You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

cURL调用Shop-ware API遇SSL冲突及401错误,求排查方向

SSL证书冲突与401授权错误排查

问题描述

我在DigitalOcean的Ubuntu 20.04.2 LTS服务器上,用cURL调用Shop-ware API的HTTPv1版本,沙箱测试地址为http://165.227.5.96/customer_create_test.php,调用时收到错误:

"There is conflicting information between the SSL connection, its certificate and/or the included HTTP requests."

已删除本地Digicert等SSL证书,移除API密钥后的调用代码如下:

// Set post field varaibles from form post from the checkin forms 'New Customer'
$post = [
'first_name' => 'John',
'last_name' => 'Doe',
'email' => 'john@doe.com',
'phones[number]' => '+18880003333',
'phones[label]' => 'cell',
'phones[perferred]' => 'true',
'detail' => 'test customer 1',
'address' => '300 H Street',
'city' => 'Vegas',
'state' => 'NV',
'zip' => '81911',
'marketing_ok' => '1'
];

//Initate cURL to POST to the New Customer to the endpoint -> /api/v1/tenants/1/customers
$ch = curl_init();
//curl_setopt($ch, CURLOPT_URL,"https://api.shop-ware.com/api/v1/tenants/1/customers"); //live endpoint
curl_setopt($ch, CURLOPT_URL,"https://api.shop-ware-api-sandbox.com/api/v1/tenants/1/customers"); //sandbox endpoint
curl_setopt($ch, CURLOPT_POST, 1); //Post true 1 false 0
curl_setopt($ch, CURLOPT_POSTFIELDS,$post);  //Post array
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); //Accept response

//Headers required by Shopware
$headers = [
'Content-Type: application/json',
'Accept: application/json',
'X-Api-Partner-Id: id-here',
'X-Api-Secret: key-here',
'Host: http://165.227.5.96/customer_create_test.php'

];

//Set HTTP headers required by Shopware
curl_setopt($ch, CURLOPT_HTTPHEADER, $headers);

//Get response from Shopware
$shopware_output = curl_exec ($ch);

//Close cURL connection with Shopware
curl_close ($ch);

//Display response
var_dump($shopware_output);

终端执行curl命令得到的关键响应片段:

* SSL connection using TLSv1.3 / TLS_AES_128_GCM_SHA256
* ALPN, server did not agree to a protocol

* Mark bundle as not supporting multiuse
< HTTP/1.1 401 Unauthorized
< Server: Cowboy

想请教该问题源于我的DigitalOcean服务器,还是API提供商的Heroku服务器?


问题根源与修复建议

1. 核心问题出在请求配置,而非服务器本身

  • Host头配置错误:你设置的Host头是http://165.227.5.96/customer_create_test.php,但实际请求的API域名是api.shop-ware-api-sandbox.com。Host头必须匹配请求的域名,不能带路径或http前缀,正确格式应为api.shop-ware-api-sandbox.com。这个错误直接导致SSL连接的域名与HTTP头中的Host不匹配,触发证书冲突提示。
  • POST数据格式不匹配:你声明了Content-Type: application/json,但直接传递PHP数组作为POSTFIELDS,cURL会默认将数组编码为application/x-www-form-urlencoded格式,导致API无法解析请求内容,间接引发授权验证失败(401)。
  • API密钥缺失:你移除了X-Api-Partner-Id和X-Api-Secret的真实值,这必然触发401 Unauthorized错误,因为API无法验证你的身份。

2. 服务器层面的影响

DigitalOcean服务器本身无问题,删除本地SSL证书不会影响对外部API的调用(cURL默认使用系统根证书验证服务器证书)。Heroku服务器的Server: Cowboy是正常的应用服务器标识,401错误是身份验证失败,而非Heroku的证书问题。

修复步骤

  • 修正Host头:将Host: http://165.227.5.96/customer_create_test.php改为Host: api.shop-ware-api-sandbox.com。
  • 正确编码POST数据:将PHP数组转为JSON字符串,设置CURLOPT_POSTFIELDS为JSON内容:
    curl_setopt($ch, CURLOPT_POSTFIELDS, json_encode($post));
    
  • 恢复真实的X-Api-Partner-Id和X-Api-Secret值,确保API能验证身份。
  • 可选:确认cURL的SSL验证选项(默认开启,若之前禁用过需恢复):
    curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, true);
    curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 2);
    

内容的提问来源于stack exchange,提问作者themeowman

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.13 08:40:27