You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在日落模式的旧版Amazon Linux实例安装curl 7.34+以支持TLS1.2

Solutions to Update curl for TLS 1.2 Support (Without Updating AMI)

Got it, let's work through this problem. Since your instances are in sunset mode and you want to avoid updating the AMI, here are actionable ways to get a curl version 7.34+ (which supports TLS 1.2) — and in turn, fix git's TLS 1.2 compatibility, since git relies on curl for HTTPS operations.

Option 1: Compile curl from Source (Most Reliable)

This gives you full control over the build and ensures you use your existing OpenSSL installation that already supports TLS 1.2.

  1. Install build dependencies:
    sudo yum install gcc openssl-devel libcurl-devel make
    
  2. Download the curl source code (pick version 7.34.0 or higher):
    Grab the tarball from the official curl repository, then extract it:
    tar -xzf curl-7.34.0.tar.gz
    cd curl-7.34.0
    
  3. Configure the build to use your system's OpenSSL:
    ./configure --with-openssl --prefix=/usr/local/curl
    
    The --prefix flag sets where the new curl will be installed — using /usr/local/curl keeps it separate from the system's default curl initially.
  4. Compile and install:
    make && sudo make install
    
  5. Make the new curl available system-wide:
    You can either replace the system curl (test this carefully first):
    sudo ln -sf /usr/local/curl/bin/curl /usr/bin/curl
    
    Or add the new curl's bin directory to your PATH (safer if other tools depend on the old curl):
    Add this line to ~/.bashrc or /etc/profile:
    export PATH=/usr/local/curl/bin:$PATH
    
    Then reload the profile:
    source ~/.bashrc
    
  6. Verify the installation:
    curl --version
    
    Check that the output shows TLSv1.2 under supported protocols.

Option 2: Use a Third-Party Repository (If Available)

If your system can still access maintained third-party repos like EPEL, this is quicker. Note that this might not work for sunset instances since repos often stop supporting old versions.

  1. Install the EPEL repository:
    sudo yum install epel-release
    
  2. Try updating curl:
    sudo yum update curl
    
    If EPEL has a curl version ≥7.34, this will install it. If not, fall back to source compilation.

Option 3: Use Precompiled Binaries (No Compilation Needed)

Look for precompiled curl binaries that match your Amazon Linux version and architecture (e.g., x86_64) and are linked against your system's OpenSSL.

  1. Download the binary from a trusted source (ensure it's compatible with your system libraries).
  2. Copy it to a system directory and set executable permissions:
    sudo cp /path/to/downloaded/curl /usr/local/bin/
    sudo chmod +x /usr/local/bin/curl
    
  3. Verify the version and TLS support:
    curl --version
    

Bonus: Configure Git to Use the New Curl (Without System-Wide Changes)

If you don't want to replace the system curl (to avoid breaking other tools), tell git explicitly to use your updated curl:

git config --global http.curlBinary /usr/local/curl/bin/curl

Test this with a git HTTPS operation, like cloning a repo:

git clone https://github.com/example/repo.git

Important Notes

  • Always test these changes in a non-production instance first — sunset instances might have unique dependency chains.
  • Since your OpenSSL already supports TLS 1.2, the updated curl will immediately leverage that for HTTPS connections.

内容的提问来源于stack exchange,提问作者Karthik T

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 06:49:32