You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS Elastic Beanstalk连接RDS加密报错:证书链签发机构不被信任

解决Elastic Beanstalk实例验证RDS SQL Server证书链的问题

你需要给Elastic Beanstalk(EB)实例导入AWS RDS对应的根证书,让系统信任RDS的证书链。以下是两种可行的配置方式:

方法1:通过.ebextensions自动配置(推荐)

这是持久化的解决方案,每次EB实例扩容或部署时都会自动安装证书:

  1. 在你的ASP.NET 4.8项目根目录创建.ebextensions文件夹
  2. 在该文件夹下新建配置文件,比如01_install_rds_cert.config,内容如下(根据EB实例的操作系统选择对应配置):

针对Windows系统的EB实例

files:
  "C:\\temp\\rds-global-bundle.pem":
    source: "https://truststore.pki.rds.amazonaws.com/global/global-bundle.pem"
container_commands:
  01_import_root_cert:
    command: certutil -addstore -f "Root" "C:\\temp\\rds-global-bundle.pem"
    ignoreErrors: false

针对Linux系统的EB实例

files:
  "/etc/pki/ca-trust/source/anchors/rds-global-bundle.pem":
    source: "https://truststore.pki.rds.amazonaws.com/global/global-bundle.pem"
    mode: "0644"
container_commands:
  01_update_ca_trust:
    command: update-ca-trust extract
    ignoreErrors: false
  1. 将修改后的代码部署到EB,实例启动时会自动下载并导入RDS根证书

方法2:手动导入证书(临时测试用)

如果需要快速验证,可直接登录EB实例手动操作:

  • Windows实例:通过远程桌面连接实例,下载global-bundle.pem,打开命令提示符执行certutil -addstore -f "Root" "下载路径\\global-bundle.pem",导入到受信任根证书颁发机构
  • Linux实例:通过SSH连接实例,执行curl -o /etc/pki/ca-trust/source/anchors/rds-global-bundle.pem https://truststore.pki.rds.amazonaws.com/global/global-bundle.pem,再运行update-ca-trust extract

关键说明

  • 若你的RDS实例使用的是区域特定的CA证书,需替换配置文件中的证书URL为对应区域的bundle地址(比如美国东部1区为https://truststore.pki.rds.amazonaws.com/us-east-1/us-east-1-bundle.pem)
  • 负载均衡仅处理入站请求,确实和EB到RDS的出站连接无关,无需调整负载均衡配置
  • 配置完成后,重启EB实例的应用池(Windows)或应用服务(Linux),确保证书生效

内容的提问来源于stack exchange,提问作者Steve Hiner

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.07 21:30:20