You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

切换自定义SSL证书后OpenSearch集群无法运行问题求助

自定义SSL证书切换后OpenSearch集群异常排查

版本信息

  • OpenSearch:2.16.0
  • Dashboard:2.3.0

问题背景

原集群使用默认自签名证书、演示配置,且传输节点启用HTTP时运行正常。切换为自定义SSL证书并移除传输节点HTTP配置后,集群无法正常启动,出现多种报错。

已执行操作:

  • 按官方文档生成自定义SSL证书(管理员+传输节点)
  • 创建含完整安全配置文件的密钥,更新管理员密码哈希值
  • 配置自定义管理员密钥、TLS相关密钥

异常现象:即使提供自定义管理员密钥,OpenSearch仍会生成一个内容相同的新密钥;Security Pod一直显示Waiting to connect to the cluster(截图:Security Pod错误截图)

节点报错示例

{"type":"log","@timestamp":"2024-09-25T21:14:21Z","tags":["warning","savedobjects-service"],"pid":1,"message":"Unable to connect to OpenSearch. Error: Given the configuration, the ConnectionPool was not able to find a usable Connection for this request."}

{"type":"log","@timestamp":"2024-09-25T21:18:08Z","tags":["error","opensearch","data"],"pid":1,"message":"[ConnectionError]: write EPROTO 139884884653952:error:1408F10B:SSL routines:ssl3_get_record:wrong version number:../deps/openssl/openssl/ssl/record/ssl3_record.c:332:\n"}

[2024-09-25T21:46:39,346][ERROR][o.o.s.a.BackendRegistry  ] [opensearch-bootstrap-0] Not yet initialized (you may need to run securityadmin)

[2024-09-25T21:46:19,167][ERROR][o.o.s.l.BuiltinLogTypeLoader] [opensearch-bootstrap-0] Failed loading builtin log types from disk!

[2024-09-25T21:47:07,816][ERROR][o.o.s.t.SecurityRequestHandler] [opensearch-bootstrap-0] OpenSearchException[Transport client authentication no longer supported.]

[2024-09-25T21:46:20,958][ERROR][o.o.s.c.ConfigurationLoaderSecurity7] [opensearch-bootstrap-0] Failure no such index [.opendistro_security] retrieving configuration for [ACTIONGROUPS, ALLOWLIST, AUDIT, CONFIG, INTERNALUSERS, NODESDN, ROLES, ROLESMAPPING, TENANTS, WHITELIST] (index=.opendistro_security)

集群配置片段

security:
  config:                   # 安全配置相关
    securityConfigSecret:
      name: securityconfigsecret.name               # 安全配置文件密钥
    adminSecret:
      name: adminsecret.name
    adminCredentialsSecret:
      name: admincredentialssecret.name
  tls:                     # TLS配置相关
    transport:             # 传输端点配置
      generate: false      # 禁用Operator自动生成证书
      perNode: false       # 所有节点使用统一证书
      secret:
        name: secret.name             # 自定义传输节点证书密钥
      caSecret:
        name: casecret.name            # CA证书密钥
      nodesDn: [CN=node.other.com,OU=SSL,O=Test,L=Test,C=DE,OU=TEST,O=TEST,C=US]         # 允许连接的节点证书DN
      adminDn: [CN=admin,OU=SSL,O=Test,L=Test,C=DE,OU=TEST,O=TEST,C=US]         # 拥有管理员权限的证书DN

排查要点

  1. 证书合法性与匹配度

    • 检查nodesDn、adminDn中的DN是否与证书实际DN完全一致,示例中DN存在重复的OU/O/C字段,大概率是配置错误,需修正
    • 确认CA证书已正确挂载到所有节点,证书链无缺失(若使用多级CA)
    • 验证证书有效期、加密算法:必须使用TLS 1.2+,密钥长度≥2048位,证书需同时支持服务端和客户端认证
  2. 安全配置初始化

    • 从Not yet initialized和.opendistro_security索引不存在的报错来看,安全配置未成功推送
    • 检查securityConfigSecret中的配置文件完整性,重点确认config.yml是否启用证书认证,internal_users.yml的密码哈希是否用OpenSearch官方工具生成
    • 手动执行securityadmin命令推送配置,确保使用正确的admin证书和CA证书
  3. TLS兼容性

    • wrong version number报错说明SSL握手版本不兼容,统一所有节点传输层的TLS版本(禁用TLS 1.1及以下)
    • 移除传输节点HTTP配置后,确认集群内部仅通过传输层TLS通信,端口配置一致
    • 检查自定义证书的扩展字段,确保包含clientAuth: true,支持客户端认证
  4. Operator行为校验

    • 针对Operator重复生成管理员密钥的问题,检查密钥的命名空间、RBAC权限配置,避免Operator因权限不足重新创建密钥
    • 查看Operator日志,排查证书挂载、配置加载过程中的隐藏错误

内容的提问来源于stack exchange,提问作者GTGabaaron

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 20:05:09