You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Amazon EMR集群Trino服务正常但Web UI无法访问求助

Trino Web UI访问报错ERR_SSL_KEY_USAGE_INCOMPATIBLE的解决方案

问题场景

Trino服务器运行正常(server.log显示"SERVER STARTED"、无错误),JDBC连接可正常执行查询,但访问Web UI时浏览器提示ERR_SSL_KEY_USAGE_INCOMPATIBLE错误,多个Trino版本(360、388)均存在该问题,通过DNS/IP访问结果一致,调整web-ui.enabled=true配置无效。

解决方案

该错误核心原因是Trino配置的SSL证书密钥用途不符合HTTPS服务器要求,以下是具体解决步骤:

  • 检查现有SSL证书的密钥用途
    执行命令查看证书的密钥用途扩展:

    openssl x509 -in <你的证书文件路径> -text -noout
    

    查看输出中的X509v3 Key Usage字段,确认是否包含Digital Signature和Key Encipherment;同时X509v3 Extended Key Usage需包含serverAuth。若缺少上述字段,需重新生成证书。

  • 重新生成符合要求的SSL证书

    1. 创建openssl配置文件(例如trino_ssl.cnf):
      [req]
      distinguished_name = req_distinguished_name
      x509_extensions = v3_ca
      prompt = no
      
      [req_distinguished_name]
      CN = <你的Trino服务器域名或IP>
      
      [v3_ca]
      keyUsage = digitalSignature, keyEncipherment
      extendedKeyUsage = serverAuth
      subjectAltName = DNS:<服务器域名>, IP:<服务器IP>
      
    2. 生成自签证书和密钥:
      openssl req -x509 -newkey rsa:4096 -keyout trino.key -out trino.crt -days 365 -config trino_ssl.cnf -nodes
      
    3. 将生成的trino.key和trino.crt放到Trino配置目录(如/etc/trino),修改config.properties中的SSL配置:
      http-server.https.enabled=true
      http-server.https.port=8443
      http-server.https.pem-certificate-file=/etc/trino/trino.crt
      http-server.https.pem-private-key-file=/etc/trino/trino.key
      web-ui.enabled=true
      
  • 清除浏览器SSL缓存
    使用浏览器隐私模式访问,或手动清除SSL缓存,避免旧证书缓存干扰。

  • 验证配置
    重启Trino服务,再次访问Web UI,确认错误是否消失。

内容的提问来源于stack exchange,提问作者PickleMick

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.15 10:45:37