Áú»¢¶Ä²© §Þ§à§Ø§Ö§ä §Ú§ã§á§à§Ý§î§Ù§à§Ó§Ñ§ä§î RSA §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§í §Ó §æ§à§â§Þ§Ñ§ä§Ö PEM, §á§à§Õ§á§Ú§ã§Ñ§ß§ß§í§Ö §á§å§Ò§Ý§Ú§é§ß§í§Þ §Ú§Ý§Ú §Ó§ß§å§ä§â§Ö§ß§ß§Ú§Þ §è§Ö§ß§ä§â§à§Þ §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§è§Ú§Ú (CA). §±§â§à§Ó§Ö§â§Ü§Ñ §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ §Ó§í§á§à§Ý§ß§ñ§Ö§ä§ã§ñ §Ó §à§ä§ß§à§ê§Ö§ß§Ú§Ú §ã §Ù§Ñ§â§Ñ§ß§Ö§Ö §á§à§Õ§Ô§à§ä§à§Ó§Ý§Ö§ß§ß§í§Þ CA §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§à§Þ. §³§Ñ§Þ§à§á§à§Õ§á§Ú§ã§Ñ§ß§ß§í§Ö §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§í §ß§Ö §á§à§Õ§Õ§Ö§â§Ø§Ú§Ó§Ñ§ð§ä§ã§ñ. §°§á§è§Ú§à§ß§Ñ§Ý§î§ß§à §Þ§à§Ø§ß§à §Ú§ã§á§à§Ý§î§Ù§à§Ó§Ñ§ä§î §ã§á§Ú§ã§Ü§Ú §à§ä§Ù§í§Ó§à§Ó §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§à§Ó (CRL). §¬§Ñ§Ø§Õ§í§Û §Ü§à§Þ§á§à§ß§Ö§ß§ä Áú»¢¶Ä²© §Þ§à§Ø§Ö§ä §Ú§Þ§Ö§ä§î §ä§à§Ý§î§Ü§à §à§Õ§Ú§ß §ß§Ñ§ã§ä§â§à§Ö§ß§ß§í§Û §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä.
§¥§Ý§ñ §á§à§Ý§å§é§Ö§ß§Ú§ñ §Ò§à§Ý§Ö§Ö §á§à§Õ§â§à§Ò§ß§à§Û §Ú§ß§æ§à§â§Þ§Ñ§è§Ú§Ú §à §ä§à§Þ §Ü§Ñ§Ü §ß§Ñ§ã§ä§â§à§Ú§ä§î §Ú §å§á§â§Ñ§Ó§Ý§ñ§ä§î §Ó§ß§å§ä§â§Ö§ß§ß§Ú§Þ CA, §Ü§Ñ§Ü §Ô§Ö§ß§Ö§â§Ú§â§à§Ó§Ñ§ä§î §Ù§Ñ§á§â§à§ã§í §ß§Ñ §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§í §Ú §á§à§Õ§á§Ú§ã§í§Ó§Ñ§ä§î §Ú§ç, §Ü§Ñ§Ü §à§ä§Ù§í§Ó§Ñ§ä§î §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§í, §Ó§ã§× §ï§ä§à §Ó§í §Þ§à§Ø§Ö§ä§Ö §ß§Ñ§Û§ä§Ú §Ó §Ò§à§Ý§î§ê§à§Þ §Ü§à§Ý§Ú§é§Ö§ã§ä§Ó§Ö §â§Ñ§Ù§Ý§Ú§é§ß§í§ç §â§å§Ü§à§Ó§à§Õ§ã§ä§Ó §Ó §ã§Ö§ä§Ú, §ß§Ñ§á§â§Ú§Þ§Ö§â, .
§´§ë§Ñ§ä§Ö§Ý§î§ß§à §á§â§à§Õ§å§Þ§í§Ó§Ñ§Û§ä§Ö §Ú §ä§Ö§ã§ä§Ú§â§å§Û§ä§Ö §Ó§Ñ§ê§Ú §â§Ñ§ã§ê§Ú§â§Ö§ß§Ú§ñ §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§à§Ó - §ã§Þ§à§ä§â§Ú §°§Ô§â§Ñ§ß§Ú§é§Ö§ß§Ú§ñ §á§â§Ú §Ú§ã§á§à§Ý§î§Ù§à§Ó§Ñ§ß§Ú§Ú §â§Ñ§ã§ê§Ú§â§Ö§ß§Ú§Û X.509 v3 §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§à§Ó.
§±§Ñ§â§Ñ§Þ§Ö§ä§â | §°§Ò§ñ§Ù§Ñ§ä§Ö§Ý§Ö§ß | §°§á§Ú§ã§Ñ§ß§Ú§Ö |
---|---|---|
TLSCAFile | * | §¡§Ò§ã§à§Ý§ð§ä§ß§í§Û §á§å§ä§î §Ü §æ§Ñ§Û§Ý§å, §Ü§à§ä§à§â§í§Û §ã§à§Õ§Ö§â§Ø§Ú§ä §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§í §Ó§Ö§â§ç§ß§Ö§Ô§à §å§â§à§Ó§ß§ñ CA(§Ú) §Õ§Ý§ñ §Ó§Ö§â§Ú§æ§Ú§Ü§Ñ§è§Ú§Ú §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ §å§Ù§Ý§Ñ. §±§â§Ú §ß§Ñ§Ý§Ú§é§Ú§Ú §è§Ö§á§à§é§Ü§Ú §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§à§Ó §ã §ß§Ö§ã§Ü§à§Ý§î§Ü§Ú§Þ§Ú §é§Ý§Ö§ß§Ñ§Þ§Ú, §à§ß§Ú §Õ§à§Ý§Ø§ß§í §Ò§í§ä§î §à§ä§ã§à§â§ä§Ú§â§à§Ó§Ñ§ß§í: §ã§ß§Ñ§é§Ñ§Ý§Ñ §ã§Ý§Ö§Õ§å§ð§ä §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§í CA §ß§Ú§Ù§Ü§à§Ô§à §å§â§à§Ó§ß§ñ §Ù§Ñ §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ§Þ§Ú §Ò§à§Ý§Ö§Ö §Ó§í§ã§à§Ü§à§Ô§à §å§â§à§Ó§ß§ñ CA(§Ú). §³§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§í §Ú§Ù §ß§Ö§ã§Ü§à§Ý§î§Ü§Ú§ç CA(§Ú) §Þ§à§Ø§ß§à §Ó§Ü§Ý§ð§é§Ñ§ä§î §Ó §à§Õ§Ú§ß §æ§Ñ§Û§Ý. |
TLSCRLFile | §¡§Ò§ã§à§Ý§ð§ä§ß§í§Û §á§å§ä§î §Ü §æ§Ñ§Û§Ý§å, §Ü§à§ä§à§â§í§Û §ã§à§Õ§Ö§â§Ø§Ú§ä §ã§á§Ú§ã§Ü§Ú §à§ä§à§Ù§Ó§Ñ§ß§ß§í§ç §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§à§Ó. §³§Þ§à§ä§â§Ú§ä§Ö §Ù§Ñ§Þ§Ö§ä§Ü§Ú §Ó §³§á§Ú§ã§Ü§Ú §à§ä§à§Ù§Ó§Ñ§ß§ß§í§ç §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§à§Ó (CRL). | |
TLSCertFile | * | §¡§Ò§ã§à§Ý§ð§ä§ß§í§Û §á§å§ä§î §Ü §æ§Ñ§Û§Ý§å, §Ü§à§ä§à§â§í§Û §ã§à§Õ§Ö§â§Ø§Ú§ä §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä (§è§Ö§á§à§é§Ü§å §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§à§Ó). §£ §ã§Ý§å§é§Ñ§Ö §è§Ö§á§à§é§Ü§Ú §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§à§Ó §ã §ß§Ö§ã§Ü§à§Ý§î§Ü§Ú§Þ§Ú §é§Ý§Ö§ß§Ñ§Þ§Ú §à§ß§Ú §Õ§à§Ý§Ø§ß§í §Ò§í§ä§î §à§ä§ã§à§â§ä§Ú§â§à§Ó§Ñ§ß§í: §ã§ß§Ñ§é§Ñ§Ý§Ñ §ã§Ö§â§Ó§Ö§â, §á§â§à§Ü§ã§Ú §Ú§Ý§Ú §Ñ§Ô§Ö§ß§ä, §ã §á§à§ã§Ý§Ö§Õ§å§ð§ë§Ú§Þ§Ú CA §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ§Þ§Ú §ß§Ú§Ù§Ü§à§Ô§à §å§â§à§Ó§ß§ñ §Ú §Ù§Ñ§ä§Ö§Þ CA §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§í §Ò§à§Ý§Ö§Ö §Ó§í§ã§à§Ü§à§Ô§à §å§â§à§Ó§ß§ñ. |
TLSKeyFile | * | §¡§Ò§ã§à§Ý§ð§ä§ß§í§Û §á§å§ä§î §Ü §æ§Ñ§Û§Ý§å, §Ü§à§ä§à§â§í§Û §ã§à§Õ§Ö§â§Ø§Ú§ä §á§â§Ú§Ó§Ñ§ä§ß§í§Û §Ü§Ý§ð§é. §©§Ñ§Õ§Ñ§Û§ä§Ö §á§â§Ñ§Ó§Ñ §Õ§à§ã§ä§å§á§Ñ §Ü §ï§ä§à§Þ§å §æ§Ñ§Û§Ý§å - §à§ß §Õ§à§Ý§Ø§Ö§ß §Ò§í§ä§î §Õ§à§ã§ä§å§á§Ö§ß §Õ§Ý§ñ §é§ä§Ö§ß§Ú§ñ §ä§à§Ý§î§Ü§à §á§à§Ý§î§Ù§à§Ó§Ñ§ä§Ö§Ý§ð Áú»¢¶Ä²©. |
TLSServerCertIssuer | §²§Ñ§Ù§â§Ö§ê§Ö§ß§ß§í§Û §ï§Þ§Ú§ä§Ö§ß§ä §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ §ã§Ö§â§Ó§Ö§â§Ñ. | |
TLSServerCertSubject | §²§Ñ§Ù§â§Ö§ê§Ö§ß§ß§í§Û §ã§å§Ò§ì§Ö§Ü§ä §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ §ã§Ö§â§Ó§Ö§â§Ñ. |
After setting up the necessary certificates, configure Áú»¢¶Ä²© components to use certificate-based encryption.
Below are detailed steps for configuring:
1. §¥§Ý§ñ §ä§à§Ô§à, §é§ä§à§Ò§í §á§â§à§Ó§Ö§â§ñ§ä§î §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§í §ç§à§ã§ä§à§Ó, Áú»¢¶Ä²© §ã§Ö§â§Ó§Ö§â §Õ§à§Ý§Ø§Ö§ß §Ú§Þ§Ö§ä§î §Õ§à§ã§ä§å§á §Ü §æ§Ñ§Û§Ý§å §ã §Ú§ç §Ü§à§â§ß§Ö§Ó§í§Þ§Ú §Ó§Ö§â§ç§ß§Ö§Ô§à §å§â§à§Ó§ß§ñ §ã§Ñ§Þ§à§á§à§Õ§á§Ú§ã§ß§í§Þ§Ú CA §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ§Þ§Ú. §¯§Ñ§á§â§Ú§Þ§Ö§â, §Ö§ã§Ý§Ú §Þ§í §à§Ø§Ú§Õ§Ñ§Ö§Þ §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§í §à§ä §Õ§Ó§å§ç §ß§Ö§Ù§Ñ§Ó§Ú§ã§Ú§Þ§í§ç §Ü§à§â§ß§Ö§Ó§í§ç CA, §Þ§í §Þ§à§Ø§Ö§Þ §á§à§Þ§Ö§ã§ä§Ú§ä§î §Ú§ç §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§í §Ó §æ§Ñ§Û§Ý /home/zabbix/zabbix_ca_file
, §á§â§Ú§Þ§Ö§â§ß§à §ã§Ý§Ö§Õ§å§ð§ë§Ú§Þ §à§Ò§â§Ñ§Ù§à§Þ:
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 1 (0x1)
Signature Algorithm: sha1WithRSAEncryption
Issuer: DC=com, DC=zabbix, O=Áú»¢¶Ä²© SIA, OU=Development group, CN=Root1 CA
...
Subject: DC=com, DC=zabbix, O=Áú»¢¶Ä²© SIA, OU=Development group, CN=Root1 CA
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
...
X509v3 extensions:
X509v3 Key Usage: critical
Certificate Sign, CRL Sign
X509v3 Basic Constraints: critical
CA:TRUE
...
-----BEGIN CERTIFICATE-----
MIID2jCCAsKgAwIBAgIBATANBgkqhkiG9w0BAQUFADB+MRMwEQYKCZImiZPyLGQB
....
9wEzdN8uTrqoyU78gi12npLj08LegRKjb5hFTVmO
-----END CERTIFICATE-----
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 1 (0x1)
Signature Algorithm: sha1WithRSAEncryption
Issuer: DC=com, DC=zabbix, O=Áú»¢¶Ä²© SIA, OU=Development group, CN=Root2 CA
...
Subject: DC=com, DC=zabbix, O=Áú»¢¶Ä²© SIA, OU=Development group, CN=Root2 CA
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
....
X509v3 extensions:
X509v3 Key Usage: critical
Certificate Sign, CRL Sign
X509v3 Basic Constraints: critical
CA:TRUE
....
-----BEGIN CERTIFICATE-----
MIID3DCCAsSgAwIBAgIBATANBgkqhkiG9w0BAQUFADB/MRMwEQYKCZImiZPyLGQB
...
vdGNYoSfvu41GQAR5Vj5FnRJRzv5XQOZ3B6894GY1zY=
-----END CERTIFICATE-----
2. §±§à§Þ§Ö§ã§ä§Ú§ä§Ö §è§Ö§á§à§é§Ü§å §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§à§Ó Áú»¢¶Ä²© §ã§Ö§â§Ó§Ö§â§Ñ §Ó §æ§Ñ§Û§Ý, §ß§Ñ§á§â§Ú§Þ§Ö§â, /home/zabbix/zabbix_server.crt
:
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 1 (0x1)
Signature Algorithm: sha1WithRSAEncryption
Issuer: DC=com, DC=zabbix, O=Áú»¢¶Ä²© SIA, OU=Development group, CN=Signing CA
...
Subject: DC=com, DC=zabbix, O=Áú»¢¶Ä²© SIA, OU=Development group, CN=Áú»¢¶Ä²© server
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
...
X509v3 extensions:
X509v3 Key Usage: critical
Digital Signature, Key Encipherment
X509v3 Basic Constraints:
CA:FALSE
...
-----BEGIN CERTIFICATE-----
MIIECDCCAvCgAwIBAgIBATANBgkqhkiG9w0BAQUFADCBgTETMBEGCgmSJomT8ixk
...
h02u1GHiy46GI+xfR3LsPwFKlkTaaLaL/6aaoQ==
-----END CERTIFICATE-----
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 2 (0x2)
Signature Algorithm: sha1WithRSAEncryption
Issuer: DC=com, DC=zabbix, O=Áú»¢¶Ä²© SIA, OU=Development group, CN=Root1 CA
...
Subject: DC=com, DC=zabbix, O=Áú»¢¶Ä²© SIA, OU=Development group, CN=Signing CA
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
...
X509v3 extensions:
X509v3 Key Usage: critical
Certificate Sign, CRL Sign
X509v3 Basic Constraints: critical
CA:TRUE, pathlen:0
...
-----BEGIN CERTIFICATE-----
MIID4TCCAsmgAwIBAgIBAjANBgkqhkiG9w0BAQUFADB+MRMwEQYKCZImiZPyLGQB
...
dyCeWnvL7u5sd6ffo8iRny0QzbHKmQt/wUtcVIvWXdMIFJM0Hw==
-----END CERTIFICATE-----
§©§Õ§Ö§ã§î §á§Ö§â§Ó§í§Þ §ñ§Ó§Ý§ñ§Ö§ä§ã§ñ §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä Áú»¢¶Ä²© §ã§Ö§â§Ó§Ö§â§Ñ, §Ù§Ñ §ß§Ú§Þ §á§â§à§Þ§Ö§Ø§å§ä§à§é§ß§í§Ö CA §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä.
3. §±§à§Þ§Ö§ã§ä§Ú§ä§Ö §á§â§Ú§Ó§Ñ§ä§ß§í§Û §Ü§Ý§ð§é Áú»¢¶Ä²© §ã§Ö§â§Ó§Ö§â§Ñ §Ó §æ§Ñ§Û§Ý, §ß§Ñ§á§â§Ú§Þ§Ö§â, /home/zabbix/zabbix_server.key
:
-----BEGIN PRIVATE KEY-----
MIIEwAIBADANBgkqhkiG9w0BAQEFAASCBKowggSmAgEAAoIBAQC9tIXIJoVnNXDl
...
IJLkhbybBYEf47MLhffWa7XvZTY=
-----END PRIVATE KEY-----
4. §ª§Ù§Þ§Ö§ß§Ú§ä§Ö §á§Ñ§â§Ñ§Þ§Ö§ä§â§í TLS §Ó §æ§Ñ§Û§Ý§Ö §Ü§à§ß§æ§Ú§Ô§å§â§Ñ§è§Ú§Ú Áú»¢¶Ä²© §ã§Ö§â§Ó§Ö§â§Ñ, §á§â§Ú§Þ§Ö§â§ß§à §ä§Ñ§Ü:
TLSCAFile=/home/zabbix/zabbix_ca_file
TLSCertFile=/home/zabbix/zabbix_server.crt
TLSKeyFile=/home/zabbix/zabbix_server.key
1. §±§à§Õ§Ô§à§ä§à§Ó§î§ä§Ö §æ§Ñ§Û§Ý§í §ã CA §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ§Þ§Ú §Ó§Ö§â§ç§ß§Ö§Ô§à §å§â§à§Ó§ß§ñ, §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§à§Þ (§è§Ö§á§à§é§Ü§à§Û) §á§â§à§Ü§ã§Ú §Ú §á§â§Ú§Ó§Ñ§ä§ß§í§Þ §Ü§Ý§ð§é§Ö§Þ, §Ü§Ñ§Ü §à§á§Ú§ã§Ñ§ß§à §Ó §¯§Ñ§ã§ä§â§à§Û§Ü§Ö §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ §ß§Ñ Áú»¢¶Ä²© §ã§Ö§â§Ó§Ö§â§Ö. §ª§Ù§Þ§Ö§ß§Ú§ä§Ö §á§Ñ§â§Ñ§Þ§Ö§ä§â§í TLSCAFile
, TLSCertFile
, TLSKeyFile
§Ó §æ§Ñ§Û§Ý§Ö §Ü§à§ß§æ§Ú§Ô§å§â§Ñ§è§Ú§Ú §á§â§à§Ü§ã§Ú §ã§à§à§ä§Ó§Ö§ä§ã§ä§Ó§Ö§ß§ß§à.
2. §±§â§Ú §Ñ§Ü§ä§Ú§Ó§ß§à§Þ §á§â§à§Ü§ã§Ú §Ú§Ù§Þ§Ö§ß§Ú§ä§Ö TLSConnect
§á§Ñ§â§Ñ§Þ§Ö§ä§â:
§±§â§Ú §á§Ñ§ã§ã§Ú§Ó§ß§à§Þ §á§â§à§Ü§ã§Ú §Ú§Ù§Þ§Ö§ß§Ú§ä§Ö TLSAccept
§á§Ñ§â§Ñ§Þ§Ö§ä§â:
3. §´§Ö§á§Ö§â§î §å §Ó§Ñ§ã §Ö§ã§ä§î §Þ§Ú§ß§Ú§Þ§Ñ§Ý§î§ß§Ñ§ñ §ß§Ñ§ã§ä§â§à§Û§Ü§Ñ §á§â§à§Ü§ã§Ú §ß§Ñ §à§ã§ß§à§Ó§Ö §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ. §£§í §Ó§à§Ù§Þ§à§Ø§ß§à §Ù§Ñ§ç§à§ä§Ú§ä§Ö §å§Ý§å§é§ê§Ú§ä§î §Ò§Ö§Ù§à§á§Ñ§ã§ß§à§ã§ä§î §á§â§à§Ü§ã§Ú, §å§Ü§Ñ§Ù§Ñ§Ó §á§Ñ§â§Ñ§Þ§Ö§ä§â§í TLSServerCertIssuer
§Ú TLSServerCertSubject
(§ã§Þ§à§ä§â§Ú §°§Ô§â§Ñ§ß§Ú§é§Ö§ß§Ú§Ö §â§Ñ§Ù§â§Ö§ê§Ö§ß§ß§í§ç §¿§Þ§Ú§ä§Ö§ß§ä§Ñ §Ú §³§å§Ò§ì§Ö§Ü§ä§Ñ §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ).
4. §£ §Ü§à§ß§Ö§é§ß§à§Þ §Ú§ä§à§Ô§Ö §á§Ñ§â§Ñ§Þ§Ö§ä§â§í TLS §Ó §æ§Ñ§Û§Ý§Ö §Ü§à§ß§æ§Ú§Ô§å§â§Ñ§è§Ú§Ú §á§â§à§Ü§ã§Ú §Þ§à§Ô§å§ä §Ó§í§Ô§Ý§ñ§Õ§Ö§ä§î §ã§Ý§Ö§Õ§å§ð§ë§Ú§Þ §à§Ò§â§Ñ§Ù§à§Þ:
TLSConnect=cert
TLSAccept=cert
TLSCAFile=/home/zabbix/zabbix_ca_file
TLSServerCertIssuer=CN=Signing CA,OU=Development group,O=Áú»¢¶Ä²© SIA,DC=zabbix,DC=com
TLSServerCertSubject=CN=Áú»¢¶Ä²© server,OU=Development group,O=Áú»¢¶Ä²© SIA,DC=zabbix,DC=com
TLSCertFile=/home/zabbix/zabbix_proxy.crt
TLSKeyFile=/home/zabbix/zabbix_proxy.key
5. §¯§Ñ§ã§ä§â§à§Û§ä§Ö §ê§Ú§æ§â§à§Ó§Ñ§ß§Ú§Ö §ï§ä§à§Þ§å §á§â§à§Ü§ã§Ú §Ó §Ó§Ö§Ò-§Ú§ß§ä§Ö§â§æ§Ö§Û§ã§Ö Áú»¢¶Ä²©:
§£ §á§â§Ú§Þ§Ö§â§Ö §ß§Ú§Ø§Ö §á§à§Ý§ñ §¿§Þ§Ú§ä§Ö§ß§ä §Ú §³§å§Ò§ì§Ö§Ü§ä §Ù§Ñ§á§à§Ý§ß§Ö§ß§í - §ã§Þ§à§ä§â§Ú§ä§Ö §°§Ô§â§Ñ§ß§Ú§é§Ö§ß§Ú§Ö §â§Ñ§Ù§â§Ö§ê§Ö§ß§ß§í§ç §¿§Þ§Ú§ä§Ö§ß§ä§Ñ §Ú §³§å§Ò§ì§Ö§Ü§ä§Ñ §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ §à §ä§à§Þ, §Ü§Ñ§Ü §Ú§ã§á§à§Ý§î§Ù§à§Ó§Ñ§ä§î §ï§ä§Ú §á§à§Ý§ñ.
§±§â§Ú §Ñ§Ü§ä§Ú§Ó§ß§à§Þ §á§â§à§Ü§ã§Ú
§±§â§Ú §á§Ñ§ã§ã§Ú§Ó§ß§à§Þ §á§â§à§Ü§ã§Ú
1. §±§à§Õ§Ô§à§ä§à§Ó§î§ä§Ö §æ§Ñ§Û§Ý§í §ã CA §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ§Þ§Ú §Ó§Ö§â§ç§ß§Ö§Ô§à §å§â§à§Ó§ß§ñ, §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§à§Þ (§è§Ö§á§à§é§Ü§à§Û) §Ñ§Ô§Ö§ß§ä§Ñ §Ú §á§â§Ú§Ó§Ñ§ä§ß§í§Þ §Ü§Ý§ð§é§Ö§Þ, §Ü§Ñ§Ü §à§á§Ú§ã§Ñ§ß§à §Ó §¯§Ñ§ã§ä§â§à§Û§Ü§Ö §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ §ß§Ñ Áú»¢¶Ä²© §ã§Ö§â§Ó§Ö§â§Ö. §ª§Ù§Þ§Ö§ß§Ú§ä§Ö §á§Ñ§â§Ñ§Þ§Ö§ä§â§í TLSCAFile
, TLSCertFile
, TLSKeyFile
§Ó §æ§Ñ§Û§Ý§Ö §Ü§à§ß§æ§Ú§Ô§å§â§Ñ§è§Ú§Ú §Ñ§Ô§Ö§ß§ä§Ñ §ã§à§à§ä§Ó§Ö§ä§ã§ä§Ó§Ö§ß§ß§à.
2. §±§â§Ú §Ñ§Ü§ä§Ú§Ó§ß§í§ç §á§â§à§Ó§Ö§â§Ü§Ñ§ç §Ú§Ù§Þ§Ö§ß§Ú§ä§Ö TLSConnect
§á§Ñ§â§Ñ§Þ§Ö§ä§â:
§±§â§Ú §á§Ñ§ã§ã§Ú§Ó§ß§í§ç §á§â§à§Ó§Ö§â§Ü§Ñ§ç §Ú§Ù§Þ§Ö§ß§Ú§ä§Ö TLSAccept
§á§Ñ§â§Ñ§Þ§Ö§ä§â:
3. §´§Ö§á§Ö§â§î §å §Ó§Ñ§ã §Ö§ã§ä§î §Þ§Ú§ß§Ú§Þ§Ñ§Ý§î§ß§Ñ§ñ §ß§Ñ§ã§ä§â§à§Û§Ü§Ñ §Ñ§Ô§Ö§ß§ä§Ñ §ß§Ñ §à§ã§ß§à§Ó§Ö §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ. §£§í §Ó§à§Ù§Þ§à§Ø§ß§à §Ù§Ñ§ç§à§ä§Ú§ä§Ö §å§Ý§å§é§ê§Ú§ä§î §Ò§Ö§Ù§à§á§Ñ§ã§ß§à§ã§ä§î §Ñ§Ô§Ö§ß§ä§Ñ, §å§Ü§Ñ§Ù§Ñ§Ó §á§Ñ§â§Ñ§Þ§Ö§ä§â§í TLSServerCertIssuer
§Ú TLSServerCertSubject
.(§ã§Þ§à§ä§â§Ú §°§Ô§â§Ñ§ß§Ú§é§Ö§ß§Ú§Ö §â§Ñ§Ù§â§Ö§ê§Ö§ß§ß§í§ç §¿§Þ§Ú§ä§Ö§ß§ä§Ñ §Ú §³§å§Ò§ì§Ö§Ü§ä§Ñ §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ).
4. §£ §Ü§à§ß§Ö§é§ß§à§Þ §Ú§ä§à§Ô§Ö §á§Ñ§â§Ñ§Þ§Ö§ä§â§í TLS §Ó §æ§Ñ§Û§Ý§Ö §Ü§à§ß§æ§Ú§Ô§å§â§Ñ§è§Ú§Ú §Ñ§Ô§Ö§ß§ä§Ñ §Þ§à§Ô§å§ä §Ó§í§Ô§Ý§ñ§Õ§Ö§ä§î §ã§Ý§Ö§Õ§å§ð§ë§Ú§Þ §à§Ò§â§Ñ§Ù§à§Þ:
TLSConnect=cert
TLSAccept=cert
TLSCAFile=/home/zabbix/zabbix_ca_file
TLSServerCertIssuer=CN=Signing CA,OU=Development group,O=Áú»¢¶Ä²© SIA,DC=zabbix,DC=com
TLSServerCertSubject=CN=Áú»¢¶Ä²© proxy,OU=Development group,O=Áú»¢¶Ä²© SIA,DC=zabbix,DC=com
TLSCertFile=/home/zabbix/zabbix_agentd.crt
TLSKeyFile=/home/zabbix/zabbix_agentd.key
(§±§â§Ú§Þ§Ö§â §á§â§Ö§Õ§á§à§Ý§Ñ§Ô§Ñ§Ö§ä, §é§ä§à §ç§à§ã§ä §ß§Ñ§Ò§Ý§ð§Õ§Ñ§Ö§ä§ã§ñ §é§Ö§â§Ö§Ù §á§â§à§Ü§ã§Ú, §à§ä§ã§ð§Õ§Ñ §³§å§Ò§ì§Ö§Ü§ä §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ §á§â§à§Ü§ã§Ú.)
5. §¯§Ñ§ã§ä§â§à§Û§ä§Ö §ê§Ú§æ§â§à§Ó§Ñ§ß§Ú§Ö §ï§ä§à§Þ§å §Ñ§Ô§Ö§ß§ä§å §Ó §Ó§Ö§Ò-§Ú§ß§ä§Ö§â§æ§Ö§Û§ã§Ö Áú»¢¶Ä²©:
§£ §á§â§Ú§Þ§Ö§â§Ö §ß§Ú§Ø§Ö §á§à§Ý§ñ §¿§Þ§Ú§ä§Ö§ß§ä §Ú §³§å§Ò§ì§Ö§Ü§ä §Ù§Ñ§á§à§Ý§ß§Ö§ß§í - §ã§Þ§à§ä§â§Ú§ä§Ö §°§Ô§â§Ñ§ß§Ú§é§Ö§ß§Ú§Ö §â§Ñ§Ù§â§Ö§ê§Ö§ß§ß§í§ç §¿§Þ§Ú§ä§Ö§ß§ä§Ñ §Ú §³§å§Ò§ì§Ö§Ü§ä§Ñ §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ §à §ä§à§Þ, §Ü§Ñ§Ü §Ú§ã§á§à§Ý§î§Ù§à§Ó§Ñ§ä§î §ï§ä§Ú §á§à§Ý§ñ.
1. Prepare files with the top-level CA certificates, the Áú»¢¶Ä²© web service certificate/certificate chain, and the private key as described in the Áú»¢¶Ä²© server section. Then, edit the TLSCAFile
, TLSCertFile
, and TLSKeyFile
parameters in the Áú»¢¶Ä²© web service configuration file accordingly.
2. Edit an additional TLS parameter in the Áú»¢¶Ä²© web service configuration file: TLSAccept=cert
TLS parameters in the final web service configuration file may look as follows:
TLSAccept=cert
TLSCAFile=/home/zabbix/zabbix_ca_file
TLSCertFile=/home/zabbix/zabbix_web_service.crt
TLSKeyFile=/home/zabbix/zabbix_web_service.key
3. Configure Áú»¢¶Ä²© server to connect to the TLS-configured Áú»¢¶Ä²© web service by editing the WebServiceURL
parameter in the Áú»¢¶Ä²© server configuration file:
§¬§à§Ô§Õ§Ñ §Õ§Ó§Ñ §Ü§à§Þ§á§à§ß§Ö§ß§ä§Ñ Áú»¢¶Ä²© (§ß§Ñ§á§â§Ú§Þ§Ö§â, §ã§Ö§â§Ó§Ö§â §Ú §Ñ§Ô§Ö§ß§ä) §å§ã§ä§Ñ§ß§Ñ§Ó§Ý§Ú§Ó§Ñ§ð§ä TLS §ã§à§Ö§Õ§Ú§ß§Ö§ß§Ú§Ö, §à§ß§Ú §à§Ò§Ñ §á§â§à§Ó§Ö§â§ñ§ð§ä §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§í §Õ§â§å§Ô §Õ§â§å§Ô§Ñ. §¦§ã§Ý§Ú §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä §å§Ù§Ý§Ñ §á§à§Õ§á§Ú§ã§Ñ§ß §Õ§à§Ó§Ö§â§Ö§ß§ß§í§Þ CA (§ã §á§â§Ö§Õ§Ó§Ñ§â§Ú§ä§Ö§Ý§î§ß§à §á§à§Õ§Ô§à§ä§à§Ó§Ý§Ö§ß§ß§í§Þ §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§à§Þ §Ó§Ö§â§ç§ß§Ö§Ô§à §å§â§à§Ó§ß§ñ §Ó TLSCAFile
), §ñ§Ó§Ý§ñ§Ö§ä§ã§ñ §Õ§Ö§Û§ã§ä§Ó§Ú§ä§Ö§Ý§î§ß§í§Þ, §à§ß §ß§Ö §Ú§ã§ä§×§Ü §Ú §á§â§à§ç§à§Õ§Ú§ä §ß§Ö§Ü§à§ä§à§â§í§Ö §Õ§â§å§Ô§Ú§Ö §á§â§à§Ó§Ö§â§Ü§Ú, §ä§à§Ô§Õ§Ñ §Ü§à§Þ§Þ§å§ß§Ú§Ü§Ñ§è§Ú§ñ §Þ§à§Ø§Ö§ä §á§â§à§Õ§à§Ý§Ø§Ñ§ä§î§ã§ñ. §¿§Þ§Ú§ä§Ö§ß§ä §Ú §ã§å§Ò§ì§Ö§Ü§ä §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ §Ó §ï§ä§à§Þ §á§â§à§ã§ä§à§Þ §ã§Ý§å§é§Ñ§Ö §ß§Ö §á§â§à§Ó§Ö§â§ñ§Ö§ä§ã§ñ.
§©§Õ§Ö§ã§î §Ú§Þ§Ö§Ö§ä§ã§ñ §â§Ú§ã§Ü - §Ü§ä§à-§å§Ô§à§Õ§ß§à §á§â§Ú §ß§Ñ§Ý§Ú§é§Ú§Ú §Õ§Ö§Û§ã§ä§Ó§Ú§ä§Ö§Ý§î§ß§à§Ô§à §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ñ §Þ§à§Ø§Ö§ä §Ó§í§Õ§Ñ§Ó§Ñ§ä§î §ã§Ö§Ò§ñ §Ù§Ñ §Õ§â§å§Ô§à§Ô§à (§ß§Ñ§á§â§Ú§Þ§Ö§â, §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä §ç§à§ã§ä§Ñ §Þ§à§Ø§ß§à §Ú§ã§á§à§Ý§î§Ù§à§Ó§Ñ§ä§î, §é§ä§à§Ò§í §Ó§í§Õ§Ñ§Ó§Ñ§ä§î §ã§Ö§Ò§ñ §Ù§Ñ §ã§Ö§â§Ó§Ö§â). §´§Ñ§Ü§à§Ö §á§à§Ó§Ö§Õ§Ö§ß§Ú§Ö §Þ§à§Ø§Ö§ä §Ò§í§ä§î §á§â§Ú§Ö§Þ§Ý§Ö§Þ§à §Ó §ß§Ö§Ò§à§Ý§î§ê§Ú§ç §ã§â§Ö§Õ§Ñ§ç, §Ô§Õ§Ö §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§í §á§à§Õ§á§Ú§ã§í§Ó§Ñ§ð§ä§ã§ñ §ã§á§Ö§è§Ú§Ñ§Ý§Ú§Ù§Ú§â§à§Ó§Ñ§ß§ß§à§Ô§à §Ó§ß§å§ä§â§Ö§ß§ß§Ö§Ô§à CA §Ú §â§Ú§ã§Ü §Õ§Ö§Û§ã§ä§Ó§Ú§Û §à§ä §é§å§Ø§à§Ô§à §Ú§Þ§Ö§ß§Ú §ñ§Ó§Ý§ñ§Ö§ä§ã§ñ §Þ§Ú§ß§Ú§Þ§Ñ§Ý§î§ß§í§Þ.
§¦§ã§Ý§Ú §Ó§Ñ§ê CA §Ó§Ö§â§ç§ß§Ö§Ô§à §å§â§à§Ó§ß§ñ §Ú§ã§á§à§Ý§î§Ù§å§Ö§ä§ã§ñ §Õ§Ý§ñ §Ó§í§Õ§Ñ§é§Ú §Õ§â§å§Ô§Ú§ç §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§à§Ó, §Ü§à§ä§à§â§í§Ö §ß§Ö §Õ§à§Ý§Ø§ß§í §á§â§Ú§ß§Ú§Þ§Ñ§ä§î§ã§ñ Áú»¢¶Ä²© §Ú§Ý§Ú §Ó§í §ç§à§ä§Ú§ä§Ö §ã§ß§Ú§Ù§Ú§ä§î §â§Ú§ã§Ü §Õ§Ö§Û§ã§ä§Ó§Ú§Û §à§ä §é§å§Ø§à§Ô§à §Ú§Þ§Ö§ß§Ú, §Ó§í §Þ§à§Ø§Ö§ä§Ö §à§Ô§â§Ñ§ß§Ú§é§Ú§ä§î §â§Ñ§Ù§â§Ö§ê§Ö§ß§ß§í§Ö §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§í, §å§Ü§Ñ§Ù§Ñ§Ó §Ú§ç §ã§ä§â§à§Ü§Ú §¿§Þ§Ú§ä§Ö§ß§ä§Ñ §Ú §³§å§Ò§ì§Ö§Ü§ä§Ñ.
§¯§Ñ§á§â§Ú§Þ§Ö§â, §Ó§í §Þ§à§Ø§Ö§ä§Ö §Ù§Ñ§á§Ú§ã§Ñ§ä§î §Ó §æ§Ñ§Û§Ý §Ü§à§ß§æ§Ú§Ô§å§â§Ñ§è§Ú§Ú Áú»¢¶Ä²© §á§â§à§Ü§ã§Ú:
TLSServerCertIssuer=CN=Signing CA,OU=Development group,O=Áú»¢¶Ä²© SIA,DC=zabbix,DC=com
TLSServerCertSubject=CN=Áú»¢¶Ä²© server,OU=Development group,O=Áú»¢¶Ä²© SIA,DC=zabbix,DC=com
§±§â§Ú §ß§Ñ§Ý§Ú§é§Ú§Ú §ï§ä§Ú§ç §ß§Ñ§ã§ä§â§à§Ö§Ü §Ñ§Ü§ä§Ú§Ó§ß§í§Û §á§â§à§Ü§ã§Ú §ß§Ö §Ò§å§Õ§Ö§ä §â§Ñ§Ù§Ô§à§Ó§Ñ§â§Ú§Ó§Ñ§ä§î §ã Áú»¢¶Ä²© §ã§Ö§â§Ó§Ö§â§à§Þ §ã §Õ§â§å§Ô§Ú§Þ§Ú §ã§ä§â§à§Ü§Ñ§Þ§Ú §¿§Þ§Ú§ä§Ö§ß§ä§Ñ §Ú §³§å§Ò§ì§Ö§Ü§ä§Ñ §Ó §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§Ö, §á§Ñ§ã§ã§Ú§Ó§ß§í§Û §á§â§à§Ü§ã§Ú §ß§Ö §á§â§Ú§Þ§Ö§â §Ù§Ñ§á§â§à§ã§í §à§ä §ä§Ñ§Ü§à§Ô§à §ã§Ö§â§Ó§Ö§â§Ñ.
§¯§Ö§ã§Ü§à§Ý§î§Ü§à §Ù§Ñ§Þ§Ö§ä§à§Ü §à §ã§à§à§ä§Ó§Ö§ä§ã§ä§Ó§Ú§Ú §ã§ä§â§à§Ü §¿§Þ§Ú§ä§Ö§ß§ä§Ñ §Ú §³§å§Ò§ì§Ö§Ü§ä§Ñ:
- §å§á§â§Ñ§Ó§Ý§ñ§ð§ë§Ú§Ö §ã§Ú§Þ§Ó§à§Ý§í '"' (U+0022), '+' U+002B, ',' U+002C, ';' U+003B, '<' U+003C, '>' U+003E, '\' U+005C §Ó §Ý§ð§Ò§à§Þ §Þ§Ö§ã§ä§Ö §Ó §ã§ä§â§à§Ü§Ö.
- §å§á§â§Ñ§Ó§Ý§ñ§ð§ë§Ú§Ö §ã§Ú§Þ§Ó§à§Ý§í §á§â§à§Ò§Ö§Ý§Ñ (' ' U+0020) §Ú§Ý§Ú §ã§Ú§Þ§Ó§à§Ý §â§Ö§ê§Ö§ä§Ü§Ú ('#' U+0023) §Ó §ß§Ñ§é§Ñ§Ý§Ö §ã§ä§â§à§Ü§Ú.
- §å§á§â§Ñ§Ó§Ý§ñ§ð§ë§Ú§Û §ã§Ú§Þ§Ó§à§Ý §á§â§à§Ò§Ö§Ý§Ñ (' ' U+0020) §Ó §Ü§à§ß§è§Ö §ã§ä§â§à§Ü§Ú.
- §³§à§Ó§á§Ñ§Õ§Ö§ß§Ú§ñ §ß§Ö §Ò§å§Õ§Ö§ä, §Ö§ã§Ý§Ú §Ó§ã§ä§â§Ö§é§Ñ§Ö§ä§ã§ñ §ß§å§Ý§Ö§Ó§à§Û §ã§Ú§Þ§Ó§à§Ý (U+0000) ([[http://tools.ietf.org/html/rfc4514|RFC 4514]] §á§à§Ù§Ó§à§Ý§ñ§Ö§ä §ï§ä§à).
- §´§â§Ö§Ò§à§Ó§Ñ§ß§Ú§ñ [[http://tools.ietf.org/html/rfc4517| RFC 4517 Lightweight Directory Access Protocol (LDAP): Syntaxes and Matching Rules]] §Ú [[http://tools.ietf.org/html/rfc4518|RFC 4518 Lightweight Directory Access Protocol (LDAP): Internationalized String Preparation]] §ß§Ö §á§à§Õ§Õ§Ö§â§Ø§Ú§Ó§Ñ§ð§ä§ã§ñ §á§à §á§â§Ú§é§Ú§ß§Ö §ß§Ö§à§Ò§ç§à§Õ§Ú§Þ§à§Ô§à §à§Ò§ì§Ö§Þ§Ñ §â§Ñ§Ò§à§ä§í.
§°§é§Ö§â§Ö§Õ§ß§à§ã§ä§î §á§à§Ý§Ö§Û §Ó §¿§Þ§Ú§ä§Ö§ß§ä§Ñ §Ú §³§å§Ò§ì§Ö§Ü§ä§Ñ §ã§ä§â§à§Ü§Ñ§ç §Ú §æ§à§â§Þ§Ñ§ä§Ú§â§à§Ó§Ñ§ß§Ú§Ö §à§é§Ö§ß§î §Ó§Ñ§Ø§ß§í! Áú»¢¶Ä²© §ã§Ý§Ö§Õ§å§Ö§ä §â§Ö§Ü§à§Þ§Ö§ß§Õ§Ñ§è§Ú§Ú §Ú §Ú§ã§á§à§Ý§î§Ù§å§Ö§ä "§à§Ò§â§Ñ§ä§ß§í§Û" §á§à§â§ñ§Õ§à§Ü §ï§ä§Ú§ç §á§à§Ý§Ö§Û.
§°§Ò§â§Ñ§ä§ß§í§Û §á§à§â§ñ§Õ§à§Ü §Þ§à§Ø§ß§à §á§â§à§Õ§Ö§Þ§à§ß§ã§ä§â§Ú§â§à§Ó§Ñ§ä§î §Ó §á§â§Ú§Þ§Ö§â§Ö:
TLSServerCertIssuer=CN=Signing CA,OU=Development group,O=Áú»¢¶Ä²© SIA,DC=zabbix,DC=com
TLSServerCertSubject=CN=Áú»¢¶Ä²© proxy,OU=Development group,O=Áú»¢¶Ä²© SIA,DC=zabbix,DC=com
§°§Ò§â§Ñ§ä§Ú§ä§Ö §Ó§ß§Ú§Þ§Ñ§ß§Ú§Ö, §é§ä§à §à§ß §ß§Ñ§é§Ú§ß§Ñ§Ö§ä§ã§ñ §ã §Ó§Ö§â§ç§ß§Ö§Ô§à §å§â§à§Ó§ß§ñ (CN), §á§Ö§â§Ö§ç§à§Õ§Ú§ä §Ü §ã§â§Ö§Õ§ß§Ö§Þ§å §å§â§à§Ó§ß§ð (OU, O) §Ú §Ù§Ñ§Ü§Ñ§ß§é§Ú§Ó§Ñ§Ö§ä§ã§ñ §á§à§Ý§ñ§Þ§Ú §Ó§Ö§â§ç§ß§Ö§Ô§à §å§â§à§Ó§ß§ñ (DC).
§±§à §å§Þ§à§Ý§é§Ñ§ß§Ú§ð OpenSSL §à§ä§à§Ò§â§Ñ§Ø§Ñ§Ö§ä §á§à§Ý§ñ §¿§Þ§Ú§ä§Ö§ß§ä§Ñ §Ú §³§å§Ò§ì§Ö§Ü§ä§Ñ §Ó "§ß§à§â§Þ§Ñ§Ý§î§ß§à§Þ" §á§à§â§ñ§Õ§Ü§Ö, §Ó §Ù§Ñ§Ó§Ú§ã§Ú§Þ§à§ã§ä§Ú §à§ä §Ú§ã§á§à§Ý§î§Ù§à§Ó§Ñ§ß§ß§í§ç §Õ§à§á§à§Ý§ß§Ú§ä§Ö§Ý§î§ß§í§ç §à§á§è§Ú§Û:
$ openssl x509 -noout -in /home/zabbix/zabbix_proxy.crt -issuer -subject
issuer= /DC=com/DC=zabbix/O=Áú»¢¶Ä²© SIA/OU=Development group/CN=Signing CA
subject= /DC=com/DC=zabbix/O=Áú»¢¶Ä²© SIA/OU=Development group/CN=Áú»¢¶Ä²© proxy
$ openssl x509 -noout -text -in /home/zabbix/zabbix_proxy.crt
Certificate:
...
Issuer: DC=com, DC=zabbix, O=Áú»¢¶Ä²© SIA, OU=Development group, CN=Signing CA
...
Subject: DC=com, DC=zabbix, O=Áú»¢¶Ä²© SIA, OU=Development group, CN=Áú»¢¶Ä²© proxy
§©§Õ§Ö§ã§î §ã§ä§â§à§Ü§Ú §¿§Þ§Ú§ä§Ö§ß§ä§Ñ §Ú §³§å§Ò§ì§Ö§Ü§ä§Ñ §ß§Ñ§é§Ú§ß§Ñ§ð§ä§ã§ñ §ã §Ó§Ö§â§ç§ß§Ö§Ô§à §å§â§à§Ó§ß§ñ (DC) §Ú §Ù§Ñ§Ü§Ñ§ß§é§Ú§í§Ó§Ñ§ð§ä§ã§ñ §á§à§Ý§Ö§Þ §ß§Ú§Ø§ß§Ö§Ô§à §å§â§à§Ó§ß§ñ (CN), §á§â§à§Ò§Ö§Ý§í §Ú §â§Ñ§Ù§Õ§Ö§Ý§Ú§ä§Ö§Ý§Ú §á§à§Ý§Ö§Û §Ù§Ñ§Ó§Ú§ã§ñ§ä §à§ä §Ú§ã§á§à§Ý§î§Ù§å§Ö§Þ§í§ç §à§á§è§Ú§Û. §¯§Ú §à§Õ§ß§à §Ú§Ù §ï§ä§Ú§ç §Ù§ß§Ñ§é§Ö§ß§Ú§Û §ß§Ö §Ò§å§Õ§Ö§ä §ã§à§Ó§á§Ñ§Õ§Ñ§ä§î §Ó Áú»¢¶Ä²© §á§à§Ý§ñ§ç §¿§Þ§Ú§ä§Ö§ß§ä§Ñ §Ú §³§å§Ò§ì§Ö§Ü§ä§Ñ!
§¥§Ý§ñ §á§à§Ý§å§é§Ö§ß§Ú§ñ §ß§Ñ§Õ§Ý§Ö§Ø§Ñ§ë§Ú§ç §ã§ä§â§à§Ü §¿§Þ§Ú§ä§Ö§ß§ä§Ñ §Ú §³§å§Ò§ì§Ö§Ü§ä§Ñ, §Õ§à§á§å§ã§ä§Þ§í§ç §Ó Áú»¢¶Ä²©, §Ó§í§Ù§à§Ó§Ú§ä§Ö OpenSSL §ã§à §ã§á§Ö§è§Ú§Ñ§Ý§î§ß§í§Þ§Ú §à§á§è§Ú§ñ§Þ§Ú
-nameopt esc_2253,esc_ctrl,utf8,dump_nostr,dump_unknown,dump_der,sep_comma_plus,dn_rev,sname
:
$ openssl x509 -noout -issuer -subject -nameopt esc_2253,esc_ctrl,utf8,dump_nostr,dump_unknown,dump_der,sep_comma_plus,dn_rev,sname -in /home/zabbix/zabbix_proxy.crt
issuer= CN=Signing CA,OU=Development group,O=Áú»¢¶Ä²© SIA,DC=zabbix,DC=com
subject= CN=Áú»¢¶Ä²© proxy,OU=Development group,O=Áú»¢¶Ä²© SIA,DC=zabbix,DC=com
§´§Ö§á§Ö§â§î §ã§ä§â§à§Ü§à§Ó§í§Ö §á§à§Ý§ñ §ß§Ñ§ç§à§Õ§ñ§ä§ã§ñ §Ó §à§Ò§â§Ñ§ä§ß§à§Þ" §á§à§â§ñ§Õ§Ü§Ö, §á§à§Ý§ñ §â§Ñ§Ù§Õ§Ö§Ý§Ö§ß§í §Ù§Ñ§á§ñ§ä§à§Û, §ã§ä§â§à§Ü§Ú §Þ§à§Ø§ß§à §Ú§ã§á§à§Ý§î§Ù§à§Ó§Ñ§ä§î §Ó §æ§Ñ§Û§Ý§Ñ§ç §Ü§à§ß§æ§Ú§Ô§å§â§Ñ§è§Ú§Ú Áú»¢¶Ä²© §Ú §Ó §Ó§Ö§Ò-§Ú§ß§ä§Ö§â§æ§Ö§Û§ã§Ö.
Issuer
and Subject
stringsThe rules for matching Issuer
and Subject
strings are as follows:
Issuer
and Subject
strings are checked independently. Both are optional.*
) or regular expressions are not supported.\
' backslash, U+005C):
"
' (U+0022), '+
' (U+002B), ',
' (U+002C), ';
' (U+003B), '<
' (U+003C), '>
' (U+003E), '\\
' (U+005C);#
', U+0023);For example, if Issuer
and Subject
organization (O
) strings contain trailing spaces and the Subject
organizational unit (OU
) string contains double quotes, these characters must be escaped:
TLSServerCertIssuer=CN=Signing CA,OU=Development head,O=\ Example SIA\ ,DC=example,DC=com
TLSServerCertSubject=CN=Áú»¢¶Ä²© server,OU=Development group \"5\",O=\ Example SIA\ ,DC=example,DC=com
Áú»¢¶Ä²© follows the recommendations of , which specifies a "reverse" order for these fields, starting with the lowest-level fields (CN
), proceeding to the mid-level fields (OU
, O
), and concluding with the highest-level fields (DC
).
TLSServerCertIssuer=CN=Signing CA,OU=Development group,O=Áú»¢¶Ä²© SIA,DC=zabbix,DC=com
TLSServerCertSubject=CN=Áú»¢¶Ä²© proxy,OU=Development group,O=Áú»¢¶Ä²© SIA,DC=zabbix,DC=com
In contrast, OpenSSL by default displays the Issuer
and Subject
strings in top-level to low-level order. In the following example, Issuer
and Subject
fields start with the top-level (DC
) and end with the low-level (CN
) field. The formatting with spaces and field separators also varies based on the options used, and thus will not match the format required by Áú»¢¶Ä²©.
$ openssl x509 -noout -in /home/zabbix/zabbix_proxy.crt -issuer -subject
issuer= /DC=com/DC=zabbix/O=Áú»¢¶Ä²© SIA/OU=Development group/CN=Signing CA
subject= /DC=com/DC=zabbix/O=Áú»¢¶Ä²© SIA/OU=Development group/CN=Áú»¢¶Ä²© proxy
$ openssl x509 -noout -text -in /home/zabbix/zabbix_proxy.crt
Certificate:
...
Issuer: DC=com, DC=zabbix, O=Áú»¢¶Ä²© SIA, OU=Development group, CN=Signing CA
...
Subject: DC=com, DC=zabbix, O=Áú»¢¶Ä²© SIA, OU=Development group, CN=Áú»¢¶Ä²© proxy
To format Issuer and Subject strings correctly for Áú»¢¶Ä²©, invoke OpenSSL with the following options:
$ openssl x509 -noout -issuer -subject \
-nameopt esc_2253,esc_ctrl,utf8,dump_nostr,dump_unknown,dump_der,sep_comma_plus,dn_rev,sname\
-in /home/zabbix/zabbix_proxy.crt
The output will then be in reverse order, comma-separated, and usable in Áú»¢¶Ä²© configuration files and frontend:
issuer= CN=Signing CA,OU=Development group,O=Áú»¢¶Ä²© SIA,DC=zabbix,DC=com
subject= CN=Áú»¢¶Ä²© proxy,OU=Development group,O=Áú»¢¶Ä²© SIA,DC=zabbix,DC=com
§¦§ã§Ý§Ú §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä §ã§Ü§à§Þ§á§â§à§Þ§Ö§ä§Ú§â§à§Ó§Ñ§ß, CA §Þ§à§Ø§Ö§ä §à§ä§à§Ù§Ó§Ñ§ä§î §Ö§Ô§à, §Ó§Ü§Ý§ð§é§Ú§Ó §Ó CRL. §³§á§Ú§ã§Ü§Ú CRL §Þ§à§Ø§ß§à §ß§Ñ§ã§ä§â§Ñ§Ú§Ó§Ñ§ä§î §Ó §æ§Ñ§Û§Ý§Ñ§ç §Ü§à§ß§æ§Ú§Ô§å§â§Ñ§è§Ú§Ú §ã§Ö§â§Ó§Ö§â§Ñ, §á§â§à§Ü§ã§Ú §Ú §Ñ§Ô§Ö§ß§ä§Ñ, §Ú§ã§á§à§Ý§î§Ù§å§ñ §á§Ñ§â§Ñ§Þ§Ö§ä§â TLSCRLFile
. §¯§Ñ§á§â§Ú§Þ§Ö§â:
§Ô§Õ§Ö zabbix_crl_file
§Þ§à§Ø§Ö§ä §ã§à§Õ§Ö§â§Ø§Ñ§ä§î §ã§á§Ú§ã§Ü§Ú CRL §à§ä §ß§Ö§ã§Ü§à§Ý§î§Ü§Ú§ç CA §Ú §Þ§à§Ø§Ö§ä §Ó§í§Ô§Ý§ñ§Õ§Ö§ä§î §ã§Ý§Ö§Õ§å§ð§ë§Ú§Þ §à§Ò§â§Ñ§Ù§à§Þ:
-----BEGIN X509 CRL-----
MIIB/DCB5QIBATANBgkqhkiG9w0BAQUFADCBgTETMBEGCgmSJomT8ixkARkWA2Nv
...
treZeUPjb7LSmZ3K2hpbZN7SoOZcAoHQ3GWd9npuctg=
-----END X509 CRL-----
-----BEGIN X509 CRL-----
MIIB+TCB4gIBATANBgkqhkiG9w0BAQUFADB/MRMwEQYKCZImiZPyLGQBGRYDY29t
...
CAEebS2CND3ShBedZ8YSil59O6JvaDP61lR5lNs=
-----END X509 CRL-----
CRL §æ§Ñ§Û§Ý §Ù§Ñ§Ô§â§å§Ø§Ñ§Ö§ä§ã§ñ §ä§à§Ý§î§Ü§à §á§â§Ú §Ù§Ñ§á§å§ã§Ü§Ö Áú»¢¶Ä²©. §±§â§Ú §à§Ò§ß§à§Ó§Ý§Ö§ß§Ú§Ú CRL §ä§â§Ö§Ò§å§Ö§ä§ã§ñ §á§Ö§â§Ö§Ù§Ñ§á§å§ã§Ü.
§¦§ã§Ý§Ú §Ü§à§Þ§á§à§ß§Ö§ß§ä Áú»¢¶Ä²© §ã§Ü§à§Þ§á§Ú§Ý§Ú§â§à§Ó§Ñ§ß §ã OpenSSL §Ú §Ú§ã§á§à§Ý§î§Ù§å§ð§ä§ã§ñ §ã§á§Ú§ã§Ü§Ú CRL, §ä§à§Ô§Õ§Ñ §Ü§Ñ§Ø§Õ§í§Û §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä §Ó§Ö§â§ç§ß§Ö§Ô§à §Ú §á§â§à§Þ§Ö§Ø§å§ä§à§é§ß§à§Ô§à §å§â§à§Ó§ß§Ö§Û CA §Ó §è§Ö§á§à§é§Ü§Ñ§ç §ã§Ö§â§ä§Ú§æ§Ú§Ü§Ñ§ä§à§Ó §Õ§à§Ý§Ø§Ö§ß §Ú§Þ§Ö§ä§î §ã§à§à§ä§Ó§Ö§ä§ã§ä§Ó§å§ð§ë§Ú§Û §ã§á§Ú§ã§à§Ü CRL (§Þ§à§Ø§Ö§ä §Ò§í§ä§î §á§å§ã§ä§í§Þ) §Ó TLSCRLFile
.