【问题标题】:Composer Require 'package' throws OpenSSL errorComposer Require 'package' 引发 OpenSSL 错误
【发布时间】:2019-01-04 08:02:00
【问题描述】:

这个问题似乎很常见,我已经浏览了很多与之相关的 SO 帖子,但没有任何效果,我快疯了。奇怪的是几周前它工作得很好,几个月以来我没有安装任何新东西......

设置:

  • PHP 7.1.9
  • WAMPSERVER 3.1.0
  • APACHE 2.4.27
  • Composer 1.6.5(最新)
  • 我没有使用代理,也没有防火墙
  • Windows 10

什么有效:

  • 作曲家自我更新

什么不起作用:

  • 安装包

  • 我无法使用 firefox 61.0.1(64 位)访问 https://packagist.org/(不安全的连接:MOZILLA_PKIX_ERROR_SELF_SIGNED_CERT

我在 composer require 中遇到的错误:

[Composer\Downloader\TransportException]
The "https://packagist.org/packages.json" file could not be downloaded: SSL operation failed with code 1. OpenSSL Error messages:
error:14090086:SSL routines:ssl3_get_server_certificate:certificate verify failed
Failed to enable crypto
failed to open stream: operation failed          

php -r "var_dump(openssl_get_cert_locations());"返回:

array(8) {
  ["default_cert_file"]=>
  string(25) "c:/usr/local/ssl/cert.pem"
  ["default_cert_file_env"]=>
  string(13) "SSL_CERT_FILE"
  ["default_cert_dir"]=>
  string(22) "c:/usr/local/ssl/certs"
  ["default_cert_dir_env"]=>
  string(12) "SSL_CERT_DIR"
  ["default_private_dir"]=>
  string(24) "c:/usr/local/ssl/private"
  ["default_default_cert_area"]=>
  string(16) "c:/usr/local/ssl"
  ["ini_cafile"]=>
  string(51) "C:/wamp64/bin/php/php7.1.9/extras/ssl/ca-bundle.crt"
  ["ini_capath"]=>
  string(0) ""
}

我已经下载了 ca-bundle.crt 并将其添加到我的 php.ini 文件中:

curl.cainfo=C:/wamp64/bin/php/php7.1.9/extras/ssl/ca-bundle.crt    
openssl.cafile=C:/wamp64/bin/php/php7.1.9/extras/ssl/ca-bundle.crt

作曲家诊断返回这个:

Checking composer.json: OK
Checking platform settings: OK
Checking git settings: OK
Checking http connectivity to packagist: WARNING
[Composer\Downloader\TransportException] The "http://packagist.org/packages.json" file could not be downloaded (HTTP/1.1 404 Not Found)
Checking https connectivity to packagist: WARNING
[Composer\Downloader\TransportException] The "https://packagist.org/packages.json" file could not be downloaded: SSL operation failed with code 1. OpenSSL Error messages:
error:14090086:SSL routines:ssl3_get_server_certificate:certificate verify failed
Failed to enable crypto
failed to open stream: operation failed
Checking github.com rate limit: OK
Checking disk free space: OK
Checking pubkeys: OK
Checking composer version: OK
Composer version: 1.6.5
PHP version: 7.1.9
PHP binary path: C:\wamp64\bin\php\php7.1.9\php.exe

作曲家表演 -p -vvv | grep ssl 返回:

Reading ./composer.json
Loading config file ./composer.json
Checked CA file C:\wamp64\bin\php\php7.1.9\extras\ssl\ca-bundle.crt: valid
Executing command (C:\wamp64\www\projectName): git branch --no-color --no-abbrev -v
Failed to initialize global composer: Composer could not find the config file: C:/Users/********/AppData/Roaming/Composer/composer.json
To initialize a project, please create a composer.json file as described in the https://getcomposer.org/ "Getting Started" section
Reading C:\wamp64\www\projectName/vendor/composer/installed.json
Loading plugin PackageVersions\Installer
Loading plugin Symfony\Flex\Flex
Composer >=1.7 not found, downloads will happen in sequence
Running 1.6.5 (2018-05-04 11:44:59) with PHP 7.1.9 on Windows NT / 10.0
ext-openssl         7.1.9    The openssl PHP extension
lib-openssl         1.0.2.11 OpenSSL 1.0.2k  26 Jan 2017

php --ini :

Configuration File (php.ini) Path: C:\WINDOWS
Loaded Configuration File:         C:\wamp64\bin\php\php7.1.9\php.ini
Scan for additional .ini files in: (none)
Additional .ini files parsed:      (none)

编辑 1
- 尝试清空缓存
- 其他网络浏览器(chrome、edge)并没有工作
- 同一网络上的另一台计算机 --> 可以工作

编辑 2
- 创建了一个新的windows用户,没有用

编辑 3
- 按照 @kallosz
的建议,我可以联系到 https://repo.packagist.org/ - Curl 给了我这个:

curl -vvv https://packagist.org/
*   Trying 144.217.203.53...
* TCP_NODELAY set
* Connected to packagist.org (144.217.203.53) port 443 (#0)
* schannel: SSL/TLS connection with packagist.org port 443 (step 1/3)
* schannel: checking server certificate revocation
* schannel: sending initial handshake data: sending 178 bytes...
* schannel: sent initial handshake data: sent 178 bytes
* schannel: SSL/TLS connection with packagist.org port 443 (step 2/3)
* schannel: failed to receive handshake, need more data
* schannel: SSL/TLS connection with packagist.org port 443 (step 2/3)
* schannel: encrypted data got 1462
* schannel: encrypted data buffer: offset 1462 length 4096
* schannel: next InitializeSecurityContext failed: SEC_E_UNTRUSTED_ROOT (0x80090325) - La chaîne de certificats a été fournie par une autorité qui n'est pas approuvée.
* Closing connection 0
* schannel: shutting down SSL/TLS connection with packagist.org port 443
* schannel: clear security context handle
curl: (77) schannel: next InitializeSecurityContext failed: SEC_E_UNTRUSTED_ROOT (0x80090325)

【问题讨论】:

  • 我可以毫无错误地访问packagist.org...
  • @BogdanBurim,我在使用 firefox 时遇到此错误:MOZILLA_PKIX_ERROR_SELF_SIGNED_CERT
  • 尝试将https://packagist.org改为https://repo.packagist.org
  • @kallosz 我可以使用 Firefox 联系到repo.packagist.org。我应该怎么做才能让作曲家工作?

标签: php composer-php ssl-certificate packagist


【解决方案1】:

我不得不更改全局配置文件

C:\Users\USERNAME\AppData\Roaming\Composer\config.json

到这里:

{
    "config": {
        "disable-tls": true,
        "secure-http": false
    },
    "repositories": [
        {
            "type": "composer",
            "url": "http://repo.packagist.org"
        }
    ]
}

【讨论】:

    【解决方案2】:

    我不得不在 Ubuntu 上重新安装 CURL 开发库,即将 NSS 风格替换为 OpenSSL 风格:

    sudo apt install -y libcurl4-openssl-dev
    

    使用 phpbrew 重建 PHP 导致 libcurl 通过适当的库调用启用;反过来,识别的 CA 证书会正确捆绑,将其指向正确的位置

    【讨论】:

      【解决方案3】:

      试试

      composer config disable-tls true
      composer config secure-http false
      

      您还可以将 composer 配置 repositories.packagist.org.url 更改为 https?://repo.packagist.org

      【讨论】:

      • 出于安全原因,我不会运行您的前 2 个 cmd。我将 "repositories": { "packagist.org": { "type": "composer", "url": "repo.packagist.org" } } 添加到我的 composer.json 文件中,现在它可以工作了,但这意味着我有将它添加到我所有使用作曲家的项目中。有没有办法全局设置?
      • 是的,您可以将其添加到 composer config。 composer config --editor --global
      • ahhhh 非常感谢您的帮助,至少您给了我一个备用解决方案。但我真的很想解决我的问题,并让 packagist.org 的默认行为起作用,我只是不明白发生了什么。
      • 他们将存储库的地址更改为新的twitter.com/seldaek/status/1021740439475347456
      • 更新存储库后,检查您的 packagegist URL 现在是否正确。 composer config --global --listrepositories.packagist.org.url 应该是这样的 [repositories.packagist.org.url] https?://repo.packagist.org
      猜你喜欢
      • 2015-11-29
      • 2016-09-30
      • 2018-03-24
      • 2023-04-07
      • 2017-09-28
      • 1970-01-01
      • 2016-02-14
      • 2020-02-29
      • 2021-07-29
      相关资源
      最近更新 更多