我遇到了一些噩梦,试图让 REE 很好地使用 SSL。
每当我连接到 SSL 站点时:
require 'open-uri'
open 'https://www.google.com'
我收到以下错误:
/Users/jon/.rvm/rubies/ree-1.8.7-2011.03/lib/ruby/1.8/net/http.rb:586:in `connect': SSL_connect returned=1 errno=0 state=SSLv3 read server certificate B: certificate verify failed (OpenSSL::SSL::SSLError)
from /Users/jon/.rvm/rubies/ree-1.8.7-2011.03/lib/ruby/1.8/net/http.rb:586:in `connect'
from /Users/jon/.rvm/rubies/ree-1.8.7-2011.03/lib/ruby/1.8/net/http.rb:553:in `do_start'
from /Users/jon/.rvm/rubies/ree-1.8.7-2011.03/lib/ruby/1.8/net/http.rb:542:in `start'
from /Users/jon/.rvm/rubies/ree-1.8.7-2011.03/lib/ruby/1.8/open-uri.rb:242:in `open_http'
from /Users/jon/.rvm/rubies/ree-1.8.7-2011.03/lib/ruby/1.8/open-uri.rb:616:in `buffer_open'
from /Users/jon/.rvm/rubies/ree-1.8.7-2011.03/lib/ruby/1.8/open-uri.rb:164:in `open_loop'
from /Users/jon/.rvm/rubies/ree-1.8.7-2011.03/lib/ruby/1.8/open-uri.rb:162:in `catch'
from /Users/jon/.rvm/rubies/ree-1.8.7-2011.03/lib/ruby/1.8/open-uri.rb:162:in `open_loop'
from /Users/jon/.rvm/rubies/ree-1.8.7-2011.03/lib/ruby/1.8/open-uri.rb:132:in `open_uri'
from /Users/jon/.rvm/rubies/ree-1.8.7-2011.03/lib/ruby/1.8/open-uri.rb:518:in `open'
from /Users/jon/.rvm/rubies/ree-1.8.7-2011.03/lib/ruby/1.8/open-uri.rb:30:in `open'
它在 Ruby 1.9.2 或常规 1.8.7 下运行良好。 我尝试重新打包OpenSSL并安装ree以链接到它,如RVM OpenSSL页面上所述,但它没有效果。 我使用的是OS X 10.6.7,但是我在OpenSolaris REE安装中看到了同样的问题。
任何建议将不胜感激。
没有正确选取受信任的 CA 证书的位置 - REE 必须具有不同的编译默认位置,这对于您的系统来说是不正确的。
留给后人:
OP的问题通过下载http://curl.haxx.se/ca/cacert.pem
并将其复制到/opt/local/etc/openssl/cert.pem
来解决。