You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何构建代码检测仍支持TLS v1.0协商的服务器?

检测支持TLS 1.0协商的服务器

方法1:Python代码实现

通过强制使用TLS 1.0协议发起连接,判断服务器是否支持该版本协商:

import ssl
import socket

def check_tls10_support(host, port=443, timeout=5):
    # 创建仅支持TLS 1.0的SSL上下文
    context = ssl.SSLContext(ssl.PROTOCOL_TLSv1)
    try:
        # 建立TCP连接并包装SSL层
        with socket.create_connection((host, port), timeout=timeout) as sock:
            with context.wrap_socket(sock, server_hostname=host) as ssock:
                # 握手成功则返回True
                return True
    except (ssl.SSLError, socket.error, TimeoutError):
        # 握手失败或连接超时则返回False
        return False

# 批量检测示例
target_servers = ["server1.example.com", "server2.example.com", "server3.example.com"]
for server in target_servers:
    status = "支持" if check_tls10_support(server) else "不支持"
    print(f"{server}: {status}TLS 1.0协商")

说明:代码通过指定PROTOCOL_TLSv1创建上下文,确保连接仅使用TLS 1.0。若握手成功,说明服务器可与TLS 1.0协商,无论它是否支持更高版本。

方法2:OpenSSL命令行批量检测

无需编写代码时,可利用openssl s_client工具强制指定TLS 1.0版本测试:

单服务器测试

openssl s_client -connect your-server.com:443 -tls1 -servername your-server.com

若输出包含SSL handshake has read X bytes and written Y bytes且无握手错误,说明服务器支持TLS 1.0。

批量检测脚本

#!/bin/bash
# 待检测服务器列表
servers=("server1.example.com" "server2.example.com")

for server in "${servers[@]}"; do
    # 执行检测并过滤结果
    openssl s_client -connect "$server":443 -tls1 -servername "$server" < /dev/null 2>&1 | grep -q "SSL handshake has read"
    if [ $? -eq 0 ]; then
        echo "$server: 支持TLS 1.0协商"
    else
        echo "$server: 不支持TLS 1.0协商"
    fi
done

注意事项

  • 若服务器需要SNI(虚拟主机),必须指定server_hostname(Python)或-servername(OpenSSL)参数,否则握手可能失败。
  • 可根据网络环境调整超时时间,避免无意义的等待。
  • 确保目标服务器的对应端口(默认443)处于开放状态。

内容的提问来源于stack exchange,提问作者Mohsin Khan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.08 10:50:16