OpenSSL验证wrong.host.badssl.com无效证书却显示验证正常的问题
解决openssl s_client无法检测wrong.host.badssl.com证书主机名不匹配的问题
问题原因
openssl s_client -connect 默认仅验证证书的签名链是否可信,不会检查证书中的主机名(SAN/CN)是否与连接的域名匹配,这就是你看到验证正常结果的核心原因。
解决方法
强制开启主机名验证
使用-servername指定目标主机名,同时通过-verify_hostname参数强制校验主机名与证书的匹配性:openssl s_client -connect wrong.host.badssl.com:443 -servername wrong.host.badssl.com -verify_hostname wrong.host.badssl.com执行后会返回
Verify return code: 62 (Hostname mismatch)的错误,成功捕获证书无效问题。查看证书绑定的主机名(可选)
若需要确认证书实际绑定的域名,可添加-showcerts参数查看证书的SAN字段:openssl s_client -connect wrong.host.badssl.com:443 -showcerts在输出中找到
X509v3 Subject Alternative Name项,会看到证书仅绑定了badssl.com等域名,并不包含wrong.host.badssl.com,这就是主机名不匹配的根源。指定根证书路径(可选)
若系统默认根证书存在异常,可手动指定可信根证书文件确保链验证准确:openssl s_client -connect wrong.host.badssl.com:443 -servername wrong.host.badssl.com -verify_hostname wrong.host.badssl.com -CAfile /path/to/ca-certificates.crt
内容的提问来源于stack exchange,提问作者Кирилл Волков
相关产品推荐
相关产品推荐

