如何更新.NET Serilog日志配置适配Elasticsearch 8安全要求
问题:.NET应用对接Elasticsearch 8.x HTTPS端点证书信任问题
背景
- 已从Elastic 7.x升级至8.x,Elastic端点要求通过HTTPS连接,需提供用户名、密码及TLS证书
- 在Kubernetes集群内测试连通性成功:将TLS证书复制到应用容器后,执行以下命令:
返回正常的集群信息:curl --cacert tls.crt -u elastic: https://elasticsearch-cluster-es-http.eck:9200{ "name" : "elasticsearch-cluster-es-default-1", "cluster_name" : "elasticsearch-cluster", "cluster_uuid" : "YqYl-gTpRd-URcoDhW5t1w", "version" : { "number" : "8.11.2", "build_flavor" : "default", "build_type" : "docker", "build_hash" : "76013fa76dcbf144c886990c6290715f5dc2ae20", "build_date" : "2023-12-05T10:03:47.729926671Z", "build_snapshot" : false, "lucene_version" : "9.8.0", "minimum_wire_compatibility_version" : "7.17.0", "minimum_index_compatibility_version" : "7.0.0" }, "tagline" : "You Know, for Search" }
问题场景
需要更新.NET日志配置以适配HTTPS、用户名密码及TLS证书要求,尝试了以下配置(也试过证书指纹)但未成功:
var elasticOptions = new ElasticsearchSinkOptions(new Uri($"https://{elasticServer}")) { AutoRegisterTemplate = true, IndexDecider = (@event, offset) => string.Format("{0}-{1}-{2:yyyy.MM.dd}", k8sNamespace, appName, offset), ModifyConnectionSettings = (settings) => { settings.EnableApiVersioningHeader(); settings.ClientCertificate(new X509Certificate2(crtBytes)); settings.BasicAuthentication("elastic", "<password>"); settings.DeadTimeout(TimeSpan.FromSeconds(300)); return settings; } };
应用抛出错误:
System.Net.Http.HttpRequestException: The SSL connection could not be established, see inner exception. ---> System.Security.Authentication.AuthenticationException: The remote certificate is invalid because of errors in the certificate chain: UntrustedRoot
环境信息
- dotnet 8
- serilog.sinks.elasticsearch: 9.0.3
- elasticsearch eck: 8.11.2
内容的提问来源于stack exchange,提问作者Matthew S
相关产品推荐
相关产品推荐

