You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Confluent Kafka Python证书验证:Ubuntu下SSL握手失败求助

解决Ubuntu上Confluent Kafka Producer SSL握手失败问题

在Windows上运行Confluent Kafka Producer正常,但部署到Ubuntu时出现以下SSL握手错误:

SSL handshake failed: error:0A000086:SSL routines::certificate verify failed: broker certificate could not be verified, verify that ssl.ca.location is correctly configured or root CA certificates are installed (install ca-certificates package) (after 5ms in state SSL_HANDSHAKE)

根据librdkafka文档说明:

File or directory path to CA certificate(s) for verifying the broker's key. Defaults: On Windows the system's CA certificates are automatically looked up in the Windows Root certificate store. On Linux install the distribution's ca-certificates package.

以下是具体解决步骤:

1. 从Windows导出对应的CA根证书

  • 按下Win+R,输入certmgr.msc打开Windows证书管理器
  • 导航到「受信任的根证书颁发机构」→「证书」,找到签发Kafka Broker证书的根CA(可通过查看Broker证书的签发链确认具体证书)
  • 右键该证书 → 「所有任务」→ 「导出」
  • 在导出向导中选择「Base-64编码X.509(.CER)」格式,将证书保存为文件(例如kafka-ca.crt)

2. 在Ubuntu上配置证书并修改Producer代码

方式一:直接在Producer配置中指定CA证书路径

  • 将导出的kafka-ca.crt上传到Ubuntu服务器的固定目录,比如/opt/kafka/certs/
  • 先安装系统证书依赖包:
    sudo apt update && sudo apt install -y ca-certificates
    
  • 修改Producer配置,添加ssl.ca.location指向证书文件路径:
    from confluent_kafka import Producer
    import socket
    
    kafka_config = {
        'bootstrap.servers': 'kafka...:9092, ... , kafka:9092',
        'client.id': socket.gethostname(),
        'security.protocol': 'SSL',
        'ssl.key.location': '/path/to/kafka-keystore.key.pem',
        'ssl.key.password': '12345',
        'ssl.certificate.location': '/path/to/kafka-keystore.crt.pem',
        'ssl.ca.location': '/opt/kafka/certs/kafka-ca.crt'  # 新增CA证书路径配置
    }
    producer = Producer(kafka_config)
    

方式二:将CA证书添加到Ubuntu系统信任库

  • 将证书复制到系统CA目录:
    sudo cp /opt/kafka/certs/kafka-ca.crt /usr/local/share/ca-certificates/
    
  • 更新系统证书库:
    sudo update-ca-certificates
    
  • 此时Producer配置无需额外指定ssl.ca.location,librdkafka会自动读取系统信任的CA证书

3. 验证运行

修改配置后重新运行Producer,确认SSL握手错误消失,Producer能正常连接Kafka Broker。

内容的提问来源于stack exchange,提问作者Killen

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.16 12:43:16