目前这台机器解析的俩节点有一个节点证书没更新,关键是已经过期了。
ubuntu@VM-0-14-ubuntu:~$ nslookup qyapi.weixin.qq.com
Server: 127.0.0.53
Address: 127.0.0.53#53
Non-authoritative answer:
Name: qyapi.weixin.qq.com
Address: 121.51.140.149
Name: qyapi.weixin.qq
ubuntu@VM-0-14-ubuntu:~$ export SERVERNAME=qyapi.weixin.qq.com
ubuntu@VM-0-14-ubuntu:~$ export TARGET_URL=qyapi.weixin.qq.com
ubuntu@VM-0-14-ubuntu:~$ for i in {0..10};do openssl s_client -servername ${SERVERNAME} -connect ${TARGET_URL}:443 < /dev/null 2> /dev/null | openssl x509 -text 2> /dev/null | grep "Not After"| sed -e 's/^ *//g' >> test_qywechat.txt;done
ubuntu@VM-0-14-ubuntu:~$ cat test_qywechat.txt
Not After : Apr 29 23:59:59 2022 GMT
Not After : May 18 12:00:00 2021 GMT
Not After : Apr 29 23:59:59 2022 GMT
Not After : May 18 12:00:00 2021 GMT
Not After : May 18 12:00:00 2021 GMT
Not After : Apr 29 23:59:59 2022 GMT
Not After : Apr 29 23:59:59 2022 GMT
Not After : Apr 29 23:59:59 2022 GMT
Not After : Apr 29 23:59:59 2022 GMT
Not After : May 18 12:00:00 2021 GMT
Not After : Apr 29 23:59:59 2022 GMT
1
Xusually 2021-04-22 14:19:35 +08:00
额。。。没看出哪一个过期了啊?
|
2
0312birdzhang OP @Xusually #1 额,应该是快要过期了。用了他们的 java sdk,然后偶尔就会报证书错误
javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target |
3
0312birdzhang OP 没有发现 append 按钮,还没过期,只是 java 提示证书错误
|
4
0312birdzhang OP 截止今天 10 点 45 分已修复
|