Openssl 无法连接到Indy SSL TCP服务器

Openssl 无法连接到Indy SSL TCP服务器,openssl,indy10,c++builder-2010,Openssl,Indy10,C++builder 2010,我正在尝试构建通过Indy SSL TCP组件进行通信的服务器和客户端应用程序(C++Builder 2010)。我已使用以下命令生成证书和私钥: openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 365 -config C:\openssl.cnf 服务器代码: #include <vcl.h> #pragma hdrstop #include <tchar.h> //---

我正在尝试构建通过Indy SSL TCP组件进行通信的服务器和客户端应用程序(C++Builder 2010)。我已使用以下命令生成证书和私钥:

openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 365 -config C:\openssl.cnf
服务器代码:

#include <vcl.h>
#pragma hdrstop

#include <tchar.h>
//---------------------------------------------------------------------------

#pragma argsused

#include <idglobal.hpp>
#include <IdTcpServer.hpp>
#include <IdSSLOpenSSL.hpp>
#include <vector>
#include <string>
#include <memory>
#include <iostream>
#include <windows.h>
#include "comm.h"

#pragma link "IndyCore140.lib"
#pragma link "IndyProtocols140.lib"
#pragma link "IndySystem140.lib"

/////////////////////////////////////////////////////////////////////////////
// Server
/////////////////////////////////////////////////////////////////////////////
class TServer
{
public:
    TServer(int Port, const std::string& cert, const std::string& key,
            const std::string& password )
    :   FPassword(password),
        FServer(new TIdTCPServer(NULL))
    {

        FServer->OnConnect = ServerOnConnect;
        FServer->OnExecute = ServerOnExecute;
        FServer->DefaultPort = Port;
        TIdServerIOHandlerSSLOpenSSL* ioHandler =
            new TIdServerIOHandlerSSLOpenSSL(NULL);
        ioHandler->OnGetPassword = SetPassword;
        ioHandler->OnVerifyPeer = VerifyPeer;
        ioHandler->SSLOptions->Mode = sslmServer;
        ioHandler->SSLOptions->VerifyDepth = 0;
        ioHandler->SSLOptions->CertFile = cert.c_str();
        ioHandler->SSLOptions->KeyFile = key.c_str();
        ioHandler->SSLOptions->SSLVersions << sslvSSLv23;
        ioHandler->SSLOptions->VerifyMode.Clear();
        FServer->IOHandler = ioHandler;
    }
    ~TServer()
    {
    }
public:
    void Start()
    {
        FServer->Active = true;
        std::cout << "Listening on port " << FServer->DefaultPort << std::endl;
    }
    void Stop()
    {
        FServer->Active = false;
    }

private:
    void __fastcall ServerOnExecute(TIdContext* ctx)
    {
        TIdTCPConnection* conn = ctx->Connection;
        try
        {
            std::string command = Recv(conn);
            std::cout << command << std::endl;
            if( strnicmp(command.c_str(), "HELLO", 5) == 0 ) // Start session
            {
                Send(conn, "HELLO");
            }
        }
        catch(Exception& e)
        {
            std::cout << AnsiString(e.Message).c_str() << std::endl;
        }
        conn->Disconnect();
    }
    void __fastcall ServerOnConnect(TIdContext* context)
    {
        std::cout << "Client connected" << std::endl;
    }
    bool __fastcall VerifyPeer(TIdX509* Certificate, bool AOk, int ADepth)
    {
        return AOk;
    }
    void __fastcall SetPassword(AnsiString& Password)
    {
        Password = FPassword.c_str();
    }

private:
    std::auto_ptr<TIdTCPServer> FServer;
    const std::string FPassword;
};

///
// Press Ctrl+C to close application
///
HANDLE hExitEvent = NULL;

BOOL CtrlHandler( DWORD ctl )
{
    if( ctl == CTRL_C_EVENT)
    {
        if( hExitEvent != NULL )
        {
            std::cout << "Closing application..." << std::endl;
            SetEvent(hExitEvent);
        }
        return TRUE;
    }
    return FALSE;
}
///
int _tmain(int argc, _TCHAR* argv[])
{
    std::auto_ptr<TServer> server(new TServer(50136,
        "c:\\cert.pem",
        "c:\\key.pem",
        "MyPassword"));
    hExitEvent = CreateEvent(NULL, FALSE, FALSE, NULL);
    if( SetConsoleCtrlHandler( (PHANDLER_ROUTINE) CtrlHandler, TRUE ) )
    {
        try
        {
            server->Start();
            WaitForSingleObject(hExitEvent, INFINITE);
            server->Stop();
            Sleep(1000);
        }
        catch(Exception& e)
        {
            std::cout << AnsiString(e.Message).c_str() << std::endl;
        }
    }
    CloseHandle(hExitEvent);
    return 0;
}

服务器进入无限循环时,异常
连接优雅地关闭。
每次迭代。我使用OpenSSL库v.1.0.1.3在Windows7上运行测试。请帮助使其正常工作。

客户端错误是因为当
TIdServerIOHandlerSSLOpenSSL
接受新的客户端连接时,客户端IOHandler的
PassThrough
属性默认设置为true,因此SSL/TLS尚未激活。这允许服务器根据每个连接动态决定是否激活SSL/TLS。例如,如果您的服务器正在侦听多个端口,并且仅在某些端口上使用SSL。或者如果您的协议实现了
STARTTLS
style命令。因此,当您准备接受SSL/TLS握手时,需要将
PassThrough
属性设置为false,例如:

void\uu快速调用服务器连接(TIdContext*context)
{
std::cout IOHandler)->PassThrough=false;
}
在客户端,当您准备启动SSL/TLS握手时,将
PassThrough
设置为false:

ioHandler->PassThrough=false;
如果调用
Connect()
PassThrough
为false,则一旦套接字成功连接到服务器,就会立即执行握手

话虽如此,Indy依赖于异常,因此您不应该在
OnExecute
事件处理程序中使用
try/catch
块。您可以使用
OnException
事件记录未捕获的异常,例如:

void\uuu fastcall ServerOnExecute(TIdContext*ctx)
{
TIdTCPConnection*conn=ctx->连接;
std::string命令=Recv(conn);

我不能谢谢你。你的答案正是我问题的答案。我只更正了
ioHandler->SSLOptions->VerifyMode=tidslverifymodeset();
#include <vcl.h>
#pragma hdrstop
#include <idglobal.hpp>
#include <IdTCPClient.hpp>
#include <IdSSLOpenSSL.hpp>
#include <vector>
#include <string>
#include <memory>
#include <iostream>
#include <tchar.h>
#include "comm.h"
//---------------------------------------------------------------------------

#pragma argsused

#pragma link "IndyCore140.lib"
#pragma link "IndyProtocols140.lib"
#pragma link "IndySystem140.lib"

void TestConnection()
{
    std::auto_ptr<TIdTCPClient> client(new TIdTCPClient(NULL));
    try
    {
        client->Host = "192.168.1.3";
        client->Port = 50136;
        client->ConnectTimeout = 10000;
        client->ReadTimeout = 10000;
        // SSL
        TIdSSLIOHandlerSocketOpenSSL* ioHandler = new TIdSSLIOHandlerSocketOpenSSL(NULL);
        ioHandler->SSLOptions->Mode = sslmClient;
        ioHandler->SSLOptions->VerifyDepth = 0;
//      ioHandler->SSLOptions->CertFile = "c:\\cert.pem";
        ioHandler->SSLOptions->SSLVersions << sslvSSLv23;
//      ioHandler->SSLOptions->VerifyMode.Clear();
        client->IOHandler = ioHandler;

        client->Connect();
        ///
        // Test session start
        ///
        Send(client.get(), "HELLO");
        std::string response = Recv(client.get());
        std::cout << response << std::endl;
    }
    catch(Exception& e)
    {
        std::cout << AnsiString(e.Message).c_str() << std::endl;
    }
}

int _tmain(int argc, _TCHAR* argv[])
{
    TestConnection();
    return 0;
}
#ifndef COMM_H
#define COMM_H

#include <idglobal.hpp>
#include <IdTcpServer.hpp>
#include <IdSSLOpenSSL.hpp>
#include <vector>
#include <string>
//---------------------------------------------------------------------------

typedef std::vector<unsigned char> TBuffer;

void SendByteArray(TIdTCPConnection* Connection,
    const TBuffer& array)
{
    TIdBytes src;
    src = Idglobal::RawToBytes(&array[0], array.size());
    Connection->IOHandler->Write(src);
}
//---------------------------------------------------------------------------
void ReceiveByteArray(TIdTCPConnection* Connection,
    TBuffer& array, unsigned int size)
{
    TIdBytes dest;
    Connection->IOHandler->ReadBytes(dest, size);
    array.resize(size);
    Idglobal::BytesToRaw(dest, &array[0], size);
}

void Send(TIdTCPConnection* Connection, const std::string& cmd)
{
    TBuffer buffer(cmd.begin(), cmd.end());
    SendByteArray(Connection, buffer);
}

std::string Recv(TIdTCPConnection* Connection)
{
    TBuffer buffer;
    ReceiveByteArray(Connection, buffer, 5);
    std::string cmd(buffer.begin(), buffer.end());
    return cmd;
}

#endif //COMM_H
Project sslclient.exe raised exception class EIdOSSLConnectError with message 'Error connecting with SSL.
EOF was observed that violates the protocol'.
void __fastcall ServerOnExecute(TIdContext* ctx)
{
    TIdTCPConnection* conn = ctx->Connection;
    try
    {
        std::string command = Recv(conn);
        std::cout << command << std::endl;
        if( strnicmp(command.c_str(), "HELLO", 5) == 0 ) // Start session
        {
            Send(conn, "HELLO");
        }
    }
    catch(const Exception& e)
    {
        std::cout << AnsiString(e.Message).c_str() << std::endl;
        if (dynamic_cast<const EIdException*>(&e))
            throw;
    }
    conn->Disconnect();
}