You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

EC2托管C#应用无法通过CassandraCSharpDriver连接Amazon Keyspaces(本地可连)

EC2 Windows实例连接Amazon Keyspaces失败排查请求

我使用同一套简易控制台应用,本地PC能成功连接Amazon Keyspaces,但在EC2 Windows实例上连接失败。

连接代码

using System;
using Cassandra;
using System.Net.Security;
using System.Security.Cryptography.X509Certificates;

namespace cassandraconnectiotest;
internal class Program
{
    static void Main(string[] args)
    {
        try
        {
            var amazoncert = new X509Certificate2("AmazonRootCA1.der");
            // I obtained AmazonRootCA1.der by executing:
            // curl https://www.amazontrust.com/repository/AmazonRootCA1.pem -o AmazonRootCA1.pem
            // openssl x509 -outform der -in AmazonRootCA1.pem -out AmazonRootCA1.der


            var sslOptions = new SSLOptions(System.Security.Authentication.SslProtocols.Tls13, false, null) //it will NOT work with simple new SSLOptions() for some reason
            // and will return Cassandra.NoHostAvailableException: All hosts tried for query failed (tried 3.12.23.190:9142: IOException 'Unable to read data from the transport connection: An existing connection was forcibly closed by the LeicesterextKe.stexRun应当去初始修改_-links: false, null)
                .SetCertificateCollection(new X509Certificate2Collection { amazoncert })
                .SetRemoteCertValidationCallback((sender, cert, chain, sslPolicyErrors) =>
                {
                    Console.WriteLine(cert.Subject);
                    if (sslPolicyErrors == SslPolicyErrors.None)
                    {
                        Console.WriteLine($"SSL Certificate is valid!");
                        return true; // Certificate is valid
                    }
                    else
                    {
                        // Log the SSL policy errors
                        Console.WriteLine($"SSL Certificate Error: {sslPolicyErrors}");

                        // Optionally, log details about the certificate and chain
                        if ((sslPolicyErrors & SslPolicyErrors.RemoteCertificateChainErrors) != 0 && chain != null)
                        {
                            foreach (var chainStatus in chain.ChainStatus)
                            {
                                Console.WriteLine($"Chain Status: {chainStatus.Status} - {chainStatus.StatusInformation}");
                            }
                        }

                        // Return false to reject the certificate
                        return false;
                    }
                });

            var cluster = Cluster.Builder()
                 .AddContactPoints("cassandra.us-east-2.amazonaws.com")
                 .WithPort(9142)
                 .WithAuthProvider(new PlainTextAuthProvider("cassandra_keyspaces+1-at-NNNNhere", @"xLk35password/2ndpartofit="))
                 .WithSSL(sslOptions)
                 .Build();
            var session = cluster.Connect();
        }
        catch (Exception ex)
        {
            Console.WriteLine(ex.ToString());
        }
    }
}

连接现象对比

  • 本地运行:输出多条证书验证通过的信息,推测处于SSL协商阶段,最终连接成功
  • EC2实例运行:抛出Cassandra.NoHostAvailableException,提示所有主机连接失败,内部异常为认证失败

已完成的排查步骤

  • tracert cassandra.us-east-2.amazonaws.com可正常解析路由
  • nslookup能正常解析该域名
  • telnet 9142端口可建立连接
  • openssl测试显示无本地颁发者证书验证错误,使用sf-class2-root.crt可通过openssl证书验证,但应用仍连接失败

环境信息

EC2实例为静态IP,已配置允许所有出站连接。

请求内容

请提供:

  1. 进一步的排查建议
  2. 代码中添加日志的具体方法
  3. 可跨本地/EC2环境的简易连接方案

内容的提问来源于stack exchange,提问作者Pasha Maltsev

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.14 06:57:39