You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

MQTTS/SSL证书连接故障:证书验证错误求助

解决MQTTS连接的Certificate Verify error问题

针对你遇到的Mosquitto切换到MQTTS后出现的证书验证错误,从配置和权限两个核心方向排查,以下是具体解决步骤:

1. 修正Mosquitto的双向认证配置

你的Mosquitto配置里设置了require_certificate true,这会强制客户端必须提交自己的SSL证书才能连接——这是双向认证模式,而大多数IoT家庭自动化场景只需要服务器端证书加密(单向认证)。如果你的设备没有配置客户端证书,这会直接导致验证失败。

修改mosquitto.conf:

# 把这行
require_certificate true
# 改为
require_certificate false

重启Mosquitto容器后再测试连接。

2. 检查证书文件的权限问题

Let's Encrypt生成的证书文件默认权限是root:root,而Mosquitto容器默认以mosquitto用户(UID/GID通常为1883)运行,会出现权限不足无法读取证书的情况。

验证权限:

进入Mosquitto容器查看证书目录权限:

docker exec -it ohmio_mqtt ls -l /mosquitto/certificates/live/npm-3/

如果输出中文件所有者是root,需要调整权限:

解决方法:

  • 临时测试可以在docker-compose的mqtt服务中添加user: "root",让容器以root用户运行:
    mqtt:
      container_name: ohmio_mqtt
      image: ohmio_mqtt_image
      restart: always
      user: "root"  # 添加这行
      volumes:
        - ./mosquitto.conf:/mosquitto/config/mosquitto.conf
        - ./pwfile:/mosquitto/config/pwfile
        - ./data:/mosquitto/data/
        - ./letsencrypt:/mosquitto/certificates 
        - ./log:/mosquitto/log
      ports:
        - "8883:8883"
    
  • 长期方案调整宿主机器上证书目录的权限:
    sudo chmod -R 755 ./letsencrypt/live/ ./letsencrypt/archive/
    sudo chown -R 1883:1883 ./letsencrypt/
    

3. 修正Nginx代理的配置错误(如果使用Nginx代理MQTT)

你的Nginx配置存在两个致命问题:

  1. 拼写错误:ssl_certficiate应该是ssl_certificate_key
  2. MQTT是TCP协议,不能用HTTP的server块,必须使用Nginx的stream模块

正确的Stream代理配置示例:

stream {
    server {
        listen 8883 ssl;
        proxy_pass ohmio_mqtt:8883;
        ssl_certificate /etc/letsencrypt/live/npm-3/fullchain.pem;
        ssl_certificate_key /etc/letsencrypt/live/npm-3/privkey.pem;
        ssl_protocols TLSv1.2 TLSv1.3;
        ssl_ciphers HIGH:!aNULL:!MD5;
    }
}

注意:如果直接让Mosquitto对外提供MQTTS服务,不需要Nginx代理,需要删除Nginx中8883端口的监听配置,避免端口冲突。

4. 验证证书有效性

用OpenSSL工具检查证书链是否完整:

openssl s_client -connect localhost:8883 -servername mqtt.ohmio.org

查看输出中的Verify return code,如果显示0 (ok)则证书验证正常;如果有错误,根据提示检查证书链是否缺失或路径错误。

内容的提问来源于stack exchange,提问作者KalosScript

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.05 00:12:48