Apache2服务器调用PyMongo find/find_one连接MongoDB Atlas报错
问题:Apache2下Flask+PyMongo连接MongoDB Atlas查询时报TLSFeature扩展缺失错误
在Apache2服务器部署的Flask应用中,使用PyMongo连接MongoDB Atlas时,插入、删除集合数据操作正常,但调用find或find_one方法查询数据时,抛出如下错误:
No <class 'cryptography.x509.extensions.TLSFeature'> extension was found
该错误仅在Apache2运行环境中出现,本地直接执行Python脚本进行查询操作无异常。
完整报错栈
Traceback (most recent call last): File "/usr/local/lib/python3.10/dist-packages/flask/app.py", line 2525, in wsgi_app response = self.full_dispatch_request() File "/usr/local/lib/python3.10/dist-packages/flask/app.py", line 1822, in full_dispatch_request rv = self.handle_user_exception(e) File "/usr/local/lib/python3.10/dist-packages/flask/app.py", line 1820, in full_dispatch_request rv = self.dispatch_request() File "/usr/local/lib/python3.10/dist-packages/flask/app.py", line 1796, in dispatch_request return self.ensure_sync(self.view_functions[rule.endpoint])(**view_args) File "/var/www/html/srv21/SRVApp.py", line 17, in downloadpage ThreadID = ThreadID.next() File "/usr/local/lib/python3.10/dist-packages/pymongo/cursor.py", line 1248, in next if len(self.__data) or self._refresh(): File "/usr/local/lib/python3.10/dist-packages/pymongo/cursor.py", line 1165, in _refresh self.__send_message(q) File "/usr/local/lib/python3.10/dist-packages/pymongo/cursor.py", line 1052, in __send_message response = client._run_operation( File "/usr/local/lib/python3.10/dist-packages/pymongo/_csot.py", line 105, in csot_wrapper return func(self, *args, **kwargs) File "/usr/local/lib/python3.10/dist-packages/pymongo/mongo_client.py", line 1330, in _run_operation return self._retryable_read( File "/usr/local/lib/python3.10/dist-packages/pymongo/_csot.py", line 105, in csot_wrapper return func(self, *args, **kwargs) File "/usr/local/lib/python3.10/dist-packages/pymongo/mongo_client.py", line 1442, in _retryable_read with self._socket_from_server(read_pref, server, session) as (sock_info, read_pref): File "/usr/lib/python3.10/contextlib.py", line 135, in __enter__ return next(self.gen) File "/usr/local/lib/python3.10/dist-packages/pymongo/mongo_client.py", line 1282, in _socket_from_server with self._get_socket(server, session) as sock_info: File "/usr/lib/python3.10/contextlib.py", line 135, in __enter__ return next(self.gen) File "/usr/local/lib/python3.10/dist-packages/pymongo/mongo_client.py", line 1217, in _get_socket with server.get_socket(handler=err_handler) as sock_info: File "/usr/lib/python3.10/contextlib.py", line 135, in __enter__ return next(self.gen) File "/usr/local/lib/python3.10/dist-packages/pymongo/pool.py", line 1407, in get_socket sock_info = self._get_socket(handler=handler) File "/usr/local/lib/python3.10/dist-packages/pymongo/pool.py", line 1520, in _get_socket sock_info = self.connect(handler=handler) File "/usr/local/lib/python3.10/dist-packages/pymongo/pool.py", line 1358, in connect sock = _configured_socket(self.address, self.opts) File "/usr/local/lib/python3.10/dist-packages/pymongo/pool.py", line 1061, in _configured_socket sock = ssl_context.wrap_socket(sock, server_hostname=host) File "/usr/local/lib/python3.10/dist-packages/pymongo/pyopenssl_context.py", line 369, in wrap_socket ssl_conn.do_handshake() File "/usr/local/lib/python3.10/dist-packages/pymongo/pyopenssl_context.py", line 125, in do_handshake return self._call(super(_sslConn, self).do_handshake, *args, **kwargs) File "/usr/local/lib/python3.10/dist-packages/pymongo/pyopenssl_context.py", line 108, in _call return call(*args, **kwargs) File "/usr/lib/python3/dist-packages/OpenSSL/SSL.py", line 1894, in do_handshake self._raise_ssl_error(self._ssl, result) File "/usr/lib/python3/dist-packages/OpenSSL/SSL.py", line 1603, in _raise_ssl_error self._context._ocsp_helper.raise_if_problem() File "/usr/lib/python3/dist-packages/OpenSSL/SSL.py", line 319, in raise_if_problem raise self._problems.pop(0) File "/usr/lib/python3/dist-packages/OpenSSL/SSL.py", line 539, in wrapper valid = callback(conn, ocsp_data, data) File "/usr/local/lib/python3.10/dist-packages/pymongo/ocsp_support.py", line 298, in _ocsp_callback ext = _get_extension(cert, _TLSFeature) File "/usr/local/lib/python3.10/dist-packages/pymongo/ocsp_support.py", line 114, in _get_extension return cert.extensions.get_extension_for_class(klass) File "/usr/local/lib/python3.10/dist-packages/cryptography/x509/extensions.py", line 135, in get_extension_for_class raise ExtensionNotFound( cryptography.x509.extensions.ExtensionNotFound: No <class 'cryptography.x509.extensions.TLSFeature'> extension was found
解决方案
方案1:禁用OCSP检查或调整SSL验证策略
错误根源是PyMongo在OCSP证书验证时找不到TLSFeature扩展,可通过创建MongoDB客户端时添加参数跳过该检查:
from pymongo import MongoClient # 禁用OCSP检查 client = MongoClient("你的MongoDB Atlas连接URI", ocsp=False) # 或者调整SSL证书验证要求 import ssl client = MongoClient( "你的MongoDB Atlas连接URI", ssl_cert_reqs=ssl.CERT_NONE )
方案2:更新依赖库版本
Apache环境的Python依赖可能与本地版本不一致导致兼容性问题,执行以下命令更新相关依赖:
pip install --upgrade cryptography pyopenssl pymongo
确保服务器上的依赖版本与本地环境一致或为最新兼容版本。
方案3:调整Apache的SSL配置
Apache的SSL配置可能与PyMongo的SSL验证冲突,修改虚拟主机配置文件,添加或更新如下内容:
SSLProtocol all -SSLv2 -SSLv3 -TLSv1 -TLSv1.1 SSLCipherSuite HIGH:!aNULL:!MD5
修改后重启Apache服务:
sudo systemctl restart apache2
内容的提问来源于stack exchange,提问作者thedude
相关产品推荐
相关产品推荐

