Confluent Kafka Python证书验证:Ubuntu下SSL握手失败求助
解决Ubuntu上Confluent Kafka Producer SSL握手失败问题
在Windows上运行Confluent Kafka Producer正常,但部署到Ubuntu时出现以下SSL握手错误:
SSL handshake failed: error:0A000086:SSL routines::certificate verify failed: broker certificate could not be verified, verify that ssl.ca.location is correctly configured or root CA certificates are installed (install ca-certificates package) (after 5ms in state SSL_HANDSHAKE)
根据librdkafka文档说明:
File or directory path to CA certificate(s) for verifying the broker's key. Defaults: On Windows the system's CA certificates are automatically looked up in the Windows Root certificate store. On Linux install the distribution's ca-certificates package.
以下是具体解决步骤:
1. 从Windows导出对应的CA根证书
- 按下Win+R,输入
certmgr.msc打开Windows证书管理器 - 导航到「受信任的根证书颁发机构」→「证书」,找到签发Kafka Broker证书的根CA(可通过查看Broker证书的签发链确认具体证书)
- 右键该证书 → 「所有任务」→ 「导出」
- 在导出向导中选择「Base-64编码X.509(.CER)」格式,将证书保存为文件(例如
kafka-ca.crt)
2. 在Ubuntu上配置证书并修改Producer代码
方式一:直接在Producer配置中指定CA证书路径
- 将导出的
kafka-ca.crt上传到Ubuntu服务器的固定目录,比如/opt/kafka/certs/ - 先安装系统证书依赖包:
sudo apt update && sudo apt install -y ca-certificates - 修改Producer配置,添加
ssl.ca.location指向证书文件路径:from confluent_kafka import Producer import socket kafka_config = { 'bootstrap.servers': 'kafka...:9092, ... , kafka:9092', 'client.id': socket.gethostname(), 'security.protocol': 'SSL', 'ssl.key.location': '/path/to/kafka-keystore.key.pem', 'ssl.key.password': '12345', 'ssl.certificate.location': '/path/to/kafka-keystore.crt.pem', 'ssl.ca.location': '/opt/kafka/certs/kafka-ca.crt' # 新增CA证书路径配置 } producer = Producer(kafka_config)
方式二:将CA证书添加到Ubuntu系统信任库
- 将证书复制到系统CA目录:
sudo cp /opt/kafka/certs/kafka-ca.crt /usr/local/share/ca-certificates/ - 更新系统证书库:
sudo update-ca-certificates - 此时Producer配置无需额外指定
ssl.ca.location,librdkafka会自动读取系统信任的CA证书
3. 验证运行
修改配置后重新运行Producer,确认SSL握手错误消失,Producer能正常连接Kafka Broker。
内容的提问来源于stack exchange,提问作者Killen
相关产品推荐
相关产品推荐

