[stunnel-users] SSL CTX use RSA Private Key error

Christophe Nanteuil christophe.nanteuil at gmail.com
Thu Mar 26 09:50:27 CET 2009


Hello,
it seems that your private key is not in a correct format.
Have a look at http://www.stunnel.org/faq/certs.html to see how to
create a key and verify your key.
Verify also that the key is readable only by its owner (chmod 600 key.pem).

-- 
Christophe Nanteuil


2009/3/26 G K <gm5729 at gmail.com>:
> Hello all. I am trying to set up stunnel for use on my machine. I
> shouldn't have a problem with iptables. But I do run tor/privoxy on a
> regular basis if that matters. I also have set up my gpg keys too.
>
> The following is the error I get. I did do some Googling but I'm not
> quite understanding what I'm looking for to change or modify. I know the
> error is the SSL CTX RSA private key.
>
> Wed Mar 25, 19:39 # /etc/rc.d/stunnel start
> :: Starting stunnel
> [BUSY] 2009.03.25 19:39:21 LOG7[7490:3082353408]: Snagged 64 random
> bytes from /root/.rnd
> 2009.03.25 19:39:21 LOG7[7490:3082353408]: Wrote 1024 new random bytes
> to /root/.rnd
> 2009.03.25 19:39:21 LOG7[7490:3082353408]: RAND_status claims sufficient
> entropy for the PRNG
> 2009.03.25 19:39:21 LOG7[7490:3082353408]: PRNG seeded successfully
> 2009.03.25 19:39:21 LOG7[7490:3082353408]:
> Certificate: /etc/stunnel/mail.pem
> 2009.03.25 19:39:21 LOG7[7490:3082353408]: Certificate loaded
> 2009.03.25 19:39:21 LOG7[7490:3082353408]: Key
> file: /etc/stunnel/mail.pem
> 2009.03.25 19:39:21 LOG3[7490:3082353408]: error stack: 140B3009 :
> error:140B3009:SSL routines:SSL_CTX_use_RSAPrivateKey_file:PEM lib
> 2009.03.25 19:39:21 LOG3[7490:3082353408]:
> SSL_CTX_use_RSAPrivateKey_file: 906D06C: error:0906D06C:PEM
> routines:PEM_read_bio:no start line
>
>
> stunnel 4.25-1
>
> Linux vampypengy 2.6.28-ARCH #1 SMP PREEMPT Tue Mar 17 06:42:43 UTC 2009
> i686 Genuine Intel(R) CPU T2060 @ 1.60GHz GenuineIntel GNU/Linux
>
> glibc 2.9-4
>
> Using built-in specs.
> Target: i686-pc-linux-gnu
> Configured with: ../configure --prefix=/usr --enable-shared
> --enable-languages=c,c++,fortran,objc,obj-c++,treelang
> --enable-threads=posix --mandir=/usr/share/man --infodir=/usr/share/info
> --enable-__cxa_atexit --disable-multilib --libdir=/usr/lib
> --libexecdir=/usr/lib --enable-clocale=gnu --disable-libstdcxx-pch
> --with-tune=generic
> Thread model: posix
> gcc version 4.3.3 (GCC)
>
> OpenSSL 0.9.8j 07 Jan 2009
>
> perl-net-ssleay 1.30-2
>
>
>
> _______________________________________________
> stunnel-users mailing list
> stunnel-users at mirt.net
> http://stunnel.mirt.net/mailman/listinfo/stunnel-users
>
>



More information about the stunnel-users mailing list