VPN环境下Curl请求SSL证书验证失败问题求助
解决VPN环境下curl访问golang.org的SSL证书问题
方案一:基于OpenSSL后端(推荐)
你已切换到OpenSSL后端,且持有公司CA证书,只需让curl信任该证书即可:
临时生效:命令行指定CA证书
在curl命令中添加--cacert参数,指向你的公司CA证书路径:curl -v --cacert "C:/path/to/your/company-ca.pem" https://golang.org/dl/?mode=json替换路径为你实际的证书文件位置(Git Bash中也可使用相对路径)。
永久生效:配置curl全局使用CA证书
- 在Git Bash中创建或编辑
~/.curlrc文件:nano ~/.curlrc - 添加以下内容并保存:
cacert = "C:/path/to/your/company-ca.pem"
后续所有curl请求都会自动加载该CA证书完成验证。
- 在Git Bash中创建或编辑
方案二:基于Schannel后端(Windows原生)
若想换回Schannel后端,解决证书吊销检查失败问题:
临时关闭吊销检查
在curl命令中添加--ssl-no-revoke参数:curl -v --ssl-no-revoke https://golang.org/dl/?mode=json永久解决:导入CA证书到Windows系统信任库
- 右键点击公司CA证书文件,选择「安装证书」
- 选择「本地计算机」,点击「下一步」
- 选择「将所有证书放入下列存储」,点击「浏览」,选择「受信任的根证书颁发机构」
- 完成导入后,Schannel会自动信任该CA,同时解决吊销检查失败问题。
问题详情
我查阅了大量相关博客,但所有临时解决方案/修复方法都无法解决我的问题。
我使用如下curl命令进行请求:
curl -v https://golang.org/dl/?mode=json * Trying 142.250.80.113:443... * Connected to golang.org (142.250.80.113) port 443 (#0) * schannel: disabled automatic use of client certificate * ALPN: offers http/1.1 * schannel: next InitializeSecurityContext failed: Unknown error (0x80092012) - The revocation function was unable to check revocation for the certificate. * Closing connection 0 curl: (35) schannel: next InitializeSecurityContext failed: Unknown error (0x80092012) - The revocation function was unable to check revocation for the certificate.
我通过以下命令修改Git Bash(Windows)的设置以使用OpenSSL:
git config --global http.sslBackend "openssl"
切换到OpenSSL后,我遇到了如下错误:
$ curl -v https://golang.org/dl/?mode=json * Trying 172.253.62.141:443... * Connected to golang.org (172.253.62.141) port 443 (#0) * ALPN, offering h2 * ALPN, offering http/1.1 * CAfile: C:/Program Files/Git/mingw64/ssl/certs/ca-bundle.crt * CApath: C:\Users\xxxxxxx * TLSv1.3 (OUT), TLS handshake, Client hello (1): * TLSv1.3 (IN), TLS handshake, Server hello (2): * TLSv1.2 (IN), TLS handshake, Certificate (11): * TLSv1.2 (OUT), TLS alert, unknown CA (560): * SSL certificate problem: self signed certificate in certificate chain * Closing connection 0 curl: (60) SSL certificate problem: self signed certificate in certificate chain curl failed to verify the legitimacy of the server and therefore could not establish a secure connection to it.
我持有公司提供的CA证书/PEM文件,仅在连接VPN时会出现上述错误(VPN为必填连接),断开VPN后请求正常。
内容的提问来源于stack exchange,提问作者thulasi39
相关产品推荐
相关产品推荐

