HIi jean
Thank you for your help!
my configuration is as follows:
(1)c2s.xml:
<local>
<id register-enable='true'
require-starttls='true'
>fuwenjuan.csi</id>
<ip>0.0.0.0</ip>
<port>5222</port>
<ssl-port>5223</ssl-port>
<pemfile>/usr/local/etc/jabberd/server.pem</pemfile>
<verify-mode>7</verify-mode>
</local>
(2)router.xml
<local>
<ip>0.0.0.0</ip>
<port>5347</port>
<users>/usr/local/etc/jabberd/router- users.xml</users>
<secret>secret</secret>
<pemfile>/usr/local/etc/jabberd/server.pem</pemfile>
</local>
(3)s2s.xml
<local>
<ip>0.0.0.0</ip>
<port>5269</port>
<resolver>resolver</resolver>
<pemfile>/usr/local/etc/jabberd/server.pem</pemfile>
<verify-mode>7</verify-mode>
<cachain>/usr/local/etc/jabberd/cachain.pem</cachain>
</local>
(4)the configuration of reslover.xml and sm.xml is just uncommont the pemfile!
When i configure TLS
according to Jabberd 2 Installation and Administration Guide
and generate CA according to
http://jabberd.jabberstudio.org/2/docs/jabberd_guide.html#ssl_key "
openssl req -new -x509 -newkey rsa:1024 -days 3650 -keyout privkey.pem-out
server.pem
//the Common name is my jabberd server name
openssl rsa -in privkey.pem -out privkey.pem
cat privkey.pem >> server.pem
rm privkey.pem
mv server.pem /usr/local/etc/jabberd/server.pem
chown root:jabber /usr/local/etc/jabberd/server.pem
chmod 640 /usr/local/etc/jabberd/server.pem
I have tow qustions:
first :how to generate or derive the cachain.pem in s2s componet?
second:how to add the certification to trust CA?
Best regards!
wenjuanfu
> Hi Wenjuanfu,
>
> it would be more helpful if you could provide the relevant parts of
> your components configuration.
> Furthermore, try running your components, especially the router, in
> debug mode (with -D), and have a look at that. Watch out, it spills a
> lot of information.
>
> A blind guess is that the jabber server isn't satisfied with the trust
> chain of your self-signed certificate.
>
> Best,
> jean
>
> On 12/5/07, ??? <[EMAIL PROTECTED]> wrote:
> >
> >
> > Hi?
> > My jabberd2 server can just work in the default mode.When i configure TLS
> > according to Jabberd 2 Installation and Administration Guide
> > and generate CA according to
> > http://jabberd.jabberstudio.org/2/docs/jabberd_guide.html#ssl_key"
> > openssl req -new -x509 -newkey rsa:1024 -days 3650 -keyout privkey.pem
> > -out server.pem
> > //the Common name is my jabberd server name
> > openssl rsa -in privkey.pem -out privkey.pem
> > cat privkey.pem >> server.pem
> > rm privkey.pem
> > mv server.pem /usr/local/etc/jabberd/server.pem
> > chown root:jabber /usr/local/etc/jabberd/server.pem
> > chmod 640 /usr/local/etc/jabberd/server.pem
> >
> > When I start jabberd server,I can not make all componet work!
> >
> > The error from the syslog is :
> > Thu Nov 29 14:38:33 2007 [notice] error from router: SSL handshake error
> > (error:14090086:SSL
> > routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify
> > failed)
> >
> > The error from debug infomation is :
> > S2S : sx (ssl.c:52) verify error:num=18:self signed
> > certificate:depth=0:/C=GB/ST=Berkshire/L=Newbury/O=My
> > Company Ltd/CN=fuwenjuan.csi
> >
> >
> > when i use commands: netstat -a
> > the result is this:
> >
> > tcp 0 0 localhost.csi:5347 localhost.csi:32852
> > ESTABLISHED
> > tcp 0 0 localhost.csi:5347 localhost.csi:32853
> > ESTABLISHED
> > tcp 0 0 localhost.csi:5347 localhost.csi:32854
> > ESTABLISHED
> > tcp 0 0 localhost.csi:5347 localhost.csi:32855
> > ESTABLISHED
> > tcp 0 0 localhost.csi:32855 localhost.csi:5347
> > ESTABLISHED
> > tcp 0 0 localhost.csi:32854 localhost.csi:5347
> > ESTABLISHED
> > tcp 0 0 localhost.csi:32853 localhost.csi:5347
> > ESTABLISHED
> > tcp 0 0 localhost.csi:32852 localhost.csi:5347
> > ESTABLISHED
> >
> >
> > Who can tell why or help me?
> >
> >
> >
> >
> > Best regards?
> >
> >
> >
> > --
> > from:wenjuanfu
> > gmail:[EMAIL PROTECTED]
> > _______________________________________________
> > Jabberd2 mailing list
> > [email protected]
> > http://lists.xiaoka.com/listinfo.cgi/jabberd2-xiaoka.com
> >
> >
--
from:wenjuanfu
gmail:[EMAIL PROTECTED]
--
from:wenjuanfu
gmail:[EMAIL PROTECTED]
_______________________________________________
Jabberd2 mailing list
[email protected]
http://lists.xiaoka.com/listinfo.cgi/jabberd2-xiaoka.com