通过Squid代理时Chilkat HTTP TLS握手失败的配置求助
Chilkat HTTP v11.4.0通过NTLM认证的Squid SSL Bump代理发起HTTPS请求时TLS握手失败的问题
问题场景
使用Chilkat HTTP v11.4.0(.NET版本)通过启用NTLM认证与SSL Bump的企业级Squid代理发起HTTPS请求,NTLM认证已成功返回200 Connection established,但TLS握手始终失败,错误日志如下:
NTLM proxy connect success convertToTls: sendClientHello - OK readHandshakeMessages: v84.84, ct=72, sz=20527 Connection closed by peer. Failed to read TLS record (2)
已尝试的操作
- 设置
SslProtocol = "TLS 1.2"或"TLS 1.3 or higher" - 设置
SslAllowedCiphers = "best-practices" - 调用
TrustedRoots.Activate()并搭配Squid CA证书 - 切换
RequireSslCertVerify = true/false - 设置
glob.DefaultNtlmVersion = 1
对比验证
使用HttpClient(Windows SChannel)通过同一代理可正常完成请求。
Wireshark分析结论
返回200 Connection established后,Squid针对Chilkat的ClientHello返回HTTP/1.1 400 Bad Request(Cloudflare),而HttpClient的ClientHello可正常通过。两者核心差异在于:
- HttpClient发送的
key_share扩展包含x25519, secp256r1, secp384r1三种椭圆曲线 - Chilkat仅发送
secp256r1一种曲线
解决方案
可以通过配置Chilkat的SslEccCurves属性,让其在ClientHello中包含多种椭圆曲线,匹配HttpClient的行为:
在建立代理连接后、调用ConvertToTls之前,设置HttpConnection对象的SslEccCurves参数:
// 假设httpConn是已创建的Chilkat.HttpConnection对象 httpConn.SslEccCurves = "x25519, secp256r1, secp384r1";
该属性用于指定TLS握手时ClientHello中key_share扩展包含的椭圆曲线列表,设置后Chilkat会生成对应曲线的密钥共享信息,与HttpClient的行为一致,从而通过Squid代理的SSL Bump校验。
同时建议保持SslProtocol设置为"TLS 1.2"或更高版本,确保支持key_share扩展。
详细Chilkat日志
ChilkatLog: QuickGetObj(563ms): DllDate: Mar 29 2026 ChilkatVersion: 11.4.0 UnlockStatusMsg: Unlocked for 30-day trial UnlockStatus: 1 Architecture: Little Endian; 64-bit Language: Visual C++ 2022 / x64 VerboseLogging: 1 quickRequestObj(563ms): url: https://httpbin.org/get verb: GET quickRequestDb(563ms): url: https://httpbin.org/get getHttpConnectionByUrl: findAddHttpConn: sbHostname0: httpbin.org port: 443 bTls: True bForceNewConnection: False sbProxyDomain: [PROXY_HOST] proxyPort: [PROXY_PORT] numExistingConnections: 0 lookingForHost: [httpbin.org] lookingForPort: 443 lookingForProxy: [[PROXY_HOST]] Will need to open a new connection. --findAddHttpConn --getHttpConnectionByUrl a_quickReq(547ms): quickHttpRequest(547ms): httpVerb: GET url: https://httpbin.org/get openHttpConnection(547ms): Opening connection through an HTTP proxy. proxyDomain: [PROXY_HOST] proxyPort: [PROXY_PORT] httpHostname: httpbin.org httpPort: 443 tls: True bUsingHttpProxy: True httpProxyAuthMethod: m_httpProxyTls: False Using a CONNECT tunnel... socket2Connect(547ms): Using HTTP proxy CONNECT... httpProxyConnect(344ms): proxyAuthMethod: proxyHostname: [PROXY_HOST] proxyPort: [PROXY_PORT] No proxy authentication method specified. proxyUsername is empty proxyPassword is empty connectSocket_v2(31ms): domainOrIpAddress: [PROXY_HOST] port: [PROXY_PORT] connectTimeoutMs: 30000 This is an IPV4 numeric address. createSocket_ipv4: Setting SO_SNDBUF size sendBufSize: 262144 Setting SO_RCVBUF size recvBufSize: 4194304 --createSocket_ipv4 connect(31ms): Waiting for the connect to complete... connectTimeoutMs: 30000 myIP: [CLIENT_IP] myPort: 56403 socket connect successful. --connect --connectSocket_v2 connectRequest: CONNECT httpbin.org:443 HTTP/1.1 Connection: Keep-Alive Proxy-Connection: Keep-Alive Host: httpbin.org:443 connectResponseHeader: HTTP/1.1 407 Proxy Authentication Required Server: squid/5.7 ... The server supports the NTLM proxy authentication method. Re-trying with NTLM proxy authentication... proxyConnectNtlm(313ms): login: domain: proxyAuthMethod: password is empty Will use MS SSPI... connectSocket_v2(16ms): domainOrIpAddress: [PROXY_HOST] port: [PROXY_PORT] connectTimeoutMs: 30000 This is an IPV4 numeric address. createSocket_ipv4: Setting SO_SNDBUF size sendBufSize: 262144 Setting SO_RCVBUF size recvBufSize: 4194304 --createSocket_ipv4 connect(16ms): Waiting for the connect to complete... connectTimeoutMs: 30000 myIP: [CLIENT_IP] myPort: 56404 socket connect successful. --connect --connectSocket_v2 Using NTLM as the default SSPI package name... sspiBegin: acquireSspiCredentials: sspi_username: sspi_domain: password is empty Using default NTLM credentials. --acquireSspiCredentials prepareOutboundPackage: SSPI will continue... --prepareOutboundPackage --sspiBegin ConnectRequest: CONNECT httpbin.org:443 HTTP/1.1 Connection: Keep-Alive Proxy-Connection: Keep-Alive Host: httpbin.org Proxy-Authorization: NTLM [NTLM_TOKEN_1] Sending CONNECT with NTLM Type1 message to proxy... Receiving NTLM TYPE2 message from proxy... type1ResponseHeader: HTTP/1.1 407 Proxy Authentication Required Server: squid/5.7 ... Proxy-Authenticate: NTLM [NTLM_CHALLENGE] ... NtlmChallenge: [NTLM_CHALLENGE] sspiNext: prepareOutboundPackage: SSPI finished. --prepareOutboundPackage --sspiNext Sending CONNECT with NTLM Type3 message to proxy... type3ResponseHeader: HTTP/1.1 200 Connection established contentLength: 0 --proxyConnectNtlm HTTP proxy connect success --httpProxyConnect convertToTls(203ms): Clearing TLS client certificates. clientHandshake(203ms): The client cert chain is NULL. cacheClientCerts: Cached TLS client certificates. Client cert chain is NULL. --cacheClientCerts clientHandshake2(203ms): sendClientHello(15ms): clientHello_buildMessage(15ms): gen_key_shares(15ms): generateNewKey_ecc(15ms): loadCurveByName: name: secp256r1 --loadCurveByName --generateNewKey_ecc --gen_key_shares --clientHello_buildMessage --sendClientHello readHandshakeMessages(188ms): maxToReceive: 20260 Connection closed by peer. passiveClose(16ms): Passive socket closing complete. --passiveClose Failed to read TLS record (2) tlsRec_msg: 0 msgLen: 20527 nReadNBytes: 0 status: 0 --readHandshakeMessages --clientHandshake2 --clientHandshake Client handshake failed. (1) connectionClosed: 1 --convertToTls Failed to establish SSL/TLS channel after HTTP proxy connection. --socket2Connect connect: Socket connection closed. --openHttpConnection --quickHttpRequest --a_quickReq --quickRequestDb Failed. --quickRequestObj --QuickGetObj --ChilkatLog
内容的提问来源于stack exchange,提问作者Serg Dmyrtuk
相关产品推荐
相关产品推荐

