Ubuntu 14.0.4+OpenSSL 1.0.1f与TLSv1_2016握手失败问题求助
Hey there, let's work through this SSL handshake issue you're facing. That error [Errno 1] _ssl.c:510: error:14077410:SSL routines:SSL23_GET_SERVER_HELLO:sslv3 alert handshake failure tells us your client is trying to use an outdated SSL/TLS version or cipher suite that the AWS server doesn't accept—since the server is configured to use the 2016-compliant TLS 1.2 standard (AWS's strict security requirements for that era).
Here are actionable steps to fix this:
1. Force your client to use TLS 1.2 explicitly
Since your error traces back to _ssl.c, I'm guessing you're using Python. Most modern Python versions (2.7.9+, 3.4+) support TLS 1.2, but some HTTP libraries don't enable it by default. Here's how to force it with requests:
import requests from requests.adapters import HTTPAdapter from urllib3.poolmanager import PoolManager import ssl # Custom adapter to enforce TLS 1.2 class TLS12Adapter(HTTPAdapter): def init_poolmanager(self, connections, maxsize, block=False): self.poolmanager = PoolManager( num_pools=connections, maxsize=maxsize, block=block, ssl_version=ssl.PROTOCOL_TLSv1_2 ) # Create a session with the adapter session = requests.Session() session.mount('https://', TLS12Adapter()) # Use this session to make your API request try: response = session.get("https://your-api-endpoint-url") response.raise_for_status() print("Success!") except Exception as e: print(f"Error: {e}")
If you're using other tools (like curl), test with explicit TLS 1.2:
curl -v --tlsv1.2 https://your-api-endpoint-url
2. Update your HTTP/SSL libraries
Old versions of libraries like requests or urllib3 might have incomplete TLS 1.2 support. Update them with:
pip install --upgrade requests urllib3
For system tools (like curl), make sure you're running a version that supports TLS 1.2—most recent versions do, but if you're on an older OS, you may need to upgrade the tool itself.
3. Verify the server's TLS configuration (for debugging)
To confirm the server is indeed accepting TLS 1.2, run this openssl command:
openssl s_client -connect your-api-domain:443 -tls1_2
If this command successfully completes the handshake and shows server certificate details, the server is configured correctly—so the issue is definitely on your client side.
4. Check system-level SSL settings
- Linux/macOS: Ensure your system has up-to-date root CA certificates. On Ubuntu/Debian, run:
sudo apt update && sudo apt install --reinstall ca-certificates - Windows: Go to Internet Options → Advanced → Security, and make sure "Use TLS 1.2" is checked (uncheck older protocols like SSL 3.0 or TLS 1.0 if they're enabled).
The key takeaway here is that AWS's 2016-compliant TLS 1.2 configuration blocks all outdated SSL/TLS versions, so your client must explicitly use TLS 1.2 to connect successfully.
内容的提问来源于stack exchange,提问作者Steve Cohen

