HTTPS stunnel 오류 : 1408F09B : SSL 루틴 : ssl3_get_record : https 프록시 요청
Sep 30 2020
stunnel과 squid로 HTTPS 프록시를 구성하고 있습니다.
그러나 포트 44444 (stunnel)를 통해 브라우저 요청을하는 경우 Mozilla 오류 페이지 "Secure Connection Failed"를 받았습니다.
내가 무엇을 놓치고 있습니까?
직접 브라우저 요청을하는 경우 (https://192.168.0.101:44444) stunnel이 44444 포트에서 연결을 수락하고 트래픽을 squid 프록시 포트 (55555)로 성공적으로 전달하므로 squid 오류 페이지가 수신되었습니다.
오징어 포트 (55555)를 통해 요청하면 모든 것이 잘 작동합니다.
SSL 인증서는 자체 서명됩니다. 이 명령으로 생성 :
sudo openssl req -nodes -new -days 365 -newkey rsa:1024 -x509 -keyout serverkey.pem -out servercert.pem
stunnel.log
2020.10.01 17:54:05 LOG7[main]: Found 1 ready file descriptor(s)
2020.10.01 17:54:05 LOG7[main]: FD=4 events=0x2001 revents=0x0
2020.10.01 17:54:05 LOG7[main]: FD=6 events=0x2001 revents=0x1
2020.10.01 17:54:05 LOG7[main]: Service [squid] accepted (FD=3) from 10.140.37.30:42284
2020.10.01 17:54:05 LOG7[33]: Service [squid] started
2020.10.01 17:54:05 LOG7[33]: Option TCP_NODELAY set on local socket
2020.10.01 17:54:05 LOG5[33]: Service [squid] accepted connection from 10.140.37.30:42284
2020.10.01 17:54:05 LOG6[33]: Peer certificate not required
2020.10.01 17:54:05 LOG7[33]: TLS state (accept): before SSL initialization
2020.10.01 17:54:05 LOG3[33]: SSL_accept: 1408F09B: error:1408F09B:SSL routines:ssl3_get_record:https proxy request
stunnel.conf
chroot = /var/lib/stunnel4/
setuid = stunnel4
setgid = stunnel4
pid = /stunnel4.pid
debug = 7
output = /stunnel.log
syslog = no
cert = /etc/stunnel/servercert.pem
key = /etc/stunnel/serverkey.pem
verify = 1
CApath = /certs
CRLpath = /crls
client = no
[squid]
accept = 44444
connect = 55555
squid.conf
acl localnet src 192.168.0.0/16
acl SSL_ports port 443
acl Safe_ports port 80
acl Safe_ports port 21
acl Safe_ports port 443
acl Safe_ports port 70
acl Safe_ports port 210
acl Safe_ports port 1025-65535
acl Safe_ports port 280
acl Safe_ports port 488
acl Safe_ports port 591
acl Safe_ports port 777
acl CONNECT method CONNECT
http_access deny !Safe_ports
http_access deny CONNECT !SSL_ports
http_access allow localhost manager
http_access deny manager
http_access allow localnet
http_access allow localhost
http_access allow all
http_port 55555
coredump_dir /var/spool/squid
refresh_pattern ^ftp: 1440 20% 10080
refresh_pattern ^gopher: 1440 0% 1440
refresh_pattern -i (/cgi-bin/|\?) 0 0% 0
refresh_pattern (Release|Packages(.gz)*)$ 0 20% 2880
refresh_pattern . 0 20% 4320
답변
AwesomeMan Oct 12 2020 at 15:44
stunnel 측의 구성으로 모든 것이 정상입니다. 문제는 내 클라이언트에 있었는데 잘못된 구성으로 인해 SSL \ TLS 핸드 셰이크가 시작되지 않습니다.