You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

通过Squid代理时Chilkat HTTP TLS握手失败的配置求助

Chilkat HTTP v11.4.0通过NTLM认证的Squid SSL Bump代理发起HTTPS请求时TLS握手失败的问题

问题场景

使用Chilkat HTTP v11.4.0(.NET版本)通过启用NTLM认证与SSL Bump的企业级Squid代理发起HTTPS请求,NTLM认证已成功返回200 Connection established,但TLS握手始终失败,错误日志如下:

NTLM proxy connect success
convertToTls:
  sendClientHello - OK
  readHandshakeMessages:
    v84.84, ct=72, sz=20527
    Connection closed by peer.
    Failed to read TLS record (2)

已尝试的操作

  • 设置SslProtocol = "TLS 1.2"或"TLS 1.3 or higher"
  • 设置SslAllowedCiphers = "best-practices"
  • 调用TrustedRoots.Activate()并搭配Squid CA证书
  • 切换RequireSslCertVerify = true/false
  • 设置glob.DefaultNtlmVersion = 1

对比验证

使用HttpClient(Windows SChannel)通过同一代理可正常完成请求。

Wireshark分析结论

返回200 Connection established后,Squid针对Chilkat的ClientHello返回HTTP/1.1 400 Bad Request(Cloudflare),而HttpClient的ClientHello可正常通过。两者核心差异在于:

  • HttpClient发送的key_share扩展包含x25519, secp256r1, secp384r1三种椭圆曲线
  • Chilkat仅发送secp256r1一种曲线

解决方案

可以通过配置Chilkat的SslEccCurves属性,让其在ClientHello中包含多种椭圆曲线,匹配HttpClient的行为:

在建立代理连接后、调用ConvertToTls之前,设置HttpConnection对象的SslEccCurves参数:

// 假设httpConn是已创建的Chilkat.HttpConnection对象
httpConn.SslEccCurves = "x25519, secp256r1, secp384r1";

该属性用于指定TLS握手时ClientHello中key_share扩展包含的椭圆曲线列表,设置后Chilkat会生成对应曲线的密钥共享信息,与HttpClient的行为一致,从而通过Squid代理的SSL Bump校验。

同时建议保持SslProtocol设置为"TLS 1.2"或更高版本,确保支持key_share扩展。

详细Chilkat日志

ChilkatLog:
  QuickGetObj(563ms):
    DllDate: Mar 29 2026
    ChilkatVersion: 11.4.0
    UnlockStatusMsg: Unlocked for 30-day trial
    UnlockStatus: 1
    Architecture: Little Endian; 64-bit
    Language: Visual C++ 2022 / x64
    VerboseLogging: 1
    quickRequestObj(563ms):
      url: https://httpbin.org/get
      verb: GET
      quickRequestDb(563ms):
        url: https://httpbin.org/get
        getHttpConnectionByUrl:
          findAddHttpConn:
            sbHostname0: httpbin.org
            port: 443
            bTls: True
            bForceNewConnection: False
            sbProxyDomain: [PROXY_HOST]
            proxyPort: [PROXY_PORT]
            numExistingConnections: 0
            lookingForHost: [httpbin.org]
            lookingForPort: 443
            lookingForProxy: [[PROXY_HOST]]
            Will need to open a new connection.
          --findAddHttpConn
        --getHttpConnectionByUrl
        a_quickReq(547ms):
          quickHttpRequest(547ms):
            httpVerb: GET
            url: https://httpbin.org/get
            openHttpConnection(547ms):
              Opening connection through an HTTP proxy.
              proxyDomain: [PROXY_HOST]
              proxyPort: [PROXY_PORT]
              httpHostname: httpbin.org
              httpPort: 443
              tls: True
              bUsingHttpProxy: True
              httpProxyAuthMethod:
              m_httpProxyTls: False
              Using a CONNECT tunnel...
              socket2Connect(547ms):
                Using HTTP proxy CONNECT...
                httpProxyConnect(344ms):
                  proxyAuthMethod:
                  proxyHostname: [PROXY_HOST]
                  proxyPort: [PROXY_PORT]
                  No proxy authentication method specified.
                  proxyUsername is empty
                  proxyPassword is empty
                  connectSocket_v2(31ms):
                    domainOrIpAddress: [PROXY_HOST]
                    port: [PROXY_PORT]
                    connectTimeoutMs: 30000
                    This is an IPV4 numeric address.
                    createSocket_ipv4:
                      Setting SO_SNDBUF size
                      sendBufSize: 262144
                      Setting SO_RCVBUF size
                      recvBufSize: 4194304
                    --createSocket_ipv4
                    connect(31ms):
                      Waiting for the connect to complete...
                      connectTimeoutMs: 30000
                      myIP: [CLIENT_IP]
                      myPort: 56403
                      socket connect successful.
                    --connect
                  --connectSocket_v2
                  connectRequest: CONNECT httpbin.org:443 HTTP/1.1
Connection: Keep-Alive
Proxy-Connection: Keep-Alive
Host: httpbin.org:443
                  connectResponseHeader: HTTP/1.1 407 Proxy Authentication Required
Server: squid/5.7
...
                  The server supports the NTLM proxy authentication method.
                  Re-trying with NTLM proxy authentication...
                  proxyConnectNtlm(313ms):
                    login:
                    domain:
                    proxyAuthMethod:
                    password is empty
                    Will use MS SSPI...
                    connectSocket_v2(16ms):
                      domainOrIpAddress: [PROXY_HOST]
                      port: [PROXY_PORT]
                      connectTimeoutMs: 30000
                      This is an IPV4 numeric address.
                      createSocket_ipv4:
                        Setting SO_SNDBUF size
                        sendBufSize: 262144
                        Setting SO_RCVBUF size
                        recvBufSize: 4194304
                      --createSocket_ipv4
                      connect(16ms):
                        Waiting for the connect to complete...
                        connectTimeoutMs: 30000
                        myIP: [CLIENT_IP]
                        myPort: 56404
                        socket connect successful.
                      --connect
                    --connectSocket_v2
                    Using NTLM as the default SSPI package name...
                    sspiBegin:
                      acquireSspiCredentials:
                        sspi_username:
                        sspi_domain:
                        password is empty
                        Using default NTLM credentials.
                      --acquireSspiCredentials
                      prepareOutboundPackage:
                        SSPI will continue...
                      --prepareOutboundPackage
                    --sspiBegin
                    ConnectRequest: CONNECT httpbin.org:443 HTTP/1.1
Connection: Keep-Alive
Proxy-Connection: Keep-Alive
Host: httpbin.org
Proxy-Authorization: NTLM [NTLM_TOKEN_1]
                    Sending CONNECT with NTLM Type1 message to proxy...
                    Receiving NTLM TYPE2 message from proxy...
                    type1ResponseHeader: HTTP/1.1 407 Proxy Authentication Required
Server: squid/5.7
...
Proxy-Authenticate: NTLM [NTLM_CHALLENGE]
...
                    NtlmChallenge: [NTLM_CHALLENGE]
                    sspiNext:
                      prepareOutboundPackage:
                        SSPI finished.
                      --prepareOutboundPackage
                    --sspiNext
                    Sending CONNECT with NTLM Type3 message to proxy...
                    type3ResponseHeader: HTTP/1.1 200 Connection established

                    contentLength: 0
                  --proxyConnectNtlm
                  HTTP proxy connect success
                --httpProxyConnect
                convertToTls(203ms):
                  Clearing TLS client certificates.
                  clientHandshake(203ms):
                    The client cert chain is NULL.
                    cacheClientCerts:
                      Cached TLS client certificates.
                      Client cert chain is NULL.
                    --cacheClientCerts
                    clientHandshake2(203ms):
                      sendClientHello(15ms):
                        clientHello_buildMessage(15ms):
                          gen_key_shares(15ms):
                            generateNewKey_ecc(15ms):
                              loadCurveByName:
                                name: secp256r1
                              --loadCurveByName
                            --generateNewKey_ecc
                          --gen_key_shares
                        --clientHello_buildMessage
                      --sendClientHello
                      readHandshakeMessages(188ms):
                        maxToReceive: 20260
                        Connection closed by peer.
                        passiveClose(16ms):
                          Passive socket closing complete.
                        --passiveClose
                        Failed to read TLS record (2)
                        tlsRec_msg: 0
                        msgLen: 20527
                        nReadNBytes: 0
                        status: 0
                      --readHandshakeMessages
                    --clientHandshake2
                  --clientHandshake
                  Client handshake failed. (1)
                  connectionClosed: 1
                --convertToTls
                Failed to establish SSL/TLS channel after HTTP proxy connection.
              --socket2Connect
              connect: Socket connection closed.
            --openHttpConnection
          --quickHttpRequest
        --a_quickReq
      --quickRequestDb
      Failed.
    --quickRequestObj
  --QuickGetObj
--ChilkatLog

内容的提问来源于stack exchange,提问作者Serg Dmyrtuk

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.01 14:29:52