Debian系统中GnuTLS引发HTTPS请求异常问题求助
解决Debian Whizzy/Jessie下部分HTTPS站点无法访问的问题
我看你在Debian Whizzy和Jessie系统上遇到了奇怪的HTTPS访问问题——像Google这类站点用wget、curl、gnutls-cli甚至openssl都连不上,但Stack Overflow却能正常访问,而且换了gnutls26和28版本也没解决。咱们一步步来排查:
先确认你的错误细节
wget访问Google的报错
$ wget https://google.com --2018-05-12 11:06:27-- https://google.com/ Resolving google.com (google.com)... 216.58.196.46 Connecting to google.com (google.com)|216.58.196.46|:443... connected. GnuTLS: A TLS packet with unexpected length was received. Unable to establish SSL connection.
curl与gnutls-cli的类似错误
curl的错误输出:
$ curl https://google.com curl: (35) Unknown SSL protocol error in connection to google.com:443
gnutls-cli的错误:
$ gnutls-cli -p 443 google.com Processed 166 CA certificate(s). Resolving 'google.com'... Connecting to '216.58.196.46:443'... *** Fatal error: Error in the pull function. No certificates found! *** Handshake has failed GnuTLS error: Error in the pull function.
openssl测试同样失败
哪怕指定TLS1.2也没用:
$ openssl s_client -connect google.com:443 CONNECTED(00000003) write:errno=104 --- no peer certificate available --- No client certificate CA names sent --- SSL handshake has read 0 bytes and written 290 bytes --- New, (NONE), Cipher is (NONE) Secure Renegotiation IS NOT supported Compression: NONE Expansion: NONE SSL-Session: Protocol : TLSv1.2 Cipher : 0000 Session-ID: Session-ID-ctx: Master-Key: Key-Arg : None PSK identity: None PSK identity hint: None SRP username: None Start Time: 1526113843 Timeout : 300 (sec) Verify return code: 0 (ok) ---
例外情况:Stack Overflow可正常访问
$ wget https://stackoverflow.com --2018-05-12 11:09:10-- https://stackoverflow.com/ Resolving stackoverflow.com (stackoverflow.com)... 151.101.1.69, 151.101.65.69, 151.101.129.69, ... Connecting to stackoverflow.com (stackoverflow.com)|151.101.1.69|:443... connected. HTTP request sent, awaiting response... 200 OK Length: 252141 (246K) [text/html] Saving to: `index.html.3' 100%[======================================>] 252,141 294K/s in 0.8s 2018-05-12 11:09:17 (294 KB/s) - `index.html.3' saved [252141/252141]
针对性的解决方案
1. 先检查系统时间——这个最容易被忽略
Google这类大站对TLS证书的时间有效性要求非常严格,如果你的系统时间偏差超过几个小时,直接会导致证书验证失败。先看看时间对不对:
date
如果时间不准,用ntp同步:
apt-get install ntpdate ntpdate pool.ntp.org
2. 更新CA证书
Debian Jessie和Whizzy的默认CA证书包可能已经过期,没法验证现在的新证书。重新安装并更新:
apt-get update apt-get install --reinstall ca-certificates update-ca-certificates
3. 排查网络拦截问题
你看到的Error in the pull function和write:errno=104(连接被重置),很大概率是网络层面的问题:比如ISP的透明HTTPS拦截、本地防火墙规则,或者代理配置出问题了。
- 换个网络试试,比如手机热点,看能不能访问Google的HTTPS
- 检查iptables有没有限制443端口:
iptables -L -n
- 如果用了代理,确认代理没拦截TLS流量,配置是正确的
4. 强制指定兼容的TLS协议和加密套件
旧版本的GnuTLS可能不支持Google现在用的加密套件,试试强制用兼容的:
- wget:
wget --secure-protocol=TLSv1_2 --ciphers=AES128-GCM-SHA256 https://google.com
- curl:
curl --tlsv1.2 --ciphers ECDHE-RSA-AES128-GCM-SHA256 https://google.com
5. 升级openssl和gnutls到新版本
Debian Jessie的backports源里有更新的openssl和gnutls包,启用后升级试试:
# 给Jessie添加backports源 echo "deb http://deb.debian.org/debian jessie-backports main" >> /etc/apt/sources.list apt-get update # 从backports升级 apt-get -t jessie-backports install openssl libgnutls30
先从最简单的时间和CA证书开始排查,这些是最常见的原因,如果不行再试后面的方案。
内容的提问来源于stack exchange,提问作者thehuyvb
相关产品推荐
相关产品推荐

