有无用户使用启用SSL的PostgreSQL搭配qTest?证书配置报错求助
环境信息
- qTest: 11.3.0
- Elasticsearch: 7.7.1
- PostgreSQL: 13.12.1
问题现象
为PostgreSQL配置SSL证书后,执行qTest安装时触发主机名验证错误,具体报错如下:
现有属性不可用,使用项目属性
[23-12-05 11:17:47] org.postgresql.util.PSQLException: 主机名[xxxxx]无法通过主机名验证器PgjdbcHostnameVerifier验证。
at org.postgresql.ssl.MakeSSL.verifyPeerName(MakeSSL.java:81)
at org.postgresql.ssl.MakeSSL.convert(MakeSSL.java:52)
at org.postgresql.core.v3.ConnectionFactoryImpl.enableSSL(ConnectionFactoryImpl.java:584)
at org.postgresql.core.v3.ConnectionFactoryImpl.tryConnect(ConnectionFactoryImpl.java:168)
at org.postgresql.core.v3.ConnectionFactoryImpl.openConnectionImpl(ConnectionFactoryImpl.java:235)
at org.postgresql.core.ConnectionFactory.openConnection(ConnectionFactory.java:49)
at org.postgresql.jdbc.PgConnection.(PgConnection.java:247)
at org.postgresql.Driver.makeConnection(Driver.java:434)
解决步骤
1. 校验SSL证书的主机名匹配
确保PostgreSQL SSL证书的Subject Alternative Name (SAN) 或Common Name (CN) 与qTest连接时使用的主机名xxxxx完全一致(包括大小写、域名后缀)。如果证书中没有包含该主机名,需要重新签发符合要求的SSL证书。
2. 修改qTest数据库连接参数
若无法立即重新签发证书,可调整qTest的PostgreSQL连接URL,降低SSL验证级别:
- 找到qTest的数据库配置文件(如
application.properties) - 修改连接URL,添加
sslmode参数:jdbc:postgresql://xxxxx:5432/your_db_name?sslmode=verify-ca&sslrootcert=/path/to/your/root.crtsslmode=verify-ca:仅验证证书是否由可信CA签发,不校验主机名sslmode=require:仅强制使用SSL连接,不验证证书合法性(安全性较低,谨慎使用)
3. 检查PostgreSQL SSL配置
确认PostgreSQL的postgresql.conf中SSL参数配置正确:
ssl = on ssl_cert_file = '/var/lib/postgresql/13/main/server.crt' ssl_key_file = '/var/lib/postgresql/13/main/server.key' ssl_root_cert_file = '/var/lib/postgresql/13/main/root.crt'
同时在pg_hba.conf中配置允许SSL连接的规则:
hostssl all all 0.0.0.0/0 scram-sha-256
4. 验证证书信息
使用openssl工具检查证书的主机名配置:
# 查看Subject Alternative Name字段 openssl x509 -in server.crt -text -noout | grep -A 2 "Subject Alternative Name" # 查看Common Name字段 openssl x509 -in server.crt -text -noout | grep "Subject:"
确认输出的主机名与qTest连接使用的xxxxx一致。
内容的提问来源于stack exchange,提问作者Nandha kumar S

