PostgreSQL 14搭配OpenSSL 3.2/3.3的SSL连接问题排查
PostgreSQL 14 + OpenSSL 3.2/3.3 远程SSL连接故障排查思路
问题背景
通过源码编译OpenSSL 3.3并以此编译PostgreSQL 14.3,启用SSL加密认证(ssl_mode=on)后,远程连接和复制出现异常,禁用SSL后一切正常。本地使用psql连接无问题,远程连接时报错。
错误信息
psql: error: connection to server at "<HostIP>", port 5433 failed: server closed the connection unexpectedly This probably means the server terminated abnormally before or while processing the request. SSL SYSCALL error: Connection reset by peer connection to server at "<HostIP>", port 5433 failed: FATAL: no PostgreSQL user name specified in startup packet free(): double free detected in tcache 2 Aborted
连接命令
psql -U <username> <dbname> -h <hostIP>
环境与配置
- 操作系统:Debian 11.7,内核5.1
- PostgreSQL配置:监听端口5433
pg_hba.conf:所有连接定义为hostSSL,认证方式md5postgresql.confSSL配置:
# SSL ssl = on ssl_ciphers = 'ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384' ssl_ca_file = 'root.crt' ssl_cert_file = 'server.crt' ssl_key_file = 'server.key'
测试对比
使用OpenSSL 3.1及以下版本编译PostgreSQL时,相同配置可正常运行;切换到3.2/3.3版本后出现故障。
排查思路
检查OpenSSL编译参数
- OpenSSL 3.2+默认可能启用了PostgreSQL 14.3不兼容的特性(如FIPS模块)。重新编译时改用保守配置:
./config --prefix=/usr/local/openssl-3.3 no-fips no-nextprotoneg no-weak-ssl-ciphers make && make install - 编译PostgreSQL时需明确指定新版OpenSSL路径,避免系统旧库干扰:
./configure --with-openssl=/usr/local/openssl-3.3 ...
- OpenSSL 3.2+默认可能启用了PostgreSQL 14.3不兼容的特性(如FIPS模块)。重新编译时改用保守配置:
验证SSL证书兼容性
- OpenSSL 3.2+对证书格式和签名算法要求更严格,用以下命令检查证书信息:
确认签名算法为PostgreSQL支持类型,证书链完整且未过期。openssl x509 -in server.crt -text -noout - 用OpenSSL 3.3自带命令重新生成ECDSA证书测试:
openssl ecparam -name prime256v1 -genkey -out server.key openssl req -new -key server.key -out server.csr openssl x509 -req -days 365 -in server.csr -signkey server.key -out server.crt
- OpenSSL 3.2+对证书格式和签名算法要求更严格,用以下命令检查证书信息:
调整SSL加密套件配置
- 当前仅指定2个ECDSA套件,OpenSSL 3.2+可能对套件优先级或支持逻辑有变化。尝试改用PostgreSQL推荐的兼容套件:
ssl_ciphers = 'HIGH:MEDIUM:+3DES:!aNULL' - 确保套件与证书类型匹配(ECDSA证书不要混用RSA套件)。
- 当前仅指定2个ECDSA套件,OpenSSL 3.2+可能对套件优先级或支持逻辑有变化。尝试改用PostgreSQL推荐的兼容套件:
查看PostgreSQL详细日志
- 在
postgresql.conf中开启详细日志:log_min_messages = debug1 log_connections = on log_error_verbosity = verbose - 重启服务后尝试远程连接,通过服务器日志定位具体错误(如SSL握手失败原因、证书验证问题、内存泄漏信息)。
- 在
验证运行时依赖库
- 检查PostgreSQL进程实际加载的OpenSSL库:
lsof -p <postgres_pid> | grep libssl - 若加载了系统旧版OpenSSL(如Debian 11自带的1.1.1),需通过
LD_LIBRARY_PATH指定新版库路径启动服务,或用ldconfig更新系统缓存。
- 检查PostgreSQL进程实际加载的OpenSSL库:
测试基础SSL握手
- 用OpenSSL命令直接测试服务器SSL握手,排除客户端问题:
openssl s_client -connect <HostIP>:5433 -CAfile root.crt - 根据握手输出的错误信息(如验证失败、握手中断原因)定位问题。
- 用OpenSSL命令直接测试服务器SSL握手,排除客户端问题:
升级PostgreSQL版本
- PostgreSQL 14.3发布于2022年3月,OpenSSL 3.2/3.3为后续版本,可能存在未修复的兼容性bug。升级到14系列最新版本(如14.11),通常会修复高版本OpenSSL的适配问题。
内容的提问来源于stack exchange,提问作者manasa
相关产品推荐
相关产品推荐

