切换自定义SSL证书后OpenSearch集群无法运行问题求助
自定义SSL证书切换后OpenSearch集群异常排查
版本信息
- OpenSearch:2.16.0
- Dashboard:2.3.0
问题背景
原集群使用默认自签名证书、演示配置,且传输节点启用HTTP时运行正常。切换为自定义SSL证书并移除传输节点HTTP配置后,集群无法正常启动,出现多种报错。
已执行操作:
- 按官方文档生成自定义SSL证书(管理员+传输节点)
- 创建含完整安全配置文件的密钥,更新管理员密码哈希值
- 配置自定义管理员密钥、TLS相关密钥
异常现象:即使提供自定义管理员密钥,OpenSearch仍会生成一个内容相同的新密钥;Security Pod一直显示Waiting to connect to the cluster(截图:
)
节点报错示例
{"type":"log","@timestamp":"2024-09-25T21:14:21Z","tags":["warning","savedobjects-service"],"pid":1,"message":"Unable to connect to OpenSearch. Error: Given the configuration, the ConnectionPool was not able to find a usable Connection for this request."} {"type":"log","@timestamp":"2024-09-25T21:18:08Z","tags":["error","opensearch","data"],"pid":1,"message":"[ConnectionError]: write EPROTO 139884884653952:error:1408F10B:SSL routines:ssl3_get_record:wrong version number:../deps/openssl/openssl/ssl/record/ssl3_record.c:332:\n"} [2024-09-25T21:46:39,346][ERROR][o.o.s.a.BackendRegistry ] [opensearch-bootstrap-0] Not yet initialized (you may need to run securityadmin) [2024-09-25T21:46:19,167][ERROR][o.o.s.l.BuiltinLogTypeLoader] [opensearch-bootstrap-0] Failed loading builtin log types from disk! [2024-09-25T21:47:07,816][ERROR][o.o.s.t.SecurityRequestHandler] [opensearch-bootstrap-0] OpenSearchException[Transport client authentication no longer supported.] [2024-09-25T21:46:20,958][ERROR][o.o.s.c.ConfigurationLoaderSecurity7] [opensearch-bootstrap-0] Failure no such index [.opendistro_security] retrieving configuration for [ACTIONGROUPS, ALLOWLIST, AUDIT, CONFIG, INTERNALUSERS, NODESDN, ROLES, ROLESMAPPING, TENANTS, WHITELIST] (index=.opendistro_security)
集群配置片段
security: config: # 安全配置相关 securityConfigSecret: name: securityconfigsecret.name # 安全配置文件密钥 adminSecret: name: adminsecret.name adminCredentialsSecret: name: admincredentialssecret.name tls: # TLS配置相关 transport: # 传输端点配置 generate: false # 禁用Operator自动生成证书 perNode: false # 所有节点使用统一证书 secret: name: secret.name # 自定义传输节点证书密钥 caSecret: name: casecret.name # CA证书密钥 nodesDn: [CN=node.other.com,OU=SSL,O=Test,L=Test,C=DE,OU=TEST,O=TEST,C=US] # 允许连接的节点证书DN adminDn: [CN=admin,OU=SSL,O=Test,L=Test,C=DE,OU=TEST,O=TEST,C=US] # 拥有管理员权限的证书DN
排查要点
证书合法性与匹配度
- 检查
nodesDn、adminDn中的DN是否与证书实际DN完全一致,示例中DN存在重复的OU/O/C字段,大概率是配置错误,需修正 - 确认CA证书已正确挂载到所有节点,证书链无缺失(若使用多级CA)
- 验证证书有效期、加密算法:必须使用TLS 1.2+,密钥长度≥2048位,证书需同时支持服务端和客户端认证
- 检查
安全配置初始化
- 从
Not yet initialized和.opendistro_security索引不存在的报错来看,安全配置未成功推送 - 检查
securityConfigSecret中的配置文件完整性,重点确认config.yml是否启用证书认证,internal_users.yml的密码哈希是否用OpenSearch官方工具生成 - 手动执行securityadmin命令推送配置,确保使用正确的admin证书和CA证书
- 从
TLS兼容性
wrong version number报错说明SSL握手版本不兼容,统一所有节点传输层的TLS版本(禁用TLS 1.1及以下)- 移除传输节点HTTP配置后,确认集群内部仅通过传输层TLS通信,端口配置一致
- 检查自定义证书的扩展字段,确保包含
clientAuth: true,支持客户端认证
Operator行为校验
- 针对Operator重复生成管理员密钥的问题,检查密钥的命名空间、RBAC权限配置,避免Operator因权限不足重新创建密钥
- 查看Operator日志,排查证书挂载、配置加载过程中的隐藏错误
内容的提问来源于stack exchange,提问作者GTGabaaron
相关产品推荐
相关产品推荐

