【发布时间】:2021-05-24 06:00:03
【问题描述】:
root@sclrdev:/home/sclr/certs/FreshCerts# curl --ftp-ssl --verbose ftp://{abc}/ -u trup:trup --cacert /etc/ssl/certs/ca-certificates.crt
* About to connect() to {abc} port 21 (#0)
* Trying {abc}...
* Connected to {abc} ({abc}) port 21 (#0)
< 220-Cerberus FTP Server - Home Edition
< 220-This is the UNLICENSED Home Edition and may be used for home, personal use only
< 220-Welcome to Cerberus FTP Server
< 220 Created by Cerberus, LLC
> AUTH SSL
< 234 Authentication method accepted
* successfully set certificate verify locations:
* CAfile: /etc/ssl/certs/ca-certificates.crt
CApath: /etc/ssl/certs
* SSLv3, TLS handshake, Client hello (1):
* SSLv3, TLS handshake, Server hello (2):
* SSLv3, TLS handshake, CERT (11):
* SSLv3, TLS alert, Server hello (2):
* SSL certificate problem: unable to get local issuer certificate
* Closing connection 0
curl: (60) SSL certificate problem: unable to get local issuer certificate
More details here: http://curl.haxx.se/docs/sslcerts.html
curl performs SSL certificate verification by default, using a "bundle"
of Certificate Authority (CA) public keys (CA certs). If the default
bundle file isn't adequate, you can specify an alternate file
using the --cacert option.
If this HTTPS server uses a certificate signed by a CA represented in
the bundle, the certificate verification probably failed due to a
problem with the certificate (it might be expired, or the name might
not match the domain name in the URL).
If you'd like to turn off curl's verification of the certificate, use
the -k (or --insecure) option.
【问题讨论】:
-
我也遇到过类似的问题。这对我有用stackoverflow.com/a/29649024
-
就我而言,superuser.com/a/719047/137881 提供了帮助。
-
// ,在我的情况下,我从向 HashiCorp Vault 服务器发出 curl 请求时收到此错误,直到我安装了 X509 证书,其中的最终实体/中间体/根仅以相反的顺序,每个这是 Base64 编码的。
-
我希望有朝一日主流工具,每时每刻都在使用数千次,在出错的情况下可以有清晰简洁的调试信息。在某些时候,这是一个笑话,说真的,这并不难。
标签: curl ssl openssl ssl-certificate x509certificate