curl/wget 无法获取自签或无效证书URL内容求助~

curl/wget 无法获取自签或无效证书URL内容
错误:routines:ssl_choose_client_version:unsupported protocol

由于是内网访问,证书为自签。无法获取正常内容,显示openssl报错!
其他公网可信域名均OK。

系统:CENTOS8
curl版本:

curl 7.61.1 (x86_64-redhat-linux-gnu) libcurl/7.61.1 OpenSSL/1.1.1c zlib/1.2.11 brotli/1.0.6 libidn2/2.0.5 libpsl/0.20.2 (+libidn2/2.0.5) libssh/0.8.5/openssl/zlib nghttp2/1.33.0
Release-Date: 2018-09-05
Protocols: dict file ftp ftps gopher http https imap imaps ldap ldaps pop3 pop3s rtsp scp sftp smb smbs smtp smtps telnet tftp 
Features: AsynchDNS IDN IPv6 Largefile GSS-API Kerberos SPNEGO NTLM NTLM_WB SSL libz brotli TLS-SRP HTTP2 UnixSockets HTTPS-proxy PSL Metalink 

curl访问如下:

[root]# curl -k https://xxx.xx:2083
curl: (35) error:1425F102:SSL routines:ssl_choose_client_version:unsupported protocol

wget访问如下:

[root]# wget --no-check-certificate https://xxx.xx:2083
--2020-02-11 03:00:23--  https://xxx.xx:2083/
Resolving xxx.xx (xxx.xx)... 1.9.1.2
Connecting to xxx.xx (xxx.xx)|1.9.1.2|:2083... connected.
GnuTLS: A packet with illegal or unsupported version was received.
Unable to establish SSL connection.
阅读 7.4k
1 个回答

update-crypto-policies --set LEGACY
systemctl restart sssd

撰写回答
你尚未登录,登录后可以
  • 和开发者交流问题的细节
  • 关注并接收问题和回答的更新提醒
  • 参与内容的编辑和改进,让解决方法与时俱进