ASP.NET Core连接SQL Server 2008遇SSL_ERROR_SSL问题求助
SQL Server 2008与Debian上ASP.NET Core 5.0应用连接失败问题分析
环境信息
- 数据库端:一台PC安装 MS SQL Server 2008 (SP4) - 10.0.6535.0
- 应用端:另一台Debian GNU/Linux系统部署的ASP.NET Core 5.0应用,使用
System.Data.SqlClient组件
错误日志
[2022-08-24 13:41:55.3955] [ERROR] [GPNA.MyApplication.Infrastructure.Modules.DataLoaderModule] System.AggregateException: One or more errors occurred. (A connection was successfully established with the server, but then an error occurred during the pre-login handshake. (provider: TCP Provider, error: 35 - An internal exception was caught)) ---> System.Data.SqlClient.SqlException (0x80131904): A connection was successfully established with the server, but then an error occurred during the pre-login handshake. (provider: TCP Provider, error: 35 - An internal exception was caught) ---> System.Security.Authentication.AuthenticationException: Authentication failed, see inner exception. ---> Interop+OpenSsl+SslException: SSL Handshake failed with OpenSSL error - SSL_ERROR_SSL. ---> Interop+Crypto+OpenSslCryptographicException: error:1425F102:SSL routines:ssl_choose_client_version:unsupported protocol --- End of inner exception stack trace ---
已尝试操作
- 关闭Visual Studio中的SSL设置
- 调整SqlConnectionString的多种配置项
- 修改Linux系统的
openssl.cnf配置
连接字符串示例
Data Source=10.20.17.76;Initial Catalog=Runtime; User ID=sa; Password=******; Connect Timeout=300; TrustServerCertificate=True; Encrypt = False
更新信息
将应用部署到可正常连接该SQL Server的Windows Server 2008远程PC上,应用运行正常,可排除SQL Server本身的问题。
问题核心
当前疑问:连接失败的问题根源是在应用、Linux系统还是SSL相关配置?
问题分析与解决方案
从错误日志中的error:1425F102:SSL routines:ssl_choose_client_version:unsupported protocol可以明确,问题出在SSL协议版本不兼容,属于Linux系统的SSL配置层面问题,和应用本身无关。
原因
- SQL Server 2008 SP4默认仅支持SSL 3.0和TLS 1.0协议
- 新版本Debian系统的OpenSSL已默认禁用TLS 1.0及以下的老旧协议,导致双方握手时无法协商出共同支持的SSL版本
解决步骤
修改Debian的OpenSSL配置,启用TLS 1.0
编辑/etc/ssl/openssl.cnf文件,找到[system_default_sect]小节(如果没有则新增),添加或修改如下配置:[system_default_sect] MinProtocol = TLSv1.0 CipherString = DEFAULT@SECLEVEL=1保存后重启应用服务,让配置生效。
验证SSL连接可用性
使用命令测试Debian与SQL Server的TLS 1.0连接:openssl s_client -connect 10.20.17.76:1433 -tls1如果命令返回成功的连接信息,说明协议层面已打通,再重新启动应用测试。
确认连接字符串配置
确保Encrypt=False和TrustServerCertificate=True的配置已正确生效,避免不必要的SSL强制验证逻辑。
内容的提问来源于stack exchange,提问作者Roman
相关产品推荐
相关产品推荐

