You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Debian系统中GnuTLS引发HTTPS请求异常问题求助

解决Debian Whizzy/Jessie下部分HTTPS站点无法访问的问题

我看你在Debian Whizzy和Jessie系统上遇到了奇怪的HTTPS访问问题——像Google这类站点用wget、curl、gnutls-cli甚至openssl都连不上,但Stack Overflow却能正常访问,而且换了gnutls26和28版本也没解决。咱们一步步来排查:

先确认你的错误细节

wget访问Google的报错

$ wget https://google.com
--2018-05-12 11:06:27--  https://google.com/
Resolving google.com (google.com)... 216.58.196.46
Connecting to google.com (google.com)|216.58.196.46|:443... connected.
GnuTLS: A TLS packet with unexpected length was received.
Unable to establish SSL connection.

curl与gnutls-cli的类似错误

curl的错误输出:

$ curl https://google.com
curl: (35) Unknown SSL protocol error in connection to google.com:443

gnutls-cli的错误:

$ gnutls-cli -p 443 google.com
Processed 166 CA certificate(s).
Resolving 'google.com'...
Connecting to '216.58.196.46:443'...
*** Fatal error: Error in the pull function.
No certificates found!
*** Handshake has failed
GnuTLS error: Error in the pull function.

openssl测试同样失败

哪怕指定TLS1.2也没用:

$ openssl s_client -connect google.com:443
CONNECTED(00000003)
write:errno=104
---
no peer certificate available ---
No client certificate CA names sent
---
SSL handshake has read 0 bytes and written 290 bytes
---
New, (NONE), Cipher is (NONE)
Secure Renegotiation IS NOT supported
Compression: NONE
Expansion: NONE
SSL-Session:
    Protocol  : TLSv1.2
    Cipher    : 0000
    Session-ID:
    Session-ID-ctx:
    Master-Key:
    Key-Arg   : None
    PSK identity: None
    PSK identity hint: None
    SRP username: None
    Start Time: 1526113843
    Timeout   : 300 (sec)
    Verify return code: 0 (ok)
---

例外情况:Stack Overflow可正常访问

$ wget https://stackoverflow.com
--2018-05-12 11:09:10--  https://stackoverflow.com/
Resolving stackoverflow.com (stackoverflow.com)... 151.101.1.69, 151.101.65.69, 151.101.129.69, ...
Connecting to stackoverflow.com (stackoverflow.com)|151.101.1.69|:443... connected.
HTTP request sent, awaiting response... 200 OK
Length: 252141 (246K) [text/html]
Saving to: `index.html.3'

100%[======================================>] 252,141     294K/s   in 0.8s

2018-05-12 11:09:17 (294 KB/s) - `index.html.3' saved [252141/252141]

针对性的解决方案

1. 先检查系统时间——这个最容易被忽略

Google这类大站对TLS证书的时间有效性要求非常严格,如果你的系统时间偏差超过几个小时,直接会导致证书验证失败。先看看时间对不对:

date

如果时间不准,用ntp同步:

apt-get install ntpdate
ntpdate pool.ntp.org

2. 更新CA证书

Debian Jessie和Whizzy的默认CA证书包可能已经过期,没法验证现在的新证书。重新安装并更新:

apt-get update
apt-get install --reinstall ca-certificates
update-ca-certificates

3. 排查网络拦截问题

你看到的Error in the pull function和write:errno=104(连接被重置),很大概率是网络层面的问题:比如ISP的透明HTTPS拦截、本地防火墙规则,或者代理配置出问题了。

  • 换个网络试试,比如手机热点,看能不能访问Google的HTTPS
  • 检查iptables有没有限制443端口:
iptables -L -n
  • 如果用了代理,确认代理没拦截TLS流量,配置是正确的

4. 强制指定兼容的TLS协议和加密套件

旧版本的GnuTLS可能不支持Google现在用的加密套件,试试强制用兼容的:

  • wget:
wget --secure-protocol=TLSv1_2 --ciphers=AES128-GCM-SHA256 https://google.com
  • curl:
curl --tlsv1.2 --ciphers ECDHE-RSA-AES128-GCM-SHA256 https://google.com

5. 升级openssl和gnutls到新版本

Debian Jessie的backports源里有更新的openssl和gnutls包,启用后升级试试:

# 给Jessie添加backports源
echo "deb http://deb.debian.org/debian jessie-backports main" >> /etc/apt/sources.list
apt-get update
# 从backports升级
apt-get -t jessie-backports install openssl libgnutls30

先从最简单的时间和CA证书开始排查,这些是最常见的原因,如果不行再试后面的方案。

内容的提问来源于stack exchange,提问作者thehuyvb

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 07:33:32