簡體   English   中英

使用PHP連接到FTPS,並使用證書作為身份驗證

[英]Connecting to FTPS using PHP and certificate as auth

我很難設置到FTPS的連接。

我應該使用SSL / TLS和AUTH(顯式標准)進行連接。 我有一個服務器地址和一個端口(:60000)和一個來自服務器所有者的公鑰以及我自己的證書。

谷歌搜索后我認為卷曲是我最好的選擇,但我真的不知道使用什么卷曲選項。

有沒有人在一個片段上有一個工作示例,它連接並上傳/下載文件到這樣的FTPS?

這個頁面有一些信息http://php.net/manual/en/function.curl-setopt.php例如,同樣的想法,但使用用戶名/密碼

$username = 'username';
$password = 'password';
$url = 'example.com';
$ftp_server = "ftp://" . $username . ":" . $password . "@" . $url;

echo "Starting CURL.\n";
$ch = curl_init();
echo "Set CURL URL.\n";

//curl FTP
curl_setopt($ch, CURLOPT_URL, $ftp_server);

//For Debugging
//curl_setopt($ch, CURLOPT_VERBOSE, TRUE);   

//SSL Settings
curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, FALSE);
curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, FALSE);
curl_setopt($ch, CURLOPT_FTP_SSL, CURLFTPSSL_TRY);

//List FTP files and directories
curl_setopt($ch, CURLOPT_FTPLISTONLY, TRUE);

//Output to curl_exec
curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);

echo "Executing CURL.\n";
$output = curl_exec($ch);
curl_close($ch);
echo "Closing CURL.\n";
echo $output . "\n";
$files = explode("\n", $output);
print_r($files);

任何想法如何使用證書?

提前致謝!

遲到的反應我知道,但我也一直在努力解決這個問題,以下兩段代碼最終為我工作,所以即使對你來說太晚了,也許它會幫助別人。 在我的情況下,我只需要使用CA證書驗證對等方,因此如果您需要與對等方進行驗證(當然超出用戶/通行證),您可能需要集成下面的第三個代碼塊。

正在下載(僅限CA證書)

$ftp_server = 'ftps://YOUR-SERVER-NAME/';
$ftp_user = 'FTP-USER-NAME';
$ftp_password = 'FTP-PASSWORD';

$ftp_certificate = 'PATH TO CA CERT'; 
// ...e.g./var/www/certs/ssl-certificate.pub.crt    
$source_file = 'REMOTE-FILE-PATH';
$destination_file = 'LOCAL-FILE-PATH';

$file = fopen($destination_file, 'w');

$ch = curl_init();

curl_setopt($ch, CURLOPT_VERBOSE, TRUE);
curl_setopt($ch, CURLOPT_URL, $ftp_server . $source_file);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_USERPWD, $ftp_user . ':' . $ftp_password);
curl_setopt($ch, CURLOPT_TIMEOUT, 400);
curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 400);
curl_setopt($ch, CURLOPT_FILE, $file);

//SSL
curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, true);
curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 2);
curl_setopt($ch, CURLOPT_CAINFO, $ftp_certificate);
curl_setopt($ch, CURLOPT_FTP_SSL, CURLFTPSSL_ALL);
curl_setopt($ch, CURLOPT_FTPSSLAUTH, CURLFTPAUTH_SSL);

curl_exec($ch);
$error_no = curl_errno($ch);
$error_msg = curl_error($ch);
curl_close ($ch);
if ($error_no == 0) {
    $msg = 'File downloaded succesfully.';
} else {
    $msg = 'File download error:' . $error_msg . ' | ' . $error_no;
}
fclose($file);
echo $msg;

上傳(僅限CA證書)

$ftp_server = 'ftps://YOUR-SERVER-NAME/';
$ftp_user = 'FTP-USER-NAME';
$ftp_password = 'FTP-PASSWORD';

$ftp_certificate = 'PATH TO CA CERT'; 
// ...e.g./var/www/certs/ssl-certificate.pub.crt    
$source_file = 'LOCAL-FILE-PATH';
$destination_file = 'REMOTE-FILE-PATH';

$file = fopen($source_file, 'r');

$ch = curl_init();

curl_setopt($ch, CURLOPT_VERBOSE, TRUE);
curl_setopt($ch, CURLOPT_URL, $ftp_server . $destination_file);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_USERPWD, $ftp_user . ':' . $ftp_password);
curl_setopt($ch, CURLOPT_TIMEOUT, 400);
curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 400);

curl_setopt($ch, CURLOPT_UPLOAD, 1);
curl_setopt($ch, CURLOPT_INFILE, $file);
curl_setopt($ch, CURLOPT_INFILESIZE, filesize($source_file));

//SSL stuff
curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, true);
curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 2);
curl_setopt($ch, CURLOPT_CAINFO, $ftp_certificate);

curl_setopt($ch, CURLOPT_FTP_SSL, CURLFTPSSL_ALL);
curl_setopt($ch, CURLOPT_FTPSSLAUTH, CURLFTPAUTH_SSL);

$upload_result = curl_exec($ch);
$upload_info = curl_getinfo($ch);
$error_no = curl_errno($ch);
$error_msg = curl_error($ch);
curl_close ($ch);
if ($error_no == 0) {
    $msg = 'File uploaded succesfully.';
} else {
    $msg = 'File upload error:' . $error_msg . ' | ' . $error_no;
}

fclose($file);
echo $msg . '(' . filesize($source_file) . ')';

您可以像這樣檢查響應代碼:

if ($upload_info['http_code'] == '226') {...}

添加公鑰/私鑰(在curl_exec之前curl_exec

// A private SSL key.
// If your key file has a password, you will need to set
// this with CURLOPT_SSLKEYPASSWD
curl_setopt($ch, CURLOPT_SSLKEY, $keyFile);

// A PEM formatted certificate- with CURLOPT_SSLCERTTYPE
// you could also use DER or ENG formats
curl_setopt($ch, CURLOPT_SSLCERT, $certFile);
curl_setopt($ch, CURLOPT_SSLCERTPASSWD, $certPass);

當然,你可能不得不在PHP,Apache和nginx中調整timemout限制,就像我在Plesk安裝中遇到麻煩一樣,如果文件很大而且傳輸速度很慢。

暫無
暫無

聲明:本站的技術帖子網頁,遵循CC BY-SA 4.0協議,如果您需要轉載,請注明本站網址或者原文地址。任何問題請咨詢:yoyou2525@163.com.

 
粵ICP備18138465號  © 2020-2024 STACKOOM.COM