【问题标题】:How to create HTTPS server with TLS 1.3 in Node.js v11如何在 Node.js v11 中使用 TLS 1.3 创建 HTTPS 服务器
【发布时间】:2019-03-24 08:52:35
【问题描述】:

我可以在 Node.js v11 中使用 https 模块来创建 TLS v1.3 服务器吗? Node.js 版本是 11.12.0 OpenSSL 版本是 1.1.1

const https = require('https');
const fs = require('fs');

const options = {
  key: fs.readFileSync('./tls/server.key'),
  cert: fs.readFileSync('./tls/server.crt')
};

https.createServer(options, (req, res) => {
  console.log('req', req)
  res.writeHead(200);
  res.end('hello world\n');
}).listen(8443, () => console.log('running'));

用OpenSSL测试一下,失败了

openssl s_client -connect 127.0.0.1:8443 -tls1_3

【问题讨论】:

  • 确保您使用的是 OpenSSL 1.1.1b。

标签: javascript node.js ssl


【解决方案1】:

如果有人偶然发现这个问题,nodejs v12 现在支持 TLS 1.3。

这里是一个示例代码 sn-p,它还生成自己的自签名证书以进行快速测试:

const https = require("https")
const fs = require("fs");
const forge = require('node-forge')
    forge.options.usePureJavaScript = true 
const express = require("express")

var pki = forge.pki;
var keys = pki.rsa.generateKeyPair(2048);
var cert = pki.createCertificate();

cert.publicKey = keys.publicKey;
cert.serialNumber = '01';
cert.validity.notBefore = new Date();
cert.validity.notAfter = new Date();
cert.validity.notAfter.setFullYear(cert.validity.notBefore.getFullYear()+1);

var attrs = [{
    name: 'commonName',
    value: 'www.cooltest.site'
  }, {
    name: 'countryName',
    value: 'US'
  }, {
    shortName: 'ST',
    value: 'Illinois'
  }, {
    name: 'localityName',
    value: 'Downers Grove'
  }, {
    name: 'organizationName',
    value: 'Test'
  }, {
    shortName: 'OU',
    value: 'Test'
  }];
cert.setSubject(attrs);
cert.setIssuer(attrs);
cert.setExtensions([{
    name: 'basicConstraints',
    cA: true
  }, {
    name: 'keyUsage',
    keyCertSign: true,
    digitalSignature: true,
    nonRepudiation: true,
    keyEncipherment: true,
    dataEncipherment: true
  }, {
    name: 'extKeyUsage',
    serverAuth: true,
    clientAuth: true,
    codeSigning: true,
    emailProtection: true,
    timeStamping: true
  }, {
    name: 'nsCertType',
    client: true,
    server: true,
    email: true,
    objsign: true,
    sslCA: true,
    emailCA: true,
    objCA: true
  }, {
    name: 'subjectAltName',
    altNames: [{
      type: 6, // URI
      value: 'http://www.mycooltest.site'
    }, {
      type: 7, // IP
      ip: '127.0.0.1'
    }]
  }, {
    name: 'subjectKeyIdentifier'
  }]);
cert.sign(keys.privateKey);

var private_key = pki.privateKeyToPem(keys.privateKey);
var public_key = pki.certificateToPem(cert);

// In case you need the newly generated keys displayed or saved
// console.log(public_key);
// console.log(private_key);
// fs.writeFileSync("private.pem",private_key)
// fs.writeFileSync("public.crt",public_key)


const options = {
    key: private_key,
    cert: public_key
    // In case you already have the keys available to you
    // key: fs.readFileSync("key.pem"),
    // cert: fs.readFileSync("chain.pem")
};

const app = express();

app.use((req, res) => {
  res.writeHead(200);
  res.end("hello world\n");
});

app.listen(8000);

https.createServer(options, app).listen(8080);

【讨论】:

  • 是否透明且默认使用?我需要做些什么来启用它吗?
  • 不,查看添加的带有 chrome 的代码,默认情况下显示 TLS 1.3
【解决方案2】:

根据 3 月 19 日的官方博客文章,TLS1.3 尚未得到官方支持。 https://developer.ibm.com/blogs/tls13-is-coming-to-nodejs/

我花了 2019 年初的时间来解决通过 API 泄​​漏的差异,并打开了一个拉取请求。希望 TLS1.3 很快会在 Node.js 11.x 中发布。

...

好消息是,在 Node.js 中获得对 TLS 1.3 的支持方面取得了进展,您应该能够很快开始使用它(希望在 10 月份 Node.js 12.x 进入 LTS 时)。

【讨论】:

  • 哦,知道了
猜你喜欢
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 2021-06-27
  • 1970-01-01
  • 2021-06-06
  • 2020-11-22
  • 1970-01-01
相关资源
最近更新 更多