You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

局域网Mosquitto MQTT TLS客户端连接失败问题求助

搭建带TLS的Mosquitto MQTT Broker时远程客户端证书验证失败问题

问题现象

客户端侧报错

执行订阅命令后提示TLS错误:

~/client# mosquitto_sub -t \$SYS/broker/bytes/\# -v --cafile ../ca/ca.crt --cert client.crt --key client.key -h remote_hostname
Error: A TLS error occurred.

添加-d调试参数后的输出:

~/client# mosquitto_sub -t \$SYS/broker/bytes/\# -v --cafile ../ca/ca.crt --cert client.crt --key client.key -h remote_hostname -d
Client null sending CONNECT
OpenSSL Error[0]: error:0A000086:SSL routines::certificate verify failed
Error: A TLS error occurred.

Broker侧日志

启动Broker并查看连接日志:

$ sudo mosquitto -v -c /etc/mosquitto/conf.d/very_basic.conf 
1687517830: mosquitto version 2.0.11 starting
1687517830: Config loaded from /etc/mosquitto/conf.d/very_basic.conf.
1687517830: Opening ipv4 listen socket on port 8883.
1687517830: Opening ipv6 listen socket on port 8883.
1687517830: mosquitto version 2.0.11 running
1687517831: New connection from 192.168.42.111:54214 on port 8883.
1687517831: OpenSSL Error[0]: error:0A000412:SSL routines::sslv3 alert bad certificate
1687517831: Client <unknown> disconnected: Protocol error.

Broker使用的OpenSSL版本:

$ openssl version
OpenSSL 3.0.2 15 Mar 2022 (Library: OpenSSL 3.0.2 15 Mar 2022)

证书生成步骤

当前使用的证书生成命令:

# CA证书生成
openssl req -newkey rsa:4096 -x509 -days 365 -extensions v3_ca -keyout ca.key -out ca.crt -nodes -sha256 -subj "/CN=ca.com"

# Broker证书生成
openssl genrsa -out broker.key 2048 && openssl req -out broker.csr -key broker.key -new -subj "/CN=${HOSTNAME}"
openssl x509 -req -in client.csr -CA ../ca/ca.crt -CAkey ../ca/ca.key -CAcreateserial -out client.crt -days 100

# 客户端证书生成
openssl genrsa -out client.key 2048 && openssl req -out client.csr -key client.key -new -subj "/CN=${HOSTNAME}"
openssl x509 -req -in client.csr -CA ../ca/ca.crt -CAkey ../ca/ca.key -CAcreateserial -out client.crt -days 100

文件目录结构

.
├── broker
│   ├── broker.crt
│   ├── broker.csr
│   └── broker.key
├── ca
│   ├── ca.crt
│   └── ca.key
└── client
    ├── client.crt
    ├── client.csr
    └── client.key

配置文件

Broker自定义配置 /etc/mosquitto/conf.d/very_basic.conf

listener 8883
require_certificate true
use_identity_as_username true

cafile /etc/mosquitto/ca_certificates/ca.crt
certfile /etc/mosquitto/certs/broker.crt
keyfile /etc/mosquitto/certs/broker.key

默认配置 /etc/mosquitto/mosquitto.conf

# Place your local configuration in /etc/mosquitto/conf.d/
#
# A full description of the configuration file is at
# /usr/share/doc/mosquitto/examples/mosquitto.conf.example

pid_file /run/mosquitto/mosquitto.pid

persistence true
persistence_location /var/lib/mosquitto/

log_dest file /var/log/mosquitto/mosquitto.log

include_dir /etc/mosquitto/conf.d

问题分析与修复方案

核心错误点

  1. Broker证书生成命令错误:生成Broker证书时,错误使用client.csr作为签名输入,且输出文件写成client.crt,导致Broker实际使用的证书并非对应自身CSR签名的有效证书,这是触发bad certificate错误的直接原因。

  2. 客户端证书CN字段混淆:客户端证书的CN使用了Broker的HOSTNAME,虽然不影响证书合法性,但容易造成标识混淆,建议改为客户端自身的主机名或自定义标识。

修复步骤

  1. 重新生成正确的Broker证书:

    cd broker
    # 用Broker自己的CSR签名生成证书
    openssl x509 -req -in broker.csr -CA ../ca/ca.crt -CAkey ../ca/ca.key -CAcreateserial -out broker.crt -days 100
    # 替换Broker设备上的证书文件并修正权限
    sudo cp broker.crt /etc/mosquitto/certs/
    sudo chown mosquitto:mosquitto /etc/mosquitto/certs/broker.crt
    
  2. 重启Mosquitto服务:

    sudo systemctl restart mosquitto
    
  3. 验证客户端连接参数:确保客户端连接时使用的remote_hostname与Broker证书的CN字段完全一致,若不一致需重新生成Broker证书,将CN设置为客户端实际使用的连接地址。

内容的提问来源于stack exchange,提问作者Antoni

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.18 09:14:57