2015-08-14 99 views
0

Perl version is = v5.12.4Perl的用户代理将无法连接到服务器TLS1.2

LWP::UserAgent->VERSION = 6.03

#.... 
    # Setup HTTP request 
    my $req = HTTP::Request->new(); 
    $req->method($cmd); 
    $req->uri($uri); 
    $req->header('content-type' => 'application/json'); 
    $req->header('Accept' => 'application/json'); 

    # Setup the call 
    my $ua = LWP::UserAgent->new(ssl_opts => { verify_hostname => 0, 
               SSL_version => 'tlsv12' }); 
    $ua->timeout(60); 

    # Do the call 
    my $resp = $ua->request($req); 
    # .... 

的HTTP代码始终是500,我得到的错误信息 -

"Can't connect to 10.0.0.1:443".

我曾尝试过各种SSL_versions串tlsv12,tslv1。 2,TSLv1,TLSv12,TLS等无济于事。我知道服务器期望TLS 1.2。通过curl进行的相同HTTP调用工作正常。

额外的调试输出..

Perl -MIO::Socket::SSL=debug4 powervc_cli.pl -O 
DEBUG: .../IO/Socket/SSL.pm:193: set domain to 2 
DEBUG: .../IO/Socket/SSL.pm:1545: new ctx 140528264056208 
DEBUG: .../IO/Socket/SSL.pm:334: socket not yet connected 
DEBUG: .../IO/Socket/SSL.pm:336: socket connected 
DEBUG: .../IO/Socket/SSL.pm:349: ssl handshake not started 
DEBUG: .../IO/Socket/SSL.pm:379: set socket to non-blocking to enforce timeout=60 
DEBUG: .../IO/Socket/SSL.pm:392: Net::SSLeay::connect -> -1 
DEBUG: .../IO/Socket/SSL.pm:402: ssl handshake in progress 
DEBUG: .../IO/Socket/SSL.pm:412: waiting for fd to become ready: SSL wants a read first 
DEBUG: .../IO/Socket/SSL.pm:432: socket ready, retrying connect 
DEBUG: .../IO/Socket/SSL.pm:392: Net::SSLeay::connect -> 0 
DEBUG: .../IO/Socket/SSL.pm:440: connection failed - connect returned 0 
DEBUG: .../IO/Socket/SSL.pm:1276: SSL connect attempt failed because of handshake problemserror:00000000:lib(0):func(0):reason(0) 

DEBUG: .../IO/Socket/SSL.pm:1276: IO::Socket::INET6 configuration failederror:00000000:lib(0):func(0):reason(0) 

DEBUG: .../IO/Socket/SSL.pm:1582: free ctx 140528264056208 open=140528264056208 
DEBUG: .../IO/Socket/SSL.pm:1590: OK free ctx 140528264056208 

请帮帮忙! -Eddie

+1

500是服务器端代码。你看过网络服务器错误日志中的内容吗? –

+1

@MarcB:LWP在错误中自行生成这样的500个代码,以将错误打包成有效的HTTP响应。 –

+0

哼.... LWP消息通常更长。 – ikegami

回答

2
DEBUG: .../IO/Socket/SSL.pm:392: Net::SSLeay::connect -> 0 
DEBUG: .../IO/Socket/SSL.pm:440: connection failed - connect returned 0 
DEBUG: .../IO/Socket/SSL.pm:1276: SSL connect attempt failed because of handshake problemserror:00000000:lib(0):func(0):reason(0) 

这看起来像服务器不喜欢客户端作为SSL握手发送的内容,因此服务器关闭了连接。为什么服务器这样做并不明确,但您可能会在服务器端找到错误消息。

Same HTTP call through curl works fine.

如果这真的是一个HTTP调用(即无HTTPS)你的卷曲程度超过你的问题做的是,服务器期望HTTP W/O SSL但LWP代码使用带有SSL的HTTP(HTTPS)。但是,如果使用curl的HTTPS调用成功,那么可以通过使用curl成功调用数据包来捕获数据包,并使用LWP不成功调试问题并比较握手。

I have tried various SSL_versions string tlsv12, tslv1.2, TSLv1, TLSv12, TLS, etc. to no avail.

随着IO ::插座:: SSL它将接受TLSv12和TLSv1_2为TLS 1.2,并使用TLSv1为TLS 1 *的最新版本,不区分大小写。仅指定“TLS”将导致IO :: Socket :: SSL嘎嘎声。老版本的IO :: Socket :: SSL(2012之前的版本1.70之前)忽略了无效设置。另请参阅描述设置的文档。