報錯信息
提示:cURL error 35: SSL connect error
排錯
檢查
目前有一臺機器正常,另一臺機器不行。
正常的機器:
curl -V
curl 7.19.7 (x86_64-redhat-linux-gnu) libcurl/7.19.7 NSS/3.27.1 zlib/1.2.3 libidn/1.18 libssh2/1.4.2
Protocols: tftp ftp telnet dict ldap ldaps http file https ftps scp sftp
Features: GSS-Negotiate IDN IPv6 Largefile NTLM SSL libz
rpm -qa | grep nss
nss-sysinit-3.28.4-4.el6_9.x86_64
openssh-clients-5.3p1-104.el6.x86_64
nss-util-3.28.4-1.el6_9.x86_64
nss-3.28.4-4.el6_9.x86_64
openssl-1.0.1e-30.el6.11.x86_64
nss-softokn-freebl-3.14.3-23.3.el6_8.x86_64
nss-tools-3.28.4-4.el6_9.x86_64
openssl-devel-1.0.1e-30.el6.11.x86_64
nss-softokn-3.14.3-23.3.el6_8.x86_64
openssh-5.3p1-104.el6.x86_64
openssh-server-5.3p1-104.el6.x86_64
rpm -qa | grep curl
libcurl-7.19.7-53.el6_9.x86_64
libcurl-devel-7.19.7-53.el6_9.x86_64
curl-7.19.7-53.el6_9.x86_64
python-pycurl-7.19.0-8.el6.x86_64
異常機器:
curl -V
curl 7.19.7 (x86_64-redhat-linux-gnu) libcurl/7.19.7 NSS/3.21 Basic ECC zlib/1.2.3 libidn/1.18 libssh2/1.4.2
Protocols: tftp ftp telnet dict ldap ldaps http file https ftps scp sftp
Features: GSS-Negotiate IDN IPv6 Largefile NTLM SSL libz
rpm -qa | grep nss
openssh-clients-5.3p1-118.1.el6_8.x86_64
nss-tools-3.28.4-4.el6_9.x86_64
nss_compat_ossl-0.9.6-2.el6_7.x86_64
nss-softokn-freebl-3.14.3-23.3.el6_8.i686
openssl-devel-1.0.1e-57.el6.x86_64
nss-util-3.28.4-1.el6_9.x86_64
nss-3.28.4-4.el6_9.x86_64
openssh-server-5.3p1-118.1.el6_8.x86_64
nss-softokn-freebl-3.14.3-23.3.el6_8.x86_64
openssh-5.3p1-118.1.el6_8.x86_64
openssl-1.0.1e-57.el6.x86_64
nss-sysinit-3.28.4-4.el6_9.x86_64
nss-softokn-3.14.3-23.3.el6_8.x86_64
rpm -qa | grep curl
libcurl-7.19.7-52.el6.x86_64
curl-7.19.7-52.el6.x86_64
python-pycurl-7.19.0-9.el6.x86_64
libcurl-devel-7.19.7-52.el6.x86_64
測試
之前由於.Net 接口切換到nginx 做負載均衡,導致PHP 以https方式 調用 .Net 接口也報同樣的錯誤,當時查到是由於NSS 的bug 導致,所以升級了NSS 只有就正常了。
現在PHP 使用調用微信接口也報cURL error 35: SSL connect error
現在其中正常的一臺,curl -V
之後看到的NSS 是3.27.1
;
異常的一臺是: NSS 3.21
再仔細查看兩臺機器之間的curl 版本,正常的是curl-7.19.7-53.el6_9.x86_64
,異常的是curl-7.19.7-52.el6.x86_64
小版本有區別
解決
yum update curl -y
統一升級到curl-7.19.7-53.el6_9.x86_64