如何让lftp从命令行使用SSL/TLS安全机制?

use*_*469 7 ftp ubuntu ftps lftp

我正在尝试登录ftps网站.我已经尝试在命令行中输入登录信息(并将set参数放入~/.lftprc,然后打开lftp会话并使用lftp作业控制语句键入这些参数.无论如何,我一直遇到相同的障碍:

 421 Sorry, cleartext sessions are not accepted on this server.
 Please reconnect using SSL/TLS security mechanisms.
Run Code Online (Sandbox Code Playgroud)

我得到了以下参数最远,但不断得到上面的错误.

如何lftp从命令行使用SSL/TLS安全机制?

目标是使用bash(不使用编程expect)编写对此ftps站点的访问的脚本.

 lftp
 lftp :~> set ssl-allow false
 lftp :~> set passive-mode yes
 lftp :~> open ftp.abc.com
 lftp ftp.abc.com:~> login theuser
 Password:
 lftp theuser@ftp.abc.com:~> cd
  `cd' at 0 [Delaying before reconnect: 26]
 CTRL-C
 lftp theuser@ftp.abc.com:~> debug
 lftp theuser@ftp.abc.com:~> cd
 ---- Connecting to ftp.abc.com (XX.XXX.XX.XX) port 21
 <--- 220-Welcome to the Yahoo! Web Hosting FTP server
 <--- 220-Need help? Get all details at:
 <--- 220-http://help.yahoo.com/help/us/webhosting/gftp/
 <--- 220-
 <--- 220-No anonymous logins accepted.
 <--- 220-Yahoo!
 <--- 220-Local time is now 15:30. Server port: 21.
 <--- 220-This is a private system - No anonymous login
 <--- 220 You will be disconnected after 5 minutes of inactivity.
 ---> FEAT
 <--- 211-Extensions supported:
 <---  EPRT
 <---  IDLE
 <---  MDTM
 <---  SIZE
 <---  MFMT
 <---  REST STREAM
 <---  MLST type*;size*;sizd*;modify*;UNIX.mode*;UNIX.uid*;UNIX.gid*;unique*;
 <---  MLSD
 <---  XDBG
 <---  AUTH TLS
 <---  PBSZ
 <---  PROT
 <---  TVFS
 <---  ESTA
 <---  PASV
 <---  EPSV
 <---  SPSV
 <---  ESTP
 <--- 211 End.
 ---> OPTS MLST type;size;modify;UNIX.mode;UNIX.uid;UNIX.gid;
 <--- 200  MLST OPTS type;size;sizd;modify;UNIX.mode;UNIX.uid;UNIX.gid;unique;
 ---> USER theuser
 <--- 421 Sorry, cleartext sessions are not accepted on this server.
 Please reconnect using SSL/TLS security mechanisms.
Run Code Online (Sandbox Code Playgroud)

Ste*_*ich 16

lftp:〜>设置ssl-allow false

您已明确将ssl-allow设置为false.但如果lftp尝试使用SSL,则必须如此.


ing*_*net 16

似乎lftp在许多系统上配置不正确,这使得它无法验证服务器证书(生成Fatal error: Certificate verification: Not trusted).

网络(以及本文中的答案)充满了通过完全禁用证书验证或加密来解决此问题的建议.这是不安全的,因为它允许中间人攻击被忽视.

更好的解决方案是正确配置证书验证,幸运的是,这很容易.为此,请将以下行添加到/etc/lftp.conf(或替代地~/.lftp/rc,或~/.config/lftp/rc):

set ssl:ca-file "/etc/ssl/certs/ca-certificates.crt"
Run Code Online (Sandbox Code Playgroud)

ca-certificates.crt是包含系统的所有CA证书的文件.上面使用的位置是来自Ubuntu的位置,可能因系统而异.要生成或更新文件,请运行update-ca-certificates:

sudo update-ca-certificates
Run Code Online (Sandbox Code Playgroud)

如果您的系统没有此命令,您可以手动创建一个,如下所示:

cat /etc/ssl/certs/*.pem | sudo tee /etc/ssl/certs/ca-certificates.crt > /dev/null
Run Code Online (Sandbox Code Playgroud)


小智 8

你可能还需要

set ssl:verify-certificate no
Run Code Online (Sandbox Code Playgroud)

  • 这是**不安全的**!有关详细信息和更好的解决方案,请参阅[我的回答](http://stackoverflow.com/a/44095714/651937). (4认同)
  • 至少,您可以执行 `set ssl:verify-certificate/myserver.com no`,将 `myserver.com` 替换为您尝试连接的服务器的实际名称。 (2认同)

sch*_*dde 6

我的答案为系统上的单个用户提供访问权限,而不是系统范围的证书。

\n

lftp 使用传输层安全性 (TLS)。因此,必须首先从 FTP 服务器获取证书。

\n
openssl s_client -connect <ftp-hostname>:21 -starttls ftp\n
Run Code Online (Sandbox Code Playgroud)\n

我将整个证书链包含cert.crt在本地~/.lftp文件夹中名为的新文件中。至少,您希望包含证书本身的所有文本: -----BEGIN CERTIFICATE----- <...> -----END CERTIFICATE-----。

\n
    \n
  • rc我在本地创建一个名为的文件~/.lftp并添加以下行\n
      \n
    • set ssl:ca-file \xe2\x80\x9ccert.crt\xe2\x80\x9d
    • \n
    • set ssl:check-hostname no(这可以防止Fatal error: Certificate verification: certificate common name doesn't match requested host name \xe2\x80\x98<ftp-hostname>\xe2\x80\x99运行类似命令时ls)
    • \n
    \n
  • \n
\n