You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

mongosh无法连接MongoDB TLS集群但mongo可连接的问题咨询

元数据

  • 版本信息:
    • Ubuntu focal
    • MongoDB 5.0.14
  • mongod启动参数:
/usr/bin/mongod --bind_ip_all --replSet=mongodb --auth --tlsCAFile=/etc/mongodb/external-ca.crt --tlsCertificateKeyFile=/etc/mongodb/external-cert.pem --tlsMode=preferTLS --clusterAuthMode=x509 --tlsAllowInvalidCertificates --tlsClusterCAFile=/etc/mongodb/internal-ca.crt --tlsClusterFile=/etc/mongodb/internal-cert.pem

问题

无法通过mongosh连接启用TLS的副本集。

我有一个双节点副本集已启用TLS,执行以下命令:

sudo mongosh 'mongodb://<username>:<password>@<my ip>/admin?replicaSet=mongodb'  --tls --tlsCAFile /etc/mongodb/external-ca.crt --tlsCertificateKeyFile /etc/mongodb/external-cert.pem

收到错误:

MongoServerSelectionError: Hostname/IP does not match certificate's altnames: IP: <my ip> is not in the cert's list:

但日志显示该IP存在于"certificateNames"中:

{"t":{"$date":"2022-12-07T09:05:19.935Z"},"s":"E",  "c":"NETWORK",  "id":23257,   "ctx":"ReplicaSetMonitor-TaskExecutor","msg":"The server certificate does not match the remote host name","attr":{"remoteHost":"juju-29df15-1","certificateNames":"SAN(s): mongodb-0, juju-29df15-1.lxd, mongodb-0.mongodb-endpoints, <my-ip>, CN:  <my-ip>"}}

已尝试操作

使用旧版mongo替代mongosh执行以下命令:

sudo mongo 'mongodb://admin:5zymveLpT3rOlD6WACEuNM0wTJaNJTax@juju-29df15-1.lxd/admin?replicaSet=mongodb'  --tls --tlsCAFile /etc/mongodb/external-ca.crt --tlsCertificateKeyFile /etc/mongodb/external-cert.pem

可成功连接,日志信息如下:

connecting to: mongodb://10.23.62.38:27017/admin?compressors=disabled&gssapiServiceName=mongodb&replicaSet=mongodb
{"t":{"$date":"2022-12-07T09:21:01.646Z"},"s":"W",  "c":"NETWORK",  "id":23237,   "ctx":"ReplicaSetMonitor-TaskExecutor","msg":"You have an IP Address in the DNS Name field on your certificate. This formulation is deprecated."}
{"t":{"$date":"2022-12-07T09:21:01.652Z"},"s":"W",  "c":"NETWORK",  "id":23237,   "ctx":"ReplicaSetMonitor-TaskExecutor","msg":"You have an IP Address in the DNS Name field on your certificate. This formulation is deprecated."}
{"t":{"$date":"2022-12-07T09:21:01.654Z"},"s":"W",  "c":"NETWORK",  "id":23237,   "ctx":"ReplicaSetMonitor-TaskExecutor","msg":"You have an IP Address in the DNS Name field on your certificate. This formulation is deprecated."}
{"t":{"$date":"2022-12-07T09:21:01.662Z"},"s":"W",  "c":"NETWORK",  "id":23237,   "ctx":"js","msg":"You have an IP Address in the DNS Name field on your certificate. This formulation is deprecated."}
{"t":{"$date":"2022-12-07T09:21:01.664Z"},"s":"W",  "c":"NETWORK",  "id":23237,   "ctx":"ReplicaSetMonitor-TaskExecutor","msg":"You have an IP Address in the DNS Name field on your certificate. This formulation is deprecated."}
Implicit session: session { "id" : UUID("97e7e144-1bd7-4a94-b33d-958da2507bec") }
MongoDB server version: 5.0.14
================
Warning: the "mongo" shell has been superseded by "mongosh",
which delivers improved usability and compatibility.The "mongo" shell has been deprecated and will be removed in
an upcoming release.
For installation instructions, see
https://docs.mongodb.com/mongodb-shell/install/
================
---
The server generated these startup warnings when booting:
        2022-12-06T16:56:40.822+00:00: Using the XFS filesystem is strongly recommended with the WiredTiger storage engine. See http://dochub.mongodb.org/core/prodnotes-filesystem
        2022-12-06T16:56:42.686+00:00: While invalid X509 certificates may be used to connect to this server, they will not be considered permissible for authentication
---
---
        Enable MongoDB's free cloud-based monitoring service, which will then receive and display
        metrics about your deployment (disk utilization, CPU, operation statistics, etc).

        The monitoring data will be available on a MongoDB website with a unique URL accessible to you
        and anyone you share the URL with. MongoDB may use this information to make product
        improvements and to suggest MongoDB products and deployment options to you.

        To enable free monitoring, run the following command: db.enableFreeMonitoring()
        To permanently disable this reminder, run the following command: db.disableFreeMonitoring()
---
mongodb:PRIMARY>

连接后可正常执行数据库命令。

疑问

  1. 为何使用mongo可连接,但mongosh无法连接?
  2. 明明在"certificateNames"中能看到<my-ip>,为何仍收到错误MongoServerSelectionError: Hostname/IP does not match certificate's altnames: IP: <my ip> is not in the cert's list:?

解答

关于mongo能连但mongosh不行的原因

旧版mongo shell和新版mongosh的TLS证书验证逻辑存在差异:

  • mongo对证书中IP的格式校验较宽松,即使IP被放在DNS类型的SAN字段(而非专门的IP地址类型SAN字段)里,也能通过验证,这也是日志中出现“IP地址放在DNS名称字段已被弃用”警告的原因。
  • mongosh遵循更严格的TLS规范,要求IP地址必须存在于证书的IP地址类型SAN字段中,而非DNS类型的SAN字段,否则会触发不匹配错误。

关于日志显示IP存在但仍报错的原因

从日志里的certificateNames内容来看,你的IP是被列在SAN的DNS条目里,而非单独的IP地址条目。mongosh验证时只会识别专门的IP类型SAN字段,不会把DNS条目中的IP字符串当作有效IP匹配,所以即使日志显示了这个IP,mongosh依然判定它不在证书的有效列表中。

解决办法

  1. 重新生成证书,将目标IP添加到证书的IP地址类型SAN字段中,而非DNS字段。
  2. 临时绕过验证(不推荐生产环境):在mongosh命令中添加--tlsAllowInvalidHostnames参数,跳过主机名/IP的匹配校验。

内容的提问来源于stack exchange,提问作者Mia Altieri

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.09 04:40:23