[OpenSIPS-Users] TLS Error

ideanet help ideanethelp at gmail.com
Sun May 22 22:53:41 UTC 2022


Hi Wang,
Can you check the user rights of that directory? ls -lrth
/etc/opensips/tls/user


On Mon, May 23, 2022 at 3:10 AM Wang Wilson <wyhc at hotmail.com> wrote:

> Hello,
>
> I am sending this to follow the issue that was reported on *Sep 17
> 13:13:06 EST 2020.*
>
>
>
> My problem is that I get the same error message, but the path to
> /etc/opensips/tls/user/user-cert.pem is correct and it is not symlink file.
>
>
>
> I just start to explore the TLS method for us to support SIP service. What
> could be the reason for this?
>
>
>
> Thanks in advance.
>
>
>
> Regards
>
> Wilson
>
>
> ------------------------------------------------------------------------------------------
>
> INFO:core:mod_init: initializing TCP-plain protocol
>
> May 22 22:32:45 wilson-VirtualBox /usr/local/opensips/sbin/opensips[7437]:
> INFO:tls_mgm:mod_init: initializing TLS management
>
> May 22 22:32:45 wilson-VirtualBox /usr/local/opensips/sbin/opensips[7437]:
> INFO:tls_mgm:mod_init: disabling compression due ZLIB problems
>
> May 22 22:32:45 wilson-VirtualBox /usr/local/opensips/sbin/opensips[7437]:
> INFO:tls_mgm:init_tls_dom: Processing TLS domain 'default'
>
> May 22 22:32:45 wilson-VirtualBox /usr/local/opensips/sbin/opensips[7437]:
> NOTICE:tls_mgm:init_tls_dom: No EC curve defined
>
> May 22 22:32:45 wilson-VirtualBox /usr/local/opensips/sbin/opensips[7437]:
> INFO:tls_mgm:get_ssl_ctx_verify_mode: client verification activated. Client
> certificates are NOT mandatory.
>
> May 22 22:32:45 wilson-VirtualBox /usr/local/opensips/sbin/opensips[7437]:
> NOTICE:tls_mgm:init_tls_dom: no CA dir for tls 'default' defined, using
> default '/etc/pki/CA/'
>
> May 22 22:32:45 wilson-VirtualBox /usr/local/opensips/sbin/opensips[7437]:
> NOTICE:tls_mgm:init_tls_dom: no crl for tls, using none
>
> May 22 22:32:45 wilson-VirtualBox /usr/local/opensips/sbin/opensips[7437]:
> ERROR:tls_mgm:tls_print_errstack: TLS errstack: error:140AB18E:SSL
> routines:SSL_CTX_use_certificate:ca md too weak
>
> May 22 22:32:45 wilson-VirtualBox /usr/local/opensips/sbin/opensips[7437]:
> ERROR:tls_mgm:load_certificate: unable to load certificate file
> '/etc/opensips/tls/user/user-cert.pem'
>
> May 22 22:32:45 wilson-VirtualBox /usr/local/opensips/sbin/opensips[7437]:
> ERROR:tls_mgm:init_tls_domains: Failed to init TLS domain 'default'
>
> May 22 22:32:45 wilson-VirtualBox /usr/local/opensips/sbin/opensips[7437]:
> ERROR:core:init_mod: failed to initialize module tls_mgm
>
> May 22 22:32:45 wilson-VirtualBox /usr/local/opensips/sbin/opensips[7437]:
> ERROR:core:main: error while initializing modules
>
> May 22 22:32:45 wilson-VirtualBox /usr/local/opensips/sbin/opensips[7437]:
> INFO:core:cleanup: cleanup
>
> May 22 22:32:45 wilson-VirtualBox /usr/local/opensips/sbin/opensips[7437]:
> NOTICE:core:main: Exiting....
>
>
>
>
> _______________________________________________
> Users mailing list
> Users at lists.opensips.org
> http://lists.opensips.org/cgi-bin/mailman/listinfo/users
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.opensips.org/pipermail/users/attachments/20220523/835a3d60/attachment-0001.html>


More information about the Users mailing list