WSL2/Cygwin中curl请求Wikidata API遇SSL错误的解决办法
解决WSL2和Cygwin中curl访问Wikidata API的SSL连接问题
问题详情
在WSL2环境执行以下命令:
$ curl -v -k "https://www.wikidata.org/w/api.php?action=wbgetentities&format=json&ids=Q111" | > jq .
出现SSL握手错误:
% Total % Received % Xferd Average Speed Time Time Time Current Dload Upload Total Spent Left Speed 0 0 0 0 0 0 0 0 --:--:-- --:--:-- --:--:-- 0* Trying 103.102.166.224:443... * Connected to www.wikidata.org (103.102.166.224) port 443 (#0) 0 0 0 0 0 0 0 0 --:--:-- --:--:-- --:--:-- 0* ALPN, offering h2 * ALPN, offering http/1.1 * CAfile: /etc/ssl/certs/ca-certificates.crt * CApath: /etc/ssl/certs * TLSv1.0 (OUT), TLS header, Certificate Status (22): } [5 bytes data] * TLSv1.3 (OUT), TLS handshake, Client hello (1): } [512 bytes data] 0 0 0 0 0 0 0 0 --:--:-- 0:01:59 --:--:-- 0* TLSv1.0 (OUT), TLS header, Unknown (21): } [5 bytes data] * TLSv1.3 (OUT), TLS alert, decode error (562): } [2 bytes data] * error:0A000126:SSL routines::unexpected eof while reading 0 0 0 0 0 0 0 0 --:--:-- 0:02:00 --:--:-- 0 * Closing connection 0 curl: (35) error:0A000126:SSL routines::unexpected eof while reading
已执行sudo apt update和sudo apt upgrade,当前curl版本:
curl 7.81.0 (x86_64-pc-linux-gnu) libcurl/7.81.0 OpenSSL/3.0.2 zlib/1.2.11 brotli/1.0.9 zstd/1.4.8 libidn2/2.3.2 libpsl/0.21.0 (+libidn2/2.3.2) libssh/0.9.6/openssl/zlib nghttp2/1.43.0 librtmp/2.3 OpenLDAP/2.5.14 Release-Date: 2022-01-05 Protocols: dict file ftp ftps gopher gophers http https imap imaps ldap ldaps mqtt pop3 pop3s rtmp rtsp scp sftp smb smbs smtp smtps telnet tftp Features: alt-svc AsynchDNS brotli GSS-API HSTS HTTP2 HTTPS-proxy IDN IPv6 Kerberos Largefile libz NTLM NTLM_WB PSL SPNEGO SSL TLS-SRP UnixSockets zstd
在Cygwin环境执行相同命令时出现连接重置错误:
% Total % Received % Xferd Average Speed Time Time Time Current Dload Upload Total Spent Left Speed 0 0 0 0 0 0 0 0 --:--:-- --:--:-- --:--:-- 0* Trying 103.102.166.224:443... * Connected to www.wikidata.org (103.102.166.224) port 443 (#0) * schannel: disabled automatic use of client certificate * ALPN: offers http/1.1 0 0 0 0 0 0 0 0 --:--:-- 0:00:19 --:--:-- 0* Recv failure: Connection was reset * schannel: failed to receive handshake, SSL/TLS connection failed 0 0 0 0 0 0 0 0 --:--:-- 0:00:19 --:--:-- 0 * Closing connection 0 * schannel: shutting down SSL/TLS connection with www.wikidata.org port 443 * Send failure: Connection was reset * schannel: failed to send close msg: Failed sending data to the peer (bytes written: -1) curl: (35) Recv failure: Connection was reset
解决方法
排查网络基础问题
- 先测试访问其他HTTPS站点(比如
curl https://example.com),确认网络本身能正常建立SSL连接 - 临时关闭Windows防火墙,测试是否是防火墙拦截了出站请求
- 检查是否配置了代理,若有,确保
http_proxy和https_proxy环境变量指向正确的代理地址,或者临时取消代理测试
- 先测试访问其他HTTPS站点(比如
强制指定TLS版本
部分服务器对TLS 1.3的兼容性存在问题,尝试强制使用TLS 1.2:- WSL2执行:
curl -v -k --tlsv1.2 "https://www.wikidata.org/w/api.php?action=wbgetentities&format=json&ids=Q111" | jq . - Cygwin执行:
curl -v -k --tlsv1.2 "https://www.wikidata.org/w/api.php?action=wbgetentities&format=json&ids=Q111"
- WSL2执行:
更换DNS服务器
错误可能是DNS解析异常导致的,尝试更换公共DNS:- WSL2中编辑
/etc/resolv.conf,添加nameserver 8.8.8.8,注释掉原有nameserver条目 - Cygwin中直接修改Windows系统的DNS设置为8.8.8.8或1.1.1.1
- WSL2中编辑
更新curl和OpenSSL(仅WSL2)
尽管已执行升级,仍可尝试手动重新安装最新版本:sudo apt install --only-upgrade curl openssl
内容的提问来源于stack exchange,提问作者Auly
相关产品推荐
相关产品推荐

