You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Docker中MongoDB的allowConnectionsWithoutCertificates在requireTLS模式下失效

MongoDB 4.4.26 TLS配置连接失败排查

按照MongoDB文档《仅在客户端提供证书时验证》的指引,在Docker中部署MongoDB 4.4.26,配置allowConnectionsWithoutCertificates: true后,无法使用初始账号密码连接,报错SSL握手失败,以下是问题详情及解决方案:

一、当前配置

mongod.conf 配置

net:
  tls:
    mode: requireTLS
    certificateKeyFile: /etc/ssl/server.pem
    CAFile: /etc/ssl/ca.pem
    allowConnectionsWithoutCertificates: true

Docker启动命令

docker run -d \
        --name mongodb \
        -e MONGO_INITDB_ROOT_USERNAME=root \
        -e MONGO_INITDB_ROOT_PASSWORD=rootpassword \
        -v /path/to/the/mongod.conf:/etc/mongod.conf \
        -v /path/to/the/server.pem:/etc/ssl/server.pem \
        -v /path/to/the/ca.pem:/etc/ssl/ca.pem \
        -v /path/to/the/client.pem:/etc/ssl/client.pem \
        -p 27017:27017 \
        mongo:4.4.26 --config /etc/mongod.conf

二、连接报错信息

执行连接命令:

root@2b95c9e5d8a8:/# mongo admin -u root -p rootpassword

返回错误:

MongoDB shell version v4.4.26
connecting to: mongodb://127.0.0.1:27017/admin?compressors=disabled&gssapiServiceName=mongodb
Error: network error while attempting to run command 'isMaster' on host '127.0.0.1:27017'  :
connect@src/mongo/shell/mongo.js:374:17
@(connect):2:6
exception: connect failed
exiting with code 1

三、Docker容器日志

{"t":{"$date":"2023-12-28T11:23:29.777+00:00"},"s":"I",  "c":"NETWORK",  "id":22988,   "ctx":"conn1","msg":"Error receiving request from client. Ending connection from remote","attr":{"error":{"code":141,"codeName":"SSLHandshakeFailed","errmsg":"The server is configured to only allow SSL connections"},"remote":"127.0.0.1:39754","connectionId":1}}

四、问题分析与解决

你的服务端配置本身没有问题,allowConnectionsWithoutCertificates: true确实允许无客户端证书的TLS连接,但客户端发起连接时必须明确启用TLS协议,否则会被服务器拒绝(因为服务器要求所有连接必须走TLS加密)。

你当前使用的mongo命令未指定TLS参数,导致客户端尝试建立非加密连接,触发SSL握手失败。

修正后的连接命令需添加TLS相关参数:

# 验证服务器证书的安全方式(推荐)
mongo admin -u root -p rootpassword --tls --tlsCAFile /etc/ssl/ca.pem

# 不验证服务器证书(仅测试环境使用)
mongo admin -u root -p rootpassword --tls --tlsInsecure

额外注意:

  • 如果在容器外部连接,需将/etc/ssl/ca.pem替换为宿主机上对应的证书路径
  • allowConnectionsWithoutCertificates的作用是允许客户端不提供证书,但所有连接仍必须通过TLS加密,因此客户端必须显式启用TLS

内容的提问来源于stack exchange,提问作者Abu Sayed

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.03 09:51:18