生产环境PHPMailer发送邮件遇SSL证书验证失败问题求助
生产服务器PHPMailer发送邮件SSL证书验证失败故障解决
故障现象
EMAIL ERROR: phpmailer error:SMTP Error: Could not connect to SMTP host. Connection failed. stream_socket_enable_crypto(): SSL operation failed with code 1. OpenSSL Error messages: error:0A000086:SSL routines::certificate verify failed
- 同配置(Ubuntu、Apache、OpenSSL、PHP版本匹配)的本地开发机及其他服务器可正常发送邮件,仅目标生产服务器异常
- 执行测试命令
echo QUIT | openssl s_client -crlf -starttls smtp -connect cwh5.canadianwebhosting.com:587,结果显示无法获取本地颁发者证书 - 使用PHPMailer的phplist也出现相同问题
- 临时关闭证书验证可解决问题,但不符合生产环境安全要求;修改加密方法无效
服务器配置
- 系统:Ubuntu 22.04
- Web服务:Apache 2.4.52
- OpenSSL:3.0.2
- PHP:8.1.2
- PHPMailer:6.7.1
问题触发时机
服务器因磁盘耗尽崩溃重启后,执行apt update(疑似包含PHP小版本更新)当天出现故障
测试用PHPMailer代码
$phpmailer->isSMTP(); $phpmailer->SMTPDebug = 2; $phpmailer->SMTPAuth = true; $phpmailer->SMTPSecure = "tls"; $phpmailer->Port = 587; $phpmailer->Host = "cwh5.canadianwebhosting.com"; $phpmailer->Username = config::get('email_user'); $phpmailer->Password = config::get('email_pass'); $phpmailer->setFrom("info@mydomain.com", $_SERVER['SERVER_NAME']); $phpmailer->addAddress("info@mydomain.com", "me"); $phpmailer->Body = "test email from $_SERVER[SERVER_NAME]"; $phpmailer->Subject = "phpmailer test"; $phpmailer->send();
安全有效解决步骤
1. 修复系统根证书完整性
磁盘耗尽可能导致根证书文件损坏或丢失,重新安装并更新证书:
sudo apt install --reinstall ca-certificates sudo update-ca-certificates
2. 校准PHP的SSL证书配置
检查PHP是否正确指向系统根证书:
- 查看当前PHP SSL配置:
php -i | grep -E "openssl.cafile|openssl.capath"
- 若输出为空或路径错误,编辑对应PHP版本的ini文件(如
/etc/php/8.1/apache2/php.ini),添加或修改:
openssl.cafile = /etc/ssl/certs/ca-certificates.crt openssl.capath = /etc/ssl/certs/
- 重启Apache使配置生效:
sudo systemctl restart apache2
3. 验证修复结果
重新执行openssl测试命令,确认输出中包含Verify return code: 0 (ok),再测试PHPMailer邮件发送功能。
4. 排查PHP更新的配置变更
若上述步骤无效,检查apt update是否覆盖了PHP配置文件:
ls -la /etc/php/8.1/apache2/ | grep .dpkg-dist
对比原配置文件与.dpkg-dist备份文件的差异,恢复证书相关配置项。
内容的提问来源于stack exchange,提问作者SuprMan
相关产品推荐
相关产品推荐

