本地Kafka配置SSL遇握手失败:证书链含自签名证书
问题
在Windows的WSL(Ubuntu 20.04)环境中配置本地Apache Kafka 2.5 SSL时,Broker出现认证失败错误:
[2023-07-24 23:41:36,219] INFO [SocketServer brokerId=0] Failed authentication with /127.0.0.1 (SSL handshake failed) (org.apache.kafka.common.network.Selector)
执行openssl检测命令:
openssl s_client -debug -connect localhost:9093 -tls1_2 -showcerts
返回验证错误码19(self signed certificate in certificate chain)。已使用Confluent的kafka-generate-ssl.sh脚本生成truststore、CA及keystore,所有证书CN均设置为localhost,Broker配置如下:
ssl.keystore.location=/mnt/e/.../keystore/kafka.keystore.jks ssl.keystore.password=password ssl.key.password=password ssl.truststore.location=/mnt/e/.../truststore/kafka.truststore.jks ssl.truststore.password=password ssl.ca.location=/mnt/e/.../ca-key ssl.endpoint.identification.algorithm= ssl.enabled.protocols=TLSv1.2,TLSv1.1,TLSv1 ssl.client.auth=required
尝试多种证书生成方式均未解决问题,寻求下一步排查方向。
下一步排查方向
- 检查CA证书是否正确导入truststore:执行
keytool -list -v -keystore /mnt/e/.../truststore/kafka.truststore.jks,查看truststore内是否包含生成的CA证书,确认别名、证书指纹与CA公钥文件一致,避免漏导或导入错误证书。 - 验证keystore的证书链完整性:运行
keytool -list -v -keystore /mnt/e/.../keystore/kafka.keystore.jks,检查证书链是否包含CA根证书条目,确保从Broker证书到CA的完整信任链路存在,缺失CA会触发自签链错误。 - 修正ssl.ca.location配置:该参数应指向CA公钥文件(如
ca-cert.pem),而非CA私钥(ca-key),私钥无需配置给Broker,替换为正确的CA证书路径。 - 排查WSL路径访问问题:用
ls -l /mnt/e/.../keystore/和cat /mnt/e/.../ca-cert.pem验证证书文件存在且可读,WSL挂载Windows磁盘可能存在权限限制,确保Kafka进程有读取证书文件的权限。 - 临时禁用客户端认证测试:将
ssl.client.auth=required改为ssl.client.auth=none,先确认Broker自身SSL服务能正常启动并完成握手,排除强制客户端认证导致的握手失败,再逐步恢复客户端认证配置。 - 对比证书指纹一致性:执行
keytool -printcert -file /mnt/e/.../ca-cert.pem获取CA证书指纹,再对比truststore中CA证书的指纹,确保两者完全一致,避免证书文件损坏或篡改。 - 开启SSL debug日志:在Broker的log4j配置中添加
log4j.logger.org.apache.kafka.common.network=DEBUG,重启Broker后查看详细的SSL握手日志,定位具体的证书验证失败环节,比如证书链缺失、证书过期等细节。
内容的提问来源于stack exchange,提问作者maxime G
相关产品推荐
相关产品推荐

