Ubuntu 22.04下如何正确编译搭配OpenSSL 1.1.1的PHP 7.4.33
自定义路径编译PHP 7.4.33(Ubuntu 22.04)SSL兼容问题
Ubuntu 22.04默认预装OpenSSL 3,该版本与PHP 7.4.33不兼容。在自定义路径下编译带SSL支持的PHP 7.4.33后,使用PHP的SSL功能(如执行file_get_contents("https://google.com");)会触发SSL operation failed错误。需在自定义路径下完成编译,无法采用Docker/容器方案。
尝试的最简编译步骤
# 安装OpenSSL wget https://www.openssl.org/source/openssl-1.1.1s.tar.gz; tar xvf openssl-1.1.1s.tar.gz; cd openssl-1.1.1s/; ./Configure --prefix=/opt/build --openssldir=/opt/build -fPIC -shared linux-x86_64 -Wl,--enable-new-dtags,-rpath,'$(LIBRPATH)'; make -j 8 && make install; cd ../; # 安装PHP wget https://www.php.net/distributions/php-7.4.33.tar.gz; tar xf php-7.4.33.tar.gz; cd php-7.4.33/; export PKG_CONFIG_PATH=/opt/build/lib/pkgconfig; ./buildconf --force; ./configure --prefix=/opt/php \ --with-curl \ --with-openssl=/opt/build \ --with-openssl-dir=/opt/build; make -j 8 && make install;
执行PHP SSL功能的错误信息
root@ubuntu2204:~/php-7.4.33# /opt/php/bin/php -r 'echo file_get_contents("https://google.com");' Warning: file_get_contents(): SSL operation failed with code 1. OpenSSL Error messages: error:1416F086:SSL routines:tls_process_server_certificate:certificate verify failed in Command line code on line 1 Warning: file_get_contents(): Failed to enable crypto in Command line code on line 1 Warning: file_get_contents(https://google.com): failed to open stream: operation failed in Command line code on line 1
Make执行时的警告
/usr/bin/ld: warning: libssl.so.3, needed by /usr/lib/gcc/x86_64-linux-gnu/11/../../../x86_64-linux-gnu/libcurl.so, may conflict with libssl.so.1.1 /usr/bin/ld: warning: libcrypto.so.3, needed by /usr/lib/gcc/x86_64-linux-gnu/11/../../../x86_64-linux-gnu/libcurl.so, may conflict with libcrypto.so.1.1 /usr/bin/ld: warning: libssl.so.3, needed by /usr/lib/gcc/x86_64-linux-gnu/11/../../../x86_64-linux-gnu/libcurl.so, may conflict with libssl.so.1.1 /usr/bin/ld: warning: libcrypto.so.3, needed by /usr/lib/gcc/x86_64-linux-gnu/11/../../../x86_64-linux-gnu/libcurl.so, may conflict with libcrypto.so.1.1 /usr/bin/ld: warning: libssl.so.3, needed by /usr/lib/gcc/x86_64-linux-gnu/11/../../../x86_64-linux-gnu/libcurl.so, may conflict with libssl.so.1.1 /usr/bin/ld: warning: libcrypto.so.3, needed by /usr/lib/gcc/x86_64-linux-gnu/11/../../../x86_64-linux-gnu/libcurl.so, may conflict with libcrypto.so.1.1
PHP检测到的OpenSSL版本
root@ubuntu2204:~/php-7.4.33# /opt/php/bin/php -i | grep OpenSSL SSL Version => OpenSSL/3.0.2 OpenSSL support => enabled OpenSSL Library Version => OpenSSL 1.1.1s 1 Nov 2022 OpenSSL Header Version => OpenSSL 1.1.1s 1 Nov 2022 OpenSSL support => enabled
尝试编译Curl的额外步骤(仍报错)
# 安装OpenSSL wget https://www.openssl.org/source/openssl-1.1.1s.tar.gz; tar xvf openssl-1.1.1s.tar.gz; cd openssl-1.1.1s/; ./Configure --prefix=/opt/build --openssldir=/opt/build -fPIC -shared linux-x86_64 -Wl,--enable-new-dtags,-rpath,'/opt/build/lib'; make -j 8 && make install; cd ../; export CFLAGS="-I/opt/build/include/ -L/opt/build/lib -Wl,-rpath,/opt/build/lib -lssl -lcrypto" export CXXFLAGS="-I/opt/build/include/ -L/opt/build/lib -Wl,-rpath,/opt/build/lib -lssl -lcrypto" # 安装Curl wget http://curl.haxx.se/download/curl-7.58.0.tar.bz2 tar -xvjf curl-7.58.0.tar.bz2 cd curl-7.58.0 export PKG_CONFIG_PATH=/opt/build/lib/pkgconfig; export LD_LIBRARY_PATH=/opt/build/lib; ./buildconf ./configure --prefix=/opt/build --with-ssl=/opt/build make -j 8 && make install; cd ../; # 安装PHP wget https://www.php.net/distributions/php-7.4.33.tar.gz; tar xf php-7.4.33.tar.gz; cd php-7.4.33/; export PKG_CONFIG_PATH=/opt/build/lib/pkgconfig; export LD_LIBRARY_PATH=/opt/build/lib; ./buildconf --force; PKG_CONFIG_PATH=/opt/build/lib/pkgconfig ./configure --prefix=/opt/php \ --with-curl=/opt/build \ --with-openssl=/opt/build --with-libdir=/opt/build/lib; make -j 8 && make install;
内容的提问来源于stack exchange,提问作者Matt
相关产品推荐
相关产品推荐

