执行Curl调用API时遭遇证书验证失败问题求助
解决Curl调用API时SSL/TLS握手失败(SEC_E_ILLEGAL_MESSAGE)的思路
问题重现
执行的Curl命令:
curl --insecure --cacert certificate.pem https://URL/api/v1/version/123/example
遇到的错误:
curl: (35) schannel: next InitializeSecurityContext failed: SEC_E_ILLEGAL_MESSAGE (0x80090326) - This error usually occurs when a fatal SSL/TLS alert is received (e.g. handshake failed). More detail may be available in the Windows System event log.
Windows系统日志提示:
The certificate received from the remote server was issued by an untrusted certificate authority. Because of this, none of the data contained in the certificate can be validated. The TLS connection request has failed. The attached data contains the server certificate.
The SSPI client process is curl (PID: 20472).
解决思路
- 检查证书文件有效性
确认certificate.pem是完整的CA证书链(包含根CA和中间CA),而非仅服务器证书。可通过openssl x509 -in certificate.pem -text -noout命令查看证书内容,验证CA信息是否正确。 - 修正Curl参数冲突
--insecure(简写-k)会跳过证书验证,--cacert则是指定信任的CA证书,两个参数同时使用存在逻辑冲突。建议移除--insecure,仅保留--cacert参数,让Curl通过指定CA完成证书验证。 - 确认证书路径正确性
确保certificate.pem的路径无误,若路径包含空格或特殊字符,需用引号包裹(例如--cacert "C:\path with spaces\certificate.pem")。 - 导入CA证书到Windows信任存储
若不想每次调用都指定--cacert,可将CA证书导入Windows「受信任的根证书颁发机构」:- 双击
certificate.pem文件,点击「安装证书」 - 选择「本地计算机」,点击「下一步」
- 选择「将所有证书放入下列存储」,点击「浏览」后选择「受信任的根证书颁发机构」
- 完成导入后,重新运行Curl命令即可无需指定
--cacert
- 双击
- 检查Curl版本及Schannel配置
旧版本Curl在Windows上使用Schannel引擎可能存在兼容性问题,建议升级到最新稳定版。同时确认系统TLS版本配置(启用TLS 1.2/1.3,禁用SSL 3.0等过时协议)。
内容的提问来源于stack exchange,提问作者Lume
相关产品推荐
相关产品推荐

