CURLOPT_RESOLVE失效求助:CentOS 6环境下强制Curl指定HTTPS内网IP
Let's break down why your CURLOPT_RESOLVE setup might be failing in your CentOS 6, PHP 5.6.35, and curl 7.59.0 stack:
Verify PHP's cURL extension is linked to the correct libcurl version
CentOS 6 ships with an older system libcurl by default. Even if you installed curl 7.59.0 manually, your PHP cURL extension might still be tied to the system's outdated version (which could lack properCURLOPT_RESOLVEsupport). To confirm this, run this quick check:<?php echo curl_version()['version']; ?>If the output isn't 7.59.0, you'll need to recompile the PHP cURL extension against your updated libcurl library.
Double-check the CURLOPT_RESOLVE syntax
Your array structure looks correct, but ensure the string is formatted perfectly without extra whitespace or typos. The required format is[domain]:[port]:[ip]. For example:curl_setopt($ch, CURLOPT_RESOLVE, array( "example.com:443:192.168.1.10" ));Make sure
$domaindoesn't have trailing slashes or unexpected characters that could break the resolve rule.Address SSL certificate mismatches
Even if the DNS override works, HTTPS connections will fail if the server's SSL certificate doesn't match the$domainyou're using. Since you're targeting a local IP, the certificate is likely issued for the actual public domain (not the LAN IP). To test if this is the issue (debug only—never use this in production), add these options to bypass certificate checks temporarily:curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, false); curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 0);If the request succeeds after adding these, you’ll need to either:
- Add the local domain to your server’s certificate as a Subject Alternative Name (SAN)
- Edit your local
/etc/hostsfile to map$domainto192.168.1.10(a simpler alternative toCURLOPT_RESOLVEfor local setups)
Check for conflicting cURL options
Some options can interfere withCURLOPT_RESOLVE. For example, if you’ve setCURLOPT_PROXYor DNS-specific options likeCURLOPT_DNS_SERVERS, they might override your resolve rule. Ensure no such conflicting options are active in your code.Enable verbose logging to debug the connection flow
Add verbose logging to get a play-by-play of how cURL handles the resolve rule and connection:curl_setopt($ch, CURLOPT_VERBOSE, true); $verboseLogFile = fopen('php://temp', 'w+'); curl_setopt($ch, CURLOPT_STDERR, $verboseLogFile); $response = curl_exec($ch); rewind($verboseLogFile); $verboseOutput = stream_get_contents($verboseLogFile); echo "Verbose Connection Log:\n" . $verboseOutput;Look for lines mentioning "Added DNS entry" or errors during resolution/SSL handshake—this will pinpoint exactly where the process is failing.
内容的提问来源于stack exchange,提问作者Bastien974

