AWS API Gateway自定义域名偶发返回错误证书问题求助
问题:API Gateway自定义域名偶发返回AWS默认证书导致SSL连接失败
我通过自定义域名SSL地址调用AWS API Gateway Regional端点,已为该自定义域名正确关联AWS证书,DNS域名通过CNAME映射至d-xxxxxxxxxx.execute-api.eu-south-1.amazonaws.com。
大部分情况下请求正常,但偶尔(约5%-10%)会返回错误证书导致连接失败,具体表现为证书的subject: CN为*.execute-api.eu-south-1.amazonaws.com,而非预期的*.example.com。若在curl中添加忽略证书问题的选项,请求始终能成功,说明端点总能被正确访问,只是约5%-10%的请求返回的证书不正确。
我已查阅大量相关资料,并仔细检查了区域内自定义域名和证书的配置步骤,但仍未找到问题原因,恳请解答。
成功请求示例
curl --location 'https://api.example.com/check' --header 'Content-Type: application/json' --data '{}' -v * Trying 123.123.123.123:443... * TCP_NODELAY set * Connected to api.example.com (123.123.123.123) port 443 (#0) * ALPN, offering h2 * ALPN, offering http/1.1 * successfully set certificate verify locations: * CAfile: /etc/ssl/certs/ca-certificates.crt CApath: /etc/ssl/certs * TLSv1.3 (OUT), TLS handshake, Client hello (1): * TLSv1.3 (IN), TLS handshake, Server hello (2): * TLSv1.2 (IN), TLS handshake, Certificate (11): * TLSv1.2 (IN), TLS handshake, Server key exchange (12): * TLSv1.2 (IN), TLS handshake, Server finished (14): * TLSv1.2 (OUT), TLS handshake, Client key exchange (16): * TLSv1.2 (OUT), TLS change cipher, Change cipher spec (1): * TLSv1.2 (OUT), TLS handshake, Finished (20): * TLSv1.2 (IN), TLS handshake, Finished (20): * SSL connection using TLSv1.2 / ECDHE-RSA-AES128-GCM-SHA256 * ALPN, server accepted to use h2 * Server certificate: * subject: CN=*.example.com * start date: Feb 14 00:00:00 2023 GMT * expire date: Nov 15 23:59:59 2023 GMT * subjectAltName: host "api.example.com" matched cert's "*.example.com" * issuer: C=US; O=Amazon; CN=Amazon RSA 2048 M01 * SSL certificate verify ok. * Using HTTP2, server supports multi-use * Connection state changed (HTTP/2 confirmed) * Copying HTTP/2 data in stream buffer to connection buffer after upgrade: len=0 * Using Stream ID: 1 (easy handle 0x563914bbeb30) > POST /AVM/check HTTP/2 > Host: api.example.com > user-agent: curl/7.68.0 > accept: */* > content-type: application/json > content-length: 124 > * Connection state changed (MAX_CONCURRENT_STREAMS == 128)! * We are completely uploaded and fine < HTTP/2 200 < date: Fri, 30 Jun 2023 10:57:44 GMT < content-type: application/json < content-length: 121 < x-amzn-requestid: a2539ff0-56b6-4e7e-be1b-e52253296a89 < x-amz-apigw-id: HVE-UGEWMu8F0gA= < x-amzn-trace-id: Root=1-649eb528-1f2b6b0f2c01686a7ca14df0;Sampled=0;lineage=6ad58234:0 < * Connection #0 to host api.example.com left intact {}
错误请求示例
curl --location 'https://api.example.com/check' --header 'Content-Type: application/json' --data '{}' -v * Trying 123.123.123.123:443... * TCP_NODELAY set * Connected to api.example.com (123.123.123.123) port 443 (#0) * ALPN, offering h2 * ALPN, offering http/1.1 * successfully set certificate verify locations: * CAfile: /etc/ssl/certs/ca-certificates.crt CApath: /etc/ssl/certs * TLSv1.3 (OUT), TLS handshake, Client hello (1): * TLSv1.3 (IN), TLS handshake, Server hello (2): * TLSv1.2 (IN), TLS handshake, Certificate (11): * TLSv1.2 (IN), TLS handshake, Server key exchange (12): * TLSv1.2 (IN), TLS handshake, Server finished (14): * TLSv1.2 (OUT), TLS handshake, Client key exchange (16): * TLSv1.2 (OUT), TLS change cipher, Change cipher spec (1): * TLSv1.2 (OUT), TLS handshake, Finished (20): * TLSv1.2 (IN), TLS handshake, Finished (20): * SSL connection using TLSv1.2 / ECDHE-RSA-AES128-GCM-SHA256 * ALPN, server accepted to use h2 * Server certificate: * subject: CN=*.execute-api.eu-south-1.amazonaws.com * start date: Mar 29 00:00:00 2023 GMT * expire date: Apr 26 23:59:59 2024 GMT * subjectAltName does not match api.example.com * SSL: no alternative certificate subject name matches target host name 'api.example.com' * Closing connection 0 * TLSv1.2 (OUT), TLS alert, close notify (256): curl: (60) SSL: no alternative certificate subject name matches target host name 'api.example.com' More details here: https://curl.haxx.se/docs/sslcerts.html curl failed to verify the legitimacy of the server and therefore could not establish a secure connection to it. To learn more about this situation and how to fix it, please visit the web page mentioned above.
内容的提问来源于stack exchange,提问作者Ascanio Orlandini
相关产品推荐
相关产品推荐

