【发布时间】:2022-01-24 20:46:56
【问题描述】:
我正在 Google Cloud 实例上安装 OpenVPN 访问服务器。它的 webUI 使用 https 侦听端口 943。它有一个自签名证书,其名称与服务器的主机名 (10.150.0.2) 不匹配。我无法启动 SSH 隧道。我正在寻找一种方法来解决从 IAP 服务到我的服务器的连接问题。
我正在运行的命令是gcloud compute start-iap-tunnel vpn 943 --local-host-port=localhost:943 我收到正常的Testing if tunnel connection works 消息。
ERROR: (gcloud.compute.start-iap-tunnel) While checking if a connection can be made: Error while connecting [4003: 'failed to connect to backend']. (Failed to connect to port 943) 出错了
如果我将--log-http 添加到命令调用中,则相关信息如下(它看起来像一个正常的请求/响应周期,我假设是从我的客户端到 IAP 服务的 200):
Testing if tunnel connection works.
=======================
==== request start ====
uri: https://oauth2.googleapis.com/token
method: POST
== headers start ==
b'content-type': b'application/x-www-form-urlencoded'
b'user-agent': b'google-cloud-sdk gcloud/367.0.0 command/gcloud.compute.start-iap-tunnel invocation-id/db27de82264f47fcb63f6680afaa8327 environment/None environment-version/None interactive/False from-script/False python/3.7.9 term/xterm-256color (Macintosh; Intel Mac OS X 21.2.0)'
== headers end ==
== body start ==
Body redacted: Contains oauth token. Set log_http_redact_token property to false to print the body of this request.
== body end ==
==== request end ====
---- response start ----
status: 200
-- headers start --
Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000,h3-Q050=":443"; ma=2592000,h3-Q046=":443"; ma=2592000,h3-Q043=":443"; ma=2592000,quic=":443"; ma=2592000; v="46,43"
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Content-Encoding: gzip
Content-Type: application/json; charset=utf-8
Date: Fri, 24 Dec 2021 02:11:52 GMT
Expires: Mon, 01 Jan 1990 00:00:00 GMT
Pragma: no-cache
Server: scaffolding on HTTPServer2
Transfer-Encoding: chunked
Vary: Origin, X-Origin, Referer
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-XSS-Protection: 0
-- headers end --
-- body start --
Body redacted: Contains oauth token. Set log_http_redact_token property to false to print the body of this response.
-- body end --
total round trip time (request+response): 0.246 secs
---- response end ----
----------------------
ERROR: (gcloud.compute.start-iap-tunnel) While checking if a connection can be made: Error while connecting [4003: 'failed to connect to backend']. (Failed to connect to port 943)
据我所知,这是start-tap-tunnel 易于访问的故障排除的限制。
在生成 la 证书之前,我们可以连接到 10.150.0.2:943 的本地计算机。
root@viongier:/usr/local/openvpn_as# wget https://10.150.0.2:943
--2021-12-24 02:01:47-- https://10.150.0.2:943/
Connecting to 10.150.0.2:943... connected.
ERROR: The certificate of ‘10.150.0.2’ is not trusted.
ERROR: The certificate of ‘10.150.0.2’ doesn't have a known issuer.
The certificate's owner does not match hostname ‘10.150.0.2’
在我看来,我的客户端很高兴连接到 IAP 服务,但无法连接到我的服务器。如果由于证书而出错,我希望看到 IAP 错误。我唯一能想到的测试方法是生成一个发行者谷歌喜欢的证书。 (例如 LetsEncrypt。)
【问题讨论】:
标签: ssl google-cloud-platform openvpn-connect