ClickHouse通过SSL连接RabbitMQ遇TLS握手失败,求排查方案
生产环境中连接RabbitMQ需使用自定义CA文件、客户端证书及密钥,已修改ClickHouse的config.xml配置如下:
<openssl> <client> <caConfig>/path/to/cafile.crt</caConfig> <certificateFile>/path/to/cert.pem</certificateFile> <privateKey>/path/to/key.pem</privateKey> </client> </openssl>
使用配置项rabbitmq_address = 'ampqs://user:password@host:port/vhost'连接时,出现错误:
tls handshake failure:contrib/openssl/ssl/record/rec_layer_s3.c:865:SSL alert number 40
但在服务器上直接执行以下命令可正常连接:
openssl s_client -connect host:port -CAfile /path/to/CAfile.crt -cert /path/to/cert.pem -key /path/to/key.pem
请问是否存在配置错误或遗漏步骤?
SSL alert number 40对应握手失败(handshake_failure),说明ClickHouse的TLS配置与RabbitMQ的要求不匹配,可从以下几个方向排查:
1. 确认OpenSSL配置层级正确性
ClickHouse的<openssl>客户端配置需直接放在<config>根节点下,不能嵌套在<rabbitmq>或其他组件配置块内。如果之前的配置层级有误,调整后重启ClickHouse服务。
2. 检查证书文件权限与路径
- 确保ClickHouse运行用户(通常为
clickhouse)对CA文件、客户端证书、密钥文件拥有读权限,可执行以下命令调整:chown clickhouse:clickhouse /path/to/cafile.crt /path/to/cert.pem /path/to/key.pem chmod 640 /path/to/cafile.crt /path/to/cert.pem /path/to/key.pem - 确认配置中的路径是绝对路径,且无拼写错误(Linux系统路径区分大小写)。
3. 补充RabbitMQ地址的TLS参数
部分ClickHouse版本中,ampqs协议URL需要显式指定证书验证相关参数,尝试修改地址为:
ampqs://user:password@host:port/vhost?verify=true&cafile=/path/to/cafile.crt&certfile=/path/to/cert.pem&keyfile=/path/to/key.pem
注:不同版本的参数支持可能有差异,以对应版本的ClickHouse文档为准。
4. 处理加密密钥文件
如果你的key.pem设置了密码(加密状态),ClickHouse无法自动解密读取,需转换为无密码版本:
openssl rsa -in /path/to/key.pem -out /path/to/key_unencrypted.pem
之后修改config.xml中的<privateKey>路径指向无密码版本的密钥文件。
5. 强制指定TLS版本匹配
RabbitMQ可能限制了TLS版本,而openssl s_client默认使用的版本与ClickHouse不一致。先通过s_client测试可用版本:
# 测试TLS 1.2 openssl s_client -connect host:port -CAfile /path/to/CAfile.crt -cert /path/to/cert.pem -key /path/to/key.pem -tls1_2 # 测试TLS 1.3 openssl s_client -connect host:port -CAfile /path/to/CAfile.crt -cert /path/to/cert.pem -key /path/to/key.pem -tls1_3
找到可用版本后,在ClickHouse的config.xml中强制指定:
<openssl> <client> <caConfig>/path/to/cafile.crt</caConfig> <certificateFile>/path/to/cert.pem</certificateFile> <privateKey>/path/to/key_unencrypted.pem</privateKey> <minProtocolVersion>TLSv1.2</minProtocolVersion> <maxProtocolVersion>TLSv1.2</maxProtocolVersion> </client> </openssl>
6. 验证RabbitMQ的客户端证书配置
确保RabbitMQ已开启客户端证书验证,并信任你的CA证书:
在rabbitmq.conf中检查以下配置:
ssl_options.verify = verify_peer ssl_options.fail_if_no_peer_cert = true ssl_options.cacertfile = /path/to/rabbitmq_trusted_cafile.crt
同时确认你的客户端证书由该CA签发,且证书主题(如CN字段)符合RabbitMQ的访问规则。
内容的提问来源于stack exchange,提问作者Sean Goldfarb

