云数据库 GAUSSDB(FOR MYSQL)-客户端TLS版本MySQL不一致导致SSL连接失败:原因分析

时间:2024-09-11 14:20:04

原因分析

排查步骤:

  1. 查看 GaussDB (for MySQL)的错误日志,观察到如下报错:
    2021-07-09T10:30:58.476586+08:00 212539 [Warning] SSL errno: 337678594, SSL errmsg: error:14209102:SSL routines:tls_early_post_process_client_hello:unsupported protocol2021-07-09T10:30:58.476647+08:00 212539 [Note] Bad handshake2021-07-09T10:32:43.535738+08:00 212631 [Warning] SSL errno: 337678594, SSL errmsg: error:14209102:SSL routines:tls_early_post_process_client_hello:unsupported protocol2021-07-09T10:32:43.535787+08:00 212631 [Note] Bad handshake2021-07-09T10:50:03.401100+08:00 213499 [Warning] SSL errno: 337678594, SSL errmsg: error:14209102:SSL routines:tls_early_post_process_client_hello:unsupported protocol2021-07-09T10:50:03.401161+08:00 213499 [Note] Bad handshake2021-07-09T10:53:44.458404+08:00 213688 [Warning] SSL errno: 337678594, SSL errmsg: error:14209102:SSL routines:tls_early_post_process_client_hello:unsupported protocol2021-07-09T10:53:44.458475+08:00 213688 [Note] Bad handshake
  2. 从报错信息unsupported protocol可以看出,很可能和TLS版本相关,使用如下命令,分别查看GaussDB(for MySQL)和自建MySQL的TLS版本。

    show variables like '%tls_version%';

    发现GaussDB(for MySQL)为TLS v1.2版本,自建MySQL为TLS v1.1版本,存在差异。进一步确认客户端TLS版本,与自建MySQL一致,因此出现连接自建MySQL成功,连接云上GaussDB(for MySQL)失败。

support.huaweicloud.com/trouble-gaussdbformysql/gaussdbformysql_trouble_0104.html