【问题标题】:TLS/SSL encryption in MQTT Mosquitto is not workingMQTT Mosquitto 中的 TLS/SSL 加密不起作用
【发布时间】:2021-08-14 02:15:01
【问题描述】:

我正在使用 Mosquitto MQTT 将一些监控测量值从远程 Raspberry Pi 发送到我的本地 Raspberry Pi。当流量未加密并通过端口 8001 运行时,一切正常。我使用密码进行身份验证,但是由于它是以纯文本形式发送的,因此并没有提供太多的安全性。因此,我想使用 TLS/SSL 加密,遗憾的是我无法设置。

我不擅长网络,但我会尽可能详细地解释所有内容。

  • sudo ufw allow 8883
  • 我的路由器中的端口转发从 LAN -> WAN with 80 -> 80, 443 -> 443, 8883 -> 8883
  • sudo ufw allow 80 # 我猜这只是获得证书所必需的。
  • sudo ufw allow 443 # 不知道有没有必要。
  • 我使用 sudo certbot certonly --standalone --preferred-challenges http -d domain.com 创建了 Let's Encrypt 证书# domain.com 只是一个占位符
  • sudo systemctl status mosquitto.service正在运行。

/etc/mosquitto/mosquitto.config

persistence false
persistence_location /var/lib/mosquitto/

listener 1883 192.168.0.235

listener 8883
certfile /etc/letsencrypt/live/domain.com/cert.pem
cafile /etc/letsencrypt/live/domain.com/fullchain.pem
keyfile /etc/letsencrypt/live/domain.com/privkey.pem
# tls_version tlsv1.2

allow_anonymous false
password_file /etc/mosquitto/passwd

log_dest file /var/log/mosquitto/mosquitto.log
include_dir /etc/mosquitto/conf.d

/etc/mosquitto/conf.d/default.conf 为空。

我的问题是发布和订阅不起作用。在带有代理的 Raspberry Pi 上,我运行 mosquitto_sub -h domain.com -t test --capath /etc/ssl/certs/ -d -p 8883。我不确定她是否--capath必须是/etc/ssl/certs/或来自letsencrypt /etc/letsencrypt/live/domain.com/的目录。

在发布站点上:我是否必须将任何证书(cert.pem、fullchain.pem 或 privkey.pem)复制到发布的 Raspberry Pi?因为我觉得我错过了什么,因为mosquitto_pub -h domain.com -t test -m "Hello World!" -d -p 8883 不起作用。

所以我认为我有所有可用的部分,但我没有正确地将它们放在一起。非常感谢任何帮助或反馈,我很乐意帮助提供额外的信息或日志。在下一步中,我想在 Python 中使用 paho-mqtt 将其自动化。

问候。

【问题讨论】:

  • 发布 Pi 是否与您的代理在同一网络上?如果是,您的路由器是否支持 Hairpin NAT?
  • 同时编辑问题以显示您从客户端收到的错误消息以及您尝试连接时的 mosquitto 日志。

标签: encryption mqtt mosquitto


【解决方案1】:

在您的mosquitto.conf 上,certfile 应指向fullchain.pem,cafile 应指向/etc/ssl/certs/DST_Root_CA_X3.pem。

当您使用mosquitto_pub 或mosquitto_sub 连接到代理时,您需要传递根证书,以便客户端可以验证代理的证书。所以在这两种情况下你都应该传递--cafile /etc/ssl/certs/DST_Root_CA_X3.pem(不要使用--capath,因为它不适用于.pem文件)

另外,您有allow_anonymous false,这意味着代理希望您在连接时传递用户名和密码。我建议先将其更改为true,这样您就可以专注于使 tls 连接正常工作。

你能试试这个并分享它是否有效吗?

【讨论】:

    猜你喜欢
    • 1970-01-01
    • 1970-01-01
    • 2013-09-24
    • 2021-03-15
    • 2023-04-08
    • 1970-01-01
    • 2016-06-12
    • 2020-06-13
    • 2017-08-12
    相关资源
    最近更新 更多