无法跨站访问PHP脚本,遇SSL握手失败等require_once错误求助
require_once for Remote PHP Scripts Hey there, let’s tackle this SSL handshake error you’re hitting when trying to require_once a remote PHP script from your new site. That SSL23_GET_SERVER_HELLO:sslv3 alert handshake failure message tells us there’s a mismatch between your new server’s SSL/TLS settings and the target server’s (https://www.example.com) security configuration. Here’s how to fix it step by step:
1. Force Modern TLS Versions in Your Request
The most common culprit here is your PHP environment defaulting to an outdated SSL/TLS protocol (like SSLv3, which is no longer secure or supported by most servers). You can override this by creating a custom SSL context before calling require_once:
// Create a secure SSL context that enforces TLS 1.2 or 1.3 $sslContext = stream_context_create([ 'ssl' => [ 'verify_peer' => true, // Verify the remote server's certificate (security best practice) 'verify_peer_name' => true, // Verify the certificate matches the domain 'allow_self_signed' => false, // Block self-signed certificates (adjust only if you trust a self-signed cert) 'crypto_method' => STREAM_CRYPTO_METHOD_TLSv1_2_CLIENT | STREAM_CRYPTO_METHOD_TLSv1_3_CLIENT, ] ]); // Set this context as the default for stream operations stream_context_set_default($sslContext); // Now try your require_once again require_once 'https://www.example.com/abc/abc.xyz.php';
This forces your script to use modern, supported TLS versions that the target server is likely expecting.
2. Verify Your PHP/OpenSSL Version
If the above doesn’t work, check that your PHP installation uses an OpenSSL version that supports TLS 1.2 or higher. Create a quick phpinfo.php file with this content:
<?php phpinfo(); ?>
Access it in your browser, then search for "OpenSSL" to find the version number. You’ll need at least OpenSSL 1.0.1 (which added TLS 1.2 support) or newer. If your version is older, you’ll need to upgrade OpenSSL and PHP on your new server.
3. Alternative: Use cURL to Fetch the Script
If require_once with a context still fails, you can use cURL to pull the remote script content first, then include it (only do this if you fully trust the remote script source):
Option A: Use eval (Quick but Risky)
$curlHandle = curl_init('https://www.example.com/abc/abc.xyz.php'); curl_setopt($curlHandle, CURLOPT_RETURNTRANSFER, true); curl_setopt($curlHandle, CURLOPT_SSL_VERIFYPEER, true); curl_setopt($curlHandle, CURLOPT_SSL_VERIFYHOST, 2); curl_setopt($curlHandle, CURLOPT_SSLVERSION, CURL_SSLVERSION_TLSv1_2 | CURL_SSLVERSION_TLSv1_3); $scriptContent = curl_exec($curlHandle); curl_close($curlHandle); if ($scriptContent !== false) { // Only use eval if you 100% trust the remote script! eval('?>' . $scriptContent); } else { die('Failed to retrieve remote script: ' . curl_error($curlHandle)); }
Option B: Use a Temporary File (Safer)
For better security, write the content to a temporary file first, then include it:
$curlHandle = curl_init('https://www.example.com/abc/abc.xyz.php'); curl_setopt($curlHandle, CURLOPT_RETURNTRANSFER, true); curl_setopt($curlHandle, CURLOPT_SSL_VERIFYPEER, true); curl_setopt($curlHandle, CURLOPT_SSL_VERIFYHOST, 2); curl_setopt($curlHandle, CURLOPT_SSLVERSION, CURL_SSLVERSION_TLSv1_2 | CURL_SSLVERSION_TLSv1_3); $scriptContent = curl_exec($curlHandle); curl_close($curlHandle); if ($scriptContent !== false) { $tempFile = tempnam(sys_get_temp_dir(), 'remote_script'); file_put_contents($tempFile, $scriptContent); require_once $tempFile; unlink($tempFile); // Clean up the temporary file } else { die('Failed to retrieve remote script'); }
4. Check the Target Server’s SSL Configuration
If none of the above works, confirm that the target server (www.example.com) supports modern TLS versions. You can test this from your server’s command line with:
# Test TLS 1.2 connection openssl s_client -connect www.example.com:443 -tls1_2 # Test TLS 1.3 connection openssl s_client -connect www.example.com:443 -tls1_3
If either command succeeds, the server supports that TLS version. If both fail, the target server might be using outdated protocols—you’ll need to reach out to its administrator to update their SSL settings.
内容的提问来源于stack exchange,提问作者newbie756

