mosquitto TLS 用于远程 mosquitto_pub 的证书

den*_*sha 5 mosquitto tls1.2

我正在尝试使用 TLS1.2 使用 Lets 加密证书来设置 mosquitto MQTT 服务器。

我已经安装了 mosquitto 并设置了 Let encrpypt。我的 /etc/mosquitto/conf.d/default.conf 是

listener 1883 localhost

listener 8883
certfile /etc/letsencrypt/live/mqtt.atom.net/cert.pem
cafile /etc/letsencrypt/live/mqtt.atom.net/chain.pem
keyfile /etc/letsencrypt/live/mqtt.atom.net/privkey.pem
Run Code Online (Sandbox Code Playgroud)

在服务器上运行 mosquitto 我可以成功发布和订阅消息

Sub 
mosquitto_sub -h localhost -t test
hello

Pub
mosquitto_pub -h mqtt.atom.net -t test -m "hello" -p 8883 --capath /etc/ssl/certs/
Run Code Online (Sandbox Code Playgroud)

从互联网上的另一个系统(或 ESP32) - 尝试建立 TLS 连接时出现错误

mosquitto_pub -h mqtt.atom.net -t test -m "hello again" -p 8883
Error: The connection was lost.
Run Code Online (Sandbox Code Playgroud)

我需要将哪些文件/证书传递给 mosquitto_pub?

har*_*llb 5

要启用 TLS,mosquitto_pub您需要在命令行上传递--capath或。--cafile

在 Linux 系统上,您应该能够通过相同的操作--capath /etc/ssl/certs/(假设您正在使用的发行版将其 CA 证书保留在同一位置)。

或者您可以将 chain.pem 文件从代理复制到另一台机器并使用--cafile chain.pem

对于像 ESP32 这样的东西,您需要弄清楚如何将 chain.pem 包含在您推送到设备的构建中。

  • 是的,在第二个 Linux 系统上 - 我使用 --capath /etc/ssl/certs/ 让它工作。我认为这证实了我的 mosquitto 服务器已正确构建。但是,在第二个 Linux 系统上,如果我复制 chain.pem 并使用 --cafile chain.pem。我收到错误:发生 TLS 错误。在wireshark中,我看到mosquitto_pub客户端发送一条TLS1.2警报消息 - 致命级别,描述:未知CA。复制的 chain.pem 文件是有效的,因为我可以使用 openssl x509 -in chain.pem -noout -text 转储它的内容。 (2认同)