Redisson SSL连接失败但Lettuce正常,如何解决该问题?
Redisson SSL连接Redis失败,Lettuce同配置可正常连接
背景
我们正在为ElastiCache/Redis连接启用SSL加密,测试环境使用配置了SSL的Redis Docker容器,容器具备完整的证书和密钥文件,使用redis-cli可正常建立安全连接。
我们为Redisson客户端创建了密钥库(keystore)和信任库(truststore),但配置后连接失败;使用相同的keystore和truststore配置Lettuce客户端时,连接却能正常建立。
Redisson失败配置代码
@Bean(destroyMethod = "shutdown") public RedissonClient redissonClient() throws MalformedURLException { File truststore = new File("docker/certs/truststore.jks"); File keystore = new File("docker/certs/redis_key_store.p12"); Config config = new Config(); //SingleServerConfig singleServerConfig = config.useSingleServer(); ReplicatedServersConfig elasticacheServersConfig = config.useReplicatedServers(); elasticacheServersConfig .setSslProtocols(new String[]{"TLSv1.3"}) .setSslCiphers(new String[] { "TLS_AES_256_GCM_SHA384", "TLS_CHACHA20_POLY1305_SHA256", "TLS_AES_128_GCM_SHA256" }) .setSslEnableEndpointIdentification(false) .setSslKeystorePassword("password") .setSslKeystore(keystore.toURI().toURL()) .setSslTruststorePassword("password") .setSslTruststore(truststore.toURI().toURL()) .setPassword("password"); redisEndpoints() .stream() .map(endpoint -> "rediss://" + endpoint.getAddress() + ":" + endpoint.getPort()) .forEach(elasticacheServersConfig::addNodeAddress); return Redisson.create(config); }
服务器端错误日志
Error accepting a client connection: error:0A000416:SSL routines::sslv3 alert certificate unknown
初步排查怀疑与证书/密钥有关,但无法完全确认。
Lettuce正常配置代码
@Bean public RedisConnectionFactory redisConnectionFactory() { File truststore = new File("docker/certs/truststore.jks"); File keystore = new File("docker/certs/redis_key_store.p12"); var endpoint = new Endpoint().withAddress("127.0.0.1").withPort(63798); final RedisStandaloneConfiguration redisStandaloneConfiguration = new RedisStandaloneConfiguration(endpoint.getAddress(), endpoint.getPort()); redisStandaloneConfiguration.setPassword("password"); final LettuceClientConfiguration.LettuceClientConfigurationBuilder builder = LettuceClientConfiguration .builder() .readFrom(ReadFrom.MASTER_PREFERRED) .commandTimeout(Duration.of(5000, ChronoUnit.MILLIS)) .clientOptions(ClientOptions.builder() .socketOptions(SocketOptions.builder() .keepAlive(true) .build()) .sslOptions(SslOptions.builder() .keystore(keystore, "password".toCharArray()) .truststore(truststore, "password") .build()) .build()); builder.useSsl().disablePeerVerification(); return new LettuceConnectionFactory(redisStandaloneConfiguration, builder.build()); }
测试代码:
var connection = redisConnectionFactory.getConnection(); connection.set("test".getBytes(), "1".getBytes()); byte [] g = connection.get("test".getBytes()); connection.close();
两者的明显差异在于Lettuce通过disablePeerVerification()禁用了peer verification,而我们必须使用Redisson(依赖其提供的执行器服务),请问如何配置才能让Redisson正常建立SSL连接?
内容的提问来源于stack exchange,提问作者IndyStef
相关产品推荐
相关产品推荐

