Windows7虚拟机出现schannel SSL/TLS握手失败问题求助
技术求助:SSL/TLS握手失败问题排查
近几日遇到一个技术问题,主机托管技术团队无法提供帮助,特此求助,任何相关信息都将十分感谢。
关键信息
- 软件收到
schannel: failed to receive handshake, SSL/TLS connection failed错误 - 软件运行在Windows 7系统的虚拟机(VM)内
- 系统正常运行2-3天后,主机上所有VM都会出现相同错误
- 问题出现后,只有关闭所有VM,等待2分钟再重启,才能恢复正常
- 问题出现时,VM内无法访问目标API,但主机(同一IP)可以正常访问
- 单独重启单个VM无法解决问题,必须关闭所有VM后重启才行
- 问题出现时,VM内访问目标网站会出现网络错误,但其他网站可正常访问
- VM内无防火墙或代理可能导致该问题
- 问题不会同时在所有主机上出现,仅影响单台主机
- 使用Hostinger的云服务
- php日志文件中无错误记录
问题出现规律
系统正常运行1-2天后,主机上所有实例突然出现该错误;其他主机在运行1-2天后也会出现同样问题。
已尝试的修复方案
- 更换服务器位置
- 将SSL/TLS加密模式改为Flexible
- 禁用/启用Universal SSL
- 暂停Cloudflare并将DNS指向托管服务器
- 在libcurl中强制使用不同的TLS版本
- 检查IP是否被封禁/拦截
代码(大概率非问题原因,重启软件无法解决)
CURL* curl; CURLcode res; std::string response; curl = curl_easy_init(); struct curl_slist* headers = NULL; if (curl) { headers = curl_slist_append(headers, "Connection: keep-alive"); headers = curl_slist_append(headers, "Accept: application/json"); headers = curl_slist_append(headers, "Content-Type: application/json"); curl_easy_setopt(curl, CURLOPT_URL,endpoint.c_str()); curl_easy_setopt(curl, CURLOPT_NOPROGRESS, 1L); if (patchOrPOST == "PATCH") { curl_easy_setopt(curl, CURLOPT_CUSTOMREQUEST, "PATCH"); } else if (patchOrPOST == "PUT") { curl_easy_setopt(curl, CURLOPT_CUSTOMREQUEST, "PUT"); } else if (patchOrPOST == "GET") { curl_easy_setopt(curl, CURLOPT_CUSTOMREQUEST, "GET"); } else if(patchOrPOST=="DELETE") { curl_easy_setopt(curl, CURLOPT_CUSTOMREQUEST, "DELETE"); } else { curl_easy_setopt(curl, CURLOPT_POST, 1); } curl_easy_setopt(curl, CURLOPT_VERBOSE, 1L); curl_easy_setopt(curl, CURLOPT_POSTFIELDSIZE, json.size()); curl_easy_setopt(curl, CURLOPT_POSTFIELDS, json.c_str()); curl_easy_setopt(curl, CURLOPT_HTTPHEADER, headers); curl_easy_setopt(curl, CURLOPT_MAXREDIRS, 5L); curl_easy_setopt(curl, CURLOPT_TIMEOUT, 10L); curl_easy_setopt(curl, CURLOPT_HEADER, 1); curl_easy_setopt(curl, CURLOPT_SSL_VERIFYPEER, 0); //IS FOR THREADING /* curl_easy_setopt(curl, CURLOPT_NOSIGNAL, 1); */ res= curl_easy_setopt(curl, CURLOPT_WRITEFUNCTION, WriteCallback); if (res!= CURLE_OK) { curl_easy_cleanup(curl); return "ERROR"; } res= curl_easy_setopt(curl, CURLOPT_WRITEDATA, &response); if (res!= CURLE_OK) { curl_easy_cleanup(curl); return "ERROR"; } res = curl_easy_perform(curl); long http_code; /* Check for errors */ if (res != CURLE_OK) { fprintf(stderr, "curl_easy_perform() failed: %s\n", curl_easy_strerror(res)); } /* always cleanup */ curl_easy_cleanup(curl); } return response;
请求后立即出现的错误响应
* Trying (OUR IP)... * Connected to ourdomain.com (OUR IP) port 443 (#0) * schannel: failed to receive handshake, SSL/TLS connection failed * Closing connection 0 * schannel: shutting down SSL/TLS connection with ourdomain.com port 443 curl_easy_perform() failed: SSL connect error
截图(主机出现错误时)


请问该问题的可能原因是什么?如何获取更多排查信息或彻底解决该问题?
内容的提问来源于stack exchange,提问作者O'con
相关产品推荐
相关产品推荐

