Mitmproxy连接老旧服务器遇TlsException握手错误的排查与解决
用mitmproxy连接老旧服务器的TLS兼容性问题解决
环境信息
$ mitmproxy --version Mitmproxy: 6.0.2 Python: 3.10.12 OpenSSL: OpenSSL 3.0.2 15 Mar 2022 Platform: Linux-6.5.0-14-generic-x86_64-with-glibc2.35
问题场景
- 通过后台
ssh -L ...端口转发后,可使用以下curl命令成功连接服务器:curl --tls-max 1.1 --ciphers DEFAULT@SECLEVEL=0 -v -k https://localhost:4433 - Chrome和Firefox浏览器无法与该服务器完成TLS协商连接,期望通过mitmproxy作为中间层提升安全协议兼容性
- 执行
mitmweb --ssl-insecure启动mitmproxy后,使用curl --proxy 127.0.0.1:8080 -k https://localhost:4433测试,返回502错误,具体错误信息如下:
<html> <head> <title>502 Bad Gateway</title> </head> <body> <h1>502 Bad Gateway</h1> <p>TlsProtocolException('Cannot establish TLS with localhost:4433 (sni: localhost): TlsException("SSL handshake error: Error([('SSL routines', '', 'unsupported protocol')])")')</p> </body> </html>
解决方法
通过配置OpenSSL系统默认参数解决该问题,已用curl验证配置有效:
- 创建名为
ssl.conf的配置文件,内容如下:
openssl_conf = default_conf [default_conf] ssl_conf = ssl_sect [ssl_sect] system_default = system_default_sect [system_default_sect] MinProtocol = TLSv1 CipherString = DEFAULT:@SECLEVEL=0
- 执行以下命令启动mitmproxy:
OPENSSL_CONF=$PWD/ssl.conf mitmproxy
内容的提问来源于stack exchange,提问作者Dan Bolfter
相关产品推荐
相关产品推荐

