cURL调用Shop-ware API遇SSL冲突及401错误,求排查方向
SSL证书冲突与401授权错误排查
问题描述
我在DigitalOcean的Ubuntu 20.04.2 LTS服务器上,用cURL调用Shop-ware API的HTTPv1版本,沙箱测试地址为http://165.227.5.96/customer_create_test.php,调用时收到错误:
"There is conflicting information between the SSL connection, its certificate and/or the included HTTP requests."
已删除本地Digicert等SSL证书,移除API密钥后的调用代码如下:
// Set post field varaibles from form post from the checkin forms 'New Customer' $post = [ 'first_name' => 'John', 'last_name' => 'Doe', 'email' => 'john@doe.com', 'phones[number]' => '+18880003333', 'phones[label]' => 'cell', 'phones[perferred]' => 'true', 'detail' => 'test customer 1', 'address' => '300 H Street', 'city' => 'Vegas', 'state' => 'NV', 'zip' => '81911', 'marketing_ok' => '1' ]; //Initate cURL to POST to the New Customer to the endpoint -> /api/v1/tenants/1/customers $ch = curl_init(); //curl_setopt($ch, CURLOPT_URL,"https://api.shop-ware.com/api/v1/tenants/1/customers"); //live endpoint curl_setopt($ch, CURLOPT_URL,"https://api.shop-ware-api-sandbox.com/api/v1/tenants/1/customers"); //sandbox endpoint curl_setopt($ch, CURLOPT_POST, 1); //Post true 1 false 0 curl_setopt($ch, CURLOPT_POSTFIELDS,$post); //Post array curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); //Accept response //Headers required by Shopware $headers = [ 'Content-Type: application/json', 'Accept: application/json', 'X-Api-Partner-Id: id-here', 'X-Api-Secret: key-here', 'Host: http://165.227.5.96/customer_create_test.php' ]; //Set HTTP headers required by Shopware curl_setopt($ch, CURLOPT_HTTPHEADER, $headers); //Get response from Shopware $shopware_output = curl_exec ($ch); //Close cURL connection with Shopware curl_close ($ch); //Display response var_dump($shopware_output);
终端执行curl命令得到的关键响应片段:
* SSL connection using TLSv1.3 / TLS_AES_128_GCM_SHA256 * ALPN, server did not agree to a protocol * Mark bundle as not supporting multiuse < HTTP/1.1 401 Unauthorized < Server: Cowboy
想请教该问题源于我的DigitalOcean服务器,还是API提供商的Heroku服务器?
问题根源与修复建议
1. 核心问题出在请求配置,而非服务器本身
- Host头配置错误:你设置的
Host头是http://165.227.5.96/customer_create_test.php,但实际请求的API域名是api.shop-ware-api-sandbox.com。Host头必须匹配请求的域名,不能带路径或http前缀,正确格式应为api.shop-ware-api-sandbox.com。这个错误直接导致SSL连接的域名与HTTP头中的Host不匹配,触发证书冲突提示。 - POST数据格式不匹配:你声明了
Content-Type: application/json,但直接传递PHP数组作为POSTFIELDS,cURL会默认将数组编码为application/x-www-form-urlencoded格式,导致API无法解析请求内容,间接引发授权验证失败(401)。 - API密钥缺失:你移除了
X-Api-Partner-Id和X-Api-Secret的真实值,这必然触发401 Unauthorized错误,因为API无法验证你的身份。
2. 服务器层面的影响
DigitalOcean服务器本身无问题,删除本地SSL证书不会影响对外部API的调用(cURL默认使用系统根证书验证服务器证书)。Heroku服务器的Server: Cowboy是正常的应用服务器标识,401错误是身份验证失败,而非Heroku的证书问题。
修复步骤
- 修正Host头:将
Host: http://165.227.5.96/customer_create_test.php改为Host: api.shop-ware-api-sandbox.com。 - 正确编码POST数据:将PHP数组转为JSON字符串,设置
CURLOPT_POSTFIELDS为JSON内容:curl_setopt($ch, CURLOPT_POSTFIELDS, json_encode($post)); - 恢复真实的
X-Api-Partner-Id和X-Api-Secret值,确保API能验证身份。 - 可选:确认cURL的SSL验证选项(默认开启,若之前禁用过需恢复):
curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, true); curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 2);
内容的提问来源于stack exchange,提问作者themeowman
相关产品推荐
相关产品推荐

