Azure / Azure/SQL-Connectivity-Checker
TLS handshake times out when CRL URLs are blocked (no internet)
- Lingua principale
- C#
- Stelle
- 81
- Fork
- 49
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Descrizione
When running the SQL Connectivity Checker in a containerized environment with no internet access (outbound HTTP blocked), the TLS handshake phase is extremely slow (30+ seconds) and times out. This occurs even when setting TrustServerCertificate = true.
We are testing connectivity from Azure Container App to Azure SQL Database via private endpoint. It appears that this tool attempts to fetch from internet the CRL (Certificate Revocation List) for the certificate presented by Azure SQL logical server (e.g., http://www.microsoft.com/pkiops/crl/Microsoft%20Azure%20RSA%20TLS%20Issuing%20CA%2007.crl) which is blocked.
```
[2026.01.23 19:41:58.9401] Connect initiated (attempt # 3).
[2026.01.23 19:41:58.9401] PreLogin phase starting
[2026.01.23 19:41:58.9527] DNS resolution took 12 ms, (10.250.117.5)
[2026.01.23 19:41:58.9593] TCP connection open
[2026.01.23 19:41:58.9593] Local endpoint is [::ffff:169.254.1.146]:47818
[2026.01.23 19:41:58.9593] Remote endpoint is [::ffff:10.250.117.5]:1433
[2026.01.23 19:41:58.9593] Building PreLogin message.
[2026.01.23 19:41:58.9593] Adding PreLogin option Encryption [EncryptOff].
[2026.01.23 19:41:58.9593] Adding PreLogin option TraceID
[2026.01.23 19:41:58.9594] ConnectionID: C2E94E1F-08F1-4631-B98F-8BBBE999A51C
[2026.01.23 19:41:58.9594] ActivityID: B5B1C026-2728-490B-92D8-6EFCE4E1EFBE
[2026.01.23 19:41:58.9594] ActivitySequence: 0
[2026.01.23 19:41:58.9594] Adding PreLogin option FedAuthRequired [FedAuthRequired].
[2026.01.23 19:41:58.9594] Adding PreLogin message terminator.
[2026.01.23 19:41:58.9594] Trying to send PreLogin.
[2026.01.23 19:41:58.9595] PreLogin message sent.
[2026.01.23 19:41:58.9595] Waiting for PreLogin response.
[2026.01.23 19:41:58.9595] Receiving response:
[2026.01.23 19:41:58.9616] Server requires encryption, enabling encryption:
[2026.01.23 19:41:58.9616] Trust Server Certificate is set to False
[2026.01.23 19:41:58.9616] Trying to authenticate using Tls12
[2026.01.23 19:41:58.9629] Checking certificate validation results:
[2026.01.23 19:41:58.9630] Certificate error: RemoteCertificateChainErrors
[2026.01.23 19:41:58.9630] unable to get certificate CRL
[2026.01.23 19:41:58.9630] unable to get certificate CRL
[2026.01.23 19:41:58.9630] Cert details:
[2026.01.23 19:41:58.9631] issued to CN=cr16.northeurope1-a.control.database.windows.net, O=Microsoft Corporation, L=Redmond, S=WA, C=US
[2026.01.23 19:41:58.9631] valid from 1/16/2026 1:53:03 PM until 7/15/2026 1:53:03 PM
[2026.01.23 19:41:58.9631] issued from CN=Microsoft Azure RSA TLS Issuing CA 07, O=Microsoft Corporation, C=US
[2026.01.23 19:41:58.9632] thumbprint E191BAEA456729A409E3A08C7CFDF49E6D75A01A
[2026.01.23 19:42:13.9680] valid: False
[2026.01.23 19:42:13.9685] key usages: KeyEncipherment, DigitalSignature
[2026.01.23 19:42:13.9685] intended purposes: TLS Web Client Authentication, TLS Web Server Authentication
[2026.01.23 19:42:13.9685] Cert details:
[2026.01.23 19:42:13.9690] issued to CN=Microsoft Azure RSA TLS Issuing CA 07, O=Microsoft Corporation, C=US
[2026.01.23 19:42:13.9690] valid from 6/8/2023 12:00:00 AM until 8/25/2026 11:59:59 PM
[2026.01.23 19:42:13.9691] issued from CN=DigiCert Global Root G2, OU=[www.digicert.com](https://www.digicert.com/), O=DigiCert Inc, C=US
[2026.01.23 19:42:13.9691] thumbprint 3382517058A0C20228D598EE7501B61256A76442
[2026.01.23 19:42:14.2904] valid: False
[2026.01.23 19:42:14.2906] this cert is CertificateAuthority
[2026.01.23 19:42:14.2906] key usages: CrlSign, KeyCertSign, DigitalSignature
[2026.01.23 19:42:14.2906] intended purposes: TLS Web Server Authentication, TLS Web Client Authentication
[2026.01.23 19:42:14.2906] Cert details:
[2026.01.23 19:42:14.2907] issued to CN=DigiCert Global Root G2, OU=[www.digicert.com](https://www.digicert.com/), O=DigiCert Inc, C=US
[2026.01.23 19:42:14.2907] valid from 8/1/2013 12:00:00 PM until 1/15/2038 12:00:00 PM
[2026.01.23 19:42:14.2907] issued from CN=DigiCert Global Root G2, OU=[www.digicert.com](https://www.digicert.com/), O=DigiCert Inc, C=US
[2026.01.23 19:42:14.2907] thumbprint DF3C24F9BFD666761B268073FE06D1CC8D4F82A4
[2026.01.23 19:42:14.2916] valid: True
[2026.01.23 19:42:14.2916] this cert is CertificateAuthority
[2026.01.23 19:42:14.2916] key usages: CrlSign, KeyCertSign, DigitalSignature
[2026.01.23 19:42:28.9659] Enabling encryption operation was not completed and cancelled at client side after 30 seconds, it should be done under 5 seconds.
[2026.01.23 19:42:28.9660] SNI timeout detected, PreLogin phase was not complete after 30025 milliseconds.
[2026.01.23 19:42:28.9661] Error
Exception:Enabling encryption operation was not completed and cancelled at client side after 30 seconds, it should be done under 5 seconds.
[2026.01.23 19:42:28.9678] Disconnect initiated.
[2026.01.23 19:42:28.9679] Disconnect done.
```
Guida per i contributori
Nessuna guida per i contributori indicizzata per questo repository
Direzione di ricerca
Iniziare con lo script PowerShell SQL Connectivity Checker e seguire il percorso di convalida del certificato PreLogin/TLS mostrato nel log. Riprodurre l’errore in una Azure Container App isolata dalla rete verso Azure SQL, quindi verificare che gli endpoint CRL bloccati non causino più il timeout di 30 secondi e che l’handshake venga completato entro i cinque secondi previsti.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Valutazione
- Stack tecnologico
- azure, csharp, powershell, sql
- Ambito
- cloud, networking, security
- Tipo di issue
- Bug
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Stato di attività
- Ferma
- Chiarezza
- Da chiarire
- Idoneità per principianti
- 35/100