升级Debian版本后OpenSSL连接新服务器出现errno=111错误的排查求助
升级Debian版本后OpenSSL连接新服务器出现errno=111错误的排查求助
大家好,我碰到了一个OpenSSL连接相关的问题,想请社区里的大佬帮忙分析下。
背景是这样的:我有一个Java应用,原本从server1连接到server2一切正常。最近我克隆了server2,并把系统从Debian 9.7升级到了Debian 11,结果新服务器的连接就出问题了。
旧server2的连接情况(正常)
执行命令 openssl s_client -connect oldserver2:143 后,输出如下:
CONNECTED(00000003) 140273164910656:error:1408F10B:SSL routines:ssl3_get_record:wrong version number:../ssl/record/ssl3_record.c:252: --- no peer certificate available --- No client certificate CA names sent --- SSL handshake has read 5 bytes and written 176 bytes Verification: OK --- New, (NONE), Cipher is (NONE) Secure Renegotiation IS NOT supported Compression: NONE Expansion: NONE No ALPN negotiated SSL-Session: Protocol : TLSv1.2 Cipher : 0000 Session-ID: Session-ID-ctx: Master-Key: PSK identity: None PSK identity hint: None SRP username: None Start Time: 1707916719 Timeout : 7200 (sec) Verify return code: 0 (ok) Extended master secret: no
新server2的连接情况(异常)
执行同样的命令 openssl s_client -connect newserver2:143 时,直接报错连接拒绝:
140319971628352:error:0200206F:system library:connect:Connection refused:../crypto/bio/b_sock2.c:110: 140319971628352:error:2008A067:BIO routines:BIO_connect:connect error:../crypto/bio/b_sock2.c:111: connect:errno=111
已做的排查
- 我尝试在网上搜索相关错误信息,但没找到匹配的解决方案
- 确认新server2的143端口是开放的:
telnet server2 143能正常连接 - 检查了iptables规则,里面有允许143端口的条目,应该不是防火墙的问题
有没有朋友遇到过类似的情况?或者能给我一些进一步排查的方向?
备注:内容来源于stack exchange,提问作者Yawa86
相关产品推荐
相关产品推荐

