You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

从ECS Fargate连接MongoDB Atlas时SSL握手失败求助

解决ECS Fargate连接MongoDB Atlas的SSL握手失败问题

问题详情

连接时触发SSL握手失败错误,具体报错内容:

error occured: SSL handshake failed: ac-xvafg1z-shard-00-00.pizmgb2.mongodb.net:27017: [SSL: TLSV1_ALERT_INTERNAL_ERROR] tlsv1 alert internal error (_ssl.c:1007) (configured timeouts: socketTimeoutMS: 20000.0ms, connectTimeoutMS: 20000.0ms),SSL handshake failed: ac-xvafg1z-shard-00-02.pizmgb2.mongodb.net:27017: [SSL: TLSV1_ALERT_INTERNAL_ERROR] tlsv1 alert internal error (_ssl.c:1007) (configured timeouts: socketTimeoutMS: 20000.0ms, connectTimeoutMS: 20000.0ms),SSL handshake failed: ac-xvafg1z-shard-00-01.pizmgb2.mongodb.net:27017: [SSL: TLSV1_ALERT_INTERNAL_ERROR] tlsv1 alert internal error (_ssl.c:1007) (configured timeouts: socketTimeoutMS: 20000.0ms, connectTimeoutMS: 20000.0ms), Timeout: 30s, Topology Description: <TopologyDescription id: 669fb320b2ab667661629f2f, topology_type: ReplicaSetNoPrimary, servers: [<ServerDescription ('ac-xvafg1z-shard-00-00.pizmgb2.mongodb.net', 27017) server_type: Unknown, rtt: None, error=AutoReconnect('SSL handshake failed: ac-xvafg1z-shard-00-00.pizmgb2.mongodb.net:27017: [SSL: TLSV1_ALERT_INTERNAL_ERROR] tlsv1 alert internal error (_ssl.c:1007) (configured timeouts: socketTimeoutMS: 20000.0ms, connectTimeoutMS: 20000.0ms)')>, <ServerDescription ('ac-xvafg1z-shard-00-01.pizmgb2.mongodb.net', 27017) server_type: Unknown, rtt: None, error=AutoReconnect('SSL handshake failed: ac-xvafg1z-shard-00-01.pizmgb2.mongodb.net:27017: [SSL: TLSV1_ALERT_INTERNAL_ERROR] tlsv1 alert internal error (_ssl.c:1007) (configured timeouts: socketTimeoutMS: 20000.0ms, connectTimeoutMS: 20000.0ms)')>, <ServerDescription ('ac-xvafg1z-shard-00-02.pizmgb2.mongodb.net', 27017) server_type: Unknown, rtt: None, error=AutoReconnect('SSL handshake failed: ac-xvafg1z-shard-00-02.pizmgb2.mongodb.net:27017: [SSL: TLSV1_ALERT_INTERNAL_ERROR] tlsv1 alert internal error (_ssl.c:1007) (configured timeouts: socketTimeoutMS: 20000.0ms, connectTimeoutMS: 20000.0ms)')>]>

使用的pymongo连接代码:

driver_URL="mongodb+srv://<user>:<password>@<domain>/?retryWrites=true&w=majority&appName=Cluster0"

with MongoClient(driver_URL) as client :
    webcamDb = client.webcam
    webCamCol = webcamDb.webcam

修复步骤

  • 检查ECS Fargate网络权限:确认Fargate任务所属安全组、网络ACL允许出站访问27017端口,同时将Fargate任务的公网IP或所在VPC的CIDR段加入MongoDB Atlas的IP白名单。
  • 强制指定TLS版本:MongoDB Atlas要求使用TLS 1.2及以上版本,修改连接代码显式指定TLS版本:
    from pymongo import MongoClient
    import ssl
    
    driver_URL="mongodb+srv://<user>:<password>@<domain>/?retryWrites=true&w=majority&appName=Cluster0"
    client = MongoClient(
        driver_URL,
        tls=True,
        tlsAllowInvalidCertificates=False,
        tlsVersion=ssl.PROTOCOL_TLSv1_2
    )
    with client:
        webcamDb = client.webcam
        webCamCol = webcamDb.webcam
    
  • 更新依赖库:执行pip install --upgrade pymongo更新到最新稳定版,同时确保系统OpenSSL版本支持TLS 1.2+。
  • 验证连接字符串有效性:确认<domain>是正确的Atlas集群域名,用户密码中的特殊字符(如@、&)已做URL编码。
  • 检查DNS解析:在Fargate任务内执行nslookup ac-xvafg1z-shard-00-00.pizmgb2.mongodb.net,确认能正常解析Atlas节点域名,排除DNS故障。

内容的提问来源于stack exchange,提问作者tthogho1

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.20 13:03:18