You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Python SSL连接Windows Server 2008R2失败但OpenSSL可正常连接的问题求助

Python SSL连接Windows Server 2008R2失败但OpenSSL可正常连接的问题求助

我最近碰到个棘手的问题:想用Python 3.12搭配WinRM连接一台Windows Server 2008R2的老服务器,结果Python这边的SSL连接总是失败,但用OpenSSL命令却能顺利建立连接。我的环境是Ubuntu 24.04(Noble),具体情况如下:

我的Python测试代码

import ssl, socket
ctx = ssl.SSLContext(ssl.PROTOCOL_TLSv1_2)
ctx.verify_mode = ssl.CERT_NONE
with socket.create_connection(('server.example.com', 5986)) as sock:
    ssock = ctx.wrap_socket(sock)
    print(ssock.cipher(), ssock.version())

代码运行报错

执行上面的代码后,直接抛出了SSL相关的错误:

SSLEOFError: [SSL: UNEXPECTED_EOF_WHILE_READING] EOF occurred in violation of protocol (_ssl.c:1010)

OpenSSL命令的正常输出

而我用openssl s_client -connect server.example.com:5986执行后,能成功建立连接,输出内容如下:

CONNECTED(00000003)
depth=0 CN = server.example.com
verify error:num=20:unable to get local issuer certificate
verify return:1
depth=0 CN = server.example.com
verify error:num=21:unable to verify the first certificate
verify return:1
---
Certificate chain
 0 s:CN = server.example.com
   i:CN = server.example.com
---
Server certificate
-----BEGIN CERTIFICATE-----
MIIFADCC....
-----END CERTIFICATE-----
subject=CN = server.example.com
issuer=CN = server.example.com
---
No client certificate CA names sent
Peer signing digest: SHA1
Peer signature type: RSA
Server Temp Key: ECDH, P-256, 256 bits
---
SSL handshake has read 2084 bytes and written 505 bytes
Verification error: unable to verify the first certificate
---
New, TLSv1.2, Cipher is ECDHE-RSA-AES256-SHA384
Server public key is 4096 bit
Secure Renegotiation IS supported
Compression: NONE
Expansion: NONE
No ALPN negotiated
SSL-Session:
    Protocol  : TLSv1.2
    Cipher    : ECDHE-RSA-AES256-SHA384
    Session-ID: E223.....
    Session-ID-ctx:
    Master-Key: 83FBC.....
    PSK identity: None
    PSK identity hint: None
    SRP username: None
    Start Time: 1751134634
    Timeout   : 7200 (sec)
    Verify return code: 21 (unable to verify the first certificate)
    Extended master secret: yes
---

看起来两者都遇到了证书验证的问题,但Python没法像OpenSSL那样优雅处理这个意外EOF。有没有大佬能指点一下,怎么让Python也能像OpenSSL或者curl那样成功建立SSL连接呢?

内容来源于stack exchange

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.08 09:54:30