You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Debezium MongoDB连接器SSL密钥库与信任库路径问题排查

Debezium MongoDB连接器SSL连接问题排查求助

连接器配置

{
"name": "debezium-mongo",
"config": {
"connector.class" : "io.debezium.connector.mongodb.MongoDbConnector",
"topic.prefix" : "testmongo",
"tasks.max" : "1",
"mongodb.members.auto.discover": "false",
"mongodb.connection.string" : "mongodb://test:dev@rcx-mongo:27017,mongors1n1:27017,mongors2n1:27017/test?replicaSet=rs0",
"mongodb.port": "27017",
"mongodb.server.name": "debezium-mongo",
"mongodb.user" : "test",
"mongodb.password" : "dev",

    "mongodb.ssl.enabled" :"true",
    "mongodb.connection.mode": "replica_set",
    "database.ssl.keystore.location":"/kafka/certificates/mongo.client.keystore.jks",
    "database.ssl.keystore.password":"rcxdev",
    "database.ssl.truststore.location":"/kafka/certificates/mongo.client.truststore.jks",

    "database.ssl.truststore.password":"dev",
    "database.ssl.keystore.type": "JKS"
} }

Docker Compose配置

connect:
image: debezium/connect:2.3
environment:
LOG_LEVEL: INFO
CONNECT_TOPIC_CREATION_ENABLE: "false"
# BOOTSTRAP_SERVERS: kafka:9092
CONFIG_STORAGE_TOPIC: config-topic
OFFSET_STORAGE_TOPIC: offset-topic
GROUP_ID: kafka-connect-consumer-group

    ADMIN_BOOTSTRAP_SERVERS: kafka:9092
    ADMIN_SSL_ENABLED: "true"
    ADMIN_SECURITY_PROTOCOL: SSL
    ADMIN_SSL_TRUSTSTORE_LOCATION: /certs/truststore.jks
    ADMIN_SSL_TRUSTSTORE_PASSWORD: dev
    ADMIN_SSL_KEYSTORE_LOCATION: /certs/keystore.jks
    ADMIN_SSL_KEYSTORE_PASSWORD: dev
    ADMIN_SSL_KEY_PASSWORD: dev

    CONSUMER_BOOTSTRAP_SERVERS: kafka:9092
    CONSUMER_SSL_ENABLED: "true"
    CONSUMER_SECURITY_PROTOCOL: SSL
    CONSUMER_SSL_TRUSTSTORE_LOCATION: /certs/truststore.jks
    CONSUMER_SSL_TRUSTSTORE_PASSWORD: rcxdev
    CONSUMER_SSL_KEYSTORE_LOCATION: /certs/keystore.jks
    CONSUMER_SSL_KEYSTORE_PASSWORD: dev
    CONSUMER_SSL_KEY_PASSWORD: rcxdev

    PRODUCER_BOOTSTRAP_SERVERS: kafka:9092
    PRODUCER_SSL_ENABLED: "true"
    PRODUCER_SECURITY_PROTOCOL: SSL
    PRODUCER_SSL_TRUSTSTORE_LOCATION: /certs/truststore.jks
    PRODUCER_SSL_TRUSTSTORE_PASSWORD: dev
    PRODUCER_SSL_KEYSTORE_LOCATION: /certs/keystore.jks
    PRODUCER_SSL_KEYSTORE_PASSWORD: dev
    PRODUCER_SSL_KEY_PASSWORD: dev

    BOOTSTRAP_SERVERS: kafka:9092
    CONNECT_SSL_ENABLED: "true"
    CONNECT_SECURITY_PROTOCOL: SSL
    CONNECT_SSL_TRUSTSTORE_LOCATION: /certs/truststore.jks
    CONNECT_SSL_TRUSTSTORE_PASSWORD: dev
    CONNECT_SSL_KEYSTORE_LOCATION: /certs/keystore.jks
    CONNECT_SSL_KEYSTORE_PASSWORD: dev
    CONNECT_SSL_KEY_PASSWORD: dev
    JAVA_OPTS: -Djavax.net.debug=all
  volumes:
    - ./build/ssl_create/ssl:/certs
    - ./build/kafka-connector:/kafka/certificates
  # command: ["kafka-connect-start", ./build/kafka-connector/mongo-connector.properties]
  depends_on:
    - kafka
    - mongo

查看的SSL启用代码片段

if (useSSL) {
settings.applyToSslSettings(
builder -> builder.enabled(true).invalidHostNameAllowed(sslAllowInvalidHostnames));
}

错误日志

ERROR MongoDB|testmongo|rs0 Error while attempting to Setting resume token: Timed out after 30000 ms while waiting for a server that matches com.mongodb.client.internal.MongoClientDelegate$1@4a1491e8. Client view of cluster state is {type=REPLICA_SET, servers=[{address=rcx-mongo:27017, type=UNKNOWN, state=CONNECTING, exception={com.mongodb.MongoSocketWriteException: Exception sending message}, caused by {javax.net.ssl.SSLHandshakeException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target}, caused by {sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target}, caused by {sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target}}, {address=mongors1n1:27017, type=UNKNOWN, state=CONNECTING, exception={com.mongodb.MongoSocketWriteException: Exception sending message}, caused by {javax.net.ssl.SSLHandshakeException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target}, caused by {sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target}, caused by {sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target}}, {address=mongors2n1:27017, type=UNKNOWN, state=CONNECTING, exception={com.mongodb.MongoSocketWriteException: Exception sending message}, caused by {javax.net.ssl.SSLHandshakeException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target}, caused by {sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target}, caused by {sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target}}]
[io.debezium.connector.mongodb.connection.MongoDbConnection] connect_1 | com.mongodb.MongoTimeoutException: Timed out after 30000 ms while waiting for a server that matches com.mongodb.client.internal.MongoClientDelegate$1@4a1491e8. Client view of cluster state is {type=REPLICA_SET, servers=[{address=rcx-mongo:27017, type=UNKNOWN, state=CONNECTING, exception={com.mongodb.MongoSocketWriteException: Exception sending message}, caused by {javax.net.ssl.SSLHandshakeException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target}, caused by {sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target}, caused by {sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target}}, {address=mongors1n1:27017, type=UNKNOWN, state=CONNECTING, exception={com.mongodb.MongoSocketWriteException: Exception sending message}, caused by {javax.net.ssl.SSLHandshakeException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target}, caused by {sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target}, caused by {sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target}}, {address=mongors2n1:27017, type=UNKNOWN, state=CONNECTING, exception={com.mongodb.MongoSocketWriteException: Exception sending message}, caused by {javax.net.ssl.SSLHandshakeException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target}, caused by {sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target}, caused by {sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target}}]

错误核心翻译

连接超时的根源是SSL握手失败:PKIX路径构建失败,无法找到到目标服务器的有效认证路径,说明连接器无法信任MongoDB副本集的服务器证书,或证书链不完整。

排查步骤

  • 修正连接器SSL参数前缀
    Debezium MongoDB连接器的SSL配置参数需使用mongodb.ssl.*前缀,原配置中的database.ssl.*参数无效,修改后如下:

    "mongodb.ssl.keystore.location":"/kafka/certificates/mongo.client.keystore.jks",
    "mongodb.ssl.keystore.password":"rcxdev",
    "mongodb.ssl.truststore.location":"/kafka/certificates/mongo.client.truststore.jks",
    "mongodb.ssl.truststore.password":"dev",
    "mongodb.ssl.keystore.type": "JKS"
    
  • 验证证书文件的存在性与权限

    1. 进入Connect容器,检查证书路径是否存在:
      docker exec -it <connect容器ID> ls /kafka/certificates
      
    2. 确认证书文件权限允许Connect进程读取:
      docker exec -it <connect容器ID> ls -l /kafka/certificates
      
  • 检查信任库内容

    1. 使用keytool验证信任库是否包含MongoDB服务器的根/中间证书:
      keytool -list -v -keystore /kafka/certificates/mongo.client.truststore.jks -storepass dev
      
    2. 若缺失,将MongoDB服务器证书导入信任库:
      keytool -import -alias mongodb-server -file mongodb-server.crt -keystore mongo.client.truststore.jks -storepass dev
      
  • 验证MongoDB证书的主机名匹配

    1. 检查MongoDB服务器证书的SAN字段是否包含所有副本集节点的主机名(rcx-mongo、mongors1n1、mongors2n1)。
    2. 临时添加mongodb.ssl.invalid.hostname.allowed=true参数跳过主机名验证,排查是否为主机名不匹配问题(生产环境禁用)。
  • 更新MongoDB连接字符串
    在连接字符串中显式指定SSL参数:

    mongodb://test:dev@rcx-mongo:27017,mongors1n1:27017,mongors2n1:27017/test?replicaSet=rs0&ssl=true
    
  • 分析SSL调试日志
    已启用-Djavax.net.debug=all,查看Connect容器日志,重点关注SSL握手环节的证书验证细节,定位具体错误节点。

内容的提问来源于stack exchange,提问作者Nagaraju M

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.01 13:37:03