Giter Site home page Giter Site logo

使用国密提供的cUrl工具(gmcurl_linux_x64)测试openresty+gmssl2.5.4国密双证书时,时通时不通,详细信息如下: about gmssl HOT 2 CLOSED

liu-allen avatar liu-allen commented on June 1, 2024
使用国密提供的cUrl工具(gmcurl_linux_x64)测试openresty+gmssl2.5.4国密双证书时,时通时不通,详细信息如下:

from gmssl.

Comments (2)

liu-allen avatar liu-allen commented on June 1, 2024

测试发现即使不校验证书,直接这样访问服务端也会报错:
guomi_cert/gmcurl_linux_x64 --gmssl -k --trace - https://localhost:1820/apple
详情:
GM Version: 1.0.2 Ported from curl/7.88.1 by www.gmssl.cn
GM options:
--gmssl, use TLCP protocol
--cert, use sm2 sig pem cert
--key, use sm2 sig pem key
--cert2, use sm2 enc pem cert
--key2, use sm2 enc pem key
== Info: Trying 127.0.0.1:1820...
== Info: Connected to localhost (127.0.0.1) port 1820 (#0)
== Info: ALPN: offers http/1.1
=> Send SSL data, 5 bytes (0x5)
0000: 16 01 01 00 78 ....x
== Info: (101) (OUT), , Unknown (1):
=> Send SSL data, 120 bytes (0x78)
0000: 01 00 00 74 01 01 4f 0a 72 99 3c f5 f6 51 5c 47 ...t..O.r.<..Q\G
0010: 9a e3 7f 55 ee 99 7d 5c dd 2d 98 4c 0b 6b 63 fb ...U..}.-.L.kc.
0020: 98 c4 05 9e 91 b8 00 00 0e e0 53 e0 51 e0 13 e0 ..........S.Q...
0030: 11 e0 03 e0 01 00 ff 01 00 00 3d 00 00 00 0e 00 ..........=.....
0040: 0c 00 00 09 6c 6f 63 61 6c 68 6f 73 74 00 0b 00 ....localhost...
0050: 04 03 00 01 02 00 0a 00 0c 00 0a 00 1d 00 17 00 ................
0060: 1e 00 19 00 18 00 10 00 0b 00 09 08 68 74 74 70 ............http
0070: 2f 31 2e 31 00 16 00 00 /1.1....
<= Recv SSL data, 5 bytes (0x5)
0000: 16 01 01 00 4a ....J
== Info: (101) (IN), , Unknown (2):
<= Recv SSL data, 74 bytes (0x4a)
0000: 02 00 00 46 01 01 5d 90 5e 82 f0 1f 82 ac 03 84 ...F..].^.......
0010: 51 3b 66 b3 7d e3 35 0f 71 35 06 03 fa d5 9f e5 Q;f.}.5.q5......
0020: f5 fc 17 c8 56 30 20 b8 93 21 43 9d 73 ac 8f 4a ....V0 ..!C.s..J
0030: 1f 55 38 fc 10 2f 3e 41 68 2d 68 4f 7b 82 36 2a .U8../>Ah-hO{.6*
0040: ce 45 57 63 39 a2 40 e0 13 00 .EWc9.@...
<= Recv SSL data, 5 bytes (0x5)
0000: 16 01 01 04 11 .....
== Info: (101) (IN), , Unknown (11):
<= Recv SSL data, 1041 bytes (0x411)
0000: 0b 00 04 0d 00 04 0a 00 02 02 30 82 01 fe 30 82 ..........0...0.
0010: 01 a4 a0 03 02 01 02 02 04 3b 9a ca 01 30 0a 06 .........;...0..
0020: 08 2a 81 1c cf 55 01 83 75 30 79 31 0b 30 09 06 ....U..u0y1.0..
0030: 03 55 04 06 13 02 43 4e 31 10 30 0e 06 03 55 04 .U....CN1.0...U.
0040: 08 0c 07 42 65 69 4a 69 6e 67 31 10 30 0e 06 03 ...BeiJing1.0...
0050: 55 04 07 0c 07 42 65 69 4a 69 6e 67 31 0c 30 0a U....BeiJing1.0.
0060: 06 03 55 04 0a 0c 03 7a 74 65 31 12 30 10 06 03 ..U....zte1.0...
0070: 55 04 03 0c 09 6c 6f 63 61 6c 68 6f 73 74 31 24 U....localhost1$
0080: 30 22 06 09 2a 86 48 86 f7 0d 01 09 01 16 15 6c 0"..
.H........l
0090: 69 75 6b 75 6e 6c 75 6e 31 40 7a 74 65 2e 63 6f [email protected]
00a0: 6d 2e 63 6e 30 1e 17 0d 32 34 30 34 30 38 31 30 m.cn0...24040810
00b0: 35 33 32 30 5a 17 0d 33 34 30 34 30 36 31 30 35 5320Z..340406105
00c0: 33 32 30 5a 30 79 31 0b 30 09 06 03 55 04 06 13 320Z0y1.0...U...
00d0: 02 43 4e 31 10 30 0e 06 03 55 04 08 0c 07 42 65 .CN1.0...U....Be
00e0: 69 4a 69 6e 67 31 10 30 0e 06 03 55 04 07 0c 07 iJing1.0...U....
00f0: 42 65 69 4a 69 6e 67 31 0c 30 0a 06 03 55 04 0a BeiJing1.0...U..
0100: 0c 03 7a 74 65 31 12 30 10 06 03 55 04 03 0c 09 ..zte1.0...U....
0110: 6c 6f 63 61 6c 68 6f 73 74 31 24 30 22 06 09 2a localhost1$0"..*
0120: 86 48 86 f7 0d 01 09 01 16 15 6c 69 75 6b 75 6e .H........liukun
0130: 6c 75 6e 31 40 7a 74 65 2e 63 6f 6d 2e 63 6e 30 [email protected]
0140: 59 30 13 06 07 2a 86 48 ce 3d 02 01 06 08 2a 81 Y0....H.=.....
0150: 1c cf 55 01 82 2d 03 42 00 04 78 3b 29 4f 23 82 ..U..-.B..x;)O#.
0160: 52 97 09 27 1d 5d 7e c1 ee 40 14 4f c7 29 e1 ce R..'.]~[email protected].)..
0170: 6e d3 d6 59 f9 58 e9 d7 47 6f 65 33 16 c2 f4 00 n..Y.X..Goe3....
0180: b7 f8 05 bf 61 72 48 82 97 a9 74 4e 52 8a 09 75 ....arH...tNR..u
0190: a3 2f 67 78 93 db e8 c1 39 37 a3 1a 30 18 30 09 ./gx....97..0.0.
01a0: 06 03 55 1d 13 04 02 30 00 30 0b 06 03 55 1d 0f ..U....0.0...U..
01b0: 04 04 03 02 05 e0 30 0a 06 08 2a 81 1c cf 55 01 ......0......U.
01c0: 83 75 03 48 00 30 45 02 20 08 49 25 d0 a0 92 b7 .u.H.0E. .I%....
01d0: dc d6 40 c7 ed 9f 9d 54 5a 78 fd ed fc 21 e8 18 [email protected]...!..
01e0: f1 27 8d d6 e3 f6 c9 62 3d 02 21 00 a8 3a 4c b5 .'.....b=.!..:L.
01f0: 88 08 73 1f aa ad c3 83 0a 8a 2c c8 cc ab 06 d2 ..s.......,.....
0200: 38 b0 ec a9 d2 ac a3 f1 b3 d3 f7 3e 00 02 02 30 8..........>...0
0210: 82 01 fe 30 82 01 a4 a0 03 02 01 02 02 04 3b 9a ...0..........;.
0220: d1 d1 30 0a 06 08 2a 81 1c cf 55 01 83 75 30 79 ..0...
...U..u0y
0230: 31 0b 30 09 06 03 55 04 06 13 02 43 4e 31 10 30 1.0...U....CN1.0
0240: 0e 06 03 55 04 08 0c 07 42 65 69 4a 69 6e 67 31 ...U....BeiJing1
0250: 10 30 0e 06 03 55 04 07 0c 07 42 65 69 4a 69 6e .0...U....BeiJin
0260: 67 31 0c 30 0a 06 03 55 04 0a 0c 03 7a 74 65 31 g1.0...U....zte1
0270: 12 30 10 06 03 55 04 03 0c 09 6c 6f 63 61 6c 68 .0...U....localh
0280: 6f 73 74 31 24 30 22 06 09 2a 86 48 86 f7 0d 01 ost1$0"...H....
0290: 09 01 16 15 6c 69 75 6b 75 6e 6c 75 6e 31 40 7a ....liukunlun1@z
02a0: 74 65 2e 63 6f 6d 2e 63 6e 30 1e 17 0d 32 34 30 te.com.cn0...240
02b0: 34 30 38 31 30 35 34 31 32 5a 17 0d 33 34 30 34 408105412Z..3404
02c0: 30 36 31 30 35 34 31 32 5a 30 79 31 0b 30 09 06 06105412Z0y1.0..
02d0: 03 55 04 06 13 02 43 4e 31 10 30 0e 06 03 55 04 .U....CN1.0...U.
02e0: 08 0c 07 42 65 69 4a 69 6e 67 31 10 30 0e 06 03 ...BeiJing1.0...
02f0: 55 04 07 0c 07 42 65 69 4a 69 6e 67 31 0c 30 0a U....BeiJing1.0.
0300: 06 03 55 04 0a 0c 03 7a 74 65 31 12 30 10 06 03 ..U....zte1.0...
0310: 55 04 03 0c 09 6c 6f 63 61 6c 68 6f 73 74 31 24 U....localhost1$
0320: 30 22 06 09 2a 86 48 86 f7 0d 01 09 01 16 15 6c 0"..
.H........l
0330: 69 75 6b 75 6e 6c 75 6e 31 40 7a 74 65 2e 63 6f [email protected]
0340: 6d 2e 63 6e 30 59 30 13 06 07 2a 86 48 ce 3d 02 m.cn0Y0....H.=.
0350: 01 06 08 2a 81 1c cf 55 01 82 2d 03 42 00 04 71 ...
...U..-.B..q
0360: 4d 41 d1 b8 82 10 c2 86 0b 37 b4 44 b4 92 25 0a MA.......7.D..%.
0370: ce b7 ae ae 7a 77 fc 7c 74 20 68 da 6e 6b b7 6b ....zw.|t h.nk.k
0380: 75 28 b6 dd 9d 50 96 7a 73 1e 4e f4 ba 1f 35 cb u(...P.zs.N...5.
0390: 9c 1a 5e ab c3 28 58 cf 78 c7 64 85 cc 4a a4 a3 ..^..(X.x.d..J..
03a0: 1a 30 18 30 09 06 03 55 1d 13 04 02 30 00 30 0b .0.0...U....0.0.
03b0: 06 03 55 1d 0f 04 04 03 02 03 38 30 0a 06 08 2a ..U.......80...*
03c0: 81 1c cf 55 01 83 75 03 48 00 30 45 02 20 2b 0a ...U..u.H.0E. +.
03d0: d2 a0 0a 6e 04 7b 91 ad 46 60 24 8a 35 e3 8d dd ...n.{..F`$.5...
03e0: 0b 1b 3f fa 9c de 0a a8 97 aa 19 1f 64 40 02 21 ..?.........d@.!
03f0: 00 fa 8a 03 58 b5 e8 43 b4 1a f8 f8 3d f4 21 c6 ....X..C....=.!.
0400: 62 ed 82 2c b4 4c 86 63 04 1a 4f 26 f9 52 81 b0 b..,.L.c..O&.R..
0410: 91 .
<= Recv SSL data, 5 bytes (0x5)
0000: 16 01 01 00 4e ....N
== Info: (101) (IN), , Unknown (12):
<= Recv SSL data, 78 bytes (0x4e)
0000: 0c 00 00 4a 00 48 30 46 02 21 00 df fc 47 3d 49 ...J.H0F.!...G=I
0010: dd 5e 48 52 27 18 cc ed 5f 21 59 db ab 79 7b 68 .^HR'...!Y..y{h
0020: 74 40 a8 e8 ef a5 3e 87 49 7f 2b 02 21 00 c6 36 t@....>.I.+.!..6
0030: 71 d0 33 23 7c 2f 12 74 c2 0e d4 ff d9 6f b6 e9 q.3#|/.t.....o..
0040: c8 0f 3f c6 0c 67 e1 1a de 45 48 07 52 94 ..?..g...EH.R.
<= Recv SSL data, 5 bytes (0x5)
0000: 16 01 01 00 04 .....
== Info: (101) (IN), , Unknown (14):
<= Recv SSL data, 4 bytes (0x4)
0000: 0e 00 00 00 ....
=> Send SSL data, 5 bytes (0x5)
0000: 16 01 01 00 a3 .....
== Info: (101) (OUT), , Unknown (16):
=> Send SSL data, 163 bytes (0xa3)
0000: 10 00 00 9f 00 9d 30 81 99 02 21 00 ba 45 eb 85 ......0...!..E..
0010: 3e 26 9b 88 fd 58 97 ae 65 02 99 f6 f7 cd e1 2e >&...X..e.......
0020: 1c 70 3b e3 d5 91 44 19 f8 46 8f 8c 02 20 08 0b .p;...D..F... ..
0030: 2a 03 6a 28 6a c8 5b 5b 92 11 37 ce d2 a4 a3 4c *.j(j.[[..7....L
0040: 68 dc 12 aa c5 34 ff 87 a2 0b 01 08 02 b2 04 20 h....4.........
0050: 0c c5 4c 54 5d 05 53 fa 35 11 73 53 70 fa 1a 78 ..LT].S.5.sSp..x
0060: 48 8b e4 03 ff ed f9 2d 0b 58 e6 41 d0 0e 0b 4f H......-.X.A...O
0070: 04 30 10 f5 01 39 94 92 e9 ae a3 93 26 3b 18 76 .0...9......&;.v
0080: eb 64 30 57 66 ab 08 4d df 26 7a 4b ac bb 04 4f .d0Wf..M.&zK...O
0090: 52 2b f6 6c 21 10 5c a2 94 1b de 57 bc d9 bb 3a R+.l!.....W...:
00a0: ca 92 00 ...
=> Send SSL data, 5 bytes (0x5)
0000: 14 01 01 00 01 .....
== Info: (101) (OUT), , Change cipher spec (1):
=> Send SSL data, 1 bytes (0x1)
0000: 01 .
=> Send SSL data, 5 bytes (0x5)
0000: 16 01 01 00 50 ....P
== Info: (101) (OUT), , Unknown (20):
=> Send SSL data, 16 bytes (0x10)
0000: 14 00 00 0c 0a 59 96 31 8b 81 bb 47 5f a6 21 8e .....Y.1...G
.!.
<= Recv SSL data, 5 bytes (0x5)
0000: 15 01 01 00 02
.....
== Info: (101) (IN), , decrypt error (563):
<= Recv SSL data, 2 bytes (0x2)
0000: 02 33 .3
== Info: OpenSSL/1.1.1z: error:1409441B:SSL routines:ssl3_read_bytes:tlsv1 alert decrypt error
== Info: Closing connection 0
curl: (35) OpenSSL/1.1.1z: error:1409441B:SSL routines:ssl3_read_bytes:tlsv1 alert decrypt error

from gmssl.

liu-allen avatar liu-allen commented on June 1, 2024

应该是国密发布的cRul工具不兼容gmssl2.5.4版本,使用360国密浏览器通信成功

from gmssl.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.