You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Dapr调用gRPC服务时SSL无法使用问题咨询

Dapr gRPC服务调用SSL问题排查解答

问题背景

使用Dapr v1.10.0实现服务间gRPC服务调用时失败,报错日志如下:

info: System.Net.Http.HttpClient.ManagerServiceClient.LogicalHandler[100]
      Start processing HTTP request POST https://localhost:64904/ManagerService/GetManagerInfo
info: System.Net.Http.HttpClient.ManagerServiceClient.ClientHandler[100]
      Sending HTTP request POST https://localhost:64904/ManagerService/GetManagerInfo
fail: Grpc.Net.Client.Internal.GrpcCall[6]
      Error starting gRPC call.
      System.Net.Http.HttpRequestException: The SSL connection could not be established, see inner exception.
       ---> System.Security.Authentication.AuthenticationException: Cannot determine the frame size or a corrupted frame was received.

该调用未在sidecar日志中生成任何记录,但若绕过Dapr,将URI端口改为服务暴露的实际端口,gRPC调用可正常执行。

仅通过以下命令安装了开发证书:

dotnet dev-certs https --clean
dotnet dev-certs https --trust

尝试启用mTLS时,sidecar出现连接placement服务的错误:

time="2023-02-21T09:57:23.5657516-05:00" level=debug msg="error connecting to placement service: rpc error: code = Unavailable desc = last connection error: connection error: desc = \"transport: authentication handshake failed: tls: first record does not look like a TLS handshake\"" app_id=manager instance=Attic scope=dapr.runtime.actor.internal.placement type=log ver=1.10.0
time="2023-02-21T09:57:24.0698186-05:00" level=debug msg="try to connect to placement service: dns:///localhost:6050" app_id=manager instance=Attic scope=dapr.runtime.actor.internal.placement type=log ver=1.10.0

问题列表

  1. Dapr是否可以使用dotnet开发证书?
  2. 使用HTTPS进行gRPC调用是否需要启用mTLS?
  3. 为何直接服务间调用可建立SSL连接,而通过sidecar调用却不行?

解答

1. Dapr是否可以使用dotnet开发证书?

可以,但需要正确配置让Dapr sidecar信任该证书。默认情况下Dapr不会自动识别dotnet开发证书,需完成以下步骤:

  • 导出dotnet开发证书:执行dotnet dev-certs https -ep $HOME/.aspnet/https/aspnetapp.pfx -p 自定义密码(Windows路径为%USERPROFILE%\.aspnet\https\aspnetapp.pfx)
  • 启动sidecar时,通过--enable-ssl参数,搭配--ssl-cert和--ssl-key(或对应的环境变量DAPR_SSL_CERT、DAPR_SSL_KEY)加载证书;由于你已执行dotnet dev-certs https --trust,根证书已加入系统信任存储,sidecar可直接信任该证书链。

2. 使用HTTPS进行gRPC调用是否需要启用mTLS?

不需要。mTLS是服务间双向身份验证的机制,而单向HTTPS(客户端验证服务端证书)是基础加密通信方式。你可以在不启用mTLS的前提下,让Dapr sidecar通过HTTPS与后端服务通信,只要sidecar信任服务端证书即可。

注意:Dapr sidecar默认使用HTTP与应用服务通信,若你的服务仅暴露HTTPS端口,需在启动sidecar时添加--app-protocol https参数,或在Dapr配置文件中设置appProtocol: "https"。

3. 为何直接服务间调用可建立SSL连接,而通过sidecar调用却不行?

核心原因是Dapr sidecar未适配你的HTTPS服务配置:

  • 直接调用时,.NET客户端会自动信任dotnet dev-certs生成的证书(因执行了--trust),SSL握手正常完成。
  • 但Dapr sidecar默认使用HTTP协议访问服务,当它把HTTP请求发往HTTPS端口时,就会出现协议不匹配的SSL错误(即日志中的"无法确定帧大小或收到损坏的帧");同时sidecar未被配置为信任dotnet开发证书,也会导致握手失败。
  • 调用未在sidecar日志中生成记录,是因为sidecar在尝试连接服务时就触发了SSL错误,请求未被转发到后端服务。

解决步骤:

  1. 告知sidecar服务使用HTTPS:启动sidecar时添加--app-protocol https参数,或在配置文件中设置appProtocol: "https"。
  2. 让sidecar信任dotnet开发证书:启动sidecar时通过--ssl-trust-cert参数指向证书文件,或确保系统信任存储已包含该根证书(你已完成--trust操作)。

内容的提问来源于stack exchange,提问作者John Vottero

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.03 16:05:15