You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Debian系统下CURL报SSL证书过期错误的解决求助

解决CURL SSL证书过期问题(已续签证书仍报错)

1. 更新系统根CA证书 bundle

Debian系统默认依赖ca-certificates包提供的根证书集合,可能是根证书过期导致验证失败,而非目标站点证书问题:

sudo apt update && sudo apt install --reinstall ca-certificates
sudo update-ca-certificates

2. 验证目标站点证书实际状态

用openssl直接检查目标域名的证书有效期,排除本地缓存干扰:

openssl s_client -connect hooks.slack.com:443 | openssl x509 -noout -dates

查看输出的notBefore(生效时间)和notAfter(过期时间),确认证书是否真的有效。如果这里显示证书正常,问题必然在本地CA配置。

3. 强制curl使用更新后的CA证书

若系统更新后curl仍报错,手动指定CA证书路径执行命令:

curl --cacert /etc/ssl/certs/ca-certificates.crt --location 'https://hooks.slack.com/services///' --header 'Content-Type: text/plain' --data '{"channel": "#team-it", "text": "Hello, world"}'

4. 检查并配置PHP的CURL证书路径

PHP的curl组件可能不使用系统默认CA证书,需单独配置:

  1. 查看当前PHP curl的CA配置:
php -i | grep curl.cainfo
  1. 若输出为空,编辑php.ini文件(路径通常为/etc/php/[版本]/fpm/php.ini或/etc/php/[版本]/cli/php.ini),添加或修改:
curl.cainfo = "/etc/ssl/certs/ca-certificates.crt"
  1. 重启PHP-FPM或web服务器(如Nginx/Apache)。

5. 清除本地DNS缓存

DNS缓存可能指向旧服务器节点,导致获取过期证书:

sudo systemctl restart systemd-resolved

(若使用其他DNS服务,如dnsmasq,替换为对应重启命令)

内容的提问来源于stack exchange,提问作者FlechMe

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.28 05:42:20