使用 Cockpit 与 Cloudflare/Portzilla 时出现 TLS 错误

使用 Cockpit 与 Cloudflare/Portzilla 时出现 TLS 错误

我最近安装了 cockpit(并且非常喜欢它),并决定在我的 cloudflare 帐户上使用 Portzilla 设置一个子域,以便我可以远程访问我的 cockpit 服务器。我一直收到连接失败错误,当我查看时journalctl -u cockpit,我得到了这个:

Dec 26 00:27:52 helios systemd[1]: Starting Cockpit Web Service...
Dec 26 00:27:52 helios remotectl[22645]: Generating temporary certificate using: sscg --quiet --lifetime 3650 --key-strength 2048 --cert-key-file /etc/cockpit/ws-certs.d/0-self-signed.cert --cert-file /etc/cockpit/ws-certs.d/0-self-signed.cert --ca-file /etc/cockpit/ws-certs.d/0-self-signed-ca.pem --hostname helios --organization 90b1c6e4a5dc40aeb98d6ccf90a3257f --subject-alt-name localhost --subject-alt-name IP:127.0.0.1/255.255.255.255
Dec 26 00:27:52 helios remotectl[22645]: Error generating temporary dummy cert using sscg, falling back to openssl
Dec 26 00:27:52 helios remotectl[22645]: Generating temporary certificate using: openssl req -x509 -days 36500 -newkey rsa:2048 -keyout /etc/cockpit/ws-certs.d/0-self-signed.S4R2V0.tmp -keyform PEM -nodes -out /etc/cockpit/ws-certs.d/0-self-signed.Z6R2V0.tmp -outform PEM -subj /O=90b1c6e4a5dc40aeb98d6ccf90a3257f/CN=helios -config /tmp/ssl.conf.47R2V0 -extensions v3_req
Dec 26 00:27:52 helios systemd[1]: Started Cockpit Web Service.
Dec 26 00:27:52 helios cockpit-tls[22649]: cockpit-tls: gnutls_handshake failed: A TLS fatal alert has been received.
Dec 26 00:27:52 helios cockpit-tls[22649]: cockpit-tls: gnutls_handshake failed: A TLS fatal alert has been received.
Dec 26 00:27:55 helios cockpit-tls[22649]: cockpit-tls: gnutls_handshake failed: A TLS fatal alert has been received.
Dec 26 00:27:55 helios cockpit-tls[22649]: cockpit-tls: gnutls_handshake failed: A TLS fatal alert has been received.
Dec 26 00:27:55 helios cockpit-tls[22649]: cockpit-tls: gnutls_handshake failed: A TLS fatal alert has been received.
Dec 26 00:27:55 helios cockpit-tls[22649]: cockpit-tls: gnutls_handshake failed: A TLS fatal alert has been received.
Dec 26 00:30:08 helios systemd[1]: cockpit.service: Succeeded.
Dec 26 00:34:18 helios systemd[1]: Starting Cockpit Web Service...
Dec 26 00:34:18 helios systemd[1]: Started Cockpit Web Service.
Dec 26 00:34:18 helios cockpit-tls[25787]: cockpit-tls: gnutls_handshake failed: A TLS fatal alert has been received.
Dec 26 00:34:18 helios cockpit-tls[25787]: cockpit-tls: gnutls_handshake failed: A TLS fatal alert has been received.
Dec 26 00:34:47 helios systemd[1]: Stopping Cockpit Web Service...
Dec 26 00:34:47 helios systemd[1]: cockpit.service: Succeeded.
Dec 26 00:34:47 helios systemd[1]: Stopped Cockpit Web Service.
Dec 26 00:34:47 helios systemd[1]: Starting Cockpit Web Service...
Dec 26 00:34:47 helios systemd[1]: Started Cockpit Web Service.
Dec 26 00:34:52 helios cockpit-tls[26028]: cockpit-tls: gnutls_handshake failed: A TLS fatal alert has been received.
Dec 26 00:34:52 helios cockpit-tls[26028]: cockpit-tls: gnutls_handshake failed: A TLS fatal alert has been received.
Dec 26 00:34:54 helios cockpit-tls[26028]: cockpit-tls: gnutls_handshake failed: A TLS fatal alert has been received.
Dec 26 00:36:56 helios systemd[1]: cockpit.service: Succeeded.
Dec 26 00:38:12 helios systemd[1]: Starting Cockpit Web Service...
Dec 26 00:38:12 helios systemd[1]: Started Cockpit Web Service.
Dec 26 00:38:12 helios cockpit-tls[27201]: cockpit-tls: gnutls_handshake failed: A TLS fatal alert has been received.
Dec 26 00:38:12 helios cockpit-tls[27201]: cockpit-tls: gnutls_handshake failed: A TLS fatal alert has been received.
Dec 26 00:38:13 helios cockpit-tls[27201]: cockpit-tls: gnutls_handshake failed: A TLS fatal alert has been received.
Dec 26 00:38:13 helios cockpit-tls[27201]: cockpit-tls: gnutls_handshake failed: A TLS fatal alert has been received.
Dec 26 00:38:13 helios cockpit-tls[27201]: cockpit-tls: gnutls_handshake failed: A TLS fatal alert has been received.
Dec 26 00:40:19 helios systemd[1]: cockpit.service: Succeeded.

我承认 Cockpit 默认不识别反向代理,必须进行cockpit.conf相应设置,我可以根据要求提供,但是我看到的必需内容(例如条目Origins(不确定是否已正确完成))ProtocolHeader = X-Forwarded-Proto已经添加到配置中。我是新手,非常希望得到任何帮助。提前谢谢

相关内容