Jump to...
redirecting...

Log for YSITD

現在變的太好移動了
wwwwwwww
WTF 滑鼠斷線
算惹
今天不適合打osu
肯定風水不佳
[photo](media:AgADAQADtqcxG9yt8EaL5ZCEb2VJJNeR3i8ABKF_rr2jlohaF2wAAgI@telegram)
他的使用時間終於符合一般人了
[photo](media:AgADAQADt6cxG9yt8EaUHCrE2gXSJeAG6C8ABG1-jOfkl2w0bC0BAAEC@telegram)
[photo](media:AgADAQADuKcxG9yt8Ea8_Tzrk4SEcQia3i8ABLfxqF3Y7kjGDG8AAgI@telegram)
[photo](media:AgADAQADuacxG9yt8EarfLiQa0PdUFGZ3i8ABEttOK6NCMrUzW4AAgI@telegram)
[photo](media:AgADAQADuqcxG9yt8Eah1lZDUrxp9Xui3i8ABF7-i5eGnJMriG8AAgI@telegram)
我覺得小畫家不是繪圖程式
[photo](media:AgADAQADu6cxG9yt8EbJrqyJyd8zOqKb3i8ABCBAgd_aHYsxXm4AAgI@telegram)
先在他變成遊戲了
新的小畫家可以吃滿我四核心CPU
你的cpu就那樣www
那是小畫家耶
windows內建的小畫家耶
小畫家VR 4/1限定更新版
看起來就很…
[sticker](media:AAQFABM_DsoyAAQC9-Is7VcRrZxGAAIC@telegram)
我的Hyper-V炸了
開不起來
我死也不碰Hyper V
臭ㄌㄇ
整個很M$所以不想碰
而且我被他雷過
M$又不是錯
沒開源的M$我不想碰
我被 ESXI Vbox Hyper-V都雷過
windows我也不想碰,但是我要玩遊戲
而且TMD Nvidia驅動在Linux很雷
April Fool
N驅動我倒覺得還好
官方有算詳細的說明可以解
不是裝不起來
是相容性悲劇
一堆Linux上的標準沒支援
我倒覺得A也很悲劇
N還好一點
Linux上I最棒了
我說顯示
I一錠沒問題啦
晚安睡覺
去睡
另外開console看
..
4/1了
有人還在的嗎?
我還在 3/31
在啊
我想問 nginx 跟 SSL 的問題能問你嗎?
nginx version: nginx/1.10.3
built with OpenSSL 1.0.2k 26 Jan 2017
openssl s_client 得到了 SSL23_GET_SERVER_HELLO
Firefox 得到了 SSL_ERROR_NO_CYPHER_OVERLAP
Chrome 得到了 ERR_SSL_VERSION_OR_CIPHER_MISMATCH
nginx proxy 得到了 SSL_do_handshake() failed (SSL: error:14FFF410:SSL routines:SSL_internal:sslv3 alert handshake failure:SSL alert number 40) while SSL handshaking to upstream

我完全沒頭緒怎麼解這問題orz...
hi~
求高人指點QWQ
目前有拉一個 public ip 出來了
p.csie.mcu.edu.tw
只是我真的不知道怎麼 debug
我只是想要自簽個CA然後內部做 proxy 用的而已啊
你有沒有設 SSL cipher?
嗚嗚為什麼那麼男
ssl_ciphers ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-
ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-GCM-SHA25
6:ECDHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA38
4:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA:ECDHE
-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES256-SHA384:ECDHE-ECDSA-AE
S256-SHA:ECDHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-RSA-A
ES256-SHA256:DHE-RSA-AES256-SHA:ECDHE-ECDSA-DES-CBC3-SHA:ECDHE-RSA-DES-CBC3-SHA:
EDH-RSA-DES-CBC3-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SH
A256:AES128-SHA:AES256-SHA:DES-CBC3-SHA;
openssl x509 -noout -text -in cert.crt
先拿掉看看
剛剛也有試過了OAO
ssl_ciphers EECDH+CHACHA20:EECDH+AES128:RSA+AES128:EECDH+AES256:RSA+AES256:EECDH+3DES:RSA+3DES:!MD5;
內部幹嘛還要 https 啊
         9f:78:7b:81:64:69:e2:1d:72:b9:d7:e7:c7:cc:83:f5:97:68:
         9a:6d:46:3e:42:b7:02:33:ec:f1:97:0e
root@www:/etc/ssl#
root@www:/etc/ssl# openssl x509 -noout -text -in www.crt
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            df:0e:01:fa:35:b6:79:63
    Signature Algorithm: ecdsa-with-SHA256
        Issuer: C=TW, ST=Taiwan, L=Taoyuan City, O=CSIE in Ming-Chuan University, OU=Networking Information Center, CN=Ballerina Certificate Authority - SHA256
        Validity
            Not Before: Mar 31 20:15:46 2017 GMT
            Not After : Mar 31 20:15:46 2025 GMT
        Subject: C=TW, ST=Taiwan, L=Taoyuan City, O=CSIE in Ming-Chuan University, OU=Networking Information Center, CN=10.100.0.2
        Subject Public Key Info:
            Public Key Algorithm: id-ecPublicKey
                Public-Key: (521 bit)
                pub:
                    04:00:d0:89:4b:76:68:09:df:d0:19:1a:f5:4f:17:
                    77:a6:48:04:ba:70:2b:76:00:e4:f0:bd:95:34:da:
                    cc:e7:7f:e0:23:25:28:bb:87:34:ae:82:a2:98:88:
                    69:66:d2:64:70:c6:e5:bb:bb:64:09:08:5f:a9:a5:
                    a9:b8:76:3f:e9:7b:45:01:93:99:eb:1c:c3:b5:5a:
                    2b:db:dc:b2:79:40:50:e1:6c:ff:26:57:86:03:f1:
                    4b:6b:b2:5c:e6:7a:c7:1c:a9:a4:08:dd:a9:d0:15:
                    cb:58:13:06:35:4f:c3:eb:98:18:a4:09:cb:f6:4b:
                    b7:f6:01:a1:a3:e1:62:ef:45:f1:12:0e:2b
                Field Type: prime-field
                Prime:
                    01:ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:
                    ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:
                    ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:
                    ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:
                    ff:ff:ff:ff:ff:ff
                A:
                    01:ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:
                    ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:
                    ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:
                    ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:
                    ff:ff:ff:ff:ff:fc
                B:
                    51:95:3e:b9:61:8e:1c:9a:1f:92:9a:21:a0:b6:85:
                    40:ee:a2:da:72:5b:99:b3:15:f3:b8:b4:89:91:8e:
                    f1:09:e1:56:19:39:51:ec:7e:93:7b:16:52:c0:bd:
                    3b:b1:bf:07:35:73:df:88:3d:2c:34:f1:ef:45:1f:
                    d4:6b:50:3f:00
                Generator (uncompressed):
                    04:00:c6:85:8e:06:b7:04:04:e9:cd:9e:3e:cb:66:
                    23:95:b4:42:9c:64:81:39:05:3f:b5:21:f8:28:af:
                    60:6b:4d:3d:ba:a1:4b:5e:77:ef:e7:59:28:fe:1d:
                    c1:27:a2:ff:a8:de:33:48:b3:c1:85:6a:42:9b:f9:
                    7e:7e:31:c2:e5:bd:66:01:18:39:29:6a:78:9a:3b:
                    c0:04:5c:8a:5f:b4:2c:7d:1b:d9:98:f5:44:49:57:
                    9b:44:68:17:af:bd:17:27:3e:66:2c:97:ee:72:99:
                    5e:f4:26:40:c5:50:b9:01:3f:ad:07:61:35:3c:70:
                    86:a2:72:c2:40:88:be:94:76:9f:d1:66:50
                Order:
                    01:ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:
                    ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:ff:
                    ff:ff:ff:fa:51:86:87:83:bf:2f:96:6b:7f:cc:01:
                    48:f7:09:a5:d0:3b:b5:c9:b8:89:9c:47:ae:bb:6f:
                    b7:1e:91:38:64:09
                Cofactor:  1 (0x1)
                Seed:
                    d0:9e:88:00:29:1c:b8:53:96:cc:67:17:39:32:84:
                    aa:a0:da:64:ba
        X509v3 extensions:
            X509v3 Basic Constraints:
                CA:FALSE
            X509v3 Key Usage:
                Digital Signature, Non Repudiation, Key Encipherment
    Signature Algorithm: ecdsa-with-SHA256
         30:81:87:02:41:0b:b6:58:5b:87:df:87:ca:17:18:a8:6f:7e:
         96:03:bc:59:57:7c:63:05:13:d6:40:92:d7:de:24:5e:f5:07:
         f6:4d:0c:dd:f0:44:dd:98:47:2e:e8:4d:b6:75:fa:cd:89:55:
         83:d8:90:21:7e:26:63:47:69:1b:85:3a:86:c0:f1:fd:02:42:
         00:a9:22:5a:65:83:af:f7:3e:07:b4:1c:13:50:db:5c:e2:4f:
         8a:b2:b7:f0:08:44:55:9b:47:cb:44:f5:15:89:ac:ad:d9:f0:
@mingtsay 試一下
更新了
然後?
restart...
目前那台 public ip 在 p.csie.mcu.edu.tw
already done
成功嗎?
nope
[photo](media:AgADBQADs6cxG49r-VbZQHSXEfeJDdlHyjIABLgQAAECPLsg7bPJAQABAg@telegram)
我看 nginx 也正常 openssl 也正常,為什麼整個都起來就爆炸QAQ
server {
        listen      80  default_server;
        listen [::]:80  default_server;
        listen      443 default_server http2 ssl;
        listen [::]:443 default_server http2 ssl;

        ssl_certificate     /etc/ssl/www.crt;
        ssl_certificate_key /etc/ssl/www.key;

        root /var/www/html;
        index index.php index.html index.htm;
        server_name _;

        location / {
                try_files $uri $uri/ =404;
        }

        location ~ \.php$ {
                include snippets/fastcgi-php.conf;
                fastcgi_pass unix:/var/run/php5-fpm.sock;
        }

        location ~ /\.ht {
                deny all;
        }
}
我在戰 swagger(暈
ssl_trusted_certificate?
root@www:/etc/ssl# grep ssl /etc/nginx/nginx.conf
        ssl_protocols TLSv1 TLSv1.1 TLSv1.2; # Dropping SSLv3, ref: POODLE
        ssl_prefer_server_ciphers on;
        ssl_ciphers EECDH+CHACHA20:EECDH+AES128:RSA+AES128:EECDH+AES256:RSA+AES256:EECDH+3DES:RSA+3DES:!MD5;
        ssl_dhparam /etc/nginx/dhparams.pem;
        ssl_session_cache shared:ssl_session_cache:10m;
剛剛加上去也是不行
我目前的設定是只留
ssl_certificate
ssl_certificate_key
ssl_trusted_certificate
然後 listen 443 http2 跟 listen [::]:443 http2
其他都沒有
給你當參考
我先移除80那兩行看看
不影響吧
還是不行QWQ
可是錯誤訊息都是 no match ciphers
Swagger UI 快逼到我用 Vue 重寫了
nginx -t
這些東西先註解掉看看
這個情況下不會有error吧
天知道
我每次改都會 nginx -t 所以有 error 我會特別說
嗚,還是沒變
是不是因為 cert 的 CN 是 10.100.0.2 的緣故?
你這件事 還是沒有解決歐?
解決一半而已
現在是內部 upstream 想加上 ssl
我晚一點看一下 我現在想繼續睡(趴
[photo](media:AgADBQADuqcxG9_C-FarIrRmJuvEulggyjIABLR9-5PqgcvY57ECAAEC@telegram)
總之是 -param_enc explicit 的問題
我先把 public ip 拿掉了
it works like a charm
explicit你可以认为是把曲线的函数式直接写进去了
要用 named_curve
TLS只认named curve
openssl ecparam -name secp384r1 -genkey -out rootCA.key
openssl req -new -x509 -key rootCA.key -sha256 -nodes -out rootCA.pem -days 7305 -config openssl.cnf
openssl ecparam -name secp384r1 -genkey -out www.key
openssl req -new -key www.key -out www.csr
openssl x509 -req -in www.csr -CA rootCA.pem -CAkey rootCA.key -CAcreateserial -out www.crt -days 2922 -sha256

這樣試試看?
TLS 不支持显示指明 curve 参数
我不懂 -param_enc explicit 是啥
然后试试
删掉 -param_enc explicit
筆記下我的步驟:
openssl ecparam -name secp384r1 -genkey -param_enc explicit -out rootCA.key
openssl req -new -x509 -key rootCA.key -sha256 -nodes -out rootCA.pem -days 7305 -config openssl.cnf
openssl ecparam -name secp384r1 -genkey -param_enc explicit -out www.key
openssl req -new -key www.key -out www.csr
openssl x509 -req -in www.csr -CA rootCA.pem -CAkey rootCA.key -CAcreateserial -out www.crt -days 2922 -sha256
以上是解法筆記
(((((
[photo](media:AgADAQADqqcxG9yt-EadAAET2uV2zI1e0OcvAAQSr5RT3w-XoNyDAQABAg@telegram)
[photo](media:AgADAQADq6cxG9yt-EYNxtvvHdzzXwABid4vAATXBIffxOlJ8XZwAAIC@telegram)
我還在想為什麼我前天C還很空今天已經1/3了
原來有個windows.old
這樣若Google Ads的100美收入恐怕也要算進去?
好的剛剛差點在 vim 裡面按 ZQ
你應該:wq
可是我比較喜歡ZZ
所以Google地圖真的弄小精靈喔
認真?
阿Google有其他產品弄愚人節的嗎
Minecraft呢
好玩🙈
可是Google玩過這招了______
今年ingress好像沒有愚人節活動?
Pokemon沒開不知道😂
他之前有嗎?
幾乎每年
去年是什麼?(我怎麼沒印象
Timezone (
今年工程師是不是特別懶得寫愚人節企劃
好的
@coin3x tested?
幫推 (?
可是多人報講者,我就沒機會了 QQ
感覺你就是會上的那一個w
.js
然後從C開始
🤔🤔🤔🤔🤔
node是用C寫的
[sticker](media:AAQBABM4Y-8vAASHcKhEGpNuEPkNAAIC@telegram)
[sticker](media:AAQBABNtVO8vAASXS2qDgcgxMVUHAAIC@telegram)
C++ 的 libuv
谁要学 C 来着?
[sticker](media:AAQBABNtVO8vAASXS2qDgcgxMVUHAAIC@telegram)
[sticker](media:AAQBABM4Y-8vAASHcKhEGpNuEPkNAAIC@telegram)
我学过了
[sticker](media:AAQEABMo3mUZAASW8XGM8bw_9IGVAAIC@telegram)
[sticker](media:AAQFABNLj8oyAAT9Yai9c3EH9WMQAAIC@telegram)
[sticker](media:AAQFABN83MsyAAQe3im1gB-h7R1jAAIC@telegram)
我想學C
[sticker](media:AAQBABRe7y8ABIlpvx2QGlw4TDkAAgI@telegram)
不要洗貼圖
穿著Google衣服去蘋果總部
U.狂
www
[photo](media:AgADAQADr6cxG2Lj-Ubk9aYfhM2JpBw47y8ABMzJT_aSmVbHyncAAgI@telegram)
Www
[photo](media:AgADBQADs6cxG49rAVeOsmLMq24LrkNDyjIABI5-igbKh7T71tMBAAEC@telegram)
那直接沒密碼算是怎的?
[photo](media:AgADBQADtKcxG49rAVe6zmXtGuotJeEdyjIABAJURtsysxQSqLkCAAEC@telegram)
wwww
幹www
[photo](media:AgADBQADtqcxG49rAVfBe8wQ0w2kb9AiyjIABIx-6qu_LgfFwq4CAAEC@telegram)
上次好像是 UI 換成什麼
[photo](media:AgADBQADt6cxG49rAVdMA8jt-Eay_3xOyjIABIb1xVgWO-Hj1tQBAAEC@telegram)
結果我姐買這個😅
希望不要雷
小精靈
[photo](media:AgADBQADuKcxG49rAVeNjNF9Gel_s04dyjIABElPXIBIpRHy6K4CAAEC@telegram)
晚安睡覺
假睡次數加一
去睡
晚安睡覺