Win64版EventStore连接问题:非不安全模式无法追加流
EventStore连接与SSL配置问题排查与解决
问题汇总
- 仅能通过
--insecure不安全模式连接,使用esdb+discover://127.0.0.1:2113?tls=false可正常追加流 - 常规模式下追加流超时;使用带用户名密码的
esdb://admin:changeit@127.0.0.1:2113?tls=false提示connection closed - 不带TLS参数的
esdb+discover://127.0.0.1:2113报错:Failed to discover candidate in 10 attempts. - 使用
esdb://admin:changeit@127.0.0.1:2113出现SSL证书不匹配错误:
Status(StatusCode="Internal", Detail="Error starting gRPC call. HttpRequestException: The SSL connection could not be established, see inner exception. AuthenticationException: The remote certificate is invalid according to the validation procedure: RemoteCertificateNameMismatch", DebugException="System.Net.Http.HttpRequestException: The SSL connection could not be established, see inner exception. ---> System.Security.Authentication.AuthenticationException: The remote certificate is invalid according to the validation procedure: RemoteCertificateNameMismatch
- 找不到
eventstore.conf文件,配置TrustedRootCertificatesPath时报错,不清楚该路径指向内容(证书已导入Windows注册表)
用户代码如下:
var connectionstring = "esdb+discover://127.0.0.1:2113?tls=false"; var settings = EventStoreClientSettings.Create(connectionstring); var client = new EventStoreClient(settings); var evt = new TestEvent { EntityId = Guid.NewGuid().ToString("N"), ImportantData = "I wrote my first event!" }; var eventData = new EventStore.Client.EventData( Uuid.NewUuid(), "TestEvent", Encoding.UTF8.GetBytes(JsonConvert.SerializeObject(evt)) ); client.AppendToStreamAsync( "some-stream2", StreamState.Any, new[] { eventData }, cancellationToken: new CancellationTokenSource().Token ).Wait();
尝试使用的YAML配置:
CertificateStoreLocation: CurrentUser CertificateStoreName: My CertificateThumbPrint: 526ECD33A9A391D655592BDC7A9A028122954EB6 CertificateSubjectName: eventstore.org CertificateReservedNodeCommonName: eventstore.org TrustedRootCertificatesPath: C:\ESDB\certs\ca
解决步骤
1. 定位eventstore.conf文件位置
- Chocolatey安装的EventStore,配置文件默认路径为
C:\ProgramData\EventStore\eventstore.conf - 解压包安装的话,配置文件通常在解压根目录下,若没有则手动创建一个
2. 修复证书不匹配问题
- 证书的
CertificateSubjectName和CertificateReservedNodeCommonName要和你访问EventStore的域名/IP一致,当前用的是127.0.0.1,所以需要将这两个字段改为127.0.0.1,或者在本地hosts文件中添加127.0.0.1 eventstore.org映射 - 确保证书是针对
127.0.0.1或eventstore.org颁发的,重新生成符合要求的证书
3. 处理TrustedRootCertificatesPath配置
- 该路径用于存放信任的根证书文件(.crt或.pem格式),即使证书已导入Windows注册表,EventStore仍可能需要读取文件形式的根证书
- 找到你导入的根证书,导出为Base64编码的.crt文件,放入
C:\ESDB\certs\ca目录下,确保EventStore服务有该目录的读取权限
4. 调整连接字符串与客户端配置
- 若使用单节点,建议直接使用非发现模式的连接字符串,避免服务发现超时:
注意:var connectionString = "esdb://admin:changeit@127.0.0.1:2113?tls=true&tlsVerifyCert=false";tlsVerifyCert=false仅用于测试环境,生产环境需开启证书验证 - 若要启用证书验证,确保客户端信任EventStore的证书(将根证书导入客户端机器的受信任根证书存储)
5. 检查EventStore服务启动参数
- 确保服务启动时没有使用
--insecure参数,而是加载了正确的配置文件:eventstore --config=C:\Path\To\eventstore.conf - 检查服务日志,确认证书加载成功,没有权限或路径错误
内容的提问来源于stack exchange,提问作者patrick
相关产品推荐
相关产品推荐

