You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

远程访问Docker容器内MariaDB服务器遭遇SSL证书问题

解决MariaDB远程SSL连接的"tlsv1 alert unknown ca"错误

问题根源

你遇到的错误是因为两个核心问题:

  1. 服务器证书并非由你生成的CA证书签发(当前是自签证书,和指定的CA不匹配)
  2. 客户端连接时未明确信任自定义CA证书

修复步骤

1. 修正证书生成流程

当前cert-gen服务的证书生成顺序错误,且服务器证书是自签而非CA签发。修改compose.yaml中cert-gen的entrypoint脚本:

cert-gen:
  image: alpine
  volumes:
    - ./certs:/certs
  entrypoint:
    - /bin/sh
    - -c
    - |
      apk add --no-cache openssl &&
      # 先生成CA密钥和根证书
      openssl genpkey -algorithm RSA -out /certs/ca.key -pkeyopt rsa_keygen_bits:2048 &&
      openssl req -new -x509 -key /certs/ca.key -out /certs/ca.crt -days 1095 -subj "/CN=Certificate Authority/O=myorg/C=US" &&
      # 生成服务器密钥和签名请求
      openssl genpkey -algorithm RSA -out /certs/mysql.key -pkeyopt rsa_keygen_bits:2048 &&
      openssl req -new -key /certs/mysql.key -out /certs/mysql.csr -subj "/CN=mysql/O=myorg/C=US" &&
      # 用CA签发服务器证书
      openssl x509 -req -in /certs/mysql.csr -CA /certs/ca.crt -CAkey /certs/ca.key -CAcreateserial -out /certs/mysql.crt -days 365 &&
      chmod 600 /certs/* && chown 999:999 /certs/*
  restart: "no"  
  networks:
    - CargoStacks-net

2. 重新生成有效证书

删除旧证书并重新运行证书生成服务:

rm -rf ./certs/*
docker-compose run --rm cert-gen

3. 客户端连接时指定CA证书

使用以下命令连接MariaDB,替换/path/to/your/certs/ca.crt为本地certs目录的实际路径:

sudo mariadb -u root -P 3307 -p --ssl-ca=/path/to/your/certs/ca.crt

4. 可选优化(避免每次输入参数)

在客户端配置文件中添加默认CA信任路径,编辑~/.my.cnf或/etc/my.cnf.d/client.cnf:

[client]
ssl-ca=/path/to/your/certs/ca.crt

额外注意事项

  • 你的mysqldb服务中有两个挂载指向/var/lib/mysql(./mysql和./data),这会导致数据目录冲突,建议删除其中一个挂载项。
  • 若需要强制所有连接使用SSL,可将MariaDB启动参数--ssl=1改为--ssl-enforce=1。

内容的提问来源于stack exchange,提问作者kaustubh

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.18 06:22:39