You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

OpenSSL 3.1.0启用FIPS后出现EE Certificate key too weak错误

启用FIPS的OpenSSL 3.1.0出站连接失败(EE certificate too weak error)

我通过脚本编译安装了启用FIPS的OpenSSL 3.1.0,安装成功且可正常运行,但启用FIPS后无法建立任何出站连接,出现EE certificate key too weak error。

编译安装脚本

wget https://www.openssl.org/source/openssl-3.1.0.tar.gz 
    && tar zxvf openssl-3.1.0.tar.gz 
    && cd openssl-3.1.0 
    && CFLAGS=-fPIC ./config enable-fips --prefix=/usr/local/openssl --openssldir=/usr/local/openssl 
    && make 
    && make test 
    && make install 
    && bash -c "echo '/usr/local/openssl/lib64' >> /etc/ld.so.conf" 
    && ldconfig

版本信息

openssl version
OpenSSL 3.1.0 14 Mar 2023 (Library: OpenSSL 3.1.0 14 Mar 2023)

FIPS启用配置

.include /usr/local/openssl/fipsmodule.cnf

..
..
..

# List of providers to load
[provider_sect]
default = default_sect

# The fips section name should match the section name inside the
# included fipsmodule.cnf.
fips = fips_sect

FIPS启用验证

openssl md5 <file_path>
Error setting digest
40C7F61E7D7F0000:error:0308010C:digital envelope routines:(unknown function):unsupported:crypto/evp/evp_fetch.c:341:Global default library context, Algorithm (MD5 : 100), Properties ()
40C7F61E7D7F0000:error:03000086:digital envelope routines:(unknown function):initialization error:crypto/evp/digest.c:272:
# 
# 
openssl sha256 <file_path>
SHA2-256(openssl)= 49c16340d51eba8d2c31dbe569ad1f686fef571a0a7c9a4545a85c22d4650259
[root@centos7 bin]# 

出站连接错误示例

openssl s_client -connect google.com:443

CONNECTED(00000003)
depth=0 CN = *.google.com
verify error:num=66:EE certificate key too weak
verify return:1
depth=0 CN = *.google.com
verify error:num=66:EE certificate key too weak
verify return:1
40D7CF19B37F0000:error:03000072:digital envelope routines:(unknown function):decode error:crypto/x509/x_pubkey.c:458:
40D7CF19B37F0000:error:0A0000EF:SSL routines:(unknown function):unable to find public key parameters:ssl/statem/statem_clnt.c:1905:
---
Certificate chain
 0 s:CN = *.google.com
   i:C = US, O = Google Trust Services LLC, CN = GTS CA 1C3
   v:NotBefore: Mar 28 16:47:33 2023 GMT; NotAfter: Jun 20 16:47:32 2023 GMT
 1 s:C = US, O = Google Trust Services LLC, CN = GTS CA 1C3
   i:C = US, O = Google Trust Services LLC, CN = GTS Root R1
   v:NotBefore: Aug 13 00:00:42 2020 GMT; NotAfter: Sep 30 00:00:42 2027 GMT
 2 s:C = US, O = Google Trust Services LLC, CN = GTS Root R1
   i:C = BE, O = GlobalSign nv-sa, OU = Root CA, CN = GlobalSign Root CA
   v:NotBefore: Jun 19 00:00:42 2020 GMT; NotAfter: Jan 28 00:00:42 2028 GMT
---
no peer certificate available
---
No client certificate CA names sent
Server Temp Key: X25519, 253 bits
---
SSL handshake has read 6777 bytes and written 311 bytes
Verification error: EE certificate key too weak
---
New, TLSv1.3, Cipher is TLS_AES_256_GCM_SHA384
This TLS version forbids renegotiation.
Compression: NONE
Expansion: NONE
No ALPN negotiated
Early data was not sent
Verify return code: 66 (EE certificate key too weak)
---

解决方案

这个错误是因为FIPS模式下,OpenSSL默认密钥强度验证规则拒绝了X25519这类未被FIPS模块标记为允许的曲线密钥,导致握手时判定为"密钥太弱"。以下是几种解决方法:

方法1:修改OpenSSL配置允许合规曲线

编辑OpenSSL主配置文件(/usr/local/openssl/openssl.cnf),在[provider_sect]后添加FIPS模块的曲线允许规则:

[fips_sect]
activate = 1
ssl_curve_list = X25519:P-256:P-384:P-521

或者直接修改/usr/local/openssl/fipsmodule.cnf的策略部分:

[fips_sect]
policy = fips_policy

[fips_policy]
EC = X25519,P-256,P-384,P-521

方法2:重新编译OpenSSL时启用合规曲线支持

清理原有编译文件后,重新编译并启用相关参数:

cd openssl-3.1.0
make clean
CFLAGS=-fPIC ./config enable-fips enable-ec_nistp_64_gcc_128 --prefix=/usr/local/openssl --openssldir=/usr/local/openssl
make && make test && make install
ldconfig

方法3:临时指定合规曲线测试(不推荐生产环境)

连接时手动指定符合FIPS要求的曲线:

openssl s_client -connect google.com:443 -curves P-256

修改完成后重新运行连接命令,即可正常建立连接。

内容的提问来源于stack exchange,提问作者user1919581

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.24 09:22:03