curl访问graph.facebook.com遇SSL错误140943E8,求故障排查方案
排查Ubuntu 20.04下curl访问graph.facebook.com的SSL握手错误
错误信息
Trying 163.70.144.8:443... TCP_NODELAY set Connected to graph.facebook.com (163.70.144.8) port 443 (#0) ALPN, offering h2 ALPN, offering http/1.1 successfully set certificate verify locations: CAfile: /etc/ssl/certs/ca-certificates.crt CApath: /etc/ssl/certs TLSv1.3 (OUT), TLS handshake, Client hello (1): TLSv1.3 (IN), TLS alert, close notify (512): error:140943E8:SSL routines:ssl3_read_bytes:reason(1000) Closing connection 0 curl: (35) error:140943E8:SSL routines:ssl3_read_bytes:reason(1000)
排查步骤
1. 验证DNS解析准确性
graph.facebook.com的IP受CDN调度影响,可能存在地域节点异常,尝试切换其他已知可用IP测试:
curl -v --resolve graph.facebook.com:443:157.240.16.35 https://graph.facebook.com
可通过dig graph.facebook.com命令获取更多官方节点IP。
2. 强制指定TLS版本握手
虽然已确认服务器支持TLS1.2/1.3,但强制指定版本可排除协商阶段的兼容问题:
- 强制使用TLS1.2:
curl -v --tlsv1.2 https://graph.facebook.com
- 强制使用TLS1.3:
curl -v --tlsv1.3 https://graph.facebook.com
3. 刷新本地CA证书库
本地CA证书过期或损坏可能导致握手失败,执行以下命令更新:
sudo update-ca-certificates --fresh
更新完成后重新发起curl请求。
4. 排查网络层干扰
- 检查本地防火墙是否限制443端口出站:
sudo iptables -L OUTPUT -n | grep 443
- 临时关闭代理(若存在)后重试:
unset http_proxy https_proxy curl -v https://graph.facebook.com
- 用mtr检测链路丢包情况:
mtr 163.70.144.8
5. 升级curl版本
Ubuntu 20.04默认curl版本可能存在TLS1.3协商的兼容性问题,执行升级:
sudo apt update && sudo apt install --only-upgrade curl
升级后重新测试请求。
内容的提问来源于stack exchange,提问作者HelloLinux
相关产品推荐
相关产品推荐

