Azure / Azure/SQL-Connectivity-Checker

TLS handshake times out when CRL URLs are blocked (no internet)

Aperta
#122 3 commenti 0 reazioni 0 assegnatari Vedi su GitHub
Lingua principale
C#
Stelle
81
Fork
49
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Descrizione

When running the SQL Connectivity Checker in a containerized environment with no internet access (outbound HTTP blocked), the TLS handshake phase is extremely slow (30+ seconds) and times out. This occurs even when setting TrustServerCertificate = true.

We are testing connectivity from Azure Container App to Azure SQL Database via private endpoint. It appears that this tool attempts to fetch from internet the CRL (Certificate Revocation List) for the certificate presented by Azure SQL logical server (e.g., http://www.microsoft.com/pkiops/crl/Microsoft%20Azure%20RSA%20TLS%20Issuing%20CA%2007.crl) which is blocked.

```
[2026.01.23 19:41:58.9401] Connect initiated (attempt # 3).
[2026.01.23 19:41:58.9401] PreLogin phase starting
[2026.01.23 19:41:58.9527] DNS resolution took 12 ms, (10.250.117.5)
[2026.01.23 19:41:58.9593] TCP connection open
[2026.01.23 19:41:58.9593] Local endpoint is [::ffff:169.254.1.146]:47818
[2026.01.23 19:41:58.9593] Remote endpoint is [::ffff:10.250.117.5]:1433

[2026.01.23 19:41:58.9593] Building PreLogin message.
[2026.01.23 19:41:58.9593] Adding PreLogin option Encryption [EncryptOff].
[2026.01.23 19:41:58.9593] Adding PreLogin option TraceID
[2026.01.23 19:41:58.9594] ConnectionID: C2E94E1F-08F1-4631-B98F-8BBBE999A51C
[2026.01.23 19:41:58.9594] ActivityID: B5B1C026-2728-490B-92D8-6EFCE4E1EFBE
[2026.01.23 19:41:58.9594] ActivitySequence: 0
[2026.01.23 19:41:58.9594] Adding PreLogin option FedAuthRequired [FedAuthRequired].
[2026.01.23 19:41:58.9594] Adding PreLogin message terminator.
[2026.01.23 19:41:58.9594] Trying to send PreLogin.
[2026.01.23 19:41:58.9595] PreLogin message sent.
[2026.01.23 19:41:58.9595] Waiting for PreLogin response.

[2026.01.23 19:41:58.9595] Receiving response:
[2026.01.23 19:41:58.9616] Server requires encryption, enabling encryption:
[2026.01.23 19:41:58.9616] Trust Server Certificate is set to False
[2026.01.23 19:41:58.9616] Trying to authenticate using Tls12
[2026.01.23 19:41:58.9629] Checking certificate validation results:
[2026.01.23 19:41:58.9630] Certificate error: RemoteCertificateChainErrors
[2026.01.23 19:41:58.9630] unable to get certificate CRL
[2026.01.23 19:41:58.9630] unable to get certificate CRL
[2026.01.23 19:41:58.9630] Cert details:
[2026.01.23 19:41:58.9631] issued to CN=cr16.northeurope1-a.control.database.windows.net, O=Microsoft Corporation, L=Redmond, S=WA, C=US
[2026.01.23 19:41:58.9631] valid from 1/16/2026 1:53:03 PM until 7/15/2026 1:53:03 PM
[2026.01.23 19:41:58.9631] issued from CN=Microsoft Azure RSA TLS Issuing CA 07, O=Microsoft Corporation, C=US
[2026.01.23 19:41:58.9632] thumbprint E191BAEA456729A409E3A08C7CFDF49E6D75A01A
[2026.01.23 19:42:13.9680] valid: False
[2026.01.23 19:42:13.9685] key usages: KeyEncipherment, DigitalSignature
[2026.01.23 19:42:13.9685] intended purposes: TLS Web Client Authentication, TLS Web Server Authentication
[2026.01.23 19:42:13.9685] Cert details:
[2026.01.23 19:42:13.9690] issued to CN=Microsoft Azure RSA TLS Issuing CA 07, O=Microsoft Corporation, C=US
[2026.01.23 19:42:13.9690] valid from 6/8/2023 12:00:00 AM until 8/25/2026 11:59:59 PM
[2026.01.23 19:42:13.9691] issued from CN=DigiCert Global Root G2, OU=[www.digicert.com](https://www.digicert.com/), O=DigiCert Inc, C=US
[2026.01.23 19:42:13.9691] thumbprint 3382517058A0C20228D598EE7501B61256A76442
[2026.01.23 19:42:14.2904] valid: False
[2026.01.23 19:42:14.2906] this cert is CertificateAuthority
[2026.01.23 19:42:14.2906] key usages: CrlSign, KeyCertSign, DigitalSignature
[2026.01.23 19:42:14.2906] intended purposes: TLS Web Server Authentication, TLS Web Client Authentication
[2026.01.23 19:42:14.2906] Cert details:
[2026.01.23 19:42:14.2907] issued to CN=DigiCert Global Root G2, OU=[www.digicert.com](https://www.digicert.com/), O=DigiCert Inc, C=US
[2026.01.23 19:42:14.2907] valid from 8/1/2013 12:00:00 PM until 1/15/2038 12:00:00 PM
[2026.01.23 19:42:14.2907] issued from CN=DigiCert Global Root G2, OU=[www.digicert.com](https://www.digicert.com/), O=DigiCert Inc, C=US
[2026.01.23 19:42:14.2907] thumbprint DF3C24F9BFD666761B268073FE06D1CC8D4F82A4
[2026.01.23 19:42:14.2916] valid: True
[2026.01.23 19:42:14.2916] this cert is CertificateAuthority
[2026.01.23 19:42:14.2916] key usages: CrlSign, KeyCertSign, DigitalSignature
[2026.01.23 19:42:28.9659] Enabling encryption operation was not completed and cancelled at client side after 30 seconds, it should be done under 5 seconds.
[2026.01.23 19:42:28.9660] SNI timeout detected, PreLogin phase was not complete after 30025 milliseconds.

[2026.01.23 19:42:28.9661] Error
Exception:Enabling encryption operation was not completed and cancelled at client side after 30 seconds, it should be done under 5 seconds.


[2026.01.23 19:42:28.9678] Disconnect initiated.
[2026.01.23 19:42:28.9679] Disconnect done.
```

Guida per i contributori

Nessuna guida per i contributori indicizzata per questo repository

Direzione di ricerca

Iniziare con lo script PowerShell SQL Connectivity Checker e seguire il percorso di convalida del certificato PreLogin/TLS mostrato nel log. Riprodurre l’errore in una Azure Container App isolata dalla rete verso Azure SQL, quindi verificare che gli endpoint CRL bloccati non causino più il timeout di 30 secondi e che l’handshake venga completato entro i cinque secondi previsti.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
azure, csharp, powershell, sql
Ambito
cloud, networking, security
Tipo di issue
Bug
Difficoltà
4/5
Tempo stimato
3-5 giorni
Stato di attività
Ferma
Chiarezza
Da chiarire
Idoneità per principianti
35/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.