You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Docker容器中BusyBox的wget无法运行:TLS握手失败

解决BusyBox wget特定网站TLS握手失败的思路

针对你遇到的BusyBox v1.36.1中wget能正常下载github资源,但无法下载netfilter网站文件(报错TLS error from peer (alert code 40): handshake failure)的问题,以下是具体解决思路:

  • 指定兼容的User-Agent
    部分服务器会拒绝BusyBox wget默认的极简User-Agent,尝试模拟主流浏览器的UA:

    wget -U "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36" --no-check-certificate https://www.netfilter.org/projects/iptables/files/iptables-1.8.9.tar.xz
    
  • 测试使用BusyBox curl替代wget
    BusyBox内置的curl通常支持更完整的TLS加密套件,若你的BusyBox版本包含curl,执行:

    curl -k -O https://www.netfilter.org/projects/iptables/files/iptables-1.8.9.tar.xz
    

    (-k参数用于跳过证书验证,符合你的需求)

  • 手动指定Host头直接访问IP
    尝试绕开DNS解析,直接访问服务器IP并添加正确的Host头,避免可能的解析或虚拟主机配置问题:

    wget --no-check-certificate --header "Host: www.netfilter.org" https://92.243.18.11/projects/iptables/files/iptables-1.8.9.tar.xz
    
  • 检查服务器支持的TLS套件(若BusyBox含openssl)
    用openssl s_client查看netfilter服务器要求的加密套件,确认BusyBox wget是否支持:

    openssl s_client -connect www.netfilter.org:443
    

    若输出中列出的套件BusyBox wget不支持,可能需要换用支持对应套件的工具或更新BusyBox。

  • 升级BusyBox到最新版本
    旧版本BusyBox的TLS实现可能存在兼容性问题,尝试使用最新版镜像测试:

    docker run -it busybox:latest
    

    进入容器后重新执行wget命令。

内容的提问来源于stack exchange,提问作者falken

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.12 05:53:27