You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ubuntu 16.04下OpenSSL调试求助:无法切换ISRG Root X1根证书

解决Ubuntu 16.04下OpenSSL仍依赖过期DST Root CA X3的问题

第一步:排查证书库中是否残留DST Root CA X3

你仅处理了ISRG Root X1的证书,但过期的DST Root CA X3可能还在系统证书库中,导致OpenSSL构建信任链时优先选择旧的交叉签名路径。执行命令检查:

ll /etc/ssl/certs/ | grep -i dst

如果存在DST_Root_CA_X3.pem之类的文件,按以下操作清理:

  1. 编辑/etc/ca-certificates.conf,注释掉mozilla/DST_Root_CA_X3.crt
  2. 重建证书库:
sudo update-ca-certificates --fresh

第二步:强制指定自签名证书验证

直接用你添加的ISRG Root X1自签名证书做验证,确认证书本身是否有效:

openssl s_client -connect api.ipgeolocation.io:443 -CAfile /etc/ssl/certs/ISRGRootX1selfsigned.pem

如果返回verify return:1,说明证书有效,问题出在OpenSSL默认的CA路径或配置上。

第三步:检查OpenSSL全局配置

查看/etc/ssl/openssl.cnf中是否指定了额外的CA路径或证书:

grep -i "CAfile\|CApath" /etc/ssl/openssl.cnf

如果存在CApath指向非/etc/ssl/certs/的目录,或CAfile指定了包含DST证书的文件,修改配置指向当前有效证书库,或直接指定你的自签名CA文件。

第四步:手动分析证书链验证过程

  1. 下载目标网站的完整证书链:
openssl s_client -connect api.ipgeolocation.io:443 -showcerts </dev/null | sed -n '/-----BEGIN CERTIFICATE-----/,/-----END CERTIFICATE-----/p' > chain.crt
  1. 用自签名证书验证链:
openssl verify -CAfile /etc/ssl/certs/ISRGRootX1selfsigned.pem chain.crt

如果验证通过,说明系统默认证书库仍有残留的DST证书干扰,或OpenSSL默认未优先使用你的自签名证书。

第五步:更新ca-certificates包

Ubuntu 16.04的ca-certificates包版本较旧,可能对新信任链支持不足,尝试更新:

sudo apt update && sudo apt install --only-upgrade ca-certificates

更新后重新执行update-ca-certificates --fresh再测试。

临时测试:用自定义配置文件验证

创建临时配置文件test-openssl.cnf:

[openssl_init]
ssl_conf = ssl_sect

[ssl_sect]
system_default = system_default_sect

[system_default_sect]
MinProtocol = TLSv1.2
CipherString = DEFAULT@SECLEVEL=1
CAfile = /etc/ssl/certs/ISRGRootX1selfsigned.pem

用该配置测试连接:

OPENSSL_CONF=./test-openssl.cnf openssl s_client -connect api.ipgeolocation.io:443

内容的提问来源于stack exchange,提问作者omer brandis

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.26 16:57:35