简体   繁体   English

Golang SSL TCP套接字证书配置

[英]Golang SSL TCP socket certificate configuration

I'm creating a Go TCP server (NOT http/s) and I'm trying to configure it to use SSL. 我正在创建一个Go TCP服务器(不是http / s),我正在尝试将其配置为使用SSL。 I have a StartCom free SSL certificate which I am trying to use to accomplish this. 我有一个StartCom免费的SSL证书,我试图用来完成这个。 My server code looks like this: 我的服务器代码如下所示:

    cert, err := tls.LoadX509KeyPair("example.com.pem", "example.com.key")
    if err != nil {
        fmt.Println("Error loading certificate. ",err)
    trustCert, err := ioutil.ReadFile("sub.class1.server.ca.pem")
    if err != nil {
        fmt.Println("Error loading trust certificate. ",err)
    validationCert, err := ioutil.ReadFile("ca.pem")
    if err != nil {
        fmt.Println("Error loading validation certificate. ",err)
    certs := x509.NewCertPool()
    if !certs.AppendCertsFromPEM(validationCert) {
        fmt.Println("Error installing validation certificate.")
    if !certs.AppendCertsFromPEM(trustCert) {
        fmt.Println("Error installing trust certificate.")

    sslConfig := tls.Config{RootCAs: certs,Certificates: []tls.Certificate{cert}}

    service := ":5555"
    tcpAddr, error := net.ResolveTCPAddr("tcp", service)
    if error != nil {
        fmt.Println("Error: Could not resolve address")
    } else {
        netListen, error := tls.Listen(tcpAddr.Network(), tcpAddr.String(), &sslConfig)
        if error != nil {
        } else {
            defer netListen.Close()

            for {
                fmt.Println("Waiting for clients")
                connection, error := netListen.Accept()

I've tried switching around the order of the certs, not including some certs, etc. but the output from openssl s_client -CApath /etc/ssl/certs/ -connect localhost:5555 remains essentially the same, verify error:num=20:unable to get local issuer certificate . 我已经尝试切换证书的顺序,不包括一些证书等,但openssl s_client -CApath /etc/ssl/certs/ -connect localhost:5555基本保持不变, verify error:num=20:unable to get local issuer certificate See here for full output. 请参阅此处获取完整输出 I seem to be doing something wrong with the intermediate certificates, but I have no idea what. 我似乎对中间证书做错了,但我不知道是什么。 I have been working on this for a few days, lots of googling and SO'ing, but nothing seemed to quite fit my situation. 我已经在这方面工作了几天,大量的谷歌搜索和SO'ing,但似乎没有什么比我的情况更合适。 I have set up many certificates in Apache and HAProxy, but this really has me stumped. 我已经在Apache和HAProxy中设置了许多证书,但这确实令我难过。

The RootCAs field is for clients verifying server certificates. RootCAs字段用于验证服务器证书的客户端。 I assume you only want to present a cert for verification, so anything you need should be loaded into the Certificates slice. 我假设您只想提供验证证书,因此您需要的任何内容都应加载到Certificates片中。

Here is a minimal example: 这是一个最小的例子:

cert, err := tls.LoadX509KeyPair("example.com.pem", "example.com.key")
if err != nil {
    log.Fatal("Error loading certificate. ", err)

tlsCfg := &tls.Config{Certificates: []tls.Certificate{cert}}

listener, err := tls.Listen("tcp4", "", tlsCfg)
if err != nil {
defer listener.Close()

for {
    log.Println("Waiting for clients")
    conn, err := listener.Accept()
    if err != nil {
    go handle(conn)

Even though you're not using HTTPS, it may still be useful to walk through the server setup starting at http.ListenAndServeTLS . 即使您没有使用HTTPS,从http.ListenAndServeTLS开始http.ListenAndServeTLS服务器设置仍然很有用。

声明:本站的技术帖子网页,遵循CC BY-SA 4.0协议,如果您需要转载,请注明本站网址或者原文地址。任何问题请咨询:yoyou2525@163.com.

粤ICP备18138465号  © 2020-2024 STACKOOM.COM