【问题标题】:MQTT PAHO [CERTIFICATE_VERIFY_FAILED]MQTT PAHO [CERTIFICATE_VERIFY_FAILED]
【发布时间】:2018-02-17 18:32:00
【问题描述】:

我对 Python 有疑问(我是 Python 新手,正在学习它)。 我在 Debian 9 系统上使用了 2.7.9 版本。我在 python 中安装了 paho 和 tinkerforge 包。

我使用 Paho MQTT 客户端开发了一个脚本来连接我的 mosquitto 代理。我想使用加密连接。我的连接在未加密时工作正常,但在加密时失败。在 openHAB(MQTT-订阅者)和 MQTTFX(MQTT-订阅者和生产者)上加密的连接工作正常

我正在为我的脚本使用这些参数:

self.client = mqtt.Client()
self.client.tls_set("/home/pi/ca-cert.pem","/home/pi/IWILR1-1-cert.pem","/home/pi/IWILR1-1.pem",tls_version=ssl.PROTOCOL_TLSv1)
# disables peer verification
self.client.tls_insecure_set(False)
    self.client.on_connect = self.mqtt_on_connect
    self.client.on_disconnect = self.mqtt_on_disconnect
self.client.on_message = self.mqtt_on_message

    self.device_proxies = {}
    self.device_proxy_classes = {}

    for subclass in DeviceProxy.subclasses():
        self.device_proxy_classes[subclass.DEVICE_CLASS.DEVICE_IDENTIFIER] = subclass

def connect(self):
    if self.broker_username is not None:
        self.client.username_pw_set(self.broker_username, self.broker_password)

    self.client.connect(self.broker_host, self.broker_port)
    self.client.loop_start()

但现在的问题是 Python 上的错误。

    sudo python /home/pi/brick-mqtt-proxy.py
Traceback (most recent call last):
  File "/home/pi/brick-mqtt-proxy.py", line 1250, in <module>
    proxy.connect()
  File "/home/pi/brick-mqtt-proxy.py", line 1109, in connect
    self.client.connect(self.broker_host, self.broker_port)
  File "/usr/local/lib/python2.7/dist-packages/paho/mqtt/client.py", line 760, in connect
    return self.reconnect()
  File "/usr/local/lib/python2.7/dist-packages/paho/mqtt/client.py", line 919, in reconnect
    sock.do_handshake()
  File "/usr/lib/python2.7/ssl.py", line 840, in do_handshake
    self._sslobj.do_handshake()
ssl.SSLError: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed (_ssl.c:661)

在 mosquitto 上,这些错误出现了。

1504896114: New connection from 143.93.197.20 on port 8883.
1504896114: OpenSSL Error: error:14094418:SSL routines:SSL3_READ_BYTES:tlsv1 alert unknown ca
1504896114: OpenSSL Error: error:140940E5:SSL routines:SSL3_READ_BYTES:ssl handshake failure
1504896114: Socket error on client <unknown>, disconnecting.

蚊子会议

# Place your local configuration in /etc/mosquitto/conf.d/
#
# A full description of the configuration file is at
# /usr/share/doc/mosquitto/examples/mosquitto.conf.example


pid_file /var/run/mosquitto.pid

persistence true
persistence_location /var/lib/mosquitto/


log_type all
log_facility 5
log_timestamp true
log_dest file /var/log/mosquitto/mosquitto.log

include_dir /etc/mosquitto/conf.d

port 8883
cafile /etc/mosquitto/ca_certificates/ca-cert.pem
certfile /etc/mosquitto/certs/server-cert.pem
keyfile /etc/mosquitto/certs/server-key.pem

只有 Server 和 Ca 与代理主机名匹配。客户端使用自己的 CN 主机名。我希望这是对的?

希望你能帮我解决我的问题。

PS:我使用的是自签名证书! TLS 1.2 版

【问题讨论】:

  • 编辑问题以包含 mosquitto.conf,以便我们查看您的配置方式。证书 CN 是否也与代理的主机名匹配?
  • 只有 Server 和 Ca 与代理主机名匹配。客户端使用自己的 CN 主机名

标签: python mqtt tls1.2 mosquitto paho


【解决方案1】:

如果您使用的是 TLS v1.2,则需要将表达式(第 2 行:self.client.tls_set())'tls_version=ssl.PROTOCOL_TLSv1' 修改为 'tls_version=ssl.PROTOCOL_TLSv1_2',而不是像预期的那样。 ..TLSv1.2。这对我有用。

【讨论】:

    【解决方案2】:

    尝试提供以下内容。 ssl 的默认端口是 8883。我们可以启动多个监听器。在这种情况下,non-ssl 上 1883 和 ssl 上 8883。

    port 1883
    listener 8883
    

    【讨论】:

      猜你喜欢
      • 1970-01-01
      • 2022-01-03
      • 2016-11-06
      • 1970-01-01
      • 2022-07-06
      • 1970-01-01
      • 2015-04-10
      • 2018-08-31
      • 2015-04-17
      相关资源
      最近更新 更多