{"id":1967,"date":"2011-03-02T22:47:05","date_gmt":"2011-03-02T22:47:05","guid":{"rendered":"http:\/\/www.icocean.com\/blog\/?p=1967"},"modified":"2011-03-02T22:50:43","modified_gmt":"2011-03-02T22:50:43","slug":"filezilla%E8%BF%9Evsftpd%E6%9C%8D%E5%8A%A1%E5%99%A8%E6%97%B6%E5%87%BA%E7%8E%B0gnutlserror8%E7%9A%84%E5%8E%9F%E5%9B%A0%E5%92%8C%E8%A7%A3%E5%86%B3%E5%8A%9E%E6%B3%95","status":"publish","type":"post","link":"https:\/\/www.icocean.com\/blog\/?p=1967","title":{"rendered":"filezilla\u8fdevsftpd\u670d\u52a1\u5668\u65f6\u51fa\u73b0GnuTLS error -8\u7684\u539f\u56e0\u548c\u89e3\u51b3\u529e\u6cd5."},"content":{"rendered":"<p>FTP\u670d\u52a1\u5668: vsftpd<br \/>FTP\u5ba2\u6237\u7aef: filezilla<br \/>\u51fa\u9519\u63d0\u793a: GnuTLS error -8: A record packet with illegal version was received.<\/p>\n<p>\u676f\u5177\u7684\u6211, \u7531\u4e8e\u4e0a\u8ff0error,\u6298\u817e\u4e86\u5f88\u4e45. \u6700\u540e\u5728\u8fd9\u7bc7\u535a\u6587(http:\/\/ramblings.linkerror.com\/?p=45)\u91cc\u627e\u5230\u4e00\u70b9\u63d0\u793a,<\/p>\n<p>\u7136\u540e\u5c31\u8bf7\u51fawireshark,\u5728\u6536\u5230\u670d\u52a1\u5668\u7684\u4e00\u6761500 opps\u4e4b\u540e<br \/><coolcode>Pg%,E>jL@2vVR#X=czgeGi394500 OOPS: <\/coolcode><\/p>\n<p>\u5ba2\u6237\u7aef\u53d1\u51fa\u4e86\u4e00\u4e2aRST<\/p>\n<p>\u7d27\u63a5\u7740,\u670d\u52a1\u5668\u8fd4\u56de\u4e86\u4e00\u4e2aresponse, <br \/><coolcode>Pg%,EcjM@2v0R#X=czgeG394unrecognised variable in config file: local_rot<\/coolcode><\/p>\n<p>\u63ed\u793a\u4e86\u51fa\u9519\u7684\u539f\u56e0,\u539f\u6765\u662fvsftpd\u670d\u52a1\u7aef\u7684\u914d\u7f6e\u6587\u4ef6\u5199\u9519\u4e86!<\/p>\n<p>\u7ecf\u68c0\u67e5,\u662f\u6211\u5c06<br \/>local_root=\/aaaa\/bbbb\/<br \/>\u9519\u5199\u6210\u4e86<br \/>local_rot=\/aaaa\/bbbb\/<\/p>\n<p>\u4e0b\u4e00\u9875\u9644\u4e0a\u90a3\u7bc7\u535a\u6587,\u4ee5\u4f5c\u8bb0\u5f55.<br \/><!--nextpage--><br \/>http:\/\/ramblings.linkerror.com\/?p=45<br \/>Posted on: Wednesday, April 22nd, 2009 at 03:56.<br \/>Filed under: All, ServerAdmin.<br \/>RSS 2.0 feed for comments.<br \/>You can leave a response, or trackback from your own site.<br \/> vsftpd debugging<br \/>If you\u2019re ever working with vsftpd, and filezilla dumps out this error:<\/p>\n<p>GnuTLS error -8: A record packet with illegal version was received<\/p>\n<p>You\u2019re not finding any relevant error messages in your vsftpd log file, nor in the xferlog, nor in \/var\/log\/messages ?<\/p>\n<p>Well, vsftpd seems to be horribly un-verbose. The cause of this error is not because of some obscure TLS problem. What\u2019s causing it is vsftpd dumping out a plain-text error in the middle of the encrypted data stream, causing the ftp client to pop out this error.<\/p>\n<p>The only way to debug this was by packet sniffing the actual connection with wireshark. Following the TCP stream with wireshark, the error I was looking for in the log files, was clearly visible at the end of the TLS encrypted data, before the connection dropped.<\/p>\n<p>Something like:<\/p>\n<p>&#92;5_TXC,[1d.c}$D12N8(,&#8221;ndKm:?Y5O&#92;M)5{nj2*Uaiym8-T4rt2c&#39;#\/K(<br \/>dvU2@:M.&#038;.X=:-A*4aUm3:)!)y5Kt$&#39;&#038;&#8221;ZQN:&#39;v%X500 OOPS: Cannot change directory: \/foo<\/p>\n<p>It turned out to be a simple permissions issue\u2026 .<br \/>Why vsftpd isn\u2019t logging these to it\u2019s own log file, or even syslogd, who knows. At the most verbose configuration, it is logging all sorts of things, except the actual error causing the problem!<\/p>\n<p>Had encryption not been enabled in vsftpd, the error would have been visible in the FTP client.<\/p>\n<p>So to any one encountering this, I would recommend either temporarily disabling encryption in vsftpd in order to see the error, or if that is not an option, use a packet sniffer to view the error.<\/p>\n<p>I figured I would post this since google didn\u2019t bring up much useful as I was debugging this. \ud83d\ude42<\/p>\n<nav class=\"page-links\"><strong>\u9875\u9762\uff1a<\/strong> <a href=\"https:\/\/www.icocean.com\/blog\/?p=1967\" class=\"post-page-numbers\"><span class=\"page-num\">1<\/span><\/a> <a href=\"https:\/\/www.icocean.com\/blog\/?p=1967&#038;page=2\" class=\"post-page-numbers\"><span class=\"page-num\">2<\/span><\/a><\/nav>\n","protected":false},"excerpt":{"rendered":"<p>FTP\u670d\u52a1\u5668: vsftpdFTP\u5ba2\u6237\u7aef: filezilla\u51fa\u9519\u63d0\u793a: GnuTLS error -8: A <a href='https:\/\/www.icocean.com\/blog\/?p=1967' class='excerpt-more'>[&#8230;]<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[3175,3129,3174,3013],"class_list":["post-1967","post","type-post","status-publish","format-standard","hentry","category-4","tag-error","tag-filezilla","tag-guntls","tag-vsftpd","category-4-id","post-seq-1","post-parity-odd","meta-position-corners","fix"],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/www.icocean.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/1967","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.icocean.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.icocean.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.icocean.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.icocean.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1967"}],"version-history":[{"count":0,"href":"https:\/\/www.icocean.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/1967\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.icocean.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1967"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.icocean.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1967"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.icocean.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1967"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}