You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

未提供证书却建立AWS RDS MySQL SSL连接,如何强制验证证书?

AWS RDS MySQL SSL/TLS连接问题:未提供证书却建立加密连接,如何强制证书验证

问题描述

首次配置AWS RDS MySQL的SSL/TLS加密连接时,遇到以下异常:

  • 按教程操作,教程中连接新用户后执行\s显示SSL状态为No SSL;但我执行相同操作,未提供证书却显示SSL加密已建立(SSL: Cipher in use is TLS_AES_256_GCM_SHA384)。
  • 手动提供证书后,\s的SSL参数无变化。
  • 仅当添加--ssl-mode=VERIFY_CA参数时,连接直接失败。
  • 已尝试修改AWS参数组中的require_secure_transport参数,但未达到强制要求证书才能连接的效果。

连接测试输出

C:\Users\mohsana>mysql -h poc-ssl-db.cozuojekgxu7.us-east-1.rds.amazonaws.com -u encrypted_user -p
Enter password: ********
Welcome to the MySQL monitor.  Commands end with ; or \g.
Your MySQL connection id is 12
Server version: 8.0.35 Source distribution

Copyright (c) 2000, 2023, Oracle and/or its affiliates.

Oracle is a registered trademark of Oracle Corporation and/or its
affiliates. Other names may be trademarks of their respective
owners.

Type 'help;' or '\h' for help. Type '\c' to clear the current input statement.

mysql> \s
--------------
mysql  Ver 8.0.35 for Win64 on x86_64 (MySQL Community Server - GPL)

Connection id:          12
Current database:
Current user:           encrypted_user@223.123.11.54
SSL:                    Cipher in use is TLS_AES_256_GCM_SHA384
Using delimiter:        ;
Server version:         8.0.35 Source distribution
Protocol version:       10
Connection:             poc-ssl-db.cozuojekgxu7.us-east-1.rds.amazonaws.com via TCP/IP
Server characterset:    utf8mb4
Db     characterset:    utf8mb4
Client characterset:    cp850
Conn.  characterset:    cp850
TCP port:               3306
Binary data as:         Hexadecimal
Uptime:                 23 min 15 sec

Threads: 3  Questions: 1048  Slow queries: 0  Opens: 162  Flush tables: 3  Open tables: 81  Queries per second avg: 0.751
--------------

mysql>

原因分析

  1. RDS MySQL默认SSL行为:MySQL 8.0及以上版本的RDS实例,默认采用ssl-mode=PREFERRED(客户端优先尝试SSL连接)。即使客户端未指定证书,只要服务器支持SSL,就会建立加密连接,但不会验证服务器证书的合法性——这就是你未提供证书却显示SSL加密的原因。
  2. VERIFY_CA连接失败的原因:未正确提供AWS RDS的根证书文件,或证书路径错误,导致客户端无法验证服务器证书的签发机构。
  3. require_secure_transport的局限性:该参数仅强制所有连接必须使用SSL加密,但不要求验证证书。因此即使开启该参数,客户端仍可在不验证证书的情况下建立加密连接。

强制证书验证的配置步骤

1. 下载AWS RDS根证书

获取对应RDS区域的官方根证书(例如rds-ca-2019-root.pem),保存到本地路径(如C:\rds-ca.pem)。

2. 确保require_secure_transport已开启

在AWS参数组中将require_secure_transport设置为ON,保存后重启RDS实例生效。此步骤确保所有连接必须使用SSL加密,杜绝明文连接。

3. 创建强制证书验证的数据库用户

仅开启参数组不够,需为用户添加证书验证约束,强制其连接时必须验证证书:

-- 创建用户(若已存在可跳过)
CREATE USER 'encrypted_user'@'%' IDENTIFIED BY 'your_strong_password';
GRANT ALL PRIVILEGES ON your_database.* TO 'encrypted_user'@'%';

-- 强制验证服务器证书主题(CN需与RDS实例端点完全一致)
ALTER USER 'encrypted_user'@'%' REQUIRE SUBJECT '/CN=poc-ssl-db.cozuojekgxu7.us-east-1.rds.amazonaws.com';

-- 或强制验证证书颁发机构(根据根证书信息调整)
ALTER USER 'encrypted_user'@'%' REQUIRE ISSUER '/C=US/O=Amazon Web Services, Inc./OU=Amazon RDS/CN=Amazon RDS Root CA 2019';

FLUSH PRIVILEGES;

4. 客户端带证书验证连接

使用以下命令连接,指定证书路径和严格的SSL模式:

-- 验证证书签发机构
mysql -h poc-ssl-db.cozuojekgxu7.us-east-1.rds.amazonaws.com -u encrypted_user -p --ssl-mode=VERIFY_CA --ssl-ca=C:\rds-ca.pem

-- 更严格:同时验证服务器主机名与证书CN
mysql -h poc-ssl-db.cozuojekgxu7.us-east-1.rds.amazonaws.com -u encrypted_user -p --ssl-mode=VERIFY_IDENTITY --ssl-ca=C:\rds-ca.pem

5. 验证连接状态

连接成功后执行\s,确认SSL状态显示加密套件,此时的连接是经过证书验证的安全连接。

常见问题排查

  • --ssl-mode=VERIFY_CA连接失败:检查证书文件是否正确、路径是否无误,确保使用的是对应RDS区域的根证书。
  • 用户仍可无证书验证连接:确认已为用户设置REQUIRE SUBJECT或REQUIRE ISSUER,且require_secure_transport已开启并生效。

内容的提问来源于stack exchange,提问作者Ali Mohsan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.24 09:52:04