将Paho用于MQTT TLS时出现错误[SSL]PEM lib(_SSL.c:4022)

2024-09-29 23:19:58 发布

您现在位置:Python中文网/ 问答频道 /正文

我正在尝试使用Paho库连接我的MQTT代理。但现在我被这个错误绊倒了。我的代码如下:

import os
import paho.mqtt.publish as publish
import paho.mqtt.client as mqtt
import ssl
from configparser import ConfigParser
.....
    try:
        publishInfo = {
            "parking": "test"
        }
        config = ConfigParser()
        config.read('config.ini')
        ipAddressMQTT = config['MQTT']['ipaddress']
        port = config['MQTT']['port']
        auth = {
            'username': config['MQTT']['username'],
            'password': config['MQTT']['password']
        }
        tls = {
            'ca_certs': config['MQTT']['cakeypath'],
            'certfile': config['MQTT']['certKeyPath'],
            'keyfile': config['MQTT']['clientkeypath'],
            'tls_version': ssl.PROTOCOL_TLSv1
        }
        
        publish.single(topic='parkingStatus', payload=publishInfo, retain=True, hostname=ipAddressMQTT, port=port, keepalive=60, auth=auth, tls=tls, protocol=mqtt.MQTTv311, transport='tcp')
    except Exception as e:
        self.showMessage(QMessageBox.Critical, "Error...", "Error "+str(e), "Error ")

我的config.ini文件如下所示:

[MQTT]
ipaddress = 172.18.0.3
port = 8883
username = parking
password = public
cakeypath = /home/atn/Documents/IUK/Abschlussarbeit/emqx_mqtt_cert/ca.pem
clientkeypath = /home/atn/Documents/IUK/Abschlussarbeit/emqx_mqtt_cert/parkingspot.pem
certkeypath = /home/atn/Documents/IUK/Abschlussarbeit/emqx_mqtt_cert/parkingspot.csr

[Geofence]
ipaddress = 172.18.0.4
port = 9851

证书是使用以下命令生成的:

openssl genrsa -out parkingspot.key 2048
openssl req -new -key parkingspot.key -out parkingspot.csr -subj "/C=DE/ST=NRW/L=Dortmund/O=EMQX/CN=client"
openssl x509 -req -days 3650 -in parkingspot.csr -CA ca.pem -CAkey ca.key -CAcreateserial -out parkingspot.pem

经过几个小时的努力,我决定问你们。请帮我一把


Tags: keyimportauthconfigportastlsusername
2条回答

在配置文件中,您有:

certkeypath = /home/atn/Documents/IUK/Abschlussarbeit/emqx_mqtt_cert/parkingspot.csr

csr文件通常是证书签名请求(向CA发送的请求,请求颁发证书)。我希望这里使用的文件具有.key扩展名(这假设您在创建证书时使用了标准扩展名)

更多信息可在this question的答案中找到

我将根据字段名(充其量是令人困惑的)猜测值应该是

cakeypath = /.../ca.pem
clientkeypath = /.../parkingspot.key
certkeypath = /.../parkingspot.pem

相关问题 更多 >

    热门问题