smartdns icon indicating copy to clipboard operation
smartdns copied to clipboard

DoH/DoT通过Proxy查询SSL报错

Open hululu1068 opened this issue 1 year ago • 3 comments

问题现象
DoH/DoT通过Proxy查询SSL无规律报错 Release46和最新的Commit均测试过 运行环境 OpenWRT x86-64 Release46

image image

hululu1068 avatar Dec 22 '24 06:12 hululu1068

我也观测到类似问题,但是我自己代理失败导致的

[2024-12-03 11:46:08,432][ERROR][     dns_client.c:2777] server 74.82.42.42 SSL read fail error: error:0A000119:SSL routines::decryption failed or bad record mac
[2024-12-03 14:04:51,074][ERROR][     dns_client.c:2777] server 74.82.42.42 SSL read fail error: error:0A000119:SSL routines::decryption failed or bad record mac
[2024-12-03 14:16:02,044][ERROR][     dns_client.c:2777] server 74.82.42.42 SSL read fail error: error:0A000119:SSL routines::decryption failed or bad record mac
[2024-12-03 15:51:38,243][ERROR][     dns_client.c:2777] server 74.82.42.42 SSL read fail error: error:0A000119:SSL routines::decryption failed or bad record mac

PikuZheng avatar Dec 22 '24 07:12 PikuZheng

我是把doh的地址从代理软件里直接强制走代理了,很久没看过日志,不知道怎么样

qwerttvv avatar Dec 22 '24 15:12 qwerttvv

测试发现,只有Google的DoH/DoT会有这个报错,其它的上游则没有。 而且从日志的时间戳来看,似乎是serve-expired-prefetch-time 3600.

[2025-05-06 16:15:30,645][ERROR][     client_tls.c:607 ] server 8.8.8.8 SSL read fail error: error:0A000119:SSL routines::decryption failed or bad record mac
[2025-05-06 17:16:53,505][ERROR][     client_tls.c:607 ] server 8.8.8.8 SSL read fail error: error:0A000119:SSL routines::decryption failed or bad record mac
[2025-05-06 18:17:09,000][ERROR][     client_tls.c:607 ] server 8.8.8.8 SSL read fail error: error:0A000119:SSL routines::decryption failed or bad record mac

hululu1068 avatar May 07 '25 06:05 hululu1068