Debezium MongoDB连接器SSL密钥库与信任库路径问题排查
连接器配置
{ "name": "debezium-mongo", "config": { "connector.class" : "io.debezium.connector.mongodb.MongoDbConnector", "topic.prefix" : "testmongo", "tasks.max" : "1", "mongodb.members.auto.discover": "false", "mongodb.connection.string" : "mongodb://test:dev@rcx-mongo:27017,mongors1n1:27017,mongors2n1:27017/test?replicaSet=rs0", "mongodb.port": "27017", "mongodb.server.name": "debezium-mongo", "mongodb.user" : "test", "mongodb.password" : "dev", "mongodb.ssl.enabled" :"true", "mongodb.connection.mode": "replica_set", "database.ssl.keystore.location":"/kafka/certificates/mongo.client.keystore.jks", "database.ssl.keystore.password":"rcxdev", "database.ssl.truststore.location":"/kafka/certificates/mongo.client.truststore.jks", "database.ssl.truststore.password":"dev", "database.ssl.keystore.type": "JKS" } }
Docker Compose配置
connect: image: debezium/connect:2.3 environment: LOG_LEVEL: INFO CONNECT_TOPIC_CREATION_ENABLE: "false" # BOOTSTRAP_SERVERS: kafka:9092 CONFIG_STORAGE_TOPIC: config-topic OFFSET_STORAGE_TOPIC: offset-topic GROUP_ID: kafka-connect-consumer-group ADMIN_BOOTSTRAP_SERVERS: kafka:9092 ADMIN_SSL_ENABLED: "true" ADMIN_SECURITY_PROTOCOL: SSL ADMIN_SSL_TRUSTSTORE_LOCATION: /certs/truststore.jks ADMIN_SSL_TRUSTSTORE_PASSWORD: dev ADMIN_SSL_KEYSTORE_LOCATION: /certs/keystore.jks ADMIN_SSL_KEYSTORE_PASSWORD: dev ADMIN_SSL_KEY_PASSWORD: dev CONSUMER_BOOTSTRAP_SERVERS: kafka:9092 CONSUMER_SSL_ENABLED: "true" CONSUMER_SECURITY_PROTOCOL: SSL CONSUMER_SSL_TRUSTSTORE_LOCATION: /certs/truststore.jks CONSUMER_SSL_TRUSTSTORE_PASSWORD: rcxdev CONSUMER_SSL_KEYSTORE_LOCATION: /certs/keystore.jks CONSUMER_SSL_KEYSTORE_PASSWORD: dev CONSUMER_SSL_KEY_PASSWORD: rcxdev PRODUCER_BOOTSTRAP_SERVERS: kafka:9092 PRODUCER_SSL_ENABLED: "true" PRODUCER_SECURITY_PROTOCOL: SSL PRODUCER_SSL_TRUSTSTORE_LOCATION: /certs/truststore.jks PRODUCER_SSL_TRUSTSTORE_PASSWORD: dev PRODUCER_SSL_KEYSTORE_LOCATION: /certs/keystore.jks PRODUCER_SSL_KEYSTORE_PASSWORD: dev PRODUCER_SSL_KEY_PASSWORD: dev BOOTSTRAP_SERVERS: kafka:9092 CONNECT_SSL_ENABLED: "true" CONNECT_SECURITY_PROTOCOL: SSL CONNECT_SSL_TRUSTSTORE_LOCATION: /certs/truststore.jks CONNECT_SSL_TRUSTSTORE_PASSWORD: dev CONNECT_SSL_KEYSTORE_LOCATION: /certs/keystore.jks CONNECT_SSL_KEYSTORE_PASSWORD: dev CONNECT_SSL_KEY_PASSWORD: dev JAVA_OPTS: -Djavax.net.debug=all volumes: - ./build/ssl_create/ssl:/certs - ./build/kafka-connector:/kafka/certificates # command: ["kafka-connect-start", ./build/kafka-connector/mongo-connector.properties] depends_on: - kafka - mongo
查看的SSL启用代码片段
if (useSSL) { settings.applyToSslSettings( builder -> builder.enabled(true).invalidHostNameAllowed(sslAllowInvalidHostnames)); }
错误日志
ERROR MongoDB|testmongo|rs0 Error while attempting to Setting resume token: Timed out after 30000 ms while waiting for a server that matches com.mongodb.client.internal.MongoClientDelegate$1@4a1491e8. Client view of cluster state is {type=REPLICA_SET, servers=[{address=rcx-mongo:27017, type=UNKNOWN, state=CONNECTING, exception={com.mongodb.MongoSocketWriteException: Exception sending message}, caused by {javax.net.ssl.SSLHandshakeException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target}, caused by {sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target}, caused by {sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target}}, {address=mongors1n1:27017, type=UNKNOWN, state=CONNECTING, exception={com.mongodb.MongoSocketWriteException: Exception sending message}, caused by {javax.net.ssl.SSLHandshakeException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target}, caused by {sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target}, caused by {sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target}}, {address=mongors2n1:27017, type=UNKNOWN, state=CONNECTING, exception={com.mongodb.MongoSocketWriteException: Exception sending message}, caused by {javax.net.ssl.SSLHandshakeException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target}, caused by {sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target}, caused by {sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target}}]
[io.debezium.connector.mongodb.connection.MongoDbConnection] connect_1 | com.mongodb.MongoTimeoutException: Timed out after 30000 ms while waiting for a server that matches com.mongodb.client.internal.MongoClientDelegate$1@4a1491e8. Client view of cluster state is {type=REPLICA_SET, servers=[{address=rcx-mongo:27017, type=UNKNOWN, state=CONNECTING, exception={com.mongodb.MongoSocketWriteException: Exception sending message}, caused by {javax.net.ssl.SSLHandshakeException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target}, caused by {sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target}, caused by {sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target}}, {address=mongors1n1:27017, type=UNKNOWN, state=CONNECTING, exception={com.mongodb.MongoSocketWriteException: Exception sending message}, caused by {javax.net.ssl.SSLHandshakeException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target}, caused by {sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target}, caused by {sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target}}, {address=mongors2n1:27017, type=UNKNOWN, state=CONNECTING, exception={com.mongodb.MongoSocketWriteException: Exception sending message}, caused by {javax.net.ssl.SSLHandshakeException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target}, caused by {sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target}, caused by {sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target}}]
错误核心翻译
连接超时的根源是SSL握手失败:PKIX路径构建失败,无法找到到目标服务器的有效认证路径,说明连接器无法信任MongoDB副本集的服务器证书,或证书链不完整。
排查步骤
修正连接器SSL参数前缀
Debezium MongoDB连接器的SSL配置参数需使用mongodb.ssl.*前缀,原配置中的database.ssl.*参数无效,修改后如下:"mongodb.ssl.keystore.location":"/kafka/certificates/mongo.client.keystore.jks", "mongodb.ssl.keystore.password":"rcxdev", "mongodb.ssl.truststore.location":"/kafka/certificates/mongo.client.truststore.jks", "mongodb.ssl.truststore.password":"dev", "mongodb.ssl.keystore.type": "JKS"验证证书文件的存在性与权限
- 进入Connect容器,检查证书路径是否存在:
docker exec -it <connect容器ID> ls /kafka/certificates - 确认证书文件权限允许Connect进程读取:
docker exec -it <connect容器ID> ls -l /kafka/certificates
- 进入Connect容器,检查证书路径是否存在:
检查信任库内容
- 使用keytool验证信任库是否包含MongoDB服务器的根/中间证书:
keytool -list -v -keystore /kafka/certificates/mongo.client.truststore.jks -storepass dev - 若缺失,将MongoDB服务器证书导入信任库:
keytool -import -alias mongodb-server -file mongodb-server.crt -keystore mongo.client.truststore.jks -storepass dev
- 使用keytool验证信任库是否包含MongoDB服务器的根/中间证书:
验证MongoDB证书的主机名匹配
- 检查MongoDB服务器证书的SAN字段是否包含所有副本集节点的主机名(rcx-mongo、mongors1n1、mongors2n1)。
- 临时添加
mongodb.ssl.invalid.hostname.allowed=true参数跳过主机名验证,排查是否为主机名不匹配问题(生产环境禁用)。
更新MongoDB连接字符串
在连接字符串中显式指定SSL参数:mongodb://test:dev@rcx-mongo:27017,mongors1n1:27017,mongors2n1:27017/test?replicaSet=rs0&ssl=true分析SSL调试日志
已启用-Djavax.net.debug=all,查看Connect容器日志,重点关注SSL握手环节的证书验证细节,定位具体错误节点。
内容的提问来源于stack exchange,提问作者Nagaraju M

