You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PostgreSQL 14搭配OpenSSL 3.2/3.3的SSL连接问题排查

PostgreSQL 14 + OpenSSL 3.2/3.3 远程SSL连接故障排查思路

问题背景

通过源码编译OpenSSL 3.3并以此编译PostgreSQL 14.3,启用SSL加密认证(ssl_mode=on)后,远程连接和复制出现异常,禁用SSL后一切正常。本地使用psql连接无问题,远程连接时报错。

错误信息

psql: error: connection to server at "<HostIP>", port 5433 failed: server closed the connection unexpectedly
    This probably means the server terminated abnormally
    before or while processing the request.
SSL SYSCALL error: Connection reset by peer
connection to server at "<HostIP>", port 5433 failed: FATAL: no PostgreSQL user name specified in startup packet
free(): double free detected in tcache 2
Aborted

连接命令

psql -U <username> <dbname> -h <hostIP>

环境与配置

  • 操作系统:Debian 11.7,内核5.1
  • PostgreSQL配置:监听端口5433
  • pg_hba.conf:所有连接定义为hostSSL,认证方式md5
  • postgresql.conf SSL配置:
# SSL
ssl = on
ssl_ciphers = 'ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384'
ssl_ca_file = 'root.crt'
ssl_cert_file = 'server.crt'
ssl_key_file = 'server.key'

测试对比

使用OpenSSL 3.1及以下版本编译PostgreSQL时,相同配置可正常运行;切换到3.2/3.3版本后出现故障。


排查思路

  1. 检查OpenSSL编译参数

    • OpenSSL 3.2+默认可能启用了PostgreSQL 14.3不兼容的特性(如FIPS模块)。重新编译时改用保守配置:
      ./config --prefix=/usr/local/openssl-3.3 no-fips no-nextprotoneg no-weak-ssl-ciphers
      make && make install
      
    • 编译PostgreSQL时需明确指定新版OpenSSL路径,避免系统旧库干扰:
      ./configure --with-openssl=/usr/local/openssl-3.3 ...
      
  2. 验证SSL证书兼容性

    • OpenSSL 3.2+对证书格式和签名算法要求更严格,用以下命令检查证书信息:
      openssl x509 -in server.crt -text -noout
      
      确认签名算法为PostgreSQL支持类型,证书链完整且未过期。
    • 用OpenSSL 3.3自带命令重新生成ECDSA证书测试:
      openssl ecparam -name prime256v1 -genkey -out server.key
      openssl req -new -key server.key -out server.csr
      openssl x509 -req -days 365 -in server.csr -signkey server.key -out server.crt
      
  3. 调整SSL加密套件配置

    • 当前仅指定2个ECDSA套件,OpenSSL 3.2+可能对套件优先级或支持逻辑有变化。尝试改用PostgreSQL推荐的兼容套件:
      ssl_ciphers = 'HIGH:MEDIUM:+3DES:!aNULL'
      
    • 确保套件与证书类型匹配(ECDSA证书不要混用RSA套件)。
  4. 查看PostgreSQL详细日志

    • 在postgresql.conf中开启详细日志:
      log_min_messages = debug1
      log_connections = on
      log_error_verbosity = verbose
      
    • 重启服务后尝试远程连接,通过服务器日志定位具体错误(如SSL握手失败原因、证书验证问题、内存泄漏信息)。
  5. 验证运行时依赖库

    • 检查PostgreSQL进程实际加载的OpenSSL库:
      lsof -p <postgres_pid> | grep libssl
      
    • 若加载了系统旧版OpenSSL(如Debian 11自带的1.1.1),需通过LD_LIBRARY_PATH指定新版库路径启动服务,或用ldconfig更新系统缓存。
  6. 测试基础SSL握手

    • 用OpenSSL命令直接测试服务器SSL握手,排除客户端问题:
      openssl s_client -connect <HostIP>:5433 -CAfile root.crt
      
    • 根据握手输出的错误信息(如验证失败、握手中断原因)定位问题。
  7. 升级PostgreSQL版本

    • PostgreSQL 14.3发布于2022年3月,OpenSSL 3.2/3.3为后续版本,可能存在未修复的兼容性bug。升级到14系列最新版本(如14.11),通常会修复高版本OpenSSL的适配问题。

内容的提问来源于stack exchange,提问作者manasa

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.19 07:16:05