如何让Azure应用网关返回完整证书链?解决Android 6 SSL握手失败
正在将Web应用从AWS迁移到Azure,部分用户通过运行Android 6的嵌入式平板访问站点。当前使用Certbot从Let's Encrypt获取证书,并在证书续订钩子(renew hook)中执行以下命令,将证书转换为PFX格式后更新Azure应用网关:
openssl pkcs12 -inkey $RENEWED_LINEAGE/privkey.pem -in $RENEWED_LINEAGE/cert.pem -certfile $RENEWED_LINEAGE/chain.pem -export -out $RENEWED_LINEAGE/cert.pfx -passout pass:$PASSWORD az network application-gateway ssl-cert update -g $RGNAME --gateway-name $AGNAME -n $DOMAIN --cert-file $RENEWED_LINEAGE/cert.pfx --cert-password $PASSWORD
通过以下命令检查生成的PFX文件,确认其包含3个证书:
openssl pkcs12 -in $RENEWED_LINEAGE/cert.pfx -passin pass:$PASSWORD -passout pass:$PASSWORD
输出内容:
subject=CN = new.(redacted).com
issuer=C = US, O = Let's Encrypt, CN = R3
...
subject=C = US, O = Let's Encrypt, CN = R3
issuer=C = US, O = Internet Security Research Group, CN = ISRG Root X1
...
subject=C = US, O = Internet Security Research Group, CN = ISRG Root X1
issuer=O = Digital Signature Trust Co., CN = DST Root CA X3
但将该PFX证书应用到Azure应用网关后,执行以下命令检查返回的证书链,发现缺失TrustID X3 Root(DST Root CA X3)证书:
openssl s_client -debug -connect new.(redacted).com:443
证书链输出:
Certificate chain
0 s:CN = new.(redacted).com
i:C = US, O = Let's Encrypt, CN = R3
a:PKEY: rsaEncryption, 2048 (bit); sigalg: RSA-SHA256
v:NotBefore: Jul 28 (HH:mm:ss) 2023 GMT; NotAfter: Oct 26 (HH:mm:ss) 2023 GMT
1 s:C = US, O = Let's Encrypt, CN = R3
i:C = US, O = Internet Security Research Group, CN = ISRG Root X1
a:PKEY: rsaEncryption, 2048 (bit); sigalg: RSA-SHA256
v:NotBefore: Sep 4 00:00:00 2020 GMT; NotAfter: Sep 15 16:00:00 2025 GMT
现代客户端可正常连接,但Android 6客户端报错:
javax.net.ssl.SSLHandshakeException: java.security.cert.CertPathValidatorException: Trust anchor for certification path not found.
尝试下载由TrustID X3 Root交叉签名的ISRG Root X1证书及自签名TrustID X3 Root证书,将其加入PFX:
curl -s -o $RENEWED_LINEAGE/isrgrootx1.pem "https://letsencrypt.org/certs/isrg-root-x1-cross-signed.pem" curl -s -o $RENEWED_LINEAGE/trustidx3.pem "https://letsencrypt.org/certs/trustid-x3-root.pem.txt" cat $RENEWED_LINEAGE/chain.pem $RENEWED_LINEAGE/isrgrootx1.pem $RENEWED_LINEAGE/trustidx3.pem > $RENEWED_LINEAGE/certs.pem openssl pkcs12 -inkey $RENEWED_LINEAGE/privkey.pem -in $RENEWED_LINEAGE/cert.pem -certfile $RENEWED_LINEAGE/certs.pem -export -out $RENEWED_LINEAGE/cert.pfx -passout pass:$PASSWORD
确认新PFX包含更多证书,但应用到网关后,返回的证书链仍无变化。尝试用fullchain.pem替代chain.pem转换PFX,出现重复证书错误。
对比AWS上的现有站点,其返回包含Trust ID X3 Root的4个证书链,Android 6平板可正常连接。
内容的提问来源于stack exchange,提问作者Tim Burrough

