在 Linux 下测试 OpenSSL 连接通常用于验证 TLS/SSL 服务是否可用、证书是否正确、端口是否通等。下面按常见场景说明。
openssl s_client -connect example.com:443
connect: Connection refused 或 SSL handshake failedopenssl s_client -connect example.com:443 -debug
echo | openssl s_client -connect example.com:443 2>/dev/null | openssl x509 -noout -text
很多服务器依赖 SNI:
openssl s_client -connect example.com:443 -servername example.com
openssl s_client -connect example.com:443 -tls1_2
openssl s_client -connect example.com:443 -tls1_3
openssl s_client -connect example.com:443 -ssl3
openssl s_client -connect mail.example.com:465
openssl s_client -connect imap.example.com:993
连接后可手动输入协议命令(如 CAPABILITY)。
openssl s_client -connect 127.0.0.1:443
或指定 CA:
openssl s_client -connect 127.0.0.1:443 -CAfile /path/ca.crt
openssl s_client -connect example.com:443 -showcerts
检查是否包含:
nc -zv example.com 443
或
telnet example.com 443
| 问题 | 原因 |
|---|---|
| timeout | 防火墙 / 端口未开 |
| certificate verify failed | CA 缺失或自签 |
| handshake failure | 协议或加密套件不支持 |
| wrong certificate | SNI 未指定 |
如果你有 具体服务(Nginx / MySQL / Redis / MQTT) 或 错误日志,我可以给你更精确的测试命令。