You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Python SSL模块TLS连接失败,openssl可正常连接问题求助

Python TLS Client Connection Failure: Certificate Verification Issues & Fixes

Let's break down your issues step by step and fix the client code.

1. What's Wrong with the Client Code?

Your client has three key issues causing the certificate verification failure:

  • Incorrect CA trust store: You're loading the system default CA bundle (/etc/ssl/certs/ca-bundle.crt), which doesn't include the custom CA that signed your server's certificate (your cert.pem contains your private CA, server cert, and client cert). The TLS client can't verify the server's identity because it doesn't recognize the issuing authority.
  • Missing client certificate for mutual TLS: Your server is configured with ssl.Purpose.CLIENT_AUTH, which requires clients to present a valid certificate during the handshake. Your original client code doesn't load any client certificate/key, so even if the server cert was trusted, the connection would fail due to missing client authentication.
  • Unnecessary context overwrite: You first call ssl.create_default_context() (which sets secure TLS client defaults) then immediately replace it with ssl.SSLContext(ssl.PROTOCOL_TLS_CLIENT), resetting those safe defaults.

2. Why Does openssl s_client Work But Python Doesn't?

The core difference is default verification strictness:

  • When you run openssl s_client -connect 127.0.0.1:10023, OpenSSL performs certificate verification but doesn't abort the connection if verification fails—it only prints a warning (like Verify return code: 18 (self signed certificate)) but completes the TLS handshake anyway.
  • Python's SSLContext (created via create_default_context() or PROTOCOL_TLS_CLIENT) has strict verification enabled by default: it aborts the connection immediately if the server's certificate can't be validated against the trusted CA store. This is a safer default for production, but it means you need to explicitly trust your custom CA.

Fixed Client Code

Here's the corrected client code that addresses all issues:

import socket, ssl

server_addr = '**.***.***.***'  # Replace with your actual server IP/hostname
server_port = 10023  # Note: Your server listens on 10023—your original client used 3335, fix this mismatch!
cert_chain = 'cert.pem'

# Create a TLS client context with secure defaults for server authentication
context = ssl.create_default_context(ssl.Purpose.SERVER_AUTH)

# Trust our custom CA (stored in cert.pem) to verify the server's certificate
context.load_verify_locations(cert_chain)

# Load client certificate and key (required for server's client auth requirement)
context.load_cert_chain(certfile=cert_chain)

# Initialize and wrap the socket
sock = socket.socket(socket.AF_INET)
conn = context.wrap_socket(sock, server_hostname=server_addr)

try:
    conn.connect((server_addr, server_port))
    print("SSL connection established successfully!")
    conn.send(b"Hello, world!")
finally:
    conn.close()

Key Improvements:

  • Uses create_default_context(ssl.Purpose.SERVER_AUTH) to leverage secure TLS defaults (modern protocols, safe cipher suites) instead of manual context setup.
  • Loads cert.pem as the trusted CA store, so the client recognizes the server's certificate issuer.
  • Adds context.load_cert_chain() to provide the client certificate/key required by the server's CLIENT_AUTH configuration.
  • Fixes the port mismatch between server (10023) and original client (3335), which would have caused a connection refusal even without certificate issues.

Additional Notes

  • Ensure your cert.pem is structured with the CA certificate first, followed by server/client certificates and private keys—this format works with both load_verify_locations and load_cert_chain.
  • Double-check that server_hostname matches the Common Name (CN) or Subject Alternative Name (SAN) in your server's certificate, otherwise you'll hit a hostname mismatch verification error.

内容的提问来源于stack exchange,提问作者Ali

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.08 18:37:55