You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用自签名客户端证书的Node.js Artillery压测出现errors.EPROTO错误求助

解决Artillery负载测试中的errors.EPROTO TLS错误

问题背景

已安装最新版本的Node.js和Artillery,使用以下YAML配置进行负载测试:

config:
  target: "https://my.ip.address:443"
  phases:
    - duration: 60
      arrivalCount: 100
  tls:
    rejectUnauthorized: false
    client:
      key: "./key.pem"
      cert: "./certificate.pem"
      ca: "./ca.cert"
      passphrase: "mypass"
    onError:
       - log: "Error: invalid tls configuration"
    extendedMetrics: true
  https:
    extendedMetrics: true
  logging:
      level: "debug"
scenarios:
  - flow:
    - log: "Current environment is set to: {{ $environment }}"
    - get:
       url: "/myapp/"
       #sslAuth: false
       capture:
          json: "$.data"
          as: "data"
          failOnError: true
          log: "Error: capturing ${json.error}"
       check:
          - json: "$.status"
            as: "status"
            comparison: "eq"
            value: 200
            not: true
            capture:
              json: "$.error"
              as: "error"
            log: "Error: check ${error}"
plugins:
    http-ssl-auth: {}

运行命令为:

artillery -e production config_tests.yml

证书由OpenSSL生成且在其他应用中正常使用,但所有虚拟用户均失败并报错errors.EPROTO。

解决方案

1. 修正TLS配置结构

Artillery的TLS客户端认证参数无需嵌套在client节点下,直接放在tls节点即可,调整后的配置片段:

config:
  target: "https://my.ip.address:443"
  phases:
    - duration: 60
      arrivalCount: 100
  tls:
    rejectUnauthorized: false
    key: "./key.pem"
    cert: "./certificate.pem"
    ca: "./ca.cert"
    passphrase: "mypass"
  logging:
      level: "debug"
# 其他配置保留

同时移除tls节点下无效的onError和extendedMetrics配置,这些参数不属于TLS配置范畴。

2. 移除冗余插件

Artillery核心已支持TLS客户端认证,无需启用http-ssl-auth插件,直接删除配置中的plugins节点。

3. 验证证书文件

  • 确认证书/密钥文件路径正确,路径需相对于运行Artillery命令的工作目录
  • 检查密钥文件格式:如果密钥带密码,确保passphrase与生成时的密码一致;也可尝试生成无密码密钥测试:
    openssl rsa -in key.pem -out key-unencrypted.pem
    
    然后修改配置中的key路径为./key-unencrypted.pem并移除passphrase参数。
  • 确保所有证书文件为标准PEM格式,无多余字符或换行。

4. 修正运行命令

原命令缺少run子命令,正确的运行命令应为:

artillery run -e production config_tests.yml

5. 优化检查逻辑(可选)

当前check逻辑中not: true的使用可能导致混淆,调整为更清晰的失败处理逻辑:

check:
  - json: "$.status"
    as: "status"
    comparison: "eq"
    value: 200
    onFailure:
      - capture:
          json: "$.error"
          as: "error"
      - log: "Request failed with error: ${error}"

内容的提问来源于stack exchange,提问作者coding

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.04 06:30:47