连接MQTTS Broker报错`get_name no start line`求助
问题:MQTTS连接报
no start line错误 尝试使用RSA公私钥PEM文件及Broker签发的证书连接MQTTS Broker时,出现no start line错误,查阅官方文档和GitHub相关问题后仍未解决,怀疑忽略了密钥格式相关要点,寻求技术帮助。
代码示例
const mqtt = require('mqtt'); const fs = require('fs'); // MQTTs broker connection string and port const brokerUrl = 'mqtts://data-broker-test.some.network'; const brokerPort = 1883; const clientId = 'develop1' // Path to your certificate file const certPath = 'dev1.crt'; //private public key paths rsa const privateKeyPath = 'proj_dev01.pem' const publicKeyPath = 'proj_dev01.pub.pem' // MQTT client options const options = { port: brokerPort, key: fs.readFileSync(privateKeyPath), cert: fs.readFileSync(publicKeyPath), ca: [fs.readFileSync(certPath)], rejectUnauthorized: false, clientId: clientId, connectTimeout: 5 * 1000, reconnectPeriod: 5 * 1000, }; // Create MQTTs client const client = mqtt.connect(brokerUrl, options); // MQTT client event handlers client.on('connect', () => { console.log('Connected to MQTTs broker'); client.subscribe(); }); client.on('message', (topic, message) => { console.log('Received message:', message.toString()); }); client.on('error', (error) => { console.error('MQTT error:', error); }); client.on('close', () => { console.log('Disconnected from MQTT broker'); }); // Handle process termination process.on('SIGINT', () => { client.end(); process.exit(); });
错误信息
Error: error:0909006C:PEM routines:get_name:no start line at node:internal/tls/secure-context:70:13 at Array.forEach (<anonymous>) at setCerts (node:internal/tls/secure-context:68:3) at configSecureContext (node:internal/tls/secure-context:157:5) at Object.createSecureContext (node:_tls_common:116:3) at Object.connect (node:_tls_wrap:1651:48) at Object.buildBuilder (/Users/xxx/xxx/xxx/node_modules/mqtt/lib/connect/tls.js:20:26) at MqttClient.wrapper [as streamBuilder] (/Users/xxx/xxx/xxx/node_modules/mqtt/lib/connect/index.js:155:36) at MqttClient._setupStream (/Users/xxx/xxx/xxx/node_modules/mqtt/lib/client.js:415:22) at new MqttClient (/Users/xxx/xxx/xxx/node_modules/mqtt/lib/client.js:395:8) { library: 'PEM routines', function: 'get_name', reason: 'no start line', code: 'ERR_OSSL_PEM_NO_START_LINE' }
解决方案
1. 修正TLS配置参数混淆(核心问题)
代码里把公钥文件传给了cert字段,这是错误的。MQTT TLS客户端认证的正确配置逻辑是:
key:客户端的RSA私钥(proj_dev01.pem)cert:Broker签发的客户端证书(dev1.crt),证书中已包含公钥,无需单独传入公钥文件ca:Broker的CA证书(若dev1.crt由该CA签发,需替换为对应CA证书路径)
修正后的options配置:
const options = { port: brokerPort, key: fs.readFileSync(privateKeyPath), cert: fs.readFileSync(certPath), // 改为客户端证书路径 ca: [fs.readFileSync(certPath)], // 若CA为单独文件,替换为CA证书路径 rejectUnauthorized: false, clientId: clientId, connectTimeout: 5 * 1000, reconnectPeriod: 5 * 1000, };
2. 验证PEM文件格式有效性
检查所有证书/密钥文件是否符合标准PEM格式:
- 私钥文件必须包含
-----BEGIN PRIVATE KEY-----起始行和-----END PRIVATE KEY-----结束行 - 客户端证书文件必须包含
-----BEGIN CERTIFICATE-----起始行和-----END CERTIFICATE-----结束行 - 确保文件无多余空行、空格或乱码,优先使用Unix格式换行符(LF),避免Windows的CRLF引发解析问题
3. 确认文件读取完整性
临时添加日志打印读取的文件内容,验证是否读取到完整的PEM内容:
console.log('Private Key:', fs.readFileSync(privateKeyPath).toString()); console.log('Client Cert:', fs.readFileSync(certPath).toString());
若输出为空或内容异常,检查文件路径是否正确,以及Node.js进程是否有文件读取权限。
4. 检查文件权限
确保运行Node.js的用户对所有证书/密钥文件有读取权限,避免因权限不足导致读取内容不完整。
内容的提问来源于stack exchange,提问作者mani9418
相关产品推荐
相关产品推荐

