You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用sendgrid-mailer发邮件时Postfix TLS库报错error:14094418的解决问询

解决PHP应用与本地Postfix的TLS验证失败问题

问题根源

你的Postfix使用的是自签名证书(/etc/pki/tls/certs/postfix.pem),而PHP的sendgrid-mailer在和Postfix建立TLS连接时,默认会验证证书的CA合法性——自签证书不在系统信任的CA列表里,所以触发了"unknown ca"错误。

方案一:让PHP信任Postfix的自签证书

  • 先导出Postfix证书的CA部分(自签证书本身就是CA):
    openssl x509 -in /etc/pki/tls/certs/postfix.pem -out /etc/pki/tls/certs/postfix_ca.crt -outform PEM
    
  • 将证书追加到系统默认的CA信任 bundle 中:
    cat /etc/pki/tls/certs/postfix_ca.crt >> /etc/pki/tls/certs/ca-bundle.crt
    
  • 或者修改PHP的php.ini文件(用php -i | grep "Loaded Configuration File"查找路径),指定包含该证书的CA文件:
    openssl.cafile = /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/postfix_ca.crt
    
  • 最后重启Apache使配置生效:
    systemctl restart httpd
    

方案二:绕过TLS证书验证(仅适合测试环境)

如果是测试场景,不想折腾证书信任,直接关闭sendgrid-mailer的证书验证:

  • 修改MAILER_DSN,添加验证关闭参数:
    MAILER_DSN=smtp://127.0.0.1:25?verify_peer=0&verify_peer_name=0
    
  • 或者在代码层配置(以Symfony Mailer为例):
    use Symfony\Component\Mailer\Transport;
    use Symfony\Component\Mailer\Mailer;
    
    $dsn = 'smtp://127.0.0.1:25?verify_peer=0&verify_peer_name=0';
    $transport = Transport::fromDsn($dsn);
    $mailer = new Mailer($transport);
    

可选优化:调整Postfix本地连接的TLS规则

让Postfix对本地127.0.0.1的连接直接跳过TLS:

  • 编辑/etc/postfix/main.cf,添加:
    smtpd_tls_security_level = ${if eq {${client_address}}{127.0.0.1}{none}{may}}
    
  • 重载Postfix配置:
    postfix reload
    

内容的提问来源于stack exchange,提问作者Confounder

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.19 13:10:04