当前位置:网站首页>Centso7 OpenSSL error Verify return code: 20 (unable to get local issuer certificate)
Centso7 OpenSSL error Verify return code: 20 (unable to get local issuer certificate)
2022-07-07 13:25:00 【Poplar siege lion】
Problem recurrence :
because centos7 default openssl The version is 1.1.0k, When I compile the media service , need openssl edition 1.1.1 above , All previous lower versions deleted openssl, Manually compiled a 1.1.1k Version of , The media service is running normally , also CA Verify normal .
As a result, the server was powered off and restarted last night , When I was getting Telecom MQ Data time ,openssl Has been an error ,Unhandled exception. System.Security.Authentication.AuthenticationException:The remote certificate was rejected by the provided RemoteCertificateValidat
Use openssl Command to test the connection status :
openssl s_client -connect msgpush.ctwing.cn:16651
The following results are obtained :

Tips , Unable to load local certificate . Various schemes are used , Compile various versions of openssl, Not yet. .
All kinds of helpless , Can only analyze the online environment openssl( Online is ECS ,openssl by 1.02K) With the local server openssl The difference between , Another few painful hours . Finally checking openssl Version of the command , See the clue , This order is very important :
openssl version -d
Results printed online :

The result of the local server :

Enter online environment openssl The catalog of : Carry out orders
ll
Show results :

The key point is this directory , Look at the part marked in red , The soft link here is the location of the certificate
Let's see , Local server

You can see , I don't see the soft link of the certificate ,
So the reason for everything is here , Didn't tell the system openssl The location of the certificate used . So we can create a soft link .
ln -s /etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem cert.pem
The results are as follows :
When we use... Again openssl When the test command of : succeed ,

边栏推荐
- Read PG in data warehouse in one article_ stat
- [Presto profile series] timeline use
- 如何让electorn打开的新窗口在window任务栏上面
- 【学习笔记】线段树选做
- 【黑马早报】华为辟谣“军师”陈春花;恒驰5预售价17.9万元;周杰伦新专辑MV 3小时播放量破亿;法华寺回应万元月薪招人...
- [learning notes] segment tree selection
- How to reset Google browser? Google Chrome restore default settings?
- ESP32系列专栏
- 迅为iTOP-IMX6ULL开发板Pinctrl和GPIO子系统实验-修改设备树文件
- 10 张图打开 CPU 缓存一致性的大门
猜你喜欢
随机推荐
Mongodb command summary
Simple and easy-to-use code specification
Mongodb slice summary
Mongodb meets spark (for integration)
Pay close attention to the work of safety production and make every effort to ensure the safety of people's lives and property
一文读懂数仓中的pg_stat
Introduce six open source protocols in detail (instructions for programmers)
Isprs2021/ remote sensing image cloud detection: a geographic information driven method and a new large-scale remote sensing cloud / snow detection data set
Conversion from non partitioned table to partitioned table and precautions
Coscon'22 community convening order is coming! Open the world, invite all communities to embrace open source and open a new world~
聊聊伪共享
Distributed transaction solution
Unity build error: the name "editorutility" does not exist in the current context
JS determines whether an object is empty
COSCon'22 社区召集令来啦!Open the World,邀请所有社区一起拥抱开源,打开新世界~
[learning notes] zkw segment tree
服务器到服务器 (S2S) 事件 (Adjust)
Cookie and session comparison
LIS 最长上升子序列问题(动态规划、贪心+二分)
信号强度(RSSI)知识整理









