You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

服务器调用api.eu.mailgun.net出现SSL_ERROR_SYSCALL错误求助

SSL连接失败:无法与api.eu.mailgun.net:443建立TLS握手

问题现象

恢复Hetzner云快照(Debian 11系统)后,所有向api.eu.mailgun.net:443发起的curl请求均返回SSL错误,sslscan检测显示目标服务器所有TLS协议均被标记为禁用。

curl命令输出:

curl --verbose https://api.eu.mailgun.net
*   Trying 34.95.107.114:443...
* Connected to api.eu.mailgun.net (34.95.107.114) port 443 (#0)
* ALPN, offering h2
* ALPN, offering http/1.1
* successfully set certificate verify locations:
*  CAfile: /etc/ssl/certs/ca-certificates.crt
*  CApath: /etc/ssl/certs
* TLSv1.3 (OUT), TLS handshake, Client hello (1):
* OpenSSL SSL_connect: SSL_ERROR_SYSCALL in connection to api.eu.mailgun.net:443 
* Closing connection 0
curl: (35) OpenSSL SSL_connect: SSL_ERROR_SYSCALL in connection to api.eu.mailgun.net:443

sslscan命令输出:

sslscan https://api.eu.mailgun.net
Version: 2.0.7
OpenSSL 1.1.1n  15 Mar 2022

Connected to 34.95.107.114

Testing SSL server api.eu.mailgun.net on port 443 using SNI name api.eu.mailgun.net

  SSL/TLS Protocols:
SSLv2     disabled
SSLv3     disabled
TLSv1.0   disabled
TLSv1.1   disabled
TLSv1.2   disabled
TLSv1.3   disabled

  TLS Fallback SCSV:
Connection failed - unable to determine TLS Fallback SCSV support

  TLS renegotiation:
Session renegotiation not supported

  TLS Compression:
OpenSSL version does not support compression
Rebuild with zlib1g-dev package for zlib support

  Heartbleed:

  Supported Server Cipher(s):
Certificate information cannot be retrieved.

已知信息:服务器时间已同步,系统为Debian 11,恢复了数月前的云快照。


排查与解决步骤

1. 更新系统CA证书

旧快照的CA证书库可能过期,执行以下命令强制更新:

apt update && apt install --reinstall ca-certificates
update-ca-certificates -f

2. 重置OpenSSL配置

检查是否存在异常的OpenSSL全局配置,重置为默认状态:

cp /etc/ssl/openssl.cnf /etc/ssl/openssl.cnf.bak
apt install --reinstall openssl

3. 排查网络拦截

  • 测试访问其他HTTPS站点(如https://google.com),确认是否为全局网络问题
  • 检查防火墙规则,排除出站443端口拦截:
ufw status
iptables -L -n
  • 联系Hetzner支持,确认云平台层面是否存在流量限制或路由异常

4. 强制指定TLS版本测试

尝试指定具体TLS版本发起请求,排查协议协商问题:

curl --verbose --tlsv1.2 https://api.eu.mailgun.net
curl --verbose --tlsv1.3 https://api.eu.mailgun.net

5. 验证DNS解析

确认域名解析IP是否正确,必要时更换DNS服务器:

dig api.eu.mailgun.net
# 若解析异常,临时更换DNS
echo "nameserver 8.8.8.8" > /etc/resolv.conf

6. 升级OpenSSL版本

Debian 11默认OpenSSL版本为1.1.1n,可尝试升级到最新可用版本:

apt update && apt upgrade openssl

内容的提问来源于stack exchange,提问作者Jakub Skąpski

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.17 06:30:35