<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://kb.rvmgroup.it/index.php?action=history&amp;feed=atom&amp;title=Configurazione_SSL%2FTLS_di_ProFtpd</id>
	<title>Configurazione SSL/TLS di ProFtpd - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://kb.rvmgroup.it/index.php?action=history&amp;feed=atom&amp;title=Configurazione_SSL%2FTLS_di_ProFtpd"/>
	<link rel="alternate" type="text/html" href="https://kb.rvmgroup.it/index.php?title=Configurazione_SSL/TLS_di_ProFtpd&amp;action=history"/>
	<updated>2026-05-06T01:55:02Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.44.2</generator>
	<entry>
		<id>https://kb.rvmgroup.it/index.php?title=Configurazione_SSL/TLS_di_ProFtpd&amp;diff=10198&amp;oldid=prev</id>
		<title>Gabriele.vivinetto at 17:00, 30 November 2018</title>
		<link rel="alternate" type="text/html" href="https://kb.rvmgroup.it/index.php?title=Configurazione_SSL/TLS_di_ProFtpd&amp;diff=10198&amp;oldid=prev"/>
		<updated>2018-11-30T17:00:17Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 17:00, 30 November 2018&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l77&quot;&gt;Line 77:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 77:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;*Provare a connettersi con filezilla&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;*Provare a connettersi con filezilla&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;* Se succede che proftpd va al 100% di cpu, provare ad aggiungere la direttiva:&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt; SocketOptions sndbuf 1024 rcvbuf 1024&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;=Riferimenti=&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;=Riferimenti=&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;https://www.server-world.info/en/note?os=Debian_8&amp;amp;p=ftp&amp;amp;f=7&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;https://www.server-world.info/en/note?os=Debian_8&amp;amp;p=ftp&amp;amp;f=7&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;*[https://forums.proftpd.org/smf/index.php?topic=3510.0 100% CPU load for any TLS secured transfer]&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Gabriele.vivinetto</name></author>
	</entry>
	<entry>
		<id>https://kb.rvmgroup.it/index.php?title=Configurazione_SSL/TLS_di_ProFtpd&amp;diff=10150&amp;oldid=prev</id>
		<title>Gabriele.vivinetto at 20:42, 26 June 2018</title>
		<link rel="alternate" type="text/html" href="https://kb.rvmgroup.it/index.php?title=Configurazione_SSL/TLS_di_ProFtpd&amp;diff=10150&amp;oldid=prev"/>
		<updated>2018-06-26T20:42:25Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 20:42, 26 June 2018&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l40&quot;&gt;Line 40:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 40:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;#&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;#&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# CA the server trusts...&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# CA the server trusts...&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;#&lt;/del&gt;TLSCACertificateFile &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;			 &lt;/del&gt;/&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;etc&lt;/del&gt;/&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;ssl&lt;/del&gt;/certs/&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;CA&lt;/del&gt;.pem&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;TLSCACertificateFile &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;                   &lt;/ins&gt;/&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;var&lt;/ins&gt;/&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;lib/dehydrated&lt;/ins&gt;/certs/&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;ftp.diesis.priv/chain&lt;/ins&gt;.pem&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# ...or avoid CA cert and be verbose&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# ...or avoid CA cert and be verbose&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;#TLSOptions                      NoCertRequest EnableDiags  &lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;#TLSOptions                      NoCertRequest EnableDiags  &lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Gabriele.vivinetto</name></author>
	</entry>
	<entry>
		<id>https://kb.rvmgroup.it/index.php?title=Configurazione_SSL/TLS_di_ProFtpd&amp;diff=10149&amp;oldid=prev</id>
		<title>Gabriele.vivinetto: Created page with &quot;Si ipotizza di avere o certificati SSL già pronti  * Attivare il la configurazione SSL   sed -i -e  &quot;s_^#Include /etc/proftpd/tls.conf_Include /etc/proftpd/tls.conf_&quot;  /etc/p...&quot;</title>
		<link rel="alternate" type="text/html" href="https://kb.rvmgroup.it/index.php?title=Configurazione_SSL/TLS_di_ProFtpd&amp;diff=10149&amp;oldid=prev"/>
		<updated>2018-06-25T10:47:14Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;Si ipotizza di avere o certificati SSL già pronti  * Attivare il la configurazione SSL   sed -i -e  &amp;quot;s_^#Include /etc/proftpd/tls.conf_Include /etc/proftpd/tls.conf_&amp;quot;  /etc/p...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;Si ipotizza di avere o certificati SSL già pronti&lt;br /&gt;
&lt;br /&gt;
* Attivare il la configurazione SSL&lt;br /&gt;
&lt;br /&gt;
 sed -i -e  &amp;quot;s_^#Include /etc/proftpd/tls.conf_Include /etc/proftpd/tls.conf_&amp;quot;  /etc/proftpd/proftpd.conf&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Modificare la configurazione TLS, inserendo i nomi dei certificati corretti:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
cat | sudo tee /etc/proftpd/tls.conf &amp;lt;&amp;lt;EOFile &lt;br /&gt;
#&lt;br /&gt;
# Proftpd sample configuration for FTPS connections.&lt;br /&gt;
#&lt;br /&gt;
# Note that FTPS impose some limitations in NAT traversing.&lt;br /&gt;
# See http://www.castaglia.org/proftpd/doc/contrib/ProFTPD-mini-HOWTO-TLS.html&lt;br /&gt;
# for more information.&lt;br /&gt;
#&lt;br /&gt;
&lt;br /&gt;
&amp;lt;IfModule mod_tls.c&amp;gt;&lt;br /&gt;
TLSEngine                               on&lt;br /&gt;
TLSLog                                  /var/log/proftpd/tls.log&lt;br /&gt;
TLSProtocol                             SSLv23&lt;br /&gt;
#&lt;br /&gt;
# Server SSL certificate. You can generate a self-signed certificate using &lt;br /&gt;
# a command like:&lt;br /&gt;
#&lt;br /&gt;
# openssl req -x509 -newkey rsa:1024 \&lt;br /&gt;
#          -keyout /etc/ssl/private/proftpd.key -out /etc/ssl/certs/proftpd.crt \&lt;br /&gt;
#          -nodes -days 365&lt;br /&gt;
#&lt;br /&gt;
# The proftpd.key file must be readable by root only. The other file can be&lt;br /&gt;
# readable by anyone.&lt;br /&gt;
#&lt;br /&gt;
# chmod 0600 /etc/ssl/private/proftpd.key &lt;br /&gt;
# chmod 0640 /etc/ssl/private/proftpd.key&lt;br /&gt;
# &lt;br /&gt;
TLSRSACertificateFile                   /var/lib/dehydrated/certs/ftp.diesis.priv/fullchain.pem&lt;br /&gt;
TLSRSACertificateKeyFile                /var/lib/dehydrated/certs/ftp.diesis.priv/privkey.pem&lt;br /&gt;
#&lt;br /&gt;
# CA the server trusts...&lt;br /&gt;
#TLSCACertificateFile 			 /etc/ssl/certs/CA.pem&lt;br /&gt;
# ...or avoid CA cert and be verbose&lt;br /&gt;
#TLSOptions                      NoCertRequest EnableDiags &lt;br /&gt;
# ... or the same with relaxed session use for some clients (e.g. FireFtp)&lt;br /&gt;
#TLSOptions                      NoCertRequest EnableDiags NoSessionReuseRequired&lt;br /&gt;
#&lt;br /&gt;
#&lt;br /&gt;
# Per default drop connection if client tries to start a renegotiate&lt;br /&gt;
# This is a fix for CVE-2009-3555 but could break some clients.&lt;br /&gt;
#&lt;br /&gt;
#TLSOptions 							AllowClientRenegotiations&lt;br /&gt;
#&lt;br /&gt;
# Authenticate clients that want to use FTP over TLS?&lt;br /&gt;
#&lt;br /&gt;
#TLSVerifyClient                         off&lt;br /&gt;
#&lt;br /&gt;
# Are clients required to use FTP over TLS when talking to this server?&lt;br /&gt;
#&lt;br /&gt;
#TLSRequired                             on&lt;br /&gt;
#&lt;br /&gt;
# Allow SSL/TLS renegotiations when the client requests them, but&lt;br /&gt;
# do not force the renegotations.  Some clients do not support&lt;br /&gt;
# SSL/TLS renegotiations; when mod_tls forces a renegotiation, these&lt;br /&gt;
# clients will close the data connection, or there will be a timeout&lt;br /&gt;
# on an idle data connection.&lt;br /&gt;
#&lt;br /&gt;
#TLSRenegotiate                          required off&lt;br /&gt;
&amp;lt;/IfModule&amp;gt;&lt;br /&gt;
EOFile&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Riavviare proftpd&lt;br /&gt;
&lt;br /&gt;
 systemctl restart proftpd &lt;br /&gt;
 systemctl status proftpd.service -l&lt;br /&gt;
&lt;br /&gt;
*Provare a connettersi con filezilla&lt;br /&gt;
&lt;br /&gt;
=Riferimenti=&lt;br /&gt;
https://www.server-world.info/en/note?os=Debian_8&amp;amp;p=ftp&amp;amp;f=7&lt;/div&gt;</summary>
		<author><name>Gabriele.vivinetto</name></author>
	</entry>
</feed>