You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

浏览器与OpenSSL获取的网站SHA1指纹不一致问题咨询

Why the SHA1 Fingerprints Don't Match

Let’s break down exactly why you’re seeing conflicting results between your OpenSSL command and browser:

1. Your OpenSSL Command is Routing Through an SSL-intercepting Proxy

The critical detail here is your use of proxy-vip:3128. Many corporate or network proxies enable SSL/TLS interception (a man-in-the-middle setup for security filtering). When this is active:

  • The proxy doesn’t pass through saucelabs.com’s real certificate chain. Instead, it generates its own fake leaf certificate for saucelabs.com, signed by an internal intermediate/root CA controlled by your network admin.
  • Your OpenSSL command receives this proxy-generated certificate chain, which explains why the three SHA1 fingerprints you get don’t match the browser’s result.

2. Your Browser is Either Bypassing the Proxy or Receiving the Real Certificate

When you check the fingerprint in your browser:

  • If you’re not using the same proxy in your browser, it connects directly to saucelabs.com and receives the real, unmodified leaf certificate (with the fingerprint 80:27:83:5F:A8:81:6B:97:E2:60:FF:B3:A9:7B:69:E1:F2:38:9A:7A).
  • Even if the browser uses the proxy, you might not have imported the proxy’s root CA into your browser’s trust store. In this case, the browser likely shows a security warning and lets you view the real certificate, or it’s configured to bypass interception for trusted sites like saucelabs.com.

3. Your OpenSSL Command Extracts the Entire Certificate Chain

Another key difference: your command pulls every certificate in the chain (leaf → intermediate → root) and computes the SHA1 for each. That’s why you get three fingerprints. Browsers, by default, only display the leaf certificate (the one directly issued to saucelabs.com) unless you dig into the full certificate chain details.

How to Confirm the Proxy is the Issue

Run your OpenSSL command without the proxy to fetch the real certificate chain:

echo "" | openssl s_client -showcerts -connect saucelabs.com:443 2>&1 | sed -ne '/-BEGIN CERTIFICATE-/,/-END CERTIFICATE-/p;/-END CERTIFICATE-/a\x0' | sed -e '$ d' | xargs -0rl -I% sh -c "echo '%' | openssl x509 -fingerprint -noout -sha1"

You’ll see the leaf certificate’s fingerprint match the one from your browser, alongside the intermediate and root certificates from saucelabs.com’s legitimate chain.

内容的提问来源于stack exchange,提问作者Frank Potter

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 08:32:21