You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ClickHouse通过SSL连接RabbitMQ遇TLS握手失败,求排查方案

问题描述

生产环境中连接RabbitMQ需使用自定义CA文件、客户端证书及密钥,已修改ClickHouse的config.xml配置如下:

<openssl>
    <client>
        <caConfig>/path/to/cafile.crt</caConfig>
        <certificateFile>/path/to/cert.pem</certificateFile>
        <privateKey>/path/to/key.pem</privateKey>
    </client>
</openssl>

使用配置项rabbitmq_address = 'ampqs://user:password@host:port/vhost'连接时,出现错误:

tls handshake failure:contrib/openssl/ssl/record/rec_layer_s3.c:865:SSL alert number 40

但在服务器上直接执行以下命令可正常连接:

openssl s_client -connect host:port -CAfile /path/to/CAfile.crt -cert /path/to/cert.pem -key /path/to/key.pem

请问是否存在配置错误或遗漏步骤?


排查方向与解决方案

SSL alert number 40对应握手失败(handshake_failure),说明ClickHouse的TLS配置与RabbitMQ的要求不匹配,可从以下几个方向排查:

1. 确认OpenSSL配置层级正确性

ClickHouse的<openssl>客户端配置需直接放在<config>根节点下,不能嵌套在<rabbitmq>或其他组件配置块内。如果之前的配置层级有误,调整后重启ClickHouse服务。

2. 检查证书文件权限与路径

  • 确保ClickHouse运行用户(通常为clickhouse)对CA文件、客户端证书、密钥文件拥有读权限,可执行以下命令调整:
    chown clickhouse:clickhouse /path/to/cafile.crt /path/to/cert.pem /path/to/key.pem
    chmod 640 /path/to/cafile.crt /path/to/cert.pem /path/to/key.pem
    
  • 确认配置中的路径是绝对路径,且无拼写错误(Linux系统路径区分大小写)。

3. 补充RabbitMQ地址的TLS参数

部分ClickHouse版本中,ampqs协议URL需要显式指定证书验证相关参数,尝试修改地址为:

ampqs://user:password@host:port/vhost?verify=true&cafile=/path/to/cafile.crt&certfile=/path/to/cert.pem&keyfile=/path/to/key.pem

注:不同版本的参数支持可能有差异,以对应版本的ClickHouse文档为准。

4. 处理加密密钥文件

如果你的key.pem设置了密码(加密状态),ClickHouse无法自动解密读取,需转换为无密码版本:

openssl rsa -in /path/to/key.pem -out /path/to/key_unencrypted.pem

之后修改config.xml中的<privateKey>路径指向无密码版本的密钥文件。

5. 强制指定TLS版本匹配

RabbitMQ可能限制了TLS版本,而openssl s_client默认使用的版本与ClickHouse不一致。先通过s_client测试可用版本:

# 测试TLS 1.2
openssl s_client -connect host:port -CAfile /path/to/CAfile.crt -cert /path/to/cert.pem -key /path/to/key.pem -tls1_2
# 测试TLS 1.3
openssl s_client -connect host:port -CAfile /path/to/CAfile.crt -cert /path/to/cert.pem -key /path/to/key.pem -tls1_3

找到可用版本后,在ClickHouse的config.xml中强制指定:

<openssl>
    <client>
        <caConfig>/path/to/cafile.crt</caConfig>
        <certificateFile>/path/to/cert.pem</certificateFile>
        <privateKey>/path/to/key_unencrypted.pem</privateKey>
        <minProtocolVersion>TLSv1.2</minProtocolVersion>
        <maxProtocolVersion>TLSv1.2</maxProtocolVersion>
    </client>
</openssl>

6. 验证RabbitMQ的客户端证书配置

确保RabbitMQ已开启客户端证书验证,并信任你的CA证书:
在rabbitmq.conf中检查以下配置:

ssl_options.verify = verify_peer
ssl_options.fail_if_no_peer_cert = true
ssl_options.cacertfile = /path/to/rabbitmq_trusted_cafile.crt

同时确认你的客户端证书由该CA签发,且证书主题(如CN字段)符合RabbitMQ的访问规则。


内容的提问来源于stack exchange,提问作者Sean Goldfarb

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 15:09:51