You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在AWS Linux 2023中使用证书通过Curl调用Exostar API的方法

解决Exostar API的Curl调用问题(基于p7b证书)
  • 步骤1:将p7b格式证书转换为PEM格式
    Exostar返回的p7b证书无法直接被Curl识别,需要先转换成PEM格式的证书链。执行以下OpenSSL命令:

    # 如果p7b是文本PEM格式
    openssl pkcs7 -in your_exostar_cert.p7b -print_certs -out full_chain.pem
    
    # 如果p7b是二进制DER格式,加-inform参数
    openssl pkcs7 -inform DER -in your_exostar_cert.p7b -print_certs -out full_chain.pem
    

    执行后会生成full_chain.pem,包含你的客户端证书及所有中间/根CA证书。

  • 步骤2:确保私钥文件权限正确
    Curl对私钥文件权限有严格要求,执行命令设置权限:

    chmod 600 privkey.pem
    
  • 步骤3:用Curl发起API请求
    使用转换后的证书链和私钥发起双向SSL认证请求,示例命令:

    curl --cert full_chain.pem --key privkey.pem https://your-exostar-api-endpoint.com/target-path
    

    如果遇到证书链验证问题,可以拆分证书链:

    • 从full_chain.pem中提取你的客户端证书(文件中第一个证书块),保存为client_cert.pem
    • 提取剩余的CA证书(中间+根),保存为ca_chain.pem
    • 使用拆分后的文件调用:
      curl --cert client_cert.pem --key privkey.pem --cacert ca_chain.pem https://your-exostar-api-endpoint.com/target-path
      
  • 排查错误
    如果请求失败,添加-v参数查看SSL握手细节,定位问题:

    curl -v --cert full_chain.pem --key privkey.pem https://your-exostar-api-endpoint.com/target-path
    

内容的提问来源于stack exchange,提问作者chen xu

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.30 19:37:06