今天在Centos7系統(tǒng)下載dell.com的問題,結(jié)果提示SSL證書驗(yàn)證異常棚菊。
# curl -O https://linux.dell.com/repo/hardware/dsu/bootstrap.cgi
% Total % Received % Xferd Average Speed Time Time Time Current
Dload Upload Total Spent Left Speed
0 0 0 0 0 0 0 0 --:--:-- 0:00:02 --:--:-- 0
curl: (60) Peer's certificate issuer has been marked as not trusted by the user.
More details here: http://curl.haxx.se/docs/sslcerts.html
curl performs SSL certificate verification by default, using a "bundle"
of Certificate Authority (CA) public keys (CA certs). If the default
bundle file isn't adequate, you can specify an alternate file
using the --cacert option.
If this HTTPS server uses a certificate signed by a CA represented in
the bundle, the certificate verification probably failed due to a
problem with the certificate (it might be expired, or the name might
not match the domain name in the URL).
If you'd like to turn off curl's verification of the certificate, use
the -k (or --insecure) option.
判斷是由于CA證書過期導(dǎo)致浸踩,更新CA證書列表即可解決。
centos 解決方法是统求,運(yùn)行:yum -y update ca-certificates