You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Node.js连接AWS RDS时如何启用verify-full选项?

问题与解决方案

背景

我编写了如下Node.js脚本用于连接PostgreSQL:

const { Pool } = require('pg');
const { parse } = require('pg-connection-string');

const config = parse(process.env.DATABASE_URL);
config.ssl = { rejectUnauthorized: true };

const pool = new Pool(config);

pool.connect((err, client, done) => {
  if (err) {
    console.error('Error acquiring client', err.stack);
    return;
  }

  const testQuery = 'SELECT * FROM information_schema.tables';
  client.query(testQuery, (err, result) => {
    done();
    if (err) {
      console.error('Error executing query', err.stack);
      return;
    }
    console.log('Query result:', result.rows);
    pool.end();
  });
});

运行前已导出环境变量NODE_EXTRA_CA_CERTS=../aws-global-bundle.pem,该PEM文件为AWS RDS的全局信任证书。

我尝试过如下配置但sslmode: 'verify-full'未生效,甚至设置为sslmode: 'foobar'也能正常连接:

config.ssl = { 
  rejectUnauthorized: true,
  sslmode: 'verify-full',
  ca: fs.readFileSync('./global-bundle.pem').toString(),
};

核心问题与解答

1. 为什么sslmode参数不生效?

node-postgres(pg库)是纯JavaScript实现的客户端,不兼容PostgreSQL官方libpq库的sslmode参数。你设置的sslmode会被客户端直接忽略,因此无论填什么值都不会影响连接逻辑,也不会报错。

2. 如何实现PostgreSQL官方的verify-full验证?

PostgreSQL的verify-full要求完成两项验证:

  • 服务器证书由可信CA签发
  • 服务器证书中的主机名与连接的数据库主机名完全匹配

在node-postgres中,通过配置Node.js TLS参数即可实现等价效果,无需使用sslmode:

方式一:直接在代码中指定CA证书

const fs = require('fs');
const { Pool } = require('pg');
const { parse } = require('pg-connection-string');

const config = parse(process.env.DATABASE_URL);
config.ssl = {
  rejectUnauthorized: true, // 开启完整验证
  ca: fs.readFileSync('./global-bundle.pem').toString() // 指定CA证书
};

const pool = new Pool(config);
// 后续连接逻辑...

方式二:使用NODE_EXTRA_CA_CERTS环境变量

如果已经通过环境变量指定了CA证书,只需保留rejectUnauthorized: true即可:

const config = parse(process.env.DATABASE_URL);
config.ssl = { rejectUnauthorized: true };

3. rejectUnauthorized: true与verify-full的实际区别?

Node.js TLS的rejectUnauthorized: true完全等价于PostgreSQL的verify-full:

  • 当rejectUnauthorized设为true时,Node.js会自动执行两项验证:
    1. 验证服务器证书是否由可信CA签发(对应verify-ca的要求)
    2. 验证证书中的主机名(或SAN字段)是否与目标主机名一致(verify-full独有的验证步骤)
  • 若仅需实现verify-ca(只验证证书可信,不验证主机名),需要额外覆盖checkServerIdentity:
config.ssl = {
  rejectUnauthorized: true,
  ca: fs.readFileSync('./global-bundle.pem').toString(),
  checkServerIdentity: () => undefined // 跳过主机名验证
};

内容的提问来源于stack exchange,提问作者pkaramol

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.29 13:25:11