Axios发送POST请求出现EPROTO SSL错误求助
问题描述
向土耳其电子发票平台端点发送POST请求时,触发AxiosError错误,错误码为EPROTO C0D7BC0EAE7F0000,核心错误提示为SSL routines:final_renegotiate:unsafe legacy renegotiation disabled。
请求代码
const config = { headers: { accept: "*/*", "accept-language": "tr,en-US;q=0.9,en;q=0.8", "cache-control": "no-cache", "content-type": "application/x-www-form-urlencoded;charset=UTF-8", pragma: "no-cache", "sec-fetch-mode": "cors", "sec-fetch-site": "same-origin", }, }; const url = process.env.MODE === "TEST" ? "https://earsivportaltest.efatura.gov.tr/earsiv-services/assos-login" : "https://earsivportal.efatura.gov.tr/earsiv-services/assos-login"; const assoscmd = process.env.MODE === "TEST" ? "login" : "anologin"; const response = await axios.post( `${url}`, { assoscmd: assoscmd, userid: userId, sifre: password, sifre2: password, parola: 1, }, config ); return response.data;
完整错误信息
AxiosError: write EPROTO C0D7BC0EAE7F0000:error:0A000152:SSL routines:final_renegotiate:unsafe legacy renegotiation disabled:../deps/openssl/openssl/ssl/statem/extensions.c:922: at AxiosError.from (/mnt/D/Yedekler/30 Aralık/Belgeler/fatura/node_modules/axios/dist/node/axios.cjs:789:14) at RedirectableRequest.handleRequestError (/mnt/D/Yedekler/30 Aralık/Belgeler/fatura/node_modules/axios/dist/node/axios.cjs:2744:25) at RedirectableRequest.emit (node:events:513:28) at eventHandlers.<computed> (/mnt/D/Yedekler/30 Aralık/Belgeler/fatura/node_modules/follow-redirects/index.js:14:24) at ClientRequest.emit (node:events:513:28) at TLSSocket.socketErrorListener (node:_http_client:494:9) at TLSSocket.emit (node:events:513:28) at emitErrorNT (node:internal/streams/destroy:151:8) at emitErrorCloseNT (node:internal/streams/destroy:116:3) at process.processTicksAndRejections (node:internal/process/task_queues:82:21) { syscall: 'write', code: 'EPROTO', errno: -71,
解决方法
该错误源于Node.js v18+版本默认禁用了不安全的旧版SSL重协商机制,而目标服务器仍采用旧版SSL/TLS配置,导致握手失败。以下是两种可行解决方案:
方法1:修改Axios配置,单独允许目标服务器的旧版重协商
在Axios请求配置中添加自定义HTTPS代理,指定允许旧版SSL连接的规则:
const axios = require('axios'); const https = require('https'); const constants = require('constants'); // 创建自定义HTTPS代理 const legacySslAgent = new https.Agent({ secureOptions: constants.SSL_OP_LEGACY_SERVER_CONNECT }); const config = { headers: { accept: "*/*", "accept-language": "tr,en-US;q=0.9,en;q=0.8", "cache-control": "no-cache", "content-type": "application/x-www-form-urlencoded;charset=UTF-8", pragma: "no-cache", "sec-fetch-mode": "cors", "sec-fetch-site": "same-origin", }, // 绑定自定义代理到请求配置 httpsAgent: legacySslAgent }; // 后续请求代码保持不变 const url = process.env.MODE === "TEST" ? "https://earsivportaltest.efatura.gov.tr/earsiv-services/assos-login" : "https://earsivportal.efatura.gov.tr/earsiv-services/assos-login"; const assoscmd = process.env.MODE === "TEST" ? "login" : "anologin"; const response = await axios.post( `${url}`, { assoscmd: assoscmd, userid: userId, sifre: password, sifre2: password, parola: 1, }, config ); return response.data;
方法2:通过环境变量全局启用旧版SSL规则(仅测试环境用)
若不想修改代码,可在启动Node.js应用时设置环境变量,强制OpenSSL允许旧版重协商:
NODE_OPTIONS=--openssl-legacy-provider node your-app.js
注意:此方法会全局降低应用的SSL安全性,仅建议在测试环境临时使用。
额外提示
- 先确认目标服务器的SSL证书是否有效,证书异常也可能引发类似SSL错误。
- 上述配置兼容Axios v1.x版本,若使用v0.x版本,仅需调整模块导入逻辑即可。
内容的提问来源于stack exchange,提问作者ugurgunes
相关产品推荐
相关产品推荐

