§Ô§â§Ñ§ß§Ú§é§Ö§ß§Ú§Ö §â§Ñ§Ù§â§Ö§ê§Ö§ß§ß§í§ç §¿§Þ§Ú§ä§Ö§ß§ä§Ñ §Ú §³§å§Ò§ì§Ö§Ü§ä§Ñ §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ).

4. §£ §Ü§à§ß§Ö§é§ß§à§Þ §Ú§ä§à§Ô§Ö §á§Ñ§â§Ñ§Þ§Ö§ä§â§í TLS §Ó §æ§Ñ§Û§Ý§Ö §Ü§à§ß§æ§Ú§Ô§å§â§Ñ§è§Ú§Ú §Ñ§Ô§Ö§ß§ä§Ñ §Þ§à§Ô§å§ä §Ó§í§Ô§Ý§ñ§Õ§Ö§ä§î §ã§Ý§Ö§Õ§å§ð§ë§Ú§Þ §à§Ò§â§Ñ§Ù§à§Þ:

TLSConnect=cert
       TLSAccept=cert
       TLSCAFile=/home/zabbix/zabbix_ca_file
       TLSServerCertIssuer=CN=Signing CA,OU=Development group,O=Áú»¢¶Ä²© SIA,DC=zabbix,DC=com
       TLSServerCertSubject=CN=Áú»¢¶Ä²© proxy,OU=Development group,O=Áú»¢¶Ä²© SIA,DC=zabbix,DC=com
       TLSCertFile=/home/zabbix/zabbix_agentd.crt
       TLSKeyFile=/home/zabbix/zabbix_agentd.key

(§±§â§Ú§Þ§Ö§â §á§â§Ö§Õ§á§à§Ý§Ñ§Ô§Ñ§Ö§ä, §é§ä§à §ç§à§ã§ä §ß§Ñ§Ò§Ý§ð§Õ§Ñ§Ö§ä§ã§ñ §é§Ö§â§Ö§Ù §á§â§à§Ü§ã§Ú, §à§ä§ã§ð§Õ§Ñ §³§å§Ò§ì§Ö§Ü§ä §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ §á§â§à§Ü§ã§Ú.)

5. §¯§Ñ§ã§ä§â§à§Û§ä§Ö §ê§Ú§æ§â§à§Ó§Ñ§ß§Ú§Ö §ï§ä§à§Þ§å §Ñ§Ô§Ö§ß§ä§å §Ó §Ó§Ö§Ò-§Ú§ß§ä§Ö§â§æ§Ö§Û§ã§Ö Áú»¢¶Ä²©:

  • §±§Ö§â§Ö§Û§Õ§Ú§ä§Ö §Ó: §¯§Ñ§ã§ä§â§à§Û§Ü§Ñ ¡ú §µ§Ù§Ý§í §ã§Ö§ä§Ú
  • §£§í§Ò§Ö§â§Ú§ä§Ö §å§Ù§Ö§Ý §ã§Ö§ä§Ú §Ú §ß§Ñ§Ø§Þ§Ú§ä§Ö §ß§Ñ §Ó§Ü§Ý§Ñ§Õ§Ü§å §º§Ú§æ§â§à§Ó§Ñ§ß§Ú§Ö

§£ §á§â§Ú§Þ§Ö§â§Ö §ß§Ú§Ø§Ö §á§à§Ý§ñ §¿§Þ§Ú§ä§Ö§ß§ä §Ú §³§å§Ò§ì§Ö§Ü§ä §Ù§Ñ§á§à§Ý§ß§Ö§ß§í - §ã§Þ§à§ä§â§Ú§ä§Ö §°§Ô§â§Ñ§ß§Ú§é§Ö§ß§Ú§Ö §â§Ñ§Ù§â§Ö§ê§Ö§ß§ß§í§ç §¿§Þ§Ú§ä§Ö§ß§ä§Ñ §Ú §³§å§Ò§ì§Ö§Ü§ä§Ñ §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ §à §ä§à§Þ, §Ü§Ñ§Ü §Ú§ã§á§à§Ý§î§Ù§à§Ó§Ñ§ä§î §ï§ä§Ú §á§à§Ý§ñ.

agent_config.png

Áú»¢¶Ä²© web service

1. Prepare files with the top-level CA certificates, the Áú»¢¶Ä²© web service certificate/certificate chain, and the private key as described in the Áú»¢¶Ä²© server section. Then, edit the TLSCAFile, TLSCertFile, and TLSKeyFile parameters in the Áú»¢¶Ä²© web service configuration file accordingly.

2. Edit an additional TLS parameter in the Áú»¢¶Ä²© web service configuration file: TLSAccept=cert

TLS parameters in the final web service configuration file may look as follows:

TLSAccept=cert
       TLSCAFile=/home/zabbix/zabbix_ca_file
       TLSCertFile=/home/zabbix/zabbix_web_service.crt
       TLSKeyFile=/home/zabbix/zabbix_web_service.key

3. Configure Áú»¢¶Ä²© server to connect to the TLS-configured Áú»¢¶Ä²© web service by editing the WebServiceURL parameter in the Áú»¢¶Ä²© server configuration file:

WebServiceURL=https://example.com

§°§Ô§â§Ñ§ß§Ú§é§Ö§ß§Ú§Ö §â§Ñ§Ù§â§Ö§ê§Ö§ß§ß§í§ç §¿§Þ§Ú§ä§Ö§ß§ä§Ñ §Ú §³§å§Ò§ì§Ö§Ü§ä§Ñ §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ

§¬§à§Ô§Õ§Ñ §Õ§Ó§Ñ §Ü§à§Þ§á§à§ß§Ö§ß§ä§Ñ Áú»¢¶Ä²© (§ß§Ñ§á§â§Ú§Þ§Ö§â, §ã§Ö§â§Ó§Ö§â §Ú §Ñ§Ô§Ö§ß§ä) §å§ã§ä§Ñ§ß§Ñ§Ó§Ý§Ú§Ó§Ñ§ð§ä TLS §ã§à§Ö§Õ§Ú§ß§Ö§ß§Ú§Ö, §à§ß§Ú §à§Ò§Ñ §á§â§à§Ó§Ö§â§ñ§ð§ä §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§í §Õ§â§å§Ô §Õ§â§å§Ô§Ñ. §¦§ã§Ý§Ú §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä §å§Ù§Ý§Ñ §á§à§Õ§á§Ú§ã§Ñ§ß §Õ§à§Ó§Ö§â§Ö§ß§ß§í§Þ CA (§ã §á§â§Ö§Õ§Ó§Ñ§â§Ú§ä§Ö§Ý§î§ß§à §á§à§Õ§Ô§à§ä§à§Ó§Ý§Ö§ß§ß§í§Þ §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§à§Þ §Ó§Ö§â§ç§ß§Ö§Ô§à §å§â§à§Ó§ß§ñ §Ó TLSCAFile), §ñ§Ó§Ý§ñ§Ö§ä§ã§ñ §Õ§Ö§Û§ã§ä§Ó§Ú§ä§Ö§Ý§î§ß§í§Þ, §à§ß §ß§Ö §Ú§ã§ä§×§Ü §Ú §á§â§à§ç§à§Õ§Ú§ä §ß§Ö§Ü§à§ä§à§â§í§Ö §Õ§â§å§Ô§Ú§Ö §á§â§à§Ó§Ö§â§Ü§Ú, §ä§à§Ô§Õ§Ñ §Ü§à§Þ§Þ§å§ß§Ú§Ü§Ñ§è§Ú§ñ §Þ§à§Ø§Ö§ä §á§â§à§Õ§à§Ý§Ø§Ñ§ä§î§ã§ñ. §¿§Þ§Ú§ä§Ö§ß§ä §Ú §ã§å§Ò§ì§Ö§Ü§ä §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ §Ó §ï§ä§à§Þ §á§â§à§ã§ä§à§Þ §ã§Ý§å§é§Ñ§Ö §ß§Ö §á§â§à§Ó§Ö§â§ñ§Ö§ä§ã§ñ.

§©§Õ§Ö§ã§î §Ú§Þ§Ö§Ö§ä§ã§ñ §â§Ú§ã§Ü - §Ü§ä§à-§å§Ô§à§Õ§ß§à §á§â§Ú §ß§Ñ§Ý§Ú§é§Ú§Ú §Õ§Ö§Û§ã§ä§Ó§Ú§ä§Ö§Ý§î§ß§à§Ô§à §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ §Þ§à§Ø§Ö§ä §Ó§í§Õ§Ñ§Ó§Ñ§ä§î §ã§Ö§Ò§ñ §Ù§Ñ §Õ§â§å§Ô§à§Ô§à (§ß§Ñ§á§â§Ú§Þ§Ö§â, §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä §ç§à§ã§ä§Ñ §Þ§à§Ø§ß§à §Ú§ã§á§à§Ý§î§Ù§à§Ó§Ñ§ä§î, §é§ä§à§Ò§í §Ó§í§Õ§Ñ§Ó§Ñ§ä§î §ã§Ö§Ò§ñ §Ù§Ñ §ã§Ö§â§Ó§Ö§â). §´§Ñ§Ü§à§Ö §á§à§Ó§Ö§Õ§Ö§ß§Ú§Ö §Þ§à§Ø§Ö§ä §Ò§í§ä§î §á§â§Ú§Ö§Þ§Ý§Ö§Þ§à §Ó §ß§Ö§Ò§à§Ý§î§ê§Ú§ç §ã§â§Ö§Õ§Ñ§ç, §Ô§Õ§Ö §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§í §á§à§Õ§á§Ú§ã§í§Ó§Ñ§ð§ä§ã§ñ §ã§á§Ö§è§Ú§Ñ§Ý§Ú§Ù§Ú§â§à§Ó§Ñ§ß§ß§à§Ô§à §Ó§ß§å§ä§â§Ö§ß§ß§Ö§Ô§à CA §Ú §â§Ú§ã§Ü §Õ§Ö§Û§ã§ä§Ó§Ú§Û §à§ä §é§å§Ø§à§Ô§à §Ú§Þ§Ö§ß§Ú §ñ§Ó§Ý§ñ§Ö§ä§ã§ñ §Þ§Ú§ß§Ú§Þ§Ñ§Ý§î§ß§í§Þ.

§¦§ã§Ý§Ú §Ó§Ñ§ê CA §Ó§Ö§â§ç§ß§Ö§Ô§à §å§â§à§Ó§ß§ñ §Ú§ã§á§à§Ý§î§Ù§å§Ö§ä§ã§ñ §Õ§Ý§ñ §Ó§í§Õ§Ñ§é§Ú §Õ§â§å§Ô§Ú§ç §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§à§Ó, §Ü§à§ä§à§â§í§Ö §ß§Ö §Õ§à§Ý§Ø§ß§í §á§â§Ú§ß§Ú§Þ§Ñ§ä§î§ã§ñ Áú»¢¶Ä²© §Ú§Ý§Ú §Ó§í §ç§à§ä§Ú§ä§Ö §ã§ß§Ú§Ù§Ú§ä§î §â§Ú§ã§Ü §Õ§Ö§Û§ã§ä§Ó§Ú§Û §à§ä §é§å§Ø§à§Ô§à §Ú§Þ§Ö§ß§Ú, §Ó§í §Þ§à§Ø§Ö§ä§Ö §à§Ô§â§Ñ§ß§Ú§é§Ú§ä§î §â§Ñ§Ù§â§Ö§ê§Ö§ß§ß§í§Ö §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§í, §å§Ü§Ñ§Ù§Ñ§Ó §Ú§ç §ã§ä§â§à§Ü§Ú §¿§Þ§Ú§ä§Ö§ß§ä§Ñ §Ú §³§å§Ò§ì§Ö§Ü§ä§Ñ.

§¯§Ñ§á§â§Ú§Þ§Ö§â, §Ó§í §Þ§à§Ø§Ö§ä§Ö §Ù§Ñ§á§Ú§ã§Ñ§ä§î §Ó §æ§Ñ§Û§Ý §Ü§à§ß§æ§Ú§Ô§å§â§Ñ§è§Ú§Ú Áú»¢¶Ä²© §á§â§à§Ü§ã§Ú:

TLSServerCertIssuer=CN=Signing CA,OU=Development group,O=Áú»¢¶Ä²© SIA,DC=zabbix,DC=com
       TLSServerCertSubject=CN=Áú»¢¶Ä²© server,OU=Development group,O=Áú»¢¶Ä²© SIA,DC=zabbix,DC=com

§±§â§Ú §ß§Ñ§Ý§Ú§é§Ú§Ú §ï§ä§Ú§ç §ß§Ñ§ã§ä§â§à§Ö§Ü §Ñ§Ü§ä§Ú§Ó§ß§í§Û §á§â§à§Ü§ã§Ú §ß§Ö §Ò§å§Õ§Ö§ä §â§Ñ§Ù§Ô§à§Ó§Ñ§â§Ú§Ó§Ñ§ä§î §ã Áú»¢¶Ä²© §ã§Ö§â§Ó§Ö§â§à§Þ §ã §Õ§â§å§Ô§Ú§Þ§Ú §ã§ä§â§à§Ü§Ñ§Þ§Ú §¿§Þ§Ú§ä§Ö§ß§ä§Ñ §Ú §³§å§Ò§ì§Ö§Ü§ä§Ñ §Ó §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ö, §á§Ñ§ã§ã§Ú§Ó§ß§í§Û §á§â§à§Ü§ã§Ú §ß§Ö §á§â§Ú§Þ§Ö§â §Ù§Ñ§á§â§à§ã§í §à§ä §ä§Ñ§Ü§à§Ô§à §ã§Ö§â§Ó§Ö§â§Ñ.

§¯§Ö§ã§Ü§à§Ý§î§Ü§à §Ù§Ñ§Þ§Ö§ä§à§Ü §à §ã§à§à§ä§Ó§Ö§ä§ã§ä§Ó§Ú§Ú §ã§ä§â§à§Ü §¿§Þ§Ú§ä§Ö§ß§ä§Ñ §Ú §³§å§Ò§ì§Ö§Ü§ä§Ñ:

  1. §³§ä§â§à§Ü§Ú §¿§Þ§Ú§ä§Ö§ß§ä§Ñ §Ú §³§å§Ò§ì§Ö§Ü§ä§Ñ §á§â§à§Ó§Ö§â§ñ§ð§ä§ã§ñ §ß§Ö§Ù§Ñ§Ó§Ú§ã§Ú§Þ§à. §°§Ò§Ö §ã§ä§â§à§Ü§Ú §à§á§è§Ú§à§ß§Ñ§Ý§î§ß§í.
  2. §¥§à§á§å§ã§ä§Ú§Þ§í §ã§Ú§Þ§Ó§à§Ý§í UTF-8.
  3. §¯§Ö §å§Ü§Ñ§Ù§Ñ§ß§ß§Ñ§ñ §ã§ä§â§à§Ü§Ñ §à§Ù§ß§Ñ§é§Ñ§Ö§ä, §é§ä§à §á§â§Ú§ß§Ú§Þ§Ñ§Ö§ä§ã§ñ §Ý§ð§Ò§Ñ§ñ §ã§ä§â§à§Ü§Ñ.
  4. §³§ä§â§à§Ü§Ú §ã§â§Ñ§Ó§ß§Ú§Ó§Ñ§ð§ä§ã§ñ "§Ü§Ñ§Ü-§Ö§ã§ä§î", §à§ß§Ú §Õ§à§Ý§Ø§ß§í §Ó §ä§à§é§ß§à§ã§ä§Ú §Ò§í§ä§î §ä§Ñ§Ü§Ú§Þ§Ú §Ø§Ö.
  5. §º§Ñ§Ò§Ý§à§ß§í §Ú §â§Ö§Ô§å§Ý§ñ§â§ß§í§Ö §Ó§í§â§Ñ§Ø§Ö§ß§Ú§ñ §á§â§Ú §á§â§à§Ó§Ö§â§Ü§Ö §ã§à§à§ä§Ó§Ö§ä§ã§ä§Ó§Ú§ñ §ß§Ö §á§à§Õ§Õ§Ö§â§Ø§Ú§Ó§Ñ§ð§ä§ã§ñ.
  6. §²§Ö§Ñ§Ý§Ú§Ù§à§Ó§Ñ§ß§í §ä§à§Ý§î§Ü§à §ß§Ö§Ü§à§ä§à§â§í§Ö §ä§â§Ö§Ò§à§Ó§Ñ§ß§Ú§ñ §Ú§Ù :
    - §å§á§â§Ñ§Ó§Ý§ñ§ð§ë§Ú§Ö §ã§Ú§Þ§Ó§à§Ý§í '"' (U+0022), '+' U+002B, ',' U+002C, ';' U+003B, '<' U+003C, '>' U+003E, '\' U+005C §Ó §Ý§ð§Ò§à§Þ §Þ§Ö§ã§ä§Ö §Ó §ã§ä§â§à§Ü§Ö.
           - §å§á§â§Ñ§Ó§Ý§ñ§ð§ë§Ú§Ö §ã§Ú§Þ§Ó§à§Ý§í §á§â§à§Ò§Ö§Ý§Ñ (' ' U+0020) §Ú§Ý§Ú §ã§Ú§Þ§Ó§à§Ý §â§Ö§ê§Ö§ä§Ü§Ú ('#' U+0023) §Ó §ß§Ñ§é§Ñ§Ý§Ö §ã§ä§â§à§Ü§Ú.
           - §å§á§â§Ñ§Ó§Ý§ñ§ð§ë§Ú§Û §ã§Ú§Þ§Ó§à§Ý §á§â§à§Ò§Ö§Ý§Ñ (' ' U+0020) §Ó §Ü§à§ß§è§Ö §ã§ä§â§à§Ü§Ú.
       - §³§à§Ó§á§Ñ§Õ§Ö§ß§Ú§ñ §ß§Ö §Ò§å§Õ§Ö§ä, §Ö§ã§Ý§Ú §Ó§ã§ä§â§Ö§é§Ñ§Ö§ä§ã§ñ §ß§å§Ý§Ö§Ó§à§Û §ã§Ú§Þ§Ó§à§Ý (U+0000) ([[http://tools.ietf.org/html/rfc4514|RFC 4514]] §á§à§Ù§Ó§à§Ý§ñ§Ö§ä §ï§ä§à).
       - §´§â§Ö§Ò§à§Ó§Ñ§ß§Ú§ñ [[http://tools.ietf.org/html/rfc4517| RFC 4517 Lightweight Directory Access Protocol (LDAP): Syntaxes and Matching Rules]] §Ú [[http://tools.ietf.org/html/rfc4518|RFC 4518 Lightweight Directory Access Protocol (LDAP): Internationalized String Preparation]] §ß§Ö §á§à§Õ§Õ§Ö§â§Ø§Ú§Ó§Ñ§ð§ä§ã§ñ §á§à §á§â§Ú§é§Ú§ß§Ö §ß§Ö§à§Ò§ç§à§Õ§Ú§Þ§à§Ô§à §à§Ò§ì§Ö§Þ§Ñ §â§Ñ§Ò§à§ä§í.

§°§é§Ö§â§Ö§Õ§ß§à§ã§ä§î §á§à§Ý§Ö§Û §Ó §¿§Þ§Ú§ä§Ö§ß§ä§Ñ §Ú §³§å§Ò§ì§Ö§Ü§ä§Ñ §ã§ä§â§à§Ü§Ñ§ç §Ú §æ§à§â§Þ§Ñ§ä§Ú§â§à§Ó§Ñ§ß§Ú§Ö §à§é§Ö§ß§î §Ó§Ñ§Ø§ß§í! Áú»¢¶Ä²© §ã§Ý§Ö§Õ§å§Ö§ä §â§Ö§Ü§à§Þ§Ö§ß§Õ§Ñ§è§Ú§Ú §Ú §Ú§ã§á§à§Ý§î§Ù§å§Ö§ä "§à§Ò§â§Ñ§ä§ß§í§Û" §á§à§â§ñ§Õ§à§Ü §ï§ä§Ú§ç §á§à§Ý§Ö§Û.

§°§Ò§â§Ñ§ä§ß§í§Û §á§à§â§ñ§Õ§à§Ü §Þ§à§Ø§ß§à §á§â§à§Õ§Ö§Þ§à§ß§ã§ä§â§Ú§â§à§Ó§Ñ§ä§î §Ó §á§â§Ú§Þ§Ö§â§Ö:

TLSServerCertIssuer=CN=Signing CA,OU=Development group,O=Áú»¢¶Ä²© SIA,DC=zabbix,DC=com
       TLSServerCertSubject=CN=Áú»¢¶Ä²© proxy,OU=Development group,O=Áú»¢¶Ä²© SIA,DC=zabbix,DC=com

§°§Ò§â§Ñ§ä§Ú§ä§Ö §Ó§ß§Ú§Þ§Ñ§ß§Ú§Ö, §é§ä§à §à§ß §ß§Ñ§é§Ú§ß§Ñ§Ö§ä§ã§ñ §ã §Ó§Ö§â§ç§ß§Ö§Ô§à §å§â§à§Ó§ß§ñ (CN), §á§Ö§â§Ö§ç§à§Õ§Ú§ä §Ü §ã§â§Ö§Õ§ß§Ö§Þ§å §å§â§à§Ó§ß§ð (OU, O) §Ú §Ù§Ñ§Ü§Ñ§ß§é§Ú§Ó§Ñ§Ö§ä§ã§ñ §á§à§Ý§ñ§Þ§Ú §Ó§Ö§â§ç§ß§Ö§Ô§à §å§â§à§Ó§ß§ñ (DC).

§±§à §å§Þ§à§Ý§é§Ñ§ß§Ú§ð OpenSSL §à§ä§à§Ò§â§Ñ§Ø§Ñ§Ö§ä §á§à§Ý§ñ §¿§Þ§Ú§ä§Ö§ß§ä§Ñ §Ú §³§å§Ò§ì§Ö§Ü§ä§Ñ §Ó "§ß§à§â§Þ§Ñ§Ý§î§ß§à§Þ" §á§à§â§ñ§Õ§Ü§Ö, §Ó §Ù§Ñ§Ó§Ú§ã§Ú§Þ§à§ã§ä§Ú §à§ä §Ú§ã§á§à§Ý§î§Ù§à§Ó§Ñ§ß§ß§í§ç §Õ§à§á§à§Ý§ß§Ú§ä§Ö§Ý§î§ß§í§ç §à§á§è§Ú§Û:

$ openssl x509 -noout -in /home/zabbix/zabbix_proxy.crt -issuer -subject
       issuer= /DC=com/DC=zabbix/O=Áú»¢¶Ä²© SIA/OU=Development group/CN=Signing CA
       subject= /DC=com/DC=zabbix/O=Áú»¢¶Ä²© SIA/OU=Development group/CN=Áú»¢¶Ä²© proxy
       
       $ openssl x509 -noout -text -in /home/zabbix/zabbix_proxy.crt
       Certificate:
               ...
               Issuer: DC=com, DC=zabbix, O=Áú»¢¶Ä²© SIA, OU=Development group, CN=Signing CA
           ...
               Subject: DC=com, DC=zabbix, O=Áú»¢¶Ä²© SIA, OU=Development group, CN=Áú»¢¶Ä²© proxy

§©§Õ§Ö§ã§î §ã§ä§â§à§Ü§Ú §¿§Þ§Ú§ä§Ö§ß§ä§Ñ §Ú §³§å§Ò§ì§Ö§Ü§ä§Ñ §ß§Ñ§é§Ú§ß§Ñ§ð§ä§ã§ñ §ã §Ó§Ö§â§ç§ß§Ö§Ô§à §å§â§à§Ó§ß§ñ (DC) §Ú §Ù§Ñ§Ü§Ñ§ß§é§Ú§í§Ó§Ñ§ð§ä§ã§ñ §á§à§Ý§Ö§Þ §ß§Ú§Ø§ß§Ö§Ô§à §å§â§à§Ó§ß§ñ (CN), §á§â§à§Ò§Ö§Ý§í §Ú §â§Ñ§Ù§Õ§Ö§Ý§Ú§ä§Ö§Ý§Ú §á§à§Ý§Ö§Û §Ù§Ñ§Ó§Ú§ã§ñ§ä §à§ä §Ú§ã§á§à§Ý§î§Ù§å§Ö§Þ§í§ç §à§á§è§Ú§Û. §¯§Ú §à§Õ§ß§à §Ú§Ù §ï§ä§Ú§ç §Ù§ß§Ñ§é§Ö§ß§Ú§Û §ß§Ö §Ò§å§Õ§Ö§ä §ã§à§Ó§á§Ñ§Õ§Ñ§ä§î §Ó Áú»¢¶Ä²© §á§à§Ý§ñ§ç §¿§Þ§Ú§ä§Ö§ß§ä§Ñ §Ú §³§å§Ò§ì§Ö§Ü§ä§Ñ!

§¥§Ý§ñ §á§à§Ý§å§é§Ö§ß§Ú§ñ §ß§Ñ§Õ§Ý§Ö§Ø§Ñ§ë§Ú§ç §ã§ä§â§à§Ü §¿§Þ§Ú§ä§Ö§ß§ä§Ñ §Ú §³§å§Ò§ì§Ö§Ü§ä§Ñ, §Õ§à§á§å§ã§ä§Þ§í§ç §Ó Áú»¢¶Ä²©, §Ó§í§Ù§à§Ó§Ú§ä§Ö OpenSSL §ã§à §ã§á§Ö§è§Ú§Ñ§Ý§î§ß§í§Þ§Ú §à§á§è§Ú§ñ§Þ§Ú
-nameopt esc_2253,esc_ctrl,utf8,dump_nostr,dump_unknown,dump_der,sep_comma_plus,dn_rev,sname:

$ openssl x509 -noout -issuer -subject -nameopt esc_2253,esc_ctrl,utf8,dump_nostr,dump_unknown,dump_der,sep_comma_plus,dn_rev,sname -in /home/zabbix/zabbix_proxy.crt
       issuer= CN=Signing CA,OU=Development group,O=Áú»¢¶Ä²© SIA,DC=zabbix,DC=com
       subject= CN=Áú»¢¶Ä²© proxy,OU=Development group,O=Áú»¢¶Ä²© SIA,DC=zabbix,DC=com

§´§Ö§á§Ö§â§î §ã§ä§â§à§Ü§à§Ó§í§Ö §á§à§Ý§ñ §ß§Ñ§ç§à§Õ§ñ§ä§ã§ñ §Ó §à§Ò§â§Ñ§ä§ß§à§Þ" §á§à§â§ñ§Õ§Ü§Ö, §á§à§Ý§ñ §â§Ñ§Ù§Õ§Ö§Ý§Ö§ß§í §Ù§Ñ§á§ñ§ä§à§Û, §ã§ä§â§à§Ü§Ú §Þ§à§Ø§ß§à §Ú§ã§á§à§Ý§î§Ù§à§Ó§Ñ§ä§î §Ó §æ§Ñ§Û§Ý§Ñ§ç §Ü§à§ß§æ§Ú§Ô§å§â§Ñ§è§Ú§Ú Áú»¢¶Ä²© §Ú §Ó §Ó§Ö§Ò-§Ú§ß§ä§Ö§â§æ§Ö§Û§ã§Ö.

Rules for matching Issuer and Subject strings

The rules for matching Issuer and Subject strings are as follows:

  • Issuer and Subject strings are checked independently. Both are optional.
  • An unspecified string means that any string is accepted.
  • Strings are compared as is and must match exactly.
  • UTF-8 characters are supported. However, wildcards (*) or regular expressions are not supported.
  • The following requirements are implemented - characters that require escaping (with a '\' backslash, U+005C):
    • anywhere in the string: '"' (U+0022), '+' (U+002B), ',' (U+002C), ';' (U+003B), '<' (U+003C), '>' (U+003E), '\\' (U+005C);
    • at the beginning of the string: space (' ', U+0020) or number sign ('#', U+0023);
    • at the end of the string: space (' ', U+0020).
  • Null characters (U+0000) are not supported. If a null character is encountered, the matching will fail.
  • and standards are not supported.

For example, if Issuer and Subject organization (O) strings contain trailing spaces and the Subject organizational unit (OU) string contains double quotes, these characters must be escaped:

TLSServerCertIssuer=CN=Signing CA,OU=Development head,O=\ Example SIA\ ,DC=example,DC=com
       TLSServerCertSubject=CN=Áú»¢¶Ä²© server,OU=Development group \"5\",O=\ Example SIA\ ,DC=example,DC=com
Field order and formatting

Áú»¢¶Ä²© follows the recommendations of , which specifies a "reverse" order for these fields, starting with the lowest-level fields (CN), proceeding to the mid-level fields (OU, O), and concluding with the highest-level fields (DC).

TLSServerCertIssuer=CN=Signing CA,OU=Development group,O=Áú»¢¶Ä²© SIA,DC=zabbix,DC=com
       TLSServerCertSubject=CN=Áú»¢¶Ä²© proxy,OU=Development group,O=Áú»¢¶Ä²© SIA,DC=zabbix,DC=com

In contrast, OpenSSL by default displays the Issuer and Subject strings in top-level to low-level order. In the following example, Issuer and Subject fields start with the top-level (DC) and end with the low-level (CN) field. The formatting with spaces and field separators also varies based on the options used, and thus will not match the format required by Áú»¢¶Ä²©.

$ openssl x509 -noout -in /home/zabbix/zabbix_proxy.crt -issuer -subject
       issuer= /DC=com/DC=zabbix/O=Áú»¢¶Ä²© SIA/OU=Development group/CN=Signing CA
       subject= /DC=com/DC=zabbix/O=Áú»¢¶Ä²© SIA/OU=Development group/CN=Áú»¢¶Ä²© proxy
       
       $ openssl x509 -noout -text -in /home/zabbix/zabbix_proxy.crt
       Certificate:
           ...
               Issuer: DC=com, DC=zabbix, O=Áú»¢¶Ä²© SIA, OU=Development group, CN=Signing CA
               ...
               Subject: DC=com, DC=zabbix, O=Áú»¢¶Ä²© SIA, OU=Development group, CN=Áú»¢¶Ä²© proxy

To format Issuer and Subject strings correctly for Áú»¢¶Ä²©, invoke OpenSSL with the following options:

$ openssl x509 -noout -issuer -subject \
           -nameopt esc_2253,esc_ctrl,utf8,dump_nostr,dump_unknown,dump_der,sep_comma_plus,dn_rev,sname\
           -in /home/zabbix/zabbix_proxy.crt

The output will then be in reverse order, comma-separated, and usable in Áú»¢¶Ä²© configuration files and frontend:

issuer= CN=Signing CA,OU=Development group,O=Áú»¢¶Ä²© SIA,DC=zabbix,DC=com
       subject= CN=Áú»¢¶Ä²© proxy,OU=Development group,O=Áú»¢¶Ä²© SIA,DC=zabbix,DC=com

§°§Ô§â§Ñ§ß§Ú§é§Ö§ß§Ú§ñ §á§â§Ú §Ú§ã§á§à§Ý§î§Ù§à§Ó§Ñ§ß§Ú§Ú §â§Ñ§ã§ê§Ú§â§Ö§ß§Ú§Û X.509 v3 §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§à§Ó

  • §²§Ñ§ã§ê§Ú§â§Ö§ß§Ú§Ö §¡§Ý§î§ä§Ö§â§ß§Ñ§ä§Ú§Ó§ß§à§Ö §Ú§Þ§ñ §ã§å§Ò§ì§Ö§Ü§ä§Ñ (subjectAltName).
    §¡§Ý§î§ä§Ö§â§ß§Ñ§ä§Ú§Ó§ß§í§Ö §Ú§Þ§Ö§ß§Ñ §ã§å§Ò§ì§Ö§Ü§ä§à§Ó §Ú§Ù subjectAltName §â§Ñ§ã§ê§Ú§â§Ö§ß§Ú§ñ (§ä§Ñ§Ü§Ú§Ö §Ü§Ñ§Ü IP §Ñ§Õ§â§Ö§ã, e-mail §Ñ§Õ§â§Ö§ã) §ß§Ö §á§à§Õ§Õ§Ö§â§Ø§Ú§Ó§Ñ§ð§ä§ã§ñ Áú»¢¶Ä²©. §£ Áú»¢¶Ä²© §á§â§à§Ó§Ö§â§ñ§Ö§ä§ã§ñ §ä§à§Ý§î§Ü§à §Ù§ß§Ñ§é§Ö§ß§Ú§Ö §á§à§Ý§ñ "§³§å§Ò§ì§Ö§Ü§ä" (§ã§Þ§à§ä§â§Ú §°§Ô§â§Ñ§ß§Ú§é§Ö§ß§Ú§Ö §â§Ñ§Ù§â§Ö§ê§Ö§ß§ß§í§ç §¿§Þ§Ú§ä§Ö§ß§ä§Ñ §Ú §³§å§Ò§ì§Ö§Ü§ä§Ñ §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ).
    §¦§ã§Ý§Ú §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä §Ú§ã§á§à§Ý§î§Ù§å§Ö§ä subjectAltName §â§Ñ§ã§ê§Ú§â§Ö§ß§Ú§Ö, §ä§à§Ô§Õ§Ñ §â§Ö§Ù§å§Ý§î§ä§Ñ§ä §Ù§Ñ§Ó§Ú§ã§Ú§ä §à§ä §Ü§à§ß§Ü§â§Ö§ä§ß§à§Û §Ü§à§Þ§Ò§Ú§ß§Ñ§è§Ú§Ú §ß§Ñ§Ò§à§â§à§Ó §Ú§ß§ã§ä§â§å§Þ§Ö§ß§ä§à§Ó §Ü§â§Ú§á§ä§à§Ô§â§Ñ§æ§Ú§Ú §ã §Ü§à§ä§à§â§í§Þ§Ú §ã§Ü§à§Þ§á§Ú§Ý§Ú§â§à§Ó§Ñ§ß§í §Ü§à§Þ§á§à§ß§Ö§ß§ä§í Áú»¢¶Ä²© (§ï§ä§à §â§Ñ§ã§ê§Ú§â§Ö§ß§Ú§Ö §Þ§à§Ø§Ö§ä §â§Ñ§Ò§à§ä§Ñ§ä§î, §Ñ §Þ§à§Ø§Ö§ä §Ú §ß§Ö §â§Ñ§Ò§à§ä§Ñ§ä§î, Áú»¢¶Ä²© §Þ§à§Ø§Ö§ä §à§ä§Ü§Ñ§Ù§Ñ§ä§î§ã§ñ §á§â§Ú§ß§Ú§Þ§Ñ§ä§î §ä§Ñ§Ü§Ú§Ö §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§í §à§ä §å§Ù§Ý§à§Ó).
  • §²§Ñ§ã§ê§Ú§â§Ö§ß§Ú§Ö §ª§ã§á§à§Ý§î§Ù§à§Ó§Ñ§ß§Ú§Ö §²§Ñ§ã§ê§Ú§â§Ö§ß§ß§à§Ô§à §¬§Ý§ð§é§Ñ.
    §¦§ã§Ý§Ú §Ú§ã§á§à§Ý§î§Ù§å§Ö§ä§ã§ñ, §ä§à, §Ü§Ñ§Ü §á§â§Ñ§Ó§Ú§Ý§à, §ß§Ö§à§Ò§ç§à§Õ§Ú§Þ§à §å§Ü§Ñ§Ù§í§Ó§Ñ§ä§î §Ü§Ñ§Ü clientAuth (TLS WWW §Ñ§å§ä§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§ñ §Ü§Ý§Ú§Ö§ß§ä§Ñ), §ä§Ñ§Ü §Ú serverAuth (TLS WWW §Ñ§å§ä§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§ñ §ã§Ö§â§Ó§Ö§â§Ñ).
    §¯§Ñ§á§â§Ú§Þ§Ö§â, §á§â§Ú §á§Ñ§ã§ã§Ú§Ó§ß§í§ç §á§â§à§Ó§Ö§â§Ü§Ñ§ç Áú»¢¶Ä²© §Ñ§Ô§Ö§ß§ä §Ó§í§ã§ä§å§á§Ñ§Ö§ä §Ó §â§à§Ý§Ú TLS §ã§Ö§â§Ó§Ö§â§Ñ, §ä§Ñ§Ü§Ú§Þ §à§Ò§â§Ñ§Ù§à§Þ §ß§Ö§à§Ò§ç§à§Õ§Ú§Þ§à §å§Ü§Ñ§Ù§Ñ§ä§î serverAuth §Ó §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ö §Ñ§Ô§Ö§ß§ä§Ñ. §±§â§Ú §Ñ§Ü§ä§Ú§Ó§ß§í§ç §á§â§à§Ó§Ö§â§Ü§Ñ§ç §Ó §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ö §Ñ§Ô§Ö§ß§ä§Ñ §ß§Ö§à§Ò§ç§à§Õ§Ú§Þ§à §Ù§Ñ§Õ§Ñ§ä§î clientAuth.
    GnuTLS §Ó§í§Ó§à§Õ§Ú§ä §á§â§Ö§Õ§å§á§â§Ö§Ø§Õ§Ö§ß§Ú§Ö §Ó §ã§Ý§å§é§Ñ§Ö §ß§Ñ§â§å§ê§Ö§ß§Ú§ñ §Ú§ã§á§à§Ý§î§Ù§à§Ó§Ñ§ß§Ú§ñ §Ü§Ý§ð§é§Ñ, §ß§à §â§Ñ§Ù§â§Ö§ê§Ñ§Ö§ä §á§â§à§Õ§à§Ý§Ø§Ö§ß§Ú§Ö §ã§à§Ö§Õ§Ú§ß§Ö§ß§Ú§ñ.
  • §²§Ñ§ã§ê§Ú§â§Ö§ß§Ú§Ö §°§Ô§â§Ñ§ß§Ú§é§Ö§ß§Ú§ñ §ª§Þ§Ö§ß§Ú.
    §¯§Ö §Ó§ã§Ö §ß§Ñ§Ò§à§â§í §Ú§ß§ã§ä§â§å§Þ§Ö§ß§ä§à§Ó §Ü§â§Ú§á§ä§à§Ô§â§Ñ§æ§Ú§Ú §á§à§Õ§Õ§Ö§â§Ø§Ú§Ó§Ñ§ð§ä §Ö§Ô§à. §¿§ä§à §â§Ñ§ã§ê§Ú§â§Ö§ß§Ú§Ö §Þ§à§Ø§Ö§ä §á§à§Þ§Ö§ê§Ñ§ä§î Áú»¢¶Ä²© §Ó §Ù§Ñ§Ô§â§å§Ù§Ü§Ö CA §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§à§Ó, §Ô§Õ§Ö §ï§ä§à§ä §â§Ñ§Ù§Õ§Ö§Ý §á§â§à§Þ§Ñ§â§Ü§Ú§â§à§Ó§Ñ§ß §Ü§Ñ§Ü §Ü§â§Ú§ä§Ú§é§Ö§ã§Ü§Ú§Û (§Ù§Ñ§Ó§Ú§ã§Ú§ä §à§ä §Ü§à§ß§Ü§â§Ö§ä§ß§à§Ô§à §ß§Ñ§Ò§à§â§Ñ §Ú§ß§ã§ä§â§å§Þ§Ö§ß§ä§à§Ó §Ü§â§Ú§á§ä§à§Ô§â§Ñ§æ§Ú§Ú).

§³§á§Ú§ã§Ü§Ú §à§ä§à§Ù§Ó§Ñ§ß§ß§í§ç §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§à§Ó (CRL)

§¦§ã§Ý§Ú §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä §ã§Ü§à§Þ§á§â§à§Þ§Ö§ä§Ú§â§à§Ó§Ñ§ß, CA §Þ§à§Ø§Ö§ä §à§ä§à§Ù§Ó§Ñ§ä§î §Ö§Ô§à, §Ó§Ü§Ý§ð§é§Ú§Ó §Ó CRL. §³§á§Ú§ã§Ü§Ú CRL §Þ§à§Ø§ß§à §ß§Ñ§ã§ä§â§Ñ§Ú§Ó§Ñ§ä§î §Ó §æ§Ñ§Û§Ý§Ñ§ç §Ü§à§ß§æ§Ú§Ô§å§â§Ñ§è§Ú§Ú §ã§Ö§â§Ó§Ö§â§Ñ, §á§â§à§Ü§ã§Ú §Ú §Ñ§Ô§Ö§ß§ä§Ñ, §Ú§ã§á§à§Ý§î§Ù§å§ñ §á§Ñ§â§Ñ§Þ§Ö§ä§â TLSCRLFile. §¯§Ñ§á§â§Ú§Þ§Ö§â:

TLSCRLFile=/home/zabbix/zabbix_crl_file

§Ô§Õ§Ö zabbix_crl_file §Þ§à§Ø§Ö§ä §ã§à§Õ§Ö§â§Ø§Ñ§ä§î §ã§á§Ú§ã§Ü§Ú CRL §à§ä §ß§Ö§ã§Ü§à§Ý§î§Ü§Ú§ç CA §Ú §Þ§à§Ø§Ö§ä §Ó§í§Ô§Ý§ñ§Õ§Ö§ä§î §ã§Ý§Ö§Õ§å§ð§ë§Ú§Þ §à§Ò§â§Ñ§Ù§à§Þ:

-----BEGIN X509 CRL-----
       MIIB/DCB5QIBATANBgkqhkiG9w0BAQUFADCBgTETMBEGCgmSJomT8ixkARkWA2Nv
       ...
       treZeUPjb7LSmZ3K2hpbZN7SoOZcAoHQ3GWd9npuctg=
       -----END X509 CRL-----
       -----BEGIN X509 CRL-----
       MIIB+TCB4gIBATANBgkqhkiG9w0BAQUFADB/MRMwEQYKCZImiZPyLGQBGRYDY29t
       ...
       CAEebS2CND3ShBedZ8YSil59O6JvaDP61lR5lNs=
       -----END X509 CRL-----

CRL §æ§Ñ§Û§Ý §Ù§Ñ§Ô§â§å§Ø§Ñ§Ö§ä§ã§ñ §ä§à§Ý§î§Ü§à §á§â§Ú §Ù§Ñ§á§å§ã§Ü§Ö Áú»¢¶Ä²©. §±§â§Ú §à§Ò§ß§à§Ó§Ý§Ö§ß§Ú§Ú CRL §ä§â§Ö§Ò§å§Ö§ä§ã§ñ §á§Ö§â§Ö§Ù§Ñ§á§å§ã§Ü.

§¦§ã§Ý§Ú §Ü§à§Þ§á§à§ß§Ö§ß§ä Áú»¢¶Ä²© §ã§Ü§à§Þ§á§Ú§Ý§Ú§â§à§Ó§Ñ§ß §ã OpenSSL §Ú §Ú§ã§á§à§Ý§î§Ù§å§ð§ä§ã§ñ §ã§á§Ú§ã§Ü§Ú CRL, §ä§à§Ô§Õ§Ñ §Ü§Ñ§Ø§Õ§í§Û §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä §Ó§Ö§â§ç§ß§Ö§Ô§à §Ú §á§â§à§Þ§Ö§Ø§å§ä§à§é§ß§à§Ô§à §å§â§à§Ó§ß§Ö§Û CA §Ó §è§Ö§á§à§é§Ü§Ñ§ç §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§à§Ó §Õ§à§Ý§Ø§Ö§ß §Ú§Þ§Ö§ä§î §ã§à§à§ä§Ó§Ö§ä§ã§ä§Ó§å§ð§ë§Ú§Û §ã§á§Ú§ã§à§Ü CRL (§Þ§à§Ø§Ö§ä §Ò§í§ä§î §á§å§ã§ä§í§Þ) §Ó TLSCRLFile.

§°§Ô§â§Ñ§ß§Ú§é§Ö§ß§Ú§ñ §Ó §Ú§ã§á§à§Ý§î§Ù§à§Ó§Ñ§ß§Ú§Ú CRL §â§Ñ§ã§ê§Ú§â§Ö§ß§Ú§Û

  • §²§Ñ§ã§ê§Ú§â§Ö§ß§Ú§Ö §ª§Õ§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§ä§à§â §¬§Ý§ð§é§Ñ §±§à§Ý§ß§à§Þ§à§é§Ú§Û.
    CRL §Õ§Ý§ñ CA §ã §Ú§Õ§Ö§ß§ä§Ú§é§ß§í§Þ§Ú §Ú§Þ§Ö§ß§Ñ§Þ§Ú §Þ§à§Ô§å§ä §ß§Ö §â§Ñ§Ò§à§ä§Ñ§Ö§ä §Ó §ã§Ý§å§é§Ñ§Ö mbedTLS (PolarSSL), §Õ§Ñ§Ø§Ö §ã §â§Ñ§ã§ê§Ú§â§Ö§ß§Ú§Ö§Þ "§ª§Õ§Ö§ß§ä§Ú§æ§Ú§Ü§Ñ§ä§à§â §¬§Ý§ð§é§Ñ §±§à§Ý§ß§à§Þ§à§é§Ú§Û" ("Authority Key Identifier").