You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

通过Istio转发至Salesforce自定义域名时出现TLS错误及503问题求助

Istio 重定向至Salesforce自定义域名时出现503错误

问题现象

通过Istio将连接重定向至Salesforce自定义域名时,浏览器返回503错误,具体提示:

upstream connect error or disconnect/reset before headers. retried and the latest reset reason: connection failure, transport failure reason: TLS error: 268436536:SSL routines:OPENSSL_internal:TLSV1_ALERT_INTERNAL_ERROR

Istio调试日志如下:

debug   envoy pool queueing stream due to no available connections (ready=0 busy=0 connecting=0)
debug   envoy pool trying to create new connection
debug   envoy pool creating a new connection (connecting=0)
debug   envoy connection [C479766] current connecting state: true
debug   envoy client [C479766] connecting
debug   envoy connection [C479766] connecting to  <removedIP>:443
debug   envoy connection[C479766] connection in progress
debug   envoy connection [C479766] connected
debug   envoy connection [C479766] remote address: <removedIP>:443,TLS error: 268436536:SSL routines:OPENSSL_internal:TLSV1_ALERT_INTERNAL_ERROR
debug   envoy connection [C479766] closing socket: 0
debug   envoy connection [C479766] remote address: <removedIP>:443,TLS error: 268436536:SSL routines:OPENSSL_internal:TLSV1_ALERT_INTERNAL_ERROR
debug   envoy client [C479766] disconnect. resetting 0 pending requests
debug   envoy pool [C479766] client disconnected, failure reason: TLS error: 268436536:SSL routines:OPENSSL_internal:TLSV1_ALERT_INTERNAL_ERROR
debug   envoy router [C479765][S8990209301599029630] upstream reset: reset reason: connection failure, transport failure reason: TLS error: 268436536:SSL 
routines:OPENSSL_internal:TLSV1_ALERT_INTERNAL_ERROR

环境信息

  • Istio版本:1.15
  • Kubernetes版本:1.24

解决方法

1. 配置正确的SNI

Salesforce自定义域名的TLS握手依赖正确的SNI字段,Istio发起上游连接时需确保SNI匹配目标域名。在DestinationRule中指定TLS模式和目标主机:

apiVersion: networking.istio.io/v1alpha3
kind: DestinationRule
metadata:
  name: salesforce-custom-domain
spec:
  host: your-salesforce-custom-domain.com
  trafficPolicy:
    tls:
      mode: SIMPLE
      host: your-salesforce-custom-domain.com

2. 匹配TLS版本与Cipher套件

Salesforce对TLS版本和Cipher套件有严格要求,需确保Istio使用兼容配置(推荐TLS 1.2及以上)。可在DestinationRule中指定:

apiVersion: networking.istio.io/v1alpha3
kind: DestinationRule
metadata:
  name: salesforce-custom-domain
spec:
  host: your-salesforce-custom-domain.com
  trafficPolicy:
    tls:
      mode: SIMPLE
      host: your-salesforce-custom-domain.com
      tlsSettings:
        minProtocolVersion: TLSV1_2
        maxProtocolVersion: TLSV1_3
        cipherSuites:
          - ECDHE-ECDSA-AES128-GCM-SHA256
          - ECDHE-RSA-AES128-GCM-SHA256
          - ECDHE-ECDSA-AES256-GCM-SHA384
          - ECDHE-RSA-AES256-GCM-SHA384

3. 信任上游证书

若Salesforce自定义域名使用私有CA或自签名证书,需将对应CA证书添加到Istio信任池中,或在DestinationRule中指定证书路径:

apiVersion: networking.istio.io/v1alpha3
kind: DestinationRule
metadata:
  name: salesforce-custom-domain
spec:
  host: your-salesforce-custom-domain.com
  trafficPolicy:
    tls:
      mode: SIMPLE
      host: your-salesforce-custom-domain.com
      caCertificates: /etc/istio/ssl/salesforce-ca.crt

4. 验证网络连通性

确认Istio sidecar能访问Salesforce自定义域名的443端口,无防火墙或安全组拦截。可在sidecar容器内执行以下命令测试TLS握手:

curl -v https://your-salesforce-custom-domain.com

内容的提问来源于stack exchange,提问作者mati kepa

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.21 09:39:57