Delphi中MyDAC连接MariaDB时SSL握手失败问题求助
解决Delphi MyDAC连接强制SSL的MariaDB时SSL握手失败问题
我在Delphi开发的应用中,使用MyDAC组件配置SSL连接强制要求SSL的MariaDB服务器时,遇到SSL握手失败错误。相关代码如下:
// Method to establish a connection to the database with SSL support procedure TSQLHelper.Connect(const Host, Database, User, Password: string; const SSLConnect: Boolean); begin // Set connection parameters FHost := Host; // Hostname or IP address of the database server FDatabase := Database; // Name of the database to connect to FUsername := User; // Database username FPassword := Password; // Database password FSSLConnect := SSLConnect; try // Uses an SSL Connection if set to true if SSLConnect then begin // Set the protocol to SSL for secure connection FConnection.Options.Protocol := TMyProtocol.mpSSL; FConnection.SSLOptions.CipherList := 'All'; // Enable all cipher suites end; // Assign connection parameters to the MyDAC connection object FConnection.Server := FHost; FConnection.Database := FDatabase; FConnection.Username := FUsername; FConnection.Password := FPassword; FConnection.Options.UseUnicode := True; // Ensure Unicode support is enabled // Attempt to connect to the database FConnection.Connected := True; except on E: Exception do begin // Handle connection errors FLastErrNo := 1001; // General error code for connection issues FLastError := 'Error connecting to Server ' + FHost + ' with User ' + FUsername + ': ' + E.Message; // Detailed error message end; end; end;
错误信息
"Could not connect to the database: Error connecting to Server 192.168.184.130 with User testuser: SSL_do_handshake = -1
SSL_get_error(..., r2) = 1
r2 = -1"
已完成的排查步骤
- 验证服务器端证书有效
- NaviCat和HeidiSQL无需手动提供证书即可通过SSL连接,使用的加密套件为ECDHE-RSA-AES256-GCM-SHA384
- 尝试将
FConnection.SSLOptions.CipherList指定为ECDHE-RSA-AES256-GCM-SHA384 - 确认连接凭据正确传递
- 创建了拥有全权限的SQL用户
- 替换了
libeay32.dll和ssleay32.dll为NaviCat使用的版本 - 确认
SSLConnect参数已设为true
解决建议
1. 切换协议为TLS而非SSL
现代MariaDB服务器通常禁用旧版SSL协议,改用TLS。修改协议配置:
FConnection.Options.Protocol := TMyProtocol.mpTLS;
2. 显式指定支持的TLS版本
限定MyDAC使用与服务器匹配的TLS版本,比如先尝试TLS 1.2:
FConnection.SSLOptions.SSLVersion := [sslvTLSv1_2]; // 若失败可尝试添加TLS 1.3:[sslvTLSv1_2, sslvTLSv1_3]
3. 调整证书验证模式
由于NaviCat无需手动提供证书即可连接,先尝试关闭证书验证测试:
FConnection.SSLOptions.VerifyMode := sslvmNone;
若连接成功,再逐步开启验证并指定CA证书路径:
FConnection.SSLOptions.VerifyMode := sslvmPeer; FConnection.SSLOptions.CACertFile := 'path/to/server-ca.pem'; // 服务器CA证书路径
4. 升级MyDAC版本
旧版MyDAC可能对新的加密套件或TLS版本支持不足,尝试升级到最新稳定版。
5. 确认OpenSSL DLL的兼容性
替换的libeay32.dll和ssleay32.dll需与应用编译位数(32/64位)完全匹配,且版本支持服务器使用的TLS版本。建议从OpenSSL官方下载对应版本的预编译DLL替换测试。
6. 启用MyDAC调试日志
开启日志获取更详细的SSL握手细节:
FConnection.LogFile := 'mydac_debug.log'; FConnection.LogLevel := llDebug;
查看日志中握手阶段的具体错误点,比如证书验证失败、协议协商不匹配等。
7. 检查用户SSL权限
确保数据库用户被明确允许使用SSL连接:
GRANT ALL PRIVILEGES ON *.* TO 'testuser'@'%' REQUIRE SSL; FLUSH PRIVILEGES;
内容的提问来源于stack exchange,提问作者Kanubbel
相关产品推荐
相关产品推荐

