Azure / Azure/SQL-Connectivity-Checker
TLS handshake times out when CRL URLs are blocked (no internet)
- Lenguaje dominante
- C#
- Estrellas
- 81
- Forks
- 49
- Métricas de merge de PR
- Sin PR fusionados en 30 d
Descripción
When running the SQL Connectivity Checker in a containerized environment with no internet access (outbound HTTP blocked), the TLS handshake phase is extremely slow (30+ seconds) and times out. This occurs even when setting TrustServerCertificate = true.
We are testing connectivity from Azure Container App to Azure SQL Database via private endpoint. It appears that this tool attempts to fetch from internet the CRL (Certificate Revocation List) for the certificate presented by Azure SQL logical server (e.g., http://www.microsoft.com/pkiops/crl/Microsoft%20Azure%20RSA%20TLS%20Issuing%20CA%2007.crl) which is blocked.
```
[2026.01.23 19:41:58.9401] Connect initiated (attempt # 3).
[2026.01.23 19:41:58.9401] PreLogin phase starting
[2026.01.23 19:41:58.9527] DNS resolution took 12 ms, (10.250.117.5)
[2026.01.23 19:41:58.9593] TCP connection open
[2026.01.23 19:41:58.9593] Local endpoint is [::ffff:169.254.1.146]:47818
[2026.01.23 19:41:58.9593] Remote endpoint is [::ffff:10.250.117.5]:1433
[2026.01.23 19:41:58.9593] Building PreLogin message.
[2026.01.23 19:41:58.9593] Adding PreLogin option Encryption [EncryptOff].
[2026.01.23 19:41:58.9593] Adding PreLogin option TraceID
[2026.01.23 19:41:58.9594] ConnectionID: C2E94E1F-08F1-4631-B98F-8BBBE999A51C
[2026.01.23 19:41:58.9594] ActivityID: B5B1C026-2728-490B-92D8-6EFCE4E1EFBE
[2026.01.23 19:41:58.9594] ActivitySequence: 0
[2026.01.23 19:41:58.9594] Adding PreLogin option FedAuthRequired [FedAuthRequired].
[2026.01.23 19:41:58.9594] Adding PreLogin message terminator.
[2026.01.23 19:41:58.9594] Trying to send PreLogin.
[2026.01.23 19:41:58.9595] PreLogin message sent.
[2026.01.23 19:41:58.9595] Waiting for PreLogin response.
[2026.01.23 19:41:58.9595] Receiving response:
[2026.01.23 19:41:58.9616] Server requires encryption, enabling encryption:
[2026.01.23 19:41:58.9616] Trust Server Certificate is set to False
[2026.01.23 19:41:58.9616] Trying to authenticate using Tls12
[2026.01.23 19:41:58.9629] Checking certificate validation results:
[2026.01.23 19:41:58.9630] Certificate error: RemoteCertificateChainErrors
[2026.01.23 19:41:58.9630] unable to get certificate CRL
[2026.01.23 19:41:58.9630] unable to get certificate CRL
[2026.01.23 19:41:58.9630] Cert details:
[2026.01.23 19:41:58.9631] issued to CN=cr16.northeurope1-a.control.database.windows.net, O=Microsoft Corporation, L=Redmond, S=WA, C=US
[2026.01.23 19:41:58.9631] valid from 1/16/2026 1:53:03 PM until 7/15/2026 1:53:03 PM
[2026.01.23 19:41:58.9631] issued from CN=Microsoft Azure RSA TLS Issuing CA 07, O=Microsoft Corporation, C=US
[2026.01.23 19:41:58.9632] thumbprint E191BAEA456729A409E3A08C7CFDF49E6D75A01A
[2026.01.23 19:42:13.9680] valid: False
[2026.01.23 19:42:13.9685] key usages: KeyEncipherment, DigitalSignature
[2026.01.23 19:42:13.9685] intended purposes: TLS Web Client Authentication, TLS Web Server Authentication
[2026.01.23 19:42:13.9685] Cert details:
[2026.01.23 19:42:13.9690] issued to CN=Microsoft Azure RSA TLS Issuing CA 07, O=Microsoft Corporation, C=US
[2026.01.23 19:42:13.9690] valid from 6/8/2023 12:00:00 AM until 8/25/2026 11:59:59 PM
[2026.01.23 19:42:13.9691] issued from CN=DigiCert Global Root G2, OU=[www.digicert.com](https://www.digicert.com/), O=DigiCert Inc, C=US
[2026.01.23 19:42:13.9691] thumbprint 3382517058A0C20228D598EE7501B61256A76442
[2026.01.23 19:42:14.2904] valid: False
[2026.01.23 19:42:14.2906] this cert is CertificateAuthority
[2026.01.23 19:42:14.2906] key usages: CrlSign, KeyCertSign, DigitalSignature
[2026.01.23 19:42:14.2906] intended purposes: TLS Web Server Authentication, TLS Web Client Authentication
[2026.01.23 19:42:14.2906] Cert details:
[2026.01.23 19:42:14.2907] issued to CN=DigiCert Global Root G2, OU=[www.digicert.com](https://www.digicert.com/), O=DigiCert Inc, C=US
[2026.01.23 19:42:14.2907] valid from 8/1/2013 12:00:00 PM until 1/15/2038 12:00:00 PM
[2026.01.23 19:42:14.2907] issued from CN=DigiCert Global Root G2, OU=[www.digicert.com](https://www.digicert.com/), O=DigiCert Inc, C=US
[2026.01.23 19:42:14.2907] thumbprint DF3C24F9BFD666761B268073FE06D1CC8D4F82A4
[2026.01.23 19:42:14.2916] valid: True
[2026.01.23 19:42:14.2916] this cert is CertificateAuthority
[2026.01.23 19:42:14.2916] key usages: CrlSign, KeyCertSign, DigitalSignature
[2026.01.23 19:42:28.9659] Enabling encryption operation was not completed and cancelled at client side after 30 seconds, it should be done under 5 seconds.
[2026.01.23 19:42:28.9660] SNI timeout detected, PreLogin phase was not complete after 30025 milliseconds.
[2026.01.23 19:42:28.9661] Error
Exception:Enabling encryption operation was not completed and cancelled at client side after 30 seconds, it should be done under 5 seconds.
[2026.01.23 19:42:28.9678] Disconnect initiated.
[2026.01.23 19:42:28.9679] Disconnect done.
```
Guía de contribución
No hay ninguna guía de contribución indexada para este repositorio
Línea de trabajo
Comience con el script de PowerShell SQL Connectivity Checker y siga la ruta de validación del certificado de PreLogin/TLS mostrada en el registro. Reproduzca el fallo en una Azure Container App aislada de la red contra Azure SQL y, a continuación, verifique que los endpoints de CRL bloqueados ya no provoquen el tiempo de espera de 30 segundos y que el handshake se complete en los cinco segundos esperados.
Escrito por el modelo de indexación a partir del texto del issue.
Evaluación
- Stack tecnológico
- azure, csharp, powershell, sql
- Área
- cloud, networking, security
- Tipo de issue
- Error
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Estado de actividad
- Estancado
- Claridad
- Necesita aclaración
- Aptitud para principiantes
- 35/100