【问题标题】:Unable to access github via curl无法通过 curl 访问 github
【发布时间】:2012-02-13 08:52:24
【问题描述】:

尝试使用以下命令访问 github 失败并出现验证失败错误。我应该怎么做才能解决这个问题

C:\software\curl-7.23.1-win64-ssl-sspi>curl -i https://api.github.com

curl: (60) SSL certificate problem, verify that the CA cert is OK. Details:
error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed
More details here: http://curl.haxx.se/docs/sslcerts.html

curl performs SSL certificate verification by default, using a "bundle"
of Certificate Authority (CA) public keys (CA certs). If the default
bundle file isn't adequate, you can specify an alternate file
using the --cacert option.
If this HTTPS server uses a certificate signed by a CA represented in
the bundle, the certificate verification probably failed due to a
problem with the certificate (it might be expired, or the name might
not match the domain name in the URL).
If you'd like to turn off curl's verification of the certificate, use the -k (or --  insecure) option.

【问题讨论】:

    标签: curl github


    【解决方案1】:

    使用 msysgit,有时我必须再次指定 http.sslcainfo 以便 msysgit 正确获取正确的 CA 证书文件。

     git config --system http.sslcainfo \bin/curl-ca-bundle.crt
    

    (还有presented herecomments of the GitHub smart http page
    如果这不起作用:

    • 尝试指定完整路径:git config --system http.sslcainfo /c/path/to/msysgit/bin/curl-ca-bundle.crt,如blog post所示:

    更简单的解决方法是将 http.sslcainfo 设置为 msysGit 安装的 bin 文件夹中 curl-ca-bundle.crt 文件的绝对路径:

    $ git config --global http.sslcainfo "/c/Program Files (x86)/Git/bin/curl-ca-bundle.crt"
    

    我选择在 --global 级别执行此操作,因此该设置不会被未来的 msysGit 安装覆盖。

    【讨论】:

      【解决方案2】:

      如果您不想使用 --cacert 选项(为什么?),如文本中所建议的,请使用关于 -k 的另一个建议

      >curl -i -k https://api.github.com
      HTTP/1.1 302 Found
      Server: nginx/1.0.4
      Date: Mon, 13 Feb 2012 09:14:24 GMT
      Content-Type: text/html;charset=utf-8
      Connection: keep-alive
      Status: 302 Found
      X-RateLimit-Limit: 5000
      ETag: "d41d8cd98f00b204e9800998ecf8427e"
      Location: http://developer.github.com
      X-RateLimit-Remaining: 4999
      Content-Length: 0
      

      【讨论】:

      • 注意:此选项禁用 SSL 证书验证。 --cacert 是首选方式。
      • 使用 cURL 访问 GitHub,使 SSL 有点多余。使用-Lk 标志也可以跟随任何重定向。
      猜你喜欢
      • 2012-06-19
      • 1970-01-01
      • 2017-03-01
      • 2021-08-27
      • 1970-01-01
      • 2011-10-19
      • 1970-01-01
      • 2019-07-11
      • 1970-01-01
      相关资源
      最近更新 更多