The new SFCB broker fails to start with a SSL-related error: Failure setting ECDH curve name (secp22

本文介绍了解决sfcbd默认ECDH曲线secp224r1在OpenSSL上不可用的问题。通过设置sslEcDhCurveName为secp384r1,可在Fedora上使软件包安装后正常工作。
# openssl ecparam -list_curves
  secp384r1 : NIST/SECG curve over a 384 bit prime field
  secp521r1 : NIST/SECG curve over a 521 bit prime field
  prime256v1: X9.62/SECG curve over a 256 bit prime field

The problem is that sfcbd's default secp224r1 ECDH curve is not currently enabled in openssl on Fedora (there's already request to enable it, see rhbz#1067697).

This can be workarounded by setting "sslEcDhCurveName: secp384r1" in "/etc/sfcb/sfcb.cfg".

I will change the default curve to "secp384r1" temporarily to make the package work right after installation.


https://bugzilla.redhat.com/show_bug.cgi?id=1097794


注意 OpenSSL的版本,旧一些的版本没有ecparam

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值