Ubuntu-14.04

Asterisk sslv3 警報握手失敗

  • August 30, 2016

我正在使用 Ubuntu v14.04.3 LTS 和 Asterisk 13.3.2。當我嘗試從 sipml5 客戶端呼叫我的分機以播放展示祝賀音頻時,我的呼叫立即斷開。當我檢查星號日誌時,出現以下錯誤

[2016-08-24 06:07:49] ERROR[31730][C-0000000c]: res_rtp_asterisk.c:2042 __rtp_recvfrom: DTLS failure occurred on RTP instance '0x7f547c013c68' due to reason 'sslv3 alert handshake failure', terminating
[2016-08-24 06:07:49] WARNING[31730][C-0000000c]: res_rtp_asterisk.c:3911 ast_rtcp_read: RTCP Read error: Unspecified.  Hanging up.
[2016-08-24 06:07:49] WARNING[31730][C-0000000c]: app_playback.c:493 playback_exec: Playback failed on SIP/104600-00000007 for /var/www/html/fetch_prompt
[2016-08-24 06:07:49] ERROR[31730][C-0000000c]: utils.c:1402 ast_carefulwrite: write() returned error: Broken pipe

我正在使用 Chrome v54。

我認為這個錯誤與openssl有關,但還沒有得到正確和完整的答案來解決這個問題。有誰知道如何解決這個問題?

通過升級 openssl 解決了這個問題。使用以下命令在 Ubuntu 14 中升級 openssl

# echo 'deb http://us.archive.ubuntu.com/ubuntu/ xenial main restricted universe multiverse' > /etc/apt/sources.list.d/xenial.list
# aptitude update
# aptitude install -y openssl libssl-dev
# rm /etc/apt/sources.list.d/xenial.list
# aptitude update

使用以下命令檢查 openssl 版本

# ldd /usr/sbin/asterisk  | grep libssl
libssl.so.1.0.0 => /lib/x86_64-linux-gnu/libssl.so.1.0.0 (0x00007f33ce117000)

# strings /lib/x86_64-linux-gnu/libssl.so.1.0.0 | grep 1.0.2
OPENSSL_1.0.2
OPENSSL_1.0.2g
SSLv3 part of OpenSSL 1.0.2g-fips  1 Mar 2016
TLSv1 part of OpenSSL 1.0.2g-fips  1 Mar 2016
DTLSv1 part of OpenSSL 1.0.2g-fips  1 Mar 2016
OpenSSL 1.0.2g-fips  1 Mar 2016

# openssl version
OpenSSL 1.0.2g-fips  1 Mar 2016

在此之後刪除所有現有的星號鍵並再次重新創建鍵

# rm /etc/asterisk/keys/*
# cd /usr/src/astersik*/contrb/scripts
# sudo ./ast_tls_cert -C pbx.mycompany.com -O "My Super Company" -d /etc/asterisk/keys
# asterisk -rx "reload"

來源

引用自:https://serverfault.com/questions/798743