You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

基于FreeRTOS+Mbed-TLS的设备无法连接AWS Device Advisor求助

AWS Device Advisor TLS握手失败排查请求

我有一台运行FreeRTOS和Mbed-TLS的自定义设备,该设备可正常连接AWS IoT Core生产端点,且能自由进行Pub/Sub操作;但当尝试通过AWS Device Advisor提供的端点执行MQTT Connect测试用例时,无法完成TLS握手。日志中仅有两条记录:客户端发送Client Hello,随后服务器返回close-notify告警。我使用自行编写的C#测试应用连接同一端点可正常工作,两者采用相同方法,仅设备不同。我已解码设备发送的Client Hello,未发现明显异常。

设备TLS交互日志

客户端发送的Client Hello

TLS Record Sender CLIENT ContentType HANDSHAKE Length 149 Timestamp 2022-12-19T18:08:58Z
         +-------------------------------------------------+
         |  0  1  2  3  4  5  6  7  8  9  a  b  c  d  e  f |
+--------+-------------------------------------------------+----------------+
|00000000| 16 03 03 00 90 01 00 00 8c 03 03 76 9d 1d 5a 67 |...........v..Zg|
|00000010| e2 db 3f 45 13 41 2d 7e 28 77 00 87 e6 35 0e 32 |..?E.A-~(w...5.2|
|00000020| c2 24 bd 23 ee 69 72 77 f3 e1 69 00 00 04 c0 2b |.$.#.irw..i....+|
|00000030| 00 ff 01 00 00 5f 00 00 00 3d 00 3b 00 00 38 74 |....._...=.;..8t|
|00000040| 33 6e 78 35 69 7a 39 76 37 73 69 6a 73 2e 64 65 |3nx5iz9v7sijs.de|
|00000050| 76 69 63 65 61 64 76 69 73 6f 72 2e 69 6f 74 2e |viceadvisor.iot.|
|00000060| 75 73 2d 65 61 73 74 2d 31 2e 61 6d 61 7a 6f 6e |us-east-1.amazon|
|00000070| 61 77 73 2e 63 6f 6d 00 0d 00 06 00 04 04 03 04 |aws.com.........|
|00000080| 01 00 0a 00 0a 00 08 00 1d 00 17 00 18 00 19 00 |................|
|00000090| 0b 00 02 01 00                                  |.....           |
+--------+-------------------------------------------------+----------------+

服务器返回的close-notify告警

TLS Record Sender SERVER ContentType ALERT Length 7 Timestamp 2022-12-19T18:08:58Z
         +-------------------------------------------------+
         |  0  1  2  3  4  5  6  7  8  9  a  b  c  d  e  f |
+--------+-------------------------------------------------+----------------+
|00000000| 15 03 03 00 02 01 00                            |.......         |
+--------+-------------------------------------------------+----------------+

解码后的Client Hello详情

16 03 03 00 a4 
Record Header
    16 - type is 0x16 (handshake record)
    03 03 - protocol version is 3.3 (also known as TLS 1.2)
    00 90 - 0x90 bytes of handshake message follows 

01 00 00 a0 
    01 - handshake message type 0x01 (client hello)
    00 00 8c - 0x8c  bytes of client hello follows 
03 03 
    The protocol version of "3,3" (meaning TLS 1.2) is given. 

80 e3 df 37 83 02 08 84 9d b0 6f e8 86 e9 e0 12 5e 77 f9 97 c6 af 62 cf 43 c6 40 63 c0 77 3a 82 
    The client provides 32 bytes of random data.

00 
    Session id
    00 - length of zero (no session id is provided) 

00 04
    Cipher Suites - 4 bytes of cipher suits follow
    c0 2b 
        TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256
    00 ff 
        TLS_EMPTY_RENEGOTIATION_INFO_SCSV

01 00 
    01 - 0x1 (1) bytes of compression methods follows
    00 - assigned value for no compression 

00 73 
    00 73 - the extensions will take 0x73 (115) bytes of data 

00 00 
    Server Name Extension
    00 47 
        71 Bytes Follow
    00 45
        69 Bytes of list entry
    00 
        List entry type is 0x00 "DNS Hostname"
    00 42 
        66 Bytes of host name follow
    74 34 31 31 62 39 36 32 35 37 74 33 6e 78 35 69 7a 39 76 37 73 69 6a 73 2e 64 65 76 69 63 6561 64 76 69 73 6f 72 2e 69 6f 74 2e 75 73 2d 65 61 73 74 2d 31 2e 61 6d 61 7a 6f 6e 61 77 73 2e 63 6f 6d 
        Hostname - "t411b96257t3nx5iz9v7sijs.deviceadvisor.iot.us-east-1.amazonaws.com"

00 0d
    Signature Algorithms
    00 06 
        6 Bytes follow
    00 04 
        4 Bytes follow
    04 03 
        ECDSA/SECP256r1/SHA256 
    04 01 
        RSA/PKCS1/SHA256 

00 0a 
    Supported Groups
    00 0a
        10 bytes of "supported groups" extension data follows 
    00 08 
        8 Bytes of data are in the curves list
    00 1d 
        x25519
    00 17 
        secp256r1
    00 18 
        secp384r1
    00 19 
        secp521r1

00 0b 
    EC Point Formats
    00 02 
        2 bytes of EC points format data follows
    01 
        1 bytes of data are in the list
    00 
        Assigned value for uncompressed formo

已尝试的排查手段

  • 添加ALPN并尝试8883和443端口,无变化
  • 使用其他测试应用可正常连接,但日志未显示设备间差异
  • 设备可正常连接常规端点并正常运行

排查建议

1. 验证证书适配性

AWS Device Advisor对证书的校验可能比生产端点更严格,确认设备使用的证书的SAN字段是否包含当前Device Advisor测试端点的完整域名,同时检查该证书是否被添加到AWS IoT的允许列表中,且绑定的Thing与测试用例匹配。

2. 对比C#应用的Client Hello细节

将设备发送的Client Hello字节流与C#应用的做逐字节对比,重点关注:

  • TLS扩展的顺序(部分服务器对扩展顺序敏感)
  • 密码套件的排序(Device Advisor可能优先选择C#应用中的套件顺序)
  • 是否存在设备端缺失的扩展(比如extended_master_secret、status_request等)

3. 开启Mbed-TLS详细调试

启用Mbed-TLS的MBEDTLS_DEBUG_C编译宏,获取更底层的TLS握手日志,比如证书链加载、密钥交换初始化、服务器返回的隐性错误信息,这些细节可能解释close-notify的触发原因。

4. 检查设备时间同步

TLS握手依赖准确的系统时间来校验证书有效期,确认设备是否通过NTP同步了时间,时间偏差超过证书有效期范围会导致服务器直接关闭连接。

5. 排查网络路径差异

虽然设备能连接生产端点,但Device Advisor端点可能有不同的网络策略:

  • 检查设备是否能正常ping通Device Advisor端点
  • 确认是否存在防火墙或代理拦截了TLS报文
  • 验证MTU设置是否合理,避免Client Hello报文被异常分片

6. 确认Mbed-TLS版本兼容性

检查当前使用的Mbed-TLS版本是否存在已知的TLS握手兼容性问题,尝试升级到AWS推荐的Mbed-TLS版本(与FreeRTOS适配的稳定版本)。

内容的提问来源于stack exchange,提问作者Aaron Decker

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.07 14:55:19