<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title><![CDATA[Форум Рутокен &mdash; Настройка Stunnel 5.5 для ГИС ЖКХ]]></title>
		<link>https://forum.rutoken.ru/topic/2952/</link>
		<atom:link href="https://forum.rutoken.ru/feed/rss/topic/2952/" rel="self" type="application/rss+xml" />
		<description><![CDATA[Недавние сообщения в теме «Настройка Stunnel 5.5 для ГИС ЖКХ».]]></description>
		<lastBuildDate>Thu, 21 Feb 2019 11:38:08 +0000</lastBuildDate>
		<generator>PunBB</generator>
		<item>
			<title><![CDATA[Re: Настройка Stunnel 5.5 для ГИС ЖКХ]]></title>
			<link>https://forum.rutoken.ru/post/12726/#p12726</link>
			<description><![CDATA[<p>Надо поменять sslVersion=TLSv1 на&nbsp; текущую версию OpenSSL sslVersion=TLSv1.1</p>]]></description>
			<author><![CDATA[null@example.com (a.pokrovsky)]]></author>
			<pubDate>Thu, 21 Feb 2019 11:38:08 +0000</pubDate>
			<guid>https://forum.rutoken.ru/post/12726/#p12726</guid>
		</item>
		<item>
			<title><![CDATA[Настройка Stunnel 5.5 для ГИС ЖКХ]]></title>
			<link>https://forum.rutoken.ru/post/12725/#p12725</link>
			<description><![CDATA[<p>Добрый день . Скачали новую версию Stunnel 5.5&nbsp; 64 разр. до этой версии была версия 2016 stunnel 5.3. 32 разрядная Столкнулись со следующей проблемой <br />1) Когда запускается сам stunnel.exe выдается ошибка в конфигурации<br />Работаем&nbsp; с ГИС ЖКХ.&nbsp; Используем при работе ГОСТ 34.10-2001<br />в старом конфиге использовали 32 разрядную&nbsp; pkcs11_gost.dll<br />Файл конфигурации</p><p>verify=2&nbsp; <br />client=yes&nbsp; </p><p>;ppak <br />CAFile=CA-PPAK.pem</p><p>sslVersion=TLSv1&nbsp; &nbsp;<br />taskbar=yes&nbsp; &nbsp;<br />DEBUG=7&nbsp; &nbsp;<br />engine=pkcs11<br />engineCtrl=MODULE_PATH:rtpkcs11ecp.dll&nbsp; &nbsp;<br />engineDefault=ALL</p><p>[pseudo-https]<br />engineNum = 1</p><p>;ppak<br />cert=client.crt&nbsp; </p><p>key = 70:6c:75:67:69:6e:32:30:31:38:30:32:32:31:31:33:34:38:34:36</p><p>accept = 127.0.0.1:8777&nbsp; <br />connect = api.dom.gosuslugi.ru:443</p><p>ciphers = GOST2001-GOST89-GOST89 <br />TIMEOUTclose = 0</p><br /><p>Выдает следующий лог <br />[ ] Running on Windows 6.2<br />[ ] No limit detected for the number of clients<br />[.] stunnel 5.50 on x64-pc-mingw32-gnu platform<br />[.] Compiled/running with OpenSSL 1.1.1a&nbsp; 20 Nov 2018<br />[.] Threading:WIN32 Sockets:SELECT,IPv6 TLS:ENGINE,OCSP,PSK,SNI<br />[ ] errno: (*_errno())<br />[ ] GUI message loop initialized<br />[ ] Running on Windows 6.2<br />[.] Reading configuration from file stunnel.conf<br />[.] UTF-8 byte order mark not detected<br />[ ] Enabling support for engine &quot;pkcs11&quot;<br />[.] UI set for engine #1 (pkcs11)<br />[ ] Executing engine control command MODULE_PATH:rtpkcs11ecp.dll<br />[ ] Engine #1 (pkcs11) set as default for ALL<br />[ ] Initializing engine #1 (pkcs11)<br />[ ] Engine #1 (pkcs11) initialized<br />[ ] Compression disabled<br />[ ] No PRNG seeding was required<br />[ ] Initializing service [pseudo-https]<br />[ ] Ciphers: GOST2001-GOST89-GOST89<br />[ ] TLS options: 0x02100004 (+0x00000000, -0x00000000)<br />[ ] Client certificate engine (pkcs11) not supported<br />[ ] Loading certificate from engine ID: client.crt<br />[!] ENGINE_ctrl_cmd: 80064064: error:80064064:pkcs11 engine:ctx_load_cert:invalid id<br />[ ] Initializing private key on engine ID: 70:6c:75:67:69:6e:32:30:31:38:30:32:32:31:31:33:34:38:34:36<br />[!] error queue: 26096080: error:26096080:engine routines:ENGINE_load_private_key:failed loading private key<br />[!] ENGINE_load_private_key: 80065064: error:80065064:pkcs11 engine:ctx_load_key:invalid id<br />[ ] Loading certificate from file: client.crt<br />[!] error queue: 140AB18F: error:140AB18F:SSL routines:SSL_CTX_use_certificate:ee key too small<br />[!] error queue: B09406F: error:0B09406F:x509 certificate routines:x509_pubkey_decode:unsupported algorithm<br />[!] SSL_CTX_use_certificate_chain_file: 609E09C: error:0609E09C:digital envelope routines:pkey_set_type:unsupported algorithm<br />[!] Service [pseudo-https]: Failed to initialize TLS context<br />[ ] Deallocating section defaults</p><p>[!] Server is down</p>]]></description>
			<author><![CDATA[null@example.com (a.pokrovsky)]]></author>
			<pubDate>Thu, 21 Feb 2019 09:51:25 +0000</pubDate>
			<guid>https://forum.rutoken.ru/post/12725/#p12725</guid>
		</item>
	</channel>
</rss>
