标签:apt div code com 传输过程 conf x509 ima img
sudo apt install stunnel
3、配置
编辑文件,启动stunnel
sudo vim /etc/default/stunnel4
4、创建证书
sudo mkdir /etc/stunnel/tls cd /etc/stunnel/tls sudo openssl genrsa -out key.pem 2048 #创建一个2048位的秘钥 sudo openssl req -new -x509 -key key2.pem -out cert2.pem -days 3650 -subj "/C=US/ST=Denial/L=Springfield/O=Dis/CN=域名或主机名" sudo chmod 640 key.pem cert.pem private.pem
上述操作是在创建自有证书,若你有从CA机构买来的证书可替换上述操作
5、编写stunnel的配置文件
sudo vim /etc/stunnel/stunnel.conf pid = /var/run/stunnel4/stunnel.pid output = /var/log/stunnel4/stunnel.log #日志位置 [node_exporter] accept = 9101 #外界访问的端口,IP默认是本机 connect = 127.0.0.1:9100 #需要加密的URL,当外界访问本机的9101端口时会访问到9100,并且9101端口出去的是ssl加密过的数据 cert = /etc/stunnel/tls/cert.pem key = /etc/stunnel/tls/key.pem
6、启动stunnel
sudo systemctl restart stunnel4.service sudo systemctl enable stunnel4.service
sudo systemctl status stunnel4.service #检查stunnel运行是否成功
7、日志位置
/var/log/stunnel4/stunnel.log
标签:apt div code com 传输过程 conf x509 ima img
原文地址:https://www.cnblogs.com/zqj-blog/p/11239638.html