温馨提示×

如何测试linux openssl连接

小樊
42
2026-09-19 21:04:56
栏目: 云计算

在 Linux 下测试 OpenSSL 连接通常用于验证 TLS/SSL 服务是否可用、证书是否正确、端口是否通等。下面按常见场景说明。


一、最常用:测试 HTTPS / TLS 连接

1. 基本连接测试

openssl s_client -connect example.com:443
  • 成功会显示证书信息、握手过程
  • 失败会提示 connect: Connection refused 或 SSL handshake failed

2. 显示详细调试信息

openssl s_client -connect example.com:443 -debug

3. 只查看证书(不显示全部内容)

echo | openssl s_client -connect example.com:443 2>/dev/null | openssl x509 -noout -text

二、指定 SNI(虚拟主机必备)

很多服务器依赖 SNI:

openssl s_client -connect example.com:443 -servername example.com

三、测试特定协议版本

TLS 1.2

openssl s_client -connect example.com:443 -tls1_2

TLS 1.3

openssl s_client -connect example.com:443 -tls1_3

旧版本(不推荐)

openssl s_client -connect example.com:443 -ssl3

四、测试 SMTP / POP3 / IMAP 等 SSL 服务

SMTP(465)

openssl s_client -connect mail.example.com:465

IMAP(993)

openssl s_client -connect imap.example.com:993

连接后可手动输入协议命令(如 CAPABILITY)。


五、测试本地服务(如 Nginx / 自签证书)

openssl s_client -connect 127.0.0.1:443

或指定 CA:

openssl s_client -connect 127.0.0.1:443 -CAfile /path/ca.crt

六、验证证书链是否完整

openssl s_client -connect example.com:443 -showcerts

检查是否包含:

  • 服务器证书
  • 中间证书
  • 根证书

七、测试端口是否通(非 SSL)

nc -zv example.com 443

或

telnet example.com 443

八、常见问题排查

问题 原因
timeout 防火墙 / 端口未开
certificate verify failed CA 缺失或自签
handshake failure 协议或加密套件不支持
wrong certificate SNI 未指定

如果你有 具体服务(Nginx / MySQL / Redis / MQTT) 或 错误日志,我可以给你更精确的测试命令。

0 踩