Dapr调用gRPC服务时SSL无法使用问题咨询
Dapr gRPC服务调用SSL问题排查解答
问题背景
使用Dapr v1.10.0实现服务间gRPC服务调用时失败,报错日志如下:
info: System.Net.Http.HttpClient.ManagerServiceClient.LogicalHandler[100] Start processing HTTP request POST https://localhost:64904/ManagerService/GetManagerInfo info: System.Net.Http.HttpClient.ManagerServiceClient.ClientHandler[100] Sending HTTP request POST https://localhost:64904/ManagerService/GetManagerInfo fail: Grpc.Net.Client.Internal.GrpcCall[6] Error starting gRPC call. System.Net.Http.HttpRequestException: The SSL connection could not be established, see inner exception. ---> System.Security.Authentication.AuthenticationException: Cannot determine the frame size or a corrupted frame was received.
该调用未在sidecar日志中生成任何记录,但若绕过Dapr,将URI端口改为服务暴露的实际端口,gRPC调用可正常执行。
仅通过以下命令安装了开发证书:
dotnet dev-certs https --clean dotnet dev-certs https --trust
尝试启用mTLS时,sidecar出现连接placement服务的错误:
time="2023-02-21T09:57:23.5657516-05:00" level=debug msg="error connecting to placement service: rpc error: code = Unavailable desc = last connection error: connection error: desc = \"transport: authentication handshake failed: tls: first record does not look like a TLS handshake\"" app_id=manager instance=Attic scope=dapr.runtime.actor.internal.placement type=log ver=1.10.0 time="2023-02-21T09:57:24.0698186-05:00" level=debug msg="try to connect to placement service: dns:///localhost:6050" app_id=manager instance=Attic scope=dapr.runtime.actor.internal.placement type=log ver=1.10.0
问题列表
- Dapr是否可以使用dotnet开发证书?
- 使用HTTPS进行gRPC调用是否需要启用mTLS?
- 为何直接服务间调用可建立SSL连接,而通过sidecar调用却不行?
解答
1. Dapr是否可以使用dotnet开发证书?
可以,但需要正确配置让Dapr sidecar信任该证书。默认情况下Dapr不会自动识别dotnet开发证书,需完成以下步骤:
- 导出dotnet开发证书:执行
dotnet dev-certs https -ep $HOME/.aspnet/https/aspnetapp.pfx -p 自定义密码(Windows路径为%USERPROFILE%\.aspnet\https\aspnetapp.pfx) - 启动sidecar时,通过
--enable-ssl参数,搭配--ssl-cert和--ssl-key(或对应的环境变量DAPR_SSL_CERT、DAPR_SSL_KEY)加载证书;由于你已执行dotnet dev-certs https --trust,根证书已加入系统信任存储,sidecar可直接信任该证书链。
2. 使用HTTPS进行gRPC调用是否需要启用mTLS?
不需要。mTLS是服务间双向身份验证的机制,而单向HTTPS(客户端验证服务端证书)是基础加密通信方式。你可以在不启用mTLS的前提下,让Dapr sidecar通过HTTPS与后端服务通信,只要sidecar信任服务端证书即可。
注意:Dapr sidecar默认使用HTTP与应用服务通信,若你的服务仅暴露HTTPS端口,需在启动sidecar时添加--app-protocol https参数,或在Dapr配置文件中设置appProtocol: "https"。
3. 为何直接服务间调用可建立SSL连接,而通过sidecar调用却不行?
核心原因是Dapr sidecar未适配你的HTTPS服务配置:
- 直接调用时,.NET客户端会自动信任dotnet dev-certs生成的证书(因执行了
--trust),SSL握手正常完成。 - 但Dapr sidecar默认使用HTTP协议访问服务,当它把HTTP请求发往HTTPS端口时,就会出现协议不匹配的SSL错误(即日志中的"无法确定帧大小或收到损坏的帧");同时sidecar未被配置为信任dotnet开发证书,也会导致握手失败。
- 调用未在sidecar日志中生成记录,是因为sidecar在尝试连接服务时就触发了SSL错误,请求未被转发到后端服务。
解决步骤:
- 告知sidecar服务使用HTTPS:启动sidecar时添加
--app-protocol https参数,或在配置文件中设置appProtocol: "https"。 - 让sidecar信任dotnet开发证书:启动sidecar时通过
--ssl-trust-cert参数指向证书文件,或确保系统信任存储已包含该根证书(你已完成--trust操作)。
内容的提问来源于stack exchange,提问作者John Vottero
相关产品推荐
相关产品推荐

