Tutorial Tutorial Tutorial Application Services Application Services Application Services ~40 phút ~40 min ~40 នាទី Đồng bộ 2026-06-10 Synced 2026-06-10 ធ្វើសមកាល 2026-06-10

Thiết lập ứng dụng di động hoặc thiết bị IoT của bạn Configure your mobile app or IoT device ការកំណត់កម្មវិធីទូរស័ព្ទដៃឬឧបករណ៍ IoT របស់អ្នក

Hướng dẫn chi tiết đồng bộ từ docs Cloudflare — mỗi section có backlink tới đúng vị trí trên trang gốc. Detailed guide synced from Cloudflare docs — each section links to the matching anchor on the official page. មគ្គុទ្ទេសក៍លម្អិតធ្វើសមកាលពី docs Cloudflare — ផ្នែកនីមួយៗមានតំណទៅទីតាំងត្រូវគ្នានៅទំព័រផ្លូវការ។

← Danh mục ← Catalog ← បញ្ជី

Giải thích nhanh Quick context បរិបទរហ័ស

Thuộc nhóm Application Services — tập trung bảo vệ, tăng tốc và vận hành ứng dụng/web phía trước origin. Tutorial «Cấu hình your mobile app or IoT device» giúp bạn làm quen luồng triển khai thật — phù hợp đọc trước khi mở tài liệu gốc tiếng Anh. Docs gốc chia khoảng 5 bước chính; bản tóm tắt dưới đây giúp bạn nắm khung trước khi làm theo từng lệnh.

This tutorial demonstrates how to configure your Internet-of-things (IoT) device and mobile application to use client certificates with API Shield.

វគ្គសិក្សានេះបង្ហាញពីរបៀបដើម្បីកំណត់រចនាសម្ព័ន្ធឧបករណ៍អ៊ីនធឺណិតនៃអ្វី (IoT) និងកម្មវិធីទូរស័ព្ទដៃរបស់អ្នកដើម្បីប្រើវិញ្ញាបនប័ត្រអតិថិជនជាមួយ API Shield ។

Lưu ý Note ចំណាំ

Lưu ý trước khi làm Notes before you start ចំណាំមុនពេលចាប់ផ្តើម

  • Đây là bản tóm tắt trên Orange Cloud Learning Hub — không thay thế tài liệu chính thức.
  • Luôn mở liên kết «Tài liệu gốc» bên dưới khi cần lệnh CLI, snippet code và ảnh minh họa đầy đủ.
  • Docs Cloudflare cập nhật thường xuyên — đối chiếu ngày «Rà soát lần cuối» trên trang gốc khi triển khai production.
  • This is a summary on Orange Cloud Learning Hub — it does not replace the official documentation.
  • Open the Official docs link below for CLI commands, code snippets, and full screenshots.
  • Cloudflare docs change frequently — verify the Last reviewed date on the official page before production use.
  • នេះគឺជាការបញ្ជាក់អំពី Orange Cloud Learning Hub — វាគឺជាការផ្លាស់ប្តូរនៃឯកសារផ្លូវការ។
  • ចុចតំណភ្ជាប់ Docs Official នៅខាងក្រោមសម្រាប់ការបញ្ជា CLI, សៀវភៅកូដនិងរូបថតពេញលេញ។
  • Cloudflare បានផ្លាស់ប្តូរជាធម្មតានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅ។

Overview Overview Overview

Phần «Tổng quan» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Overview" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «Overview» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Hướng dẫn này cho thấy cách cấu hình thiết bị Internet of Things (IoT) và ứng dụng di động của bạn để sử dụng chứng chỉ khách hàng với API Shield.
This tutorial demonstrates how to configure your Internet-of-things (IoT) device and mobile application to use client certificates with API Shield.
វគ្គបណ្តុះបណ្តាលនេះបង្ហាញពីរបៀបកំណត់រចនាសម្ព័ន្ធឧបករណ៍អ៊ីនធឺណិតនៃអ្វី (IoT) និងកម្មវិធីទូរស័ព្ទដៃរបស់អ្នកដើម្បីប្រើវិញ្ញាបនប័ត្រអតិថិជនជាមួយ API Shield ។

Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)

Chi tiết kịch bản Scenario details លក្ខណៈពិសេស Scenario

Phần «Scenario details» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Scenario details" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «លក្ខណៈពិសេស Scenario» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Trình duyệt này sử dụng ví dụ về một thiết bị ghi lại các con số nhiệt độ và truyền chúng bằng cách gửi yêu cầu POST đến Cloudflare được bảo vệ API. Một ứng dụng di động được xây dựng trong Swift cho iOS sẽ thu thập những đọc đó và hiển thị chúng.
This walkthrough uses the example of a device that captures temperature readings and transmits them by sending a POST request to a Cloudflare-protected API. A mobile application built in Swift for iOS retrieves those readings and displays them.
ការដោះស្រាយនេះប្រើសម្រាប់ឧបករណ៍មួយដែលទទួលបានកំណត់សីតុណ្ហភាពនិងផ្ញើវាដោយផ្ញើសំណួរ POST ទៅ Cloudflare ដែលមានការពារ API ។ កម្មវិធីទូរស័ព្ទដៃដែលបានបង្កើតឡើងនៅក្នុង Swift សម្រាប់ iOS ទទួលបានការអានទាំងនេះនិងបង្ហាញវា។
Để làm cho ví dụ này đơn giản, API được thực hiện dưới dạng Cloudflare Worker (mượn mã từ To-Do List tutorial on building a jamstack app).
To keep this example simple, the API is implemented as a Cloudflare Worker (borrowing code from the To-Do List tutorial on building a jamstack app).
ដើម្បីរក្សាទុកឧទាហរណ៍នេះយ៉ាងងាយស្រួល API ត្រូវបានអនុវត្តជា Cloudflare Worker (កូដបង់ពី To-Do List tutorial on building a jamstack app) ។
Nhiệt độ được lưu trữ trong Workers KV bằng cách sử dụng địa chỉ nguồn IP làm khóa, nhưng bạn có thể dễ dàng sử dụng một value from the client certificate, chẳng hạn như dấu vân tay.
Temperatures are stored in Workers KV using the source IP address as a key, but you can easily use a value from the client certificate, such as the fingerprint.
សីតុណ្ហភាពត្រូវបានរក្សាទុកនៅក្នុង Workers KV ដោយប្រើអាសយដ្ឋានប្រភព IP ជាគោលបំណងប៉ុន្តែអ្នកអាចប្រើបានយ៉ាងងាយស្រួលជាគោលបំណង value from the client certificate ។
Ví dụ API mã dưới đây lưu nhiệt độ và dấu thời gian vào KV khi một POST được thực hiện và trả về năm nhiệt độ gần đây nhất khi một yêu cầu GET được thực hiện.
The example API code below saves a temperature and timestamp into KV when a POST is made and returns the most recent five temperatures when a GET request is made.
លេខកូដឧទាហរណ៍ API នៅក្រោមនេះបានសរសេរសីតុណ្ហភាពនិងម៉ាកពេលវេលាទៅ KV នៅពេលដែល POST ត្រូវបានធ្វើឡើងនិងបង្ហាញពីសីតុណ្ហភាពចុងក្រោយបំផុត 5 នៅពេលដែល GET ត្រូវបានធ្វើឡើង។
JavaScript Đánh giá
JavaScript
កុំព្យូទ័រ
text
const defaultData = { temperatures: [] };


const getCache = (key) => TEMPERATURES.get(key);

const setCache = (key, data) => TEMPERATURES.put(key, data);


async function addTemperature(request) {

  // Pull previously recorded temperatures for this client.

  const ip = request.headers.get("CF-Connecting-IP");

  const cacheKey = `data-${ip}`;

  let data;

  const cache = await getCache(cacheKey);

  if (!cache) {

    await setCache(cacheKey, JSON.stringify(defaultData));

    data = defaultData;

  } else {

    data = JSON.parse(cache);

  }


  // Append the recorded temperatures with the submitted reading (assuming it has both temperature and a timestamp).

  try {

    const body = await request.text();

    const val = JSON.parse(body);


    if (val.temperature && val.time) {

      data.temperatures.push(val);

      await setCache(cacheKey, JSON.stringify(data));

      return new Response("", { status: 201 });

    } else {

      return new Response(

        "Unable to parse temperature and/or timestamp from JSON POST body",

        { status: 400 },

      );

    }

  } catch (err) {

    return new Response(err, { status: 500 });

  }

}


function compareTimestamps(a, b) {

  return -1 * (Date.parse(a.time) - Date.parse(b.time));

}


// Return the 5 most recent temperature measurements.

async function getTemperatures(request) {

  const ip = request.headers.get("CF-Connecting-IP");

  const cacheKey = `data-${ip}`;


  const cache = await getCache(cacheKey);

  if (!cache) {

    return new Response(JSON.stringify(defaultData), {

      status: 200,

      headers: { "content-type": "application/json" },

    });

  } else {

    data = JSON.parse(cache);

    const retval = JSON.stringify(

      data.temperatures.sort(compareTimestamps).splice(0, 5),

    );

    return new Response(retval, {

      status: 200,

      headers: { "content-type": "application/json" },

    });

  }

}


export default {

  async fetch(request, env, ctx) {

    return request.method === "POST"

      ? addTemperature(request)

      : getTemperatures(request);

  },

};
---
---
---

Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)

Dữ liệu mẫu POST đến API POST sample data to API ទិន្នន័យគំរូ POST ទៅ API

Phần «POST sample data to API» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "POST sample data to API" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «ទិន្នន័យគំរូ POST ទៅ API» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Để xác nhận API trước khi thêm xác thực mTLS, POST một đánh giá nhiệt độ ngẫu nhiên:
To validate the API before adding mTLS authentication, POST a random temperature reading:
ដើម្បីត្រួតពិនិត្យ API មុនពេលបន្ថែមការត្រួតពិនិត្យ mTLS, POST ការត្រួតពិនិត្យសីតុណ្ហភាពជាទូទៅ:
Cửa sổ Terminal
Terminal window
បង្វិល Terminal
text
$ TEMPERATURE=$(echo $((361 + RANDOM %11)) | awk '{printf("%.2f",$1/10.0)}')

$ TIMESTAMP=$(date -u +"%Y-%m-%dT%H:%M:%SZ")


$ echo -e "$TEMPERATURE\n$TIMESTAMP"

36.70

2020-09-28T02:54:56Z


$ curl --verbose --header "Content-Type: application/json" --data '{"temperature":'''$TEMPERATURE''', "time": "'''$TIMESTAMP'''"}' https://shield.upinatoms.com/temps 2>&1 | grep "< HTTP/2"

< HTTP/2 201

Nhận dữ liệu mẫu từ API GET sample data from API ទាញយកទិន្នន័យគំរូពី API

Phần «GET sample data từ API» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "GET sample data from API" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «ទាញយកទិន្នន័យគំរូពី API» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Yêu cầu GET đến điểm cuối temps trả về các bài đọc gần đây nhất, bao gồm cả bài đọc được gửi trong ví dụ ở trên:
A GET request to the temps endpoint returns the most recent readings, including the one submitted in the example above:
A GET request to the temps endpoint returns the most recent readings, including the one submitted in the example above:
Cửa sổ Terminal
Terminal window
បង្វិល Terminal
text
$ curl --silent https://shield.upinatoms.com/temps | jq .

[

  {

    "temperature": 36.3,

    "time": "2020-09-28T02:57:49Z"

  },

  {

    "temperature": 36.7,

    "time": "2020-09-28T02:54:56Z"

  },

  {

    "temperature": 36.2,

    "time": "2020-09-28T02:33:08Z"

  }

]
---
---
---

2.Đối với Tạo Cloudflare-được phát hành chứng chỉ 2. Create Cloudflare-issued certificates 2 ។ ការបង្កើតសញ្ញាបនប័ត្រ Cloudflare ដែលបានចេញ

Phần «Tạo Cloudflare-issued certificates» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "2. Create Cloudflare-issued certificates" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «2 ។ ការបង្កើតសញ្ញាបនប័ត្រ Cloudflare ដែលបានចេញ» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Trước khi bạn có thể sử dụng API Shield để bảo vệ API hoặc ứng dụng web của bạn, hãy tạo chứng chỉ khách hàng được phát hành Cloudflare.
Before you can use API Shield to protect your API or web application, create Cloudflare-issued client certificates.
មុនពេលដែលអ្នកអាចប្រើ API Shield ដើម្បីការពារ API ឬកម្មវិធីបណ្ដាញរបស់អ្នកបានបង្កើតវិញ្ញាបនប័ត្រអតិថិជនដែលបានចេញ Cloudflare ។
Tuy nhiên, vì hầu hết các nhà phát triển làm việc trên quy mô tạo khóa riêng của họ và yêu cầu chữ ký chứng chỉ thông qua API, ví dụ này sử dụng Cloudflare API để tạo chứng chỉ khách hàng.
However, since most developers working at scale generate their own private keys and certificate signing requests via API, this example uses the Cloudflare API to create client certificates.
ទោះបីជាអ្នកអភិវឌ្ឍន៍ដែលធ្វើការនៅទំហំជាច្រើនបានបង្កើតគោលបំណងឯកជនរបស់ពួកគេនិងការសរសេរសញ្ញាបនប័ត្ររបស់ពួកគេតាមរយៈ API ដូច្នេះឧទាហរណ៍នេះប្រើ Cloudflare API ដើម្បីបង្កើតសញ្ញាបនប័ត្រអតិថិជន។
Để tạo chứng chỉ bootstrap cho ứng dụng iOS và thiết bị IoT, ví dụ này sử dụng Cloudflare’s public key infrastructure toolkit, CFSSL ↗:
To create a bootstrap certificate for the iOS application and the IoT device, this example uses Cloudflare’s public key infrastructure toolkit, CFSSL ↗:
ដើម្បីបង្កើតវិញ្ញាបនប័ត្រ bootstrap សម្រាប់កម្មវិធី iOS និងឧបករណ៍ IoT នេះឧទាហរណ៍នេះប្រើ Cloudflare’s public key infrastructure toolkit, CFSSL ↗:
Cửa sổ Terminal
Terminal window
បង្វិល Terminal
text
# Generate a private key and CSR for the iOS device.


$ cat <<'EOF' | tee -a csr.json

{

    "hosts": [

        "ios-bootstrap.devices.upinatoms.com"

    ],

    "CN": "ios-bootstrap.devices.upinatoms.com",

    "key": {

        "algo": "rsa",

        "size": 2048

    },

    "names": [{

        "C": "US",

        "L": "Austin",

        "O": "Temperature Testers, Inc.",

        "OU": "Tech Operations",

        "ST": "Texas"

    }]

}

EOF


$ cfssl genkey csr.json | cfssljson -bare certificate


2020/09/27 21:28:46 [INFO] generate received request

2020/09/27 21:28:46 [INFO] received CSR

2020/09/27 21:28:46 [INFO] generating key: rsa-2048

2020/09/27 21:28:47 [INFO] encoded CSR


$ mv certificate-key.pem ios-key.pem

$ mv certificate.csr ios.csr


# Do the same for the IoT sensor.


$ sed -i.bak 's/ios-bootstrap/sensor-001/g' csr.json

$ cfssl genkey csr.json | cfssljson -bare certificate

...

$ mv certificate-key.pem sensor-key.pem

$ mv certificate.csr sensor.csr


# now ask that these CSRs be signed by the private CA issued for your zone

# we need to replace actual newlines in the CSR with ‘\n’ before POST’ing

$ CSR=$(cat ios.csr | perl -pe 's/\n/\\n/g')

$ request_body=$(< <(cat <<EOF

{

  "validity_days": 3650,

  "csr":"$CSR"

}

EOF

))


# save the response so we can view it and then extra the certificate

$ curl https://api.cloudflare.com/client/v4/zones/{zone_id}/client_certificates \

--header "X-Auth-Email: <EMAIL>" \

--header "X-Auth-Key: <API_KEY>" \

--header "Content-Type: application/json" \

--data "$request_body" > response.json


$ cat response.json | jq .


{

  "success": true,

  "errors": [],

  "messages": [],

  "result": {

    "id": "7bf7f70c-7600-42e1-81c4-e4c0da9aa515",

    "certificate_authority": {

      "id": "8f5606d9-5133-4e53-b062-a2e5da51be5e",

      "name": "Cloudflare Managed CA for account 11cbe197c050c9e422aaa103cfe30ed8"

    },

    "certificate": "-----BEGIN CERTIFICATE-----\nMIIEkzCCA...\n-----END CERTIFICATE-----\n",

    "csr": "-----BEGIN CERTIFICATE REQUEST-----\nMIIDITCCA...\n-----END CERTIFICATE REQUEST-----\n",

    "ski": "eb2a48a19802a705c0e8a39489a71bd586638fdf",

    "serial_number": "133270673305904147240315902291726509220894288063",

    "signature": "SHA256WithRSA",

    "common_name": "ios-bootstrap.devices.upinatoms.com",

    "organization": "Temperature Testers, Inc.",

    "organizational_unit": "Tech Operations",

    "country": "US",

    "state": "Texas",

    "location": "Austin",

    "expires_on": "2030-09-26T02:41:00Z",

    "issued_on": "2020-09-28T02:41:00Z",

    "fingerprint_sha256": "84b045d498f53a59bef53358441a3957de81261211fc9b6d46b0bf5880bdaf25",

    "validity_days": 3650

  }

}


$ cat response.json | jq .result.certificate | perl -npe 's/\\n/\n/g; s/"//g' > ios.pem


# Now ask that the second client certificate signing request be signed.


$ CSR=$(cat sensor.csr | perl -pe 's/\n/\\n/g')

$ request_body=$(< <(cat <<EOF

{

  "validity_days": 3650,

  "csr":"$CSR"

}

EOF

))


$ curl https://api.cloudflare.com/client/v4/zones/{zone_id}/client_certificates \

--header "X-Auth-Email: <EMAIL>" \

--header "X-Auth-Key: <API_KEY>" \

--header "Content-Type: application/json" \

--data "$request_body" | perl -npe 's/\\n/\n/g; s/"//g' > sensor.pem
---
---
---

Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)

3 Cái Nhúng chứng chỉ khách hàng vào ứng dụng di động của bạn 3. Embed the client certificate in your mobile app 3 ។ ទាញយកវិញ្ញាបនប័ត្រអតិថិជនក្នុងកម្មវិធីទូរស័ព្ទដៃរបស់អ្នក

Phần «Embed client certificate in your mobile app» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "3. Embed the client certificate in your mobile app" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «3 ។ ទាញយកវិញ្ញាបនប័ត្រអតិថិជនក្នុងកម្មវិធីទូរស័ព្ទដៃរបស់អ្នក» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Để cấu hình ứng dụng di động để yêu cầu dữ liệu nhiệt độ được gửi bởi thiết bị IoT một cách an toàn, hãy nhúng chứng chỉ khách hàng vào ứng dụng di động.
To configure the mobile app to securely request temperature data submitted by the IoT device, embed the client certificate in the mobile app.
ប្រសិនបើអ្នកចង់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់
Để đơn giản hóa, ví dụ này nhúng một chứng chỉ “bootstrap” và khóa trong gói ứng dụng dưới dạng tệp định dạng PKCS#12:
For simplicity, this example embeds a “bootstrap” certificate and key in the application bundle as a PKCS#12-formatted file:
សម្រាប់ភាពងាយស្រួលនេះឧទាហរណ៍នេះបានបំពាក់វិញ្ញាបនប័ត្រ "bootstrap" និងគោលបំណងនៅក្នុងកញ្ចប់កម្មវិធីដូចជាឯកសារ PKCS#12-formatted ។
Cửa sổ Terminal
Terminal window
បង្វិល Terminal
text
$ openssl pkcs12 -export -out bootstrap-cert.pfx -inkey ios-key.pem -in ios.pem

Enter Export Password:

Verifying - Enter Export Password:
Trong một triển khai thực tế, chứng chỉ bootstrap chỉ nên được sử dụng kết hợp với thông tin xác thực của người dùng để xác thực với điểm cuối API có thể trả về chứng chỉ người dùng duy nhất. Người dùng doanh nghiệp sẽ muốn sử dụng quản lý thiết bị di động (MDM) để phân phối chứng chỉ.
In a real-world deployment, a bootstrap certificate should only be used in conjunction with users' credentials to authenticate with an API endpoint that can return a unique user certificate. Corporate users will want to use mobile device management (MDM) to distribute certificates.
នៅក្នុងការដំឡើងនៅក្នុងពិភពលោកពិតប្រាកដអ្នកគួរតែប្រើវិញ្ញាបនប័ត្រ bootstrap ជាមួយនឹងវិញ្ញាបនប័ត្ររបស់អ្នកប្រើដើម្បីត្រួតពិនិត្យដោយ API ដែលអាចបង្ហាញវិញ្ញាបនប័ត្រអ្នកប្រើតែមួយ។ អ្នកប្រើប្រាស់អាជីវកម្មនឹងចង់ប្រើការគ្រប់គ្រងឧបករណ៍ទូរស័ព្ទដៃ (MDM) ដើម្បីផ្គត់ផ្គង់វិញ្ញាបនបត្រ។

Nhúng chứng chỉ khách hàng trong một ứng dụng Android Embed the client certificate in an Android app ទាញយកប្រព័ន្ធប្រតិបត្តិការ Android ក្នុងកម្មវិធី Android

Phần «Embed client certificate in Android app» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Embed the client certificate in an Android app" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «ទាញយកប្រព័ន្ធប្រតិបត្តិការ Android ក្នុងកម្មវិធី Android» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Dưới đây là một ví dụ về cách bạn có thể sử dụng chứng chỉ khách hàng trong ứng dụng Android để thực hiện cuộc gọi HTTP. Bạn cần thêm quyền sau đây trong AndroidManifest.xml để cho phép kết nối Internet.
The following is an example of how you may use a client certificate in an Android app to make HTTP calls. You need to add the following permission in AndroidManifest.xml to allow an Internet connection.
នេះគឺជាឧទាហរណ៍អំពីរបៀបដែលអ្នកអាចប្រើវិញ្ញាបនប័ត្រអតិថិជននៅក្នុងកម្មវិធី Android ដើម្បីធ្វើការហៅ HTTP ។ ប្រសិនបើអ្នកត្រូវបន្ថែមការអនុញ្ញាតដូចខាងក្រោមនៅក្នុង AndroidManifest.xml ដើម្បីអនុញ្ញាតការតភ្ជាប់អ៊ីនធឺណិត។
text
<uses-permission android:name="android.permission.INTERNET" />
Đối với mục đích thể hiện, chứng chỉ trong ví dụ này được lưu trữ trong app/src/main/res/raw/cert.pem và khóa riêng được lưu trữ trong app/src/main/res/raw/key.pem. Bạn cũng có thể lưu trữ các tập tin này theo những cách an toàn khác.
For demonstration purposes, the certificate in this example is stored in app/src/main/res/raw/cert.pem and the private key is stored in app/src/main/res/raw/key.pem. You may also store these files in other secure manners.
សម្រាប់គោលបំណងការបង្ហាញ, វិញ្ញាបនប័ត្រនៅក្នុងឧទាហរណ៍នេះត្រូវបានរក្សាទុកនៅក្នុង app/src/main/res/raw/cert.pem និងគោលបំណងឯកជនត្រូវបានរក្សាទុកនៅក្នុង app/src/main/res/raw/key.pem ។ អ្នកក៏អាចផ្ទុកឯកសារទាំងនេះនៅក្នុងវិធីសាស្រ្តសុវត្ថិភាពផ្សេងទៀត។
Ví dụ sau đây sử dụng OkHttpClient, nhưng bạn cũng có thể sử dụng các khách hàng khác như HttpURLConnection theo những cách tương tự. Chìa khóa là sử dụng SSLSocketFactory.
The following example uses an OkHttpClient, but you may also use other clients such as HttpURLConnection in similar ways. The key is to use the SSLSocketFactory.
ឧទាហរណ៍ខាងក្រោមនេះប្រើ OkHttpClient ប៉ុន្តែអ្នកអាចប្រើអតិថិជនផ្សេងទៀតដូចជា HttpURLConnection ដូចគ្នា។ គោលបំណងនេះគឺដើម្បីប្រើ SSLSocketFactory ។
text
private OkHttpClient setUpClient() {

    try {

        final String SECRET = "secret"; // You may also store this String somewhere more secure.

        CertificateFactory certificateFactory = CertificateFactory.getInstance("X.509");


        // Get private key

        InputStream privateKeyInputStream = getResources().openRawResource(R.raw.key);

        byte[] privateKeyByteArray = new byte[privateKeyInputStream.available()];

        privateKeyInputStream.read(privateKeyByteArray);


        String privateKeyContent = new String(privateKeyByteArray, Charset.defaultCharset())

                .replace("-----BEGIN PRIVATE KEY-----", "")

                .replaceAll(System.lineSeparator(), "")

                .replace("-----END PRIVATE KEY-----", "");


        byte[] rawPrivateKeyByteArray = Base64.getDecoder().decode(privateKeyContent);

        KeyFactory keyFactory = KeyFactory.getInstance("RSA");

        PKCS8EncodedKeySpec keySpec = new PKCS8EncodedKeySpec(rawPrivateKeyByteArray);


        // Get certificate

        InputStream certificateInputStream = getResources().openRawResource(R.raw.cert);

        Certificate certificate = certificateFactory.generateCertificate(certificateInputStream);


        // Set up KeyStore

        KeyStore keyStore = KeyStore.getInstance(KeyStore.getDefaultType());

        keyStore.load(null, SECRET.toCharArray());

        keyStore.setKeyEntry("client", keyFactory.generatePrivate(keySpec), SECRET.toCharArray(), new Certificate[]{certificate});

        certificateInputStream.close();


        // Set up Trust Managers

        TrustManagerFactory trustManagerFactory = TrustManagerFactory.getInstance(TrustManagerFactory.getDefaultAlgorithm());

        trustManagerFactory.init((KeyStore) null);

        TrustManager[] trustManagers = trustManagerFactory.getTrustManagers();


        // Set up Key Managers

        KeyManagerFactory keyManagerFactory = KeyManagerFactory.getInstance(KeyManagerFactory.getDefaultAlgorithm());

        keyManagerFactory.init(keyStore, SECRET.toCharArray());

        KeyManager[] keyManagers = keyManagerFactory.getKeyManagers();


        // Obtain SSL Socket Factory

        SSLContext sslContext = SSLContext.getInstance("TLS");

        sslContext.init(keyManagers, trustManagers, new SecureRandom());

        SSLSocketFactory sslSocketFactory = sslContext.getSocketFactory();


        // Finally, return the client, which will then be used to make HTTP calls.

        OkHttpClient client = new OkHttpClient.Builder()

                .sslSocketFactory(sslSocketFactory, (X509TrustManager) trustManagers[0])

                .build();


        return client;


    } catch (CertificateException | IOException | NoSuchAlgorithmException | KeyStoreException | UnrecoverableKeyException | KeyManagementException | InvalidKeySpecException e) {

        e.printStackTrace();

        return null;

    }

}
Chức năng trên trả về OkHttpClient được nhúng với chứng chỉ khách hàng. Bây giờ bạn có thể sử dụng máy khách này để thực hiện yêu cầu HTTP đến điểm cuối API được bảo vệ bằng mTLS.
The above function returns an OkHttpClient embedded with the client certificate. You can now use this client to make HTTP requests to your API endpoint protected with mTLS.
សម្ភារៈខាងលើបង្ហាញ OkHttpClient ដែលត្រូវបានបំពាក់ជាមួយនឹងវិញ្ញាបនប័ត្រអតិថិជន។ ឥឡូវនេះអ្នកអាចប្រើអតិថិជននេះដើម្បីធ្វើតេស្ត HTTP ទៅបញ្ចប់ API របស់អ្នកដែលមានការពារដោយ mTLS ។
---
---
---

Bốn Nhúng chứng chỉ khách hàng vào thiết bị IoT của bạn 4. Embed the client certificate on your IoT device 4 ។ ទាញយកវិញ្ញាបនប័ត្រអតិថិជនលើឧបករណ៍ IoT របស់អ្នក

Phần «Embed client certificate on your IoT device» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "4. Embed the client certificate on your IoT device" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «4 ។ ទាញយកវិញ្ញាបនប័ត្រអតិថិជនលើឧបករណ៍ IoT របស់អ្នក» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Để chuẩn bị thiết bị IoT cho giao tiếp an toàn với điểm cuối API, nhúng chứng chỉ vào thiết bị và cấu hình thiết bị để sử dụng chứng chỉ khi thực hiện yêu cầu POST.
To prepare the IoT device for secure communication with the API endpoint, embed the certificate on the device and configure the device to use the certificate when making POST requests.
ដើម្បីរៀបចំឧបករណ៍ IoT សម្រាប់ការផ្លាស់ប្តូរសុវត្ថិភាពជាមួយ API ដំណាក់កាលបញ្ចប់, បំពាក់វិញ្ញាបនប័ត្រនៅលើឧបករណ៍និងកំណត់ឧបករណ៍ដើម្បីប្រើវិញ្ញាបនប័ត្រនៅពេលធ្វើតេស្ត POST ។
Ví dụ này giả định rằng chứng chỉ và khóa riêng được sao chép an toàn thành /etc/ssl/private/sensor-key.pem và /etc/ssl/certs/sensor.pem.
This example assumes the certificate and the private key are securely copied to /etc/ssl/private/sensor-key.pem and /etc/ssl/certs/sensor.pem.
លក្ខណៈពិសេសនេះគឺប្រសិនបើសញ្ញាបនប័ត្រនិងគោលបំណងឯកជនត្រូវបានចែកចាយដោយសុវត្ថិភាពទៅ /etc/ssl/private/sensor-key.pem និង /etc/ssl/certs/sensor.pem ។
Script mẫu được sửa đổi để chỉ các tập tin này:
The sample script is modified to point to these files:
ប្រព័ន្ធ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ
Python
Python
Python
text
import requests

import json

from datetime import datetime


def readSensor():


    # Takes a reading from a temperature sensor and store it to temp_measurement


    dateTimeObj = datetime.now()

    timestampStr = dateTimeObj.strftime('%Y-%m-%dT%H:%M:%SZ')


    measurement = {'temperature':str(temp_measurement),'time':timestampStr}

    return measurement


def main():


    print("Cloudflare API Shield [IoT device demonstration]")


    temperature = readSensor()

    payload = json.dumps(temperature)


    url = 'https://shield.upinatoms.com/temps'

    json_headers = {'Content-Type': 'application/json'}

    cert_file = ('/etc/ssl/certs/sensor.pem', '/etc/ssl/private/sensor-key.pem')


    r = requests.post(url, headers = json_headers, data = payload, cert = cert_file)


    print("Request body: ", r.request.body)

    print("Response status code: %d" % r.status_code)
Khi kịch bản cố gắng kết nối với https://shield.upinatoms.com/temps, Cloudflare yêu cầu một chứng chỉ máy khách được gửi và kịch bản gửi nội dung của /etc/ssl/certs/sensor.pem. Sau đó, như yêu cầu để hoàn thành SSL/TLS handshake, kịch bản cho thấy nó có quyền sở hữu của /etc/ssl/private/sensor-key.pem.
When the script attempts to connect to https://shield.upinatoms.com/temps, Cloudflare requests that a client certificate is sent and the script sends the contents of /etc/ssl/certs/sensor.pem. Then, as required to complete the SSL/TLS handshake, the script demonstrates it has possession of /etc/ssl/private/sensor-key.pem.
When the script attempts to connect to https://shield.upinatoms.com/temps, Cloudflare requests that a client certificate is sent and the script sends the contents of /etc/ssl/certs/sensor.pem. Then, as required to complete the SSL/TLS handshake, the script demonstrates it has possession of /etc/ssl/private/sensor-key.pem.
Nếu không có chứng chỉ khách hàng, Cloudflare sẽ từ chối yêu cầu:
Without the client certificate, the Cloudflare rejects the request:
ដោយគ្មានវិញ្ញាបនប័ត្រអតិថិជន, Cloudflare បាត់បង់សំណួរនេះ:
text
Cloudflare API Shield [IoT device demonstration]

Request body:  {"temperature": "36.5", "time": "2020-09-28T15:52:19Z"}

Response status code: 403
Khi thiết bị IoT trình bày chứng chỉ khách hàng hợp lệ, yêu cầu POST thành công và đọc nhiệt độ được ghi lại:
When the IoT device presents a valid client certificate, the POST request succeeds and the temperature reading is recorded:
នៅពេលដែលឧបករណ៍ IoT ផ្តល់នូវវិញ្ញាបនប័ត្រអតិថិជនដែលមានប្រសិទ្ធិភាពការទូទាត់ការទូទាត់ POST គឺជោគជ័យនិងការសរសេរសីតុណ្ហភាពត្រូវបានសរសេរ:
text
Cloudflare API Shield [IoT device demonstration]

Request body:  {"temperature": "36.5", "time": "2020-09-28T15:56:45Z"}

Response status code: 201
---
---
---

5 Khả năng mTLS 5. Enable mTLS 5 ។ លក្ខណៈពិសេស MTLS

Phần «Enable mTLS» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "5. Enable mTLS" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «5 ។ លក្ខណៈពិសេស MTLS» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Sau khi tạo chứng chỉ được phát hành Cloudflare, bước tiếp theo là enable mTLS cho các máy chủ mà bạn muốn bảo vệ với API Shield.
After creating Cloudflare-issued certificates, the next step is to enable mTLS for the hosts you want to protect with API Shield.
បន្ទាប់ពីបង្កើតវិញ្ញាបនប័ត្រដែលបានចេញ Cloudflare, ការដោះស្រាយបន្ទាប់នេះគឺ enable mTLS សម្រាប់ក្រុមហ៊ុនផ្គត់ផ្គង់ដែលអ្នកចង់ការពារជាមួយ API Shield ។
---
---
---

Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)

Sáu Cài đặt API Shield để yêu cầu chứng chỉ khách hàng 6. Configure API Shield to require client certificates 6 ។ ការកំណត់ API Shield ដើម្បីតម្រូវការវិញ្ញាបនប័ត្រអតិថិជន

Phần «Cấu hình API Shield to require client certificates» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "6. Configure API Shield to require client certificates" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «6 ។ ការកំណត់ API Shield ដើម្បីតម្រូវការវិញ្ញាបនប័ត្រអតិថិជន» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Để cấu hình API Shield để yêu cầu chứng chỉ khách hàng, create a mTLS rule.
To configure API Shield to require client certificates, create a mTLS rule.
ដើម្បីកំណត់ API Shield ដើម្បីត្រូវការវិញ្ញាបនប័ត្រអតិថិជន, create a mTLS rule ។
json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"item":{"@id":"/directory/","name":"Directory"}},{"@type":"ListItem","position":2,"item":{"@id":"/ssl/","name":"SSL/TLS"}},{"@type":"ListItem","position":3,"item":{"@id":"/ssl/client-certificates/","name":"Client certificates (mTLS)"}},{"@type":"ListItem","position":4,"item":{"@id":"/ssl/client-certificates/configure-your-mobile-app-or-iot-device/","name":"Configure your mobile app or IoT device"}}]}

Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)

Xem bản đầy đủ trên developers.cloudflare.com (ảnh, tab cấu hình). View the full guide on developers.cloudflare.com (images, config tabs). មើលមគ្គុទ្ទេសក៍ពេញលើ developers.cloudflare.com (រូបភាព, tab កំណត់)។

Tài liệu gốc ↗ Official docs ↗ ឯកសារផ្លូវការ ↗