从ECS Fargate连接MongoDB Atlas时SSL握手失败求助
解决ECS Fargate连接MongoDB Atlas的SSL握手失败问题
问题详情
连接时触发SSL握手失败错误,具体报错内容:
error occured: SSL handshake failed: ac-xvafg1z-shard-00-00.pizmgb2.mongodb.net:27017: [SSL: TLSV1_ALERT_INTERNAL_ERROR] tlsv1 alert internal error (_ssl.c:1007) (configured timeouts: socketTimeoutMS: 20000.0ms, connectTimeoutMS: 20000.0ms),SSL handshake failed: ac-xvafg1z-shard-00-02.pizmgb2.mongodb.net:27017: [SSL: TLSV1_ALERT_INTERNAL_ERROR] tlsv1 alert internal error (_ssl.c:1007) (configured timeouts: socketTimeoutMS: 20000.0ms, connectTimeoutMS: 20000.0ms),SSL handshake failed: ac-xvafg1z-shard-00-01.pizmgb2.mongodb.net:27017: [SSL: TLSV1_ALERT_INTERNAL_ERROR] tlsv1 alert internal error (_ssl.c:1007) (configured timeouts: socketTimeoutMS: 20000.0ms, connectTimeoutMS: 20000.0ms), Timeout: 30s, Topology Description: <TopologyDescription id: 669fb320b2ab667661629f2f, topology_type: ReplicaSetNoPrimary, servers: [<ServerDescription ('ac-xvafg1z-shard-00-00.pizmgb2.mongodb.net', 27017) server_type: Unknown, rtt: None, error=AutoReconnect('SSL handshake failed: ac-xvafg1z-shard-00-00.pizmgb2.mongodb.net:27017: [SSL: TLSV1_ALERT_INTERNAL_ERROR] tlsv1 alert internal error (_ssl.c:1007) (configured timeouts: socketTimeoutMS: 20000.0ms, connectTimeoutMS: 20000.0ms)')>, <ServerDescription ('ac-xvafg1z-shard-00-01.pizmgb2.mongodb.net', 27017) server_type: Unknown, rtt: None, error=AutoReconnect('SSL handshake failed: ac-xvafg1z-shard-00-01.pizmgb2.mongodb.net:27017: [SSL: TLSV1_ALERT_INTERNAL_ERROR] tlsv1 alert internal error (_ssl.c:1007) (configured timeouts: socketTimeoutMS: 20000.0ms, connectTimeoutMS: 20000.0ms)')>, <ServerDescription ('ac-xvafg1z-shard-00-02.pizmgb2.mongodb.net', 27017) server_type: Unknown, rtt: None, error=AutoReconnect('SSL handshake failed: ac-xvafg1z-shard-00-02.pizmgb2.mongodb.net:27017: [SSL: TLSV1_ALERT_INTERNAL_ERROR] tlsv1 alert internal error (_ssl.c:1007) (configured timeouts: socketTimeoutMS: 20000.0ms, connectTimeoutMS: 20000.0ms)')>]>
使用的pymongo连接代码:
driver_URL="mongodb+srv://<user>:<password>@<domain>/?retryWrites=true&w=majority&appName=Cluster0" with MongoClient(driver_URL) as client : webcamDb = client.webcam webCamCol = webcamDb.webcam
修复步骤
- 检查ECS Fargate网络权限:确认Fargate任务所属安全组、网络ACL允许出站访问27017端口,同时将Fargate任务的公网IP或所在VPC的CIDR段加入MongoDB Atlas的IP白名单。
- 强制指定TLS版本:MongoDB Atlas要求使用TLS 1.2及以上版本,修改连接代码显式指定TLS版本:
from pymongo import MongoClient import ssl driver_URL="mongodb+srv://<user>:<password>@<domain>/?retryWrites=true&w=majority&appName=Cluster0" client = MongoClient( driver_URL, tls=True, tlsAllowInvalidCertificates=False, tlsVersion=ssl.PROTOCOL_TLSv1_2 ) with client: webcamDb = client.webcam webCamCol = webcamDb.webcam - 更新依赖库:执行
pip install --upgrade pymongo更新到最新稳定版,同时确保系统OpenSSL版本支持TLS 1.2+。 - 验证连接字符串有效性:确认
<domain>是正确的Atlas集群域名,用户密码中的特殊字符(如@、&)已做URL编码。 - 检查DNS解析:在Fargate任务内执行
nslookup ac-xvafg1z-shard-00-00.pizmgb2.mongodb.net,确认能正常解析Atlas节点域名,排除DNS故障。
内容的提问来源于stack exchange,提问作者tthogho1
相关产品推荐
相关产品推荐

