You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

nRF9151对接AWS IoT Core自定义策略连接失败排查求助

问题:nRF9151对接AWS IoT Core MQTT时自定义策略授权失败

现象概述

  • 使用宽松策略(允许所有IoT操作、所有资源)时,设备可正常完成连接、订阅、发布操作,证明证书有效
  • 配置自定义精细策略后,连接请求始终被AWS拒绝,开启IoT日志后显示AUTHORIZATION_FAILURE

配置细节

尝试的自定义策略

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "iot:Connect",
        "iot:Publish",
        "iot:Receive",
        "iot:Subscribe"
      ],
      "Resource": [
        "arn:aws:iot:*******:client/TryIt",
        "arn:aws:iot:*******:topic/top/1112222/*",
        "arn:aws:iot:*******:topicfilter/top/1112222/*"
      ]
    }
  ]
}

设备连接代码

static void connect_work_fn(struct k_work *work)
{
    int err;

    LOG_INF("Connecting to AWS IoT");

    struct aws_iot_config config = {
        .client_id = "TryIt"
    };

    err = aws_iot_connect(&config);
    if (err) {
        LOG_ERR("aws_iot_connect, error: %d", err);
    }

    LOG_INF("Next connection retry in %d seconds",
        30);

    (void)k_work_reschedule(&connect_work,
                K_SECONDS(30));
}

AWS IoT日志内容

{
    "timestamp": "2025-05-02 13:49:11.671",
    "logLevel": "ERROR",
    "traceId": "xxxxxxxxxxx",
    "accountId": "xxxx",
    "status": "Failure",
    "eventType": "Connect",
    "protocol": "MQTT",
    "clientId": "3594042302222",
    "principalId": "xxxxxxxxxxxxxxx",
    "sourceIp": "xxxxxxxx",
    "sourcePort": 56734,
    "reason": "AUTHORIZATION_FAILURE",
    "details": "Authorization Failure"
}

问题根源

代码中指定的client_id为TryIt,但日志显示实际发起连接的clientId是3594042302222,策略中iot:Connect对应的资源仅授权了client/TryIt,与实际使用的客户端ID不匹配,导致连接授权失败。

解决方案

  1. 修正策略的Connect资源:将策略中iot:Connect对应的ARN替换为日志中实际的客户端ID,即arn:aws:iot:eu-west-3:xxxx:client/3594042302222
  2. 确认代码中client_id的实际生效值:检查nRF SDK的aws_iot_connect接口是否存在默认行为(比如自动使用设备IMEI作为客户端ID),如果是,要么在代码中强制指定TryIt作为客户端ID,要么在策略中允许该默认ID的连接权限
  3. 拆分策略语句(可选):将不同操作的权限拆分为独立Statement,提升策略可读性:
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "iot:Connect",
      "Resource": "arn:aws:iot:eu-west-3:xxxx:client/3594042302222"
    },
    {
      "Effect": "Allow",
      "Action": ["iot:Publish", "iot:Receive"],
      "Resource": "arn:aws:iot:eu-west-3:xxxx:topic/top/1112222/*"
    },
    {
      "Effect": "Allow",
      "Action": "iot:Subscribe",
      "Resource": "arn:aws:iot:eu-west-3:xxxx:topicfilter/top/1112222/*"
    }
  ]
}

内容的提问来源于stack exchange,提问作者simon

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 07:19:54