You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

启用HTTPS时Trino与Elasticsearch集成报错求助

Trino与Elasticsearch集成TLS认证问题排查

问题背景

未启用认证时,Trino可通过CLI正常访问Elasticsearch并执行查询;启用TLS和认证后,Trino容器启动报错。

证书生成命令

执行以下命令生成自签名证书(通用名称填写localhost):

openssl req -x509 -newkey rsa:4096 -keyout http.pem -out trino-certificates.pem -days 365

Elasticsearch连接器配置(elasticsearch.properties)

connector.name=elasticsearch
elasticsearch.host=asci-eds
elasticsearch.port=9200
elasticsearch.default-schema-name=default
elasticsearch.ignore-publish-address=true
#elasticsearch.tls.verify-hostnames=true
elasticsearch.tls.enabled=true
elasticsearch.auth.user=elastic
elasticsearch.auth.password=elastic
elasticsearch.tls.keystore-password=elastic
elasticsearch.security=PASSWORD
elasticsearch.tls.keystore-path=/etc/trino/http.pem
elasticsearch.tls.truststore-path=/etc/trino/trino-certificates.pem

启动错误日志

Caused by: IOException: toDerInputStream rejects tag type 45
at java.base/DerValue.toDerInputStream(DerValue.java:1156)
at java.base/PKCS12KeyStore.engineLoad(PKCS12KeyStore.java:2013)
at java.base/KeyStoreDelegator.engineLoad(KeyStoreDelegator.java:221)
at java.base/KeyStore.load(KeyStore.java:1473)
at SslUtils.createSSLContext(SslUtils.java:69)

Trino主配置(config.properties)

coordinator=true
node-scheduler.include-coordinator=true
http-server.http.port=8080
discovery.uri=https://localhost:8443
http-server.https.enabled=true
http-server.https.port=8443
http-server.https.keystore.path=/etc/trino/trino.pem
http-server.https.keystore.key=pass

http-server.process-forwarded=true
http-server.authentication.allow-insecure-over-http=true

internal-communication.https.required=false
http-server.authentication.type=PASSWORD
internal-communication.shared-secret=9sScljbKVW6tY8eXuJncJMa8Su5mCVH04YC5fx7wMhoqKTDH2qLmqt8gKpmdgG3YQcAjoIuj

问题分析与解决步骤

核心错误原因

toDerInputStream rejects tag type 45 错误表明Java无法加载指定的keystore/truststore文件,因为Trino要求TLS配置使用PKCS12格式(.p12文件)的密钥库和信任库,而当前使用的是PEM格式文件,Java KeyStore不直接支持PEM格式。此外配置中存在多处参数名称错误,也会导致启动失败。

解决步骤

  1. 重新生成PKCS12格式的密钥库与信任库

    • 将生成的PEM证书和私钥合并为PKCS12密钥库(设置密码为elastic,与配置中keystore-password一致):
      openssl pkcs12 -export -in trino-certificates.pem -inkey http.pem -out trino-keystore.p12 -name trino -password pass:elastic
      
    • 生成PKCS12格式的信任库(导入证书,密码设为elastic):
      keytool -importcert -file trino-certificates.pem -keystore trino-truststore.p12 -storetype PKCS12 -alias elasticsearch -storepass elastic -noprompt
      
  2. 修正Elasticsearch连接器配置
    修改elasticsearch.properties中的以下配置项:

    # 替换为PKCS12密钥库路径
    elasticsearch.tls.keystore-path=/etc/trino/trino-keystore.p12
    # 替换为PKCS12信任库路径
    elasticsearch.tls.truststore-path=/etc/trino/trino-truststore.p12
    # 修正认证类型配置项(原配置项名称错误)
    elasticsearch.auth.type=PASSWORD
    # 删除错误的elasticsearch.security=PASSWORD配置
    
  3. 修正Trino主配置
    修改config.properties中的以下配置项:

    # 替换为PKCS12密钥库路径
    http-server.https.keystore.path=/etc/trino/trino-keystore.p12
    # 修正密钥库密码配置项名称(原配置项名称错误)
    http-server.https.keystore.password=elastic
    # 删除错误的http-server.https.keystore.key=pass配置
    
  4. 重启Trino容器
    替换配置文件和证书文件后,重启Trino容器验证是否正常启动。


内容的提问来源于stack exchange,提问作者sooriyaa pr

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.19 14:00:47