Amazon EMR集群Trino服务正常但Web UI无法访问求助
Trino Web UI访问报错ERR_SSL_KEY_USAGE_INCOMPATIBLE的解决方案
问题场景
Trino服务器运行正常(server.log显示"SERVER STARTED"、无错误),JDBC连接可正常执行查询,但访问Web UI时浏览器提示ERR_SSL_KEY_USAGE_INCOMPATIBLE错误,多个Trino版本(360、388)均存在该问题,通过DNS/IP访问结果一致,调整web-ui.enabled=true配置无效。
解决方案
该错误核心原因是Trino配置的SSL证书密钥用途不符合HTTPS服务器要求,以下是具体解决步骤:
检查现有SSL证书的密钥用途
执行命令查看证书的密钥用途扩展:openssl x509 -in <你的证书文件路径> -text -noout查看输出中的
X509v3 Key Usage字段,确认是否包含Digital Signature和Key Encipherment;同时X509v3 Extended Key Usage需包含serverAuth。若缺少上述字段,需重新生成证书。重新生成符合要求的SSL证书
- 创建openssl配置文件(例如
trino_ssl.cnf):[req] distinguished_name = req_distinguished_name x509_extensions = v3_ca prompt = no [req_distinguished_name] CN = <你的Trino服务器域名或IP> [v3_ca] keyUsage = digitalSignature, keyEncipherment extendedKeyUsage = serverAuth subjectAltName = DNS:<服务器域名>, IP:<服务器IP> - 生成自签证书和密钥:
openssl req -x509 -newkey rsa:4096 -keyout trino.key -out trino.crt -days 365 -config trino_ssl.cnf -nodes - 将生成的
trino.key和trino.crt放到Trino配置目录(如/etc/trino),修改config.properties中的SSL配置:http-server.https.enabled=true http-server.https.port=8443 http-server.https.pem-certificate-file=/etc/trino/trino.crt http-server.https.pem-private-key-file=/etc/trino/trino.key web-ui.enabled=true
- 创建openssl配置文件(例如
清除浏览器SSL缓存
使用浏览器隐私模式访问,或手动清除SSL缓存,避免旧证书缓存干扰。验证配置
重启Trino服务,再次访问Web UI,确认错误是否消失。
内容的提问来源于stack exchange,提问作者PickleMick
相关产品推荐
相关产品推荐

