You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

MacOS部署Ruby项目遭遇OpenSSL证书验证问题求助

解决MacOS上Ruby项目部署的SSL证书验证错误

问题分析

你遇到的certificate verify failed (Host mismatch)错误,本质是Ruby编译时绑定的OpenSSL版本和当前系统使用的OpenSSL3不兼容,加上.zshrc配置存在语法错误,导致证书路径和主机名验证逻辑冲突。

修复步骤

1. 修正.zshrc的语法错误

当前配置最后一行存在重复的export,修改为:

export SSL_CERT_DIR=/opt/homebrew/opt/openssl@3/certs
export SSL_CERT_FILE=/opt/homebrew/opt/openssl@3/cert.pem
export PATH="/opt/homebrew/opt/openssl@3/bin:$PATH"

执行source ~/.zshrc加载修正后的配置。

2. 重新安装Ruby,绑定正确的OpenSSL版本

Ruby 3.0.3默认编译时可能使用系统旧版OpenSSL,需要重新指定Homebrew的OpenSSL3路径编译:

# 卸载当前Ruby版本
rvm remove 3.0.3

# 指定OpenSSL路径重新安装
rvm install 3.0.3 --with-openssl-dir=/opt/homebrew/opt/openssl@3

# 设置为默认版本
rvm use 3.0.3 --default

3. 验证Ruby与OpenSSL的绑定

运行以下命令确认Ruby使用的是目标OpenSSL版本:

ruby -r openssl -e 'puts OpenSSL::OPENSSL_VERSION'

输出应为OpenSSL 3.1.0 14 Mar 2023,说明绑定成功。

4. 同步系统根证书到OpenSSL库

将MacOS系统信任的根证书导入Homebrew OpenSSL的证书文件,避免证书链不完整:

sudo security find-certificate -a -p /Library/Keychains/System.keychain > /opt/homebrew/opt/openssl@3/cert.pem
sudo security find-certificate -a -p /System/Library/Keychains/SystemRootCertificates.keychain >> /opt/homebrew/opt/openssl@3/cert.pem

5. 测试SSL连接

运行以下命令测试Ruby的SSL请求是否正常:

ruby -r net/https -e 'Net::HTTP.get(URI("https://rubygems.org"))'

如果没有报错,说明问题已解决。

为什么同事的方案对你无效

同事使用的是系统自带OpenSSL,证书路径为/etc/ssl,而你使用Homebrew安装的OpenSSL3,路径不同;且你的Ruby编译时未绑定当前的OpenSSL3,仅修改环境变量会导致版本不兼容,触发主机名验证错误。

内容的提问来源于stack exchange,提问作者Vlad

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.21 17:17:23