You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GCP Kubernetes中MongoDB集群启用TLS后无法连接问题求助

MongoDB Kubernetes集群启用TLS后连接失败排查

问题描述

在GCP Kubernetes集群中通过MongoDB Kubernetes Operator部署3节点MongoDB集群,设置tls=false时可通过mongosh正常连接。启用TLS后集群启动正常,但无法通过mongosh建立连接。

连接信息

{
  "connectionString.standard": "mongodb://mongo-user:stl-m0ng0-dev@mongodb-dev-0.mongodb-dev-svc.dev.svc.cluster.local:27017,mongodb-dev-1.mongodb-dev-svc.dev.svc.cluster.local:27017,mongodb-dev-2.mongodb-dev-svc.dev.svc.cluster.local:27017/dev?replicaSet=mongodb-dev&ssl=true",
  "connectionString.standardSrv": "mongodb+srv://mongo-user:stl-m0ng0-dev@mongodb-dev-svc.dev.svc.cluster.local/dev?replicaSet=mongodb-dev&ssl=true",
  "password": "xxxxxxx",
  "username": "mongo-user"
}

证书详情

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 2 (0x2)
        Signature Algorithm: sha256WithRSAEncryption
        Issuer: CN = TLSGenSelfSignedtRootCA, L = $$$$
        Validity
            Not Before: Jul 27 09:07:50 2022 GMT
            Not After : Jul 24 09:07:50 2032 GMT
        Subject: CN = *.mongodb-dev-svc.dev.svc.cluster.local, O = client
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (2048 bit)
                Modulus:
                    00:c4:44:a6:21:95:85:9a:dc:96:63:8e:76:ed:d9:
                    3a:59
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints:
                CA:FALSE
            X509v3 Key Usage:
                Digital Signature, Key Encipherment
            X509v3 Extended Key Usage:
                TLS Web Client Authentication
            X509v3 Subject Alternative Name:
                DNS:mongodb-dev-1.mongodb-dev-svc.dev.svc.cluster.local, DNS:mongodb-dev-2.mongodb-dev-svc.dev.svc.cluster.local, DNS:mongodb-dev-3.mongodb-dev-svc.dev.svc.cluster.local
    Signature Algorithm: sha256WithRSAEncryption
         7b:78:43:73:ae:2f:ce:97:de:b2:19:56:4c:38:71:8e:3d:ff:
         5b:15:79:c1
Will display server certificate info


Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 1 (0x1)
        Signature Algorithm: sha256WithRSAEncryption
        Issuer: CN = TLSGenSelfSignedtRootCA, L = $$$$
        Validity
            Not Before: Jul 27 09:07:50 2022 GMT
            Not After : Jul 24 09:07:50 2032 GMT
        Subject: CN = *.mongodb-dev-svc.dev.svc.cluster.local, O = server
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (2048 bit)
                Modulus:
                    00:bc:1e:4a:a7:4f:c4:01:71:2c:78:eb:ac:c9:53:
                    24:c1
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints:
                CA:FALSE
            X509v3 Key Usage:
                Digital Signature, Key Encipherment
            X509v3 Extended Key Usage:
                TLS Web Server Authentication
            X509v3 Subject Alternative Name:
                DNS:mongodb-dev-0.mongodb-dev-svc.dev.svc.cluster.local, DNS:mongodb-dev-1.mongodb-dev-svc.dev.svc.cluster.local, DNS:mongodb-dev-2.mongodb-dev-svc.dev.svc.cluster.local
    Signature Algorithm: sha256WithRSAEncryption
         16:0f:09:02:66:05:69:7b:91:3b:93:73:86:64:d5:8f:53:2d:
         08:19:68:a7 

客户端错误信息

root@xxxxxxxxxxxxxxxxxx-55955c9fcd-bpp98:/usr/src/app# mongosh "mongodb+srv://mongo-user:stl-m0ng0-dev@mongodb-dev-svc.dev.svc.cluster.local/dev?replicaSet=mongodb-dev&ssl=false&tlsCAFile=ca.pem&tlsCertificateKeyFile=key.pem"                                                                                                            
Current Mongosh Log ID: 62e1029487b960f1bd204b1d
Connecting to:          mongodb+srv://<credentials>@mongodb-dev-svc.dev.svc.cluster.local/dev?replicaSet=mongodb-dev&ssl=false&tlsCAFile=ca.pem&tlsCertificateKeyFile=key.pem&appName=mongosh+1.5.1
MongoServerSelectionError: connection <monitor> to 10.120.6.8:27017 closed

服务端错误信息

2022-07-27T09:25:44.992+0000 I  NETWORK  [conn25852] end connection 10.120.6.9:33914 (14 connections now open)
2022-07-27T09:25:44.993+0000 I  NETWORK  [listener] connection accepted from 10.120.6.9:33918 #25855 (15 connections now open)
2022-07-27T09:25:44.993+0000 E  NETWORK  [conn25854] SSL peer certificate validation failed: unsupported certificate purpose
2022-07-27T09:25:44.994+0000 I  NETWORK  [conn25854] Error receiving request from client: SSLHandshakeFailed: SSL peer certificate validation failed: unsupported certificate purpose. Ending connection from 10.120.8.127:58220 (connection id: 25854)
2022-07-27T09:25:44.994+0000 I  NETWORK  [conn25854] end connection 10.120.8.127:58220 (14 connections now open)
2022-07-27T09:25:44.995+0000 I  NETWORK  [listener] connection accepted from 10.120.8.127:58224 #25856 (15 connections now open)
2022-07-27T09:25:44.998+0000 E  NETWORK  [conn25855] SSL peer certificate validation failed: unsupported certificate purpose
2022-07-27T09:25:44.998+0000 I  NETWORK  [conn25855] Error receiving request from client: SSLHandshakeFailed: SSL peer certificate validation failed: unsupported certificate purpose. Ending connection from 10.120.6.9:33918 (connection id: 25855)
2022-07-27T09:25:44.998+0000 I  NETWORK  [conn25855] end connection 10.120.6.9:33918 (14 connections now open)
2022-07-27T09:25:45.000+0000 E  NETWORK  [conn25856] SSL peer certificate validation failed: unsupported certificate purpose
2022-07-27T09:25:45.000+0000 I  NETWORK  [conn25856] Error receiving request from client: SSLHandshakeFailed: SSL peer certificate validation failed: unsupported certificate purpose. Ending connection from 10.120.8.127:58224 (connection id: 25856)
2022-07-27T09:25:45.000+0000 I  NETWORK  [conn25856] end connection 10.120.8.127:58224 (13 connections now open)
2022-07-27T09:25:45.001+0000 I  REPL_HB  [replexec-2] Heartbeat to mongodb-dev-1.mongodb-dev-svc.dev.svc.cluster.local:27017 failed after 2 retries, response status: HostUnreachable: stream truncated
2022-07-27T09:25:45.003+0000 I  NETWORK  [listener] connection accepted from 10.120.8.127:58228 #25858 (14 connections now open)
2022-07-27T09:25:45.007+0000 E  NETWORK  [conn25858] SSL peer certificate validation failed: unsupported certificate purpose
2022-07-27T09:25:45.007+0000 I  NETWORK  [conn25858] Error receiving request from client: SSLHandshakeFailed: SSL peer certificate validation failed: unsupported certificate purpose. Ending connection from 10.120.8.127:58228 (connection id: 25858)
2022-07-27T09:25:45.007+0000 I  NETWORK  [conn25858] end connection 10.120.8.127:58228 (13 connections now open)

Operator日志信息

2022-07-27T10:06:05.893Z        INFO    controllers/mongodb_status_options.go:110       TLS config is not yet valid, retrying in 10 seconds
2022-07-27T10:06:15.899Z        INFO    controllers/replica_set_controller.go:140       Reconciling MongoDB     {"ReplicaSet": "dev/mongodb-replica-set"}
2022-07-27T10:06:15.900Z        DEBUG   controllers/replica_set_controller.go:142       Validating MongoDB.Spec {"ReplicaSet": "dev/mongodb-replica-set"}
2022-07-27T10:06:15.900Z        DEBUG   controllers/replica_set_controller.go:151       Ensuring the service exists     {"ReplicaSet": "dev/mongodb-replica-set"}
2022-07-27T10:06:15.900Z        DEBUG   agent/agent_readiness.go:101    The Pod '' doesn't have annotation 'agent.mongodb.com/version' yet      {"ReplicaSet": "dev/mongodb-replica-set"}
2022-07-27T10:06:15.900Z        DEBUG   agent/agent_readiness.go:101    The Pod '' doesn't have annotation 'agent.mongodb.com/version' yet      {"ReplicaSet": "dev/mongodb-replica-set"}
2022-07-27T10:06:15.900Z        DEBUG   agent/agent_readiness.go:101    The Pod '' doesn't have annotation 'agent.mongodb.com/version' yet      {"ReplicaSet": "dev/mongodb-replica-set"}
2022-07-27T10:06:15.900Z        DEBUG   agent/replica_set_port_manager.go:122   No port change required {"ReplicaSet": "dev/mongodb-replica-set"}
2022-07-27T10:06:15.906Z        INFO    controllers/replica_set_controller.go:462       Create/Update operation succeeded       {"ReplicaSet": "dev/mongodb-replica-set","operation": "updated"}
2022-07-27T10:06:15.906Z        INFO    controllers/mongodb_tls.go:40   Ensuring TLS is correctly configured    {"ReplicaSet": "dev/mongodb-replica-set"}
2022-07-27T10:06:15.906Z        WARN    controllers/mongodb_tls.go:47   CA resource not found: Secret "tls-ca-key-pair" not found       {"ReplicaSet": "dev/mongodb-replica-set"}

问题根源及解决步骤

  1. 证书用途不匹配
    服务端日志明确提示证书用途不支持,MongoDB副本集节点间通信需要证书同时支持客户端和服务端认证。当前客户端证书仅配置TLS Web Client Authentication,服务端证书仅配置TLS Web Server Authentication,需重新生成证书,确保所有证书的Extended Key Usage同时包含这两项用途。

  2. CA证书密钥对缺失
    Operator无法找到名为tls-ca-key-pair的Secret,需确认:

    • 集群中已创建该Secret,包含CA证书和私钥;
    • MongoDB集群的TLS配置正确引用了该Secret。
  3. 连接参数冲突
    客户端连接命令中同时指定ssl=false和TLS证书参数,需将ssl=false改为ssl=true,确保启用TLS连接:

    mongosh "mongodb+srv://mongo-user:stl-m0ng0-dev@mongodb-dev-svc.dev.svc.cluster.local/dev?replicaSet=mongodb-dev&ssl=true&tlsCAFile=ca.pem&tlsCertificateKeyFile=key.pem"
    

内容的提问来源于stack exchange,提问作者Nuwan Sameera

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.25 05:06:35