You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Delphi中MyDAC连接MariaDB时SSL握手失败问题求助

解决Delphi MyDAC连接强制SSL的MariaDB时SSL握手失败问题

我在Delphi开发的应用中,使用MyDAC组件配置SSL连接强制要求SSL的MariaDB服务器时,遇到SSL握手失败错误。相关代码如下:

// Method to establish a connection to the database with SSL support
procedure TSQLHelper.Connect(const Host, Database, User, Password: string; const SSLConnect: Boolean);
begin
  // Set connection parameters
  FHost := Host; // Hostname or IP address of the database server
  FDatabase := Database; // Name of the database to connect to
  FUsername := User; // Database username
  FPassword := Password; // Database password
  FSSLConnect := SSLConnect;

  try
    // Uses an SSL Connection if set to true
    if SSLConnect then
    begin
      // Set the protocol to SSL for secure connection
      FConnection.Options.Protocol := TMyProtocol.mpSSL;

      FConnection.SSLOptions.CipherList := 'All'; // Enable all cipher suites
    end;

    // Assign connection parameters to the MyDAC connection object
    FConnection.Server := FHost;
    FConnection.Database := FDatabase;
    FConnection.Username := FUsername;
    FConnection.Password := FPassword;
    FConnection.Options.UseUnicode := True; // Ensure Unicode support is enabled

    // Attempt to connect to the database
    FConnection.Connected := True;
  except
    on E: Exception do
    begin
      // Handle connection errors
      FLastErrNo := 1001; // General error code for connection issues
      FLastError := 'Error connecting to Server ' + FHost + ' with User ' + FUsername + ': ' + E.Message; // Detailed error message
    end;
  end;
end;

错误信息

"Could not connect to the database: Error connecting to Server 192.168.184.130 with User testuser: SSL_do_handshake = -1
SSL_get_error(..., r2) = 1
r2 = -1"

已完成的排查步骤

  • 验证服务器端证书有效
  • NaviCat和HeidiSQL无需手动提供证书即可通过SSL连接,使用的加密套件为ECDHE-RSA-AES256-GCM-SHA384
  • 尝试将FConnection.SSLOptions.CipherList指定为ECDHE-RSA-AES256-GCM-SHA384
  • 确认连接凭据正确传递
  • 创建了拥有全权限的SQL用户
  • 替换了libeay32.dll和ssleay32.dll为NaviCat使用的版本
  • 确认SSLConnect参数已设为true

解决建议

1. 切换协议为TLS而非SSL

现代MariaDB服务器通常禁用旧版SSL协议,改用TLS。修改协议配置:

FConnection.Options.Protocol := TMyProtocol.mpTLS;

2. 显式指定支持的TLS版本

限定MyDAC使用与服务器匹配的TLS版本,比如先尝试TLS 1.2:

FConnection.SSLOptions.SSLVersion := [sslvTLSv1_2];
// 若失败可尝试添加TLS 1.3:[sslvTLSv1_2, sslvTLSv1_3]

3. 调整证书验证模式

由于NaviCat无需手动提供证书即可连接,先尝试关闭证书验证测试:

FConnection.SSLOptions.VerifyMode := sslvmNone;

若连接成功,再逐步开启验证并指定CA证书路径:

FConnection.SSLOptions.VerifyMode := sslvmPeer;
FConnection.SSLOptions.CACertFile := 'path/to/server-ca.pem'; // 服务器CA证书路径

4. 升级MyDAC版本

旧版MyDAC可能对新的加密套件或TLS版本支持不足,尝试升级到最新稳定版。

5. 确认OpenSSL DLL的兼容性

替换的libeay32.dll和ssleay32.dll需与应用编译位数(32/64位)完全匹配,且版本支持服务器使用的TLS版本。建议从OpenSSL官方下载对应版本的预编译DLL替换测试。

6. 启用MyDAC调试日志

开启日志获取更详细的SSL握手细节:

FConnection.LogFile := 'mydac_debug.log';
FConnection.LogLevel := llDebug;

查看日志中握手阶段的具体错误点,比如证书验证失败、协议协商不匹配等。

7. 检查用户SSL权限

确保数据库用户被明确允许使用SSL连接:

GRANT ALL PRIVILEGES ON *.* TO 'testuser'@'%' REQUIRE SSL;
FLUSH PRIVILEGES;

内容的提问来源于stack exchange,提问作者Kanubbel

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 14:25:08