如何在日落模式的旧版Amazon Linux实例安装curl 7.34+以支持TLS1.2
Got it, let's work through this problem. Since your instances are in sunset mode and you want to avoid updating the AMI, here are actionable ways to get a curl version 7.34+ (which supports TLS 1.2) — and in turn, fix git's TLS 1.2 compatibility, since git relies on curl for HTTPS operations.
Option 1: Compile curl from Source (Most Reliable)
This gives you full control over the build and ensures you use your existing OpenSSL installation that already supports TLS 1.2.
- Install build dependencies:
sudo yum install gcc openssl-devel libcurl-devel make - Download the curl source code (pick version 7.34.0 or higher):
Grab the tarball from the official curl repository, then extract it:tar -xzf curl-7.34.0.tar.gz cd curl-7.34.0 - Configure the build to use your system's OpenSSL:
The./configure --with-openssl --prefix=/usr/local/curl--prefixflag sets where the new curl will be installed — using/usr/local/curlkeeps it separate from the system's default curl initially. - Compile and install:
make && sudo make install - Make the new curl available system-wide:
You can either replace the system curl (test this carefully first):
Or add the new curl's bin directory to your PATH (safer if other tools depend on the old curl):sudo ln -sf /usr/local/curl/bin/curl /usr/bin/curl
Add this line to~/.bashrcor/etc/profile:
Then reload the profile:export PATH=/usr/local/curl/bin:$PATHsource ~/.bashrc - Verify the installation:
Check that the output showscurl --versionTLSv1.2under supported protocols.
Option 2: Use a Third-Party Repository (If Available)
If your system can still access maintained third-party repos like EPEL, this is quicker. Note that this might not work for sunset instances since repos often stop supporting old versions.
- Install the EPEL repository:
sudo yum install epel-release - Try updating curl:
If EPEL has a curl version ≥7.34, this will install it. If not, fall back to source compilation.sudo yum update curl
Option 3: Use Precompiled Binaries (No Compilation Needed)
Look for precompiled curl binaries that match your Amazon Linux version and architecture (e.g., x86_64) and are linked against your system's OpenSSL.
- Download the binary from a trusted source (ensure it's compatible with your system libraries).
- Copy it to a system directory and set executable permissions:
sudo cp /path/to/downloaded/curl /usr/local/bin/ sudo chmod +x /usr/local/bin/curl - Verify the version and TLS support:
curl --version
Bonus: Configure Git to Use the New Curl (Without System-Wide Changes)
If you don't want to replace the system curl (to avoid breaking other tools), tell git explicitly to use your updated curl:
git config --global http.curlBinary /usr/local/curl/bin/curl
Test this with a git HTTPS operation, like cloning a repo:
git clone https://github.com/example/repo.git
Important Notes
- Always test these changes in a non-production instance first — sunset instances might have unique dependency chains.
- Since your OpenSSL already supports TLS 1.2, the updated curl will immediately leverage that for HTTPS connections.
内容的提问来源于stack exchange,提问作者Karthik T

