AWS Elastic Beanstalk连接RDS加密报错:证书链签发机构不被信任
解决Elastic Beanstalk实例验证RDS SQL Server证书链的问题
你需要给Elastic Beanstalk(EB)实例导入AWS RDS对应的根证书,让系统信任RDS的证书链。以下是两种可行的配置方式:
方法1:通过.ebextensions自动配置(推荐)
这是持久化的解决方案,每次EB实例扩容或部署时都会自动安装证书:
- 在你的ASP.NET 4.8项目根目录创建
.ebextensions文件夹 - 在该文件夹下新建配置文件,比如
01_install_rds_cert.config,内容如下(根据EB实例的操作系统选择对应配置):
针对Windows系统的EB实例
files: "C:\\temp\\rds-global-bundle.pem": source: "https://truststore.pki.rds.amazonaws.com/global/global-bundle.pem" container_commands: 01_import_root_cert: command: certutil -addstore -f "Root" "C:\\temp\\rds-global-bundle.pem" ignoreErrors: false
针对Linux系统的EB实例
files: "/etc/pki/ca-trust/source/anchors/rds-global-bundle.pem": source: "https://truststore.pki.rds.amazonaws.com/global/global-bundle.pem" mode: "0644" container_commands: 01_update_ca_trust: command: update-ca-trust extract ignoreErrors: false
- 将修改后的代码部署到EB,实例启动时会自动下载并导入RDS根证书
方法2:手动导入证书(临时测试用)
如果需要快速验证,可直接登录EB实例手动操作:
- Windows实例:通过远程桌面连接实例,下载
global-bundle.pem,打开命令提示符执行certutil -addstore -f "Root" "下载路径\\global-bundle.pem",导入到受信任根证书颁发机构 - Linux实例:通过SSH连接实例,执行
curl -o /etc/pki/ca-trust/source/anchors/rds-global-bundle.pem https://truststore.pki.rds.amazonaws.com/global/global-bundle.pem,再运行update-ca-trust extract
关键说明
- 若你的RDS实例使用的是区域特定的CA证书,需替换配置文件中的证书URL为对应区域的bundle地址(比如美国东部1区为
https://truststore.pki.rds.amazonaws.com/us-east-1/us-east-1-bundle.pem) - 负载均衡仅处理入站请求,确实和EB到RDS的出站连接无关,无需调整负载均衡配置
- 配置完成后,重启EB实例的应用池(Windows)或应用服务(Linux),确保证书生效
内容的提问来源于stack exchange,提问作者Steve Hiner
相关产品推荐
相关产品推荐

