Azure / Azure/SQL-Connectivity-Checker
TLS handshake times out when CRL URLs are blocked (no internet)
- 主要语言
- C#
- 星标
- 81
- 派生
- 49
- PR 合并指标
- 30 天内没有已合并 PR
描述
When running the SQL Connectivity Checker in a containerized environment with no internet access (outbound HTTP blocked), the TLS handshake phase is extremely slow (30+ seconds) and times out. This occurs even when setting TrustServerCertificate = true.
We are testing connectivity from Azure Container App to Azure SQL Database via private endpoint. It appears that this tool attempts to fetch from internet the CRL (Certificate Revocation List) for the certificate presented by Azure SQL logical server (e.g., http://www.microsoft.com/pkiops/crl/Microsoft%20Azure%20RSA%20TLS%20Issuing%20CA%2007.crl) which is blocked.
```
[2026.01.23 19:41:58.9401] Connect initiated (attempt # 3).
[2026.01.23 19:41:58.9401] PreLogin phase starting
[2026.01.23 19:41:58.9527] DNS resolution took 12 ms, (10.250.117.5)
[2026.01.23 19:41:58.9593] TCP connection open
[2026.01.23 19:41:58.9593] Local endpoint is [::ffff:169.254.1.146]:47818
[2026.01.23 19:41:58.9593] Remote endpoint is [::ffff:10.250.117.5]:1433
[2026.01.23 19:41:58.9593] Building PreLogin message.
[2026.01.23 19:41:58.9593] Adding PreLogin option Encryption [EncryptOff].
[2026.01.23 19:41:58.9593] Adding PreLogin option TraceID
[2026.01.23 19:41:58.9594] ConnectionID: C2E94E1F-08F1-4631-B98F-8BBBE999A51C
[2026.01.23 19:41:58.9594] ActivityID: B5B1C026-2728-490B-92D8-6EFCE4E1EFBE
[2026.01.23 19:41:58.9594] ActivitySequence: 0
[2026.01.23 19:41:58.9594] Adding PreLogin option FedAuthRequired [FedAuthRequired].
[2026.01.23 19:41:58.9594] Adding PreLogin message terminator.
[2026.01.23 19:41:58.9594] Trying to send PreLogin.
[2026.01.23 19:41:58.9595] PreLogin message sent.
[2026.01.23 19:41:58.9595] Waiting for PreLogin response.
[2026.01.23 19:41:58.9595] Receiving response:
[2026.01.23 19:41:58.9616] Server requires encryption, enabling encryption:
[2026.01.23 19:41:58.9616] Trust Server Certificate is set to False
[2026.01.23 19:41:58.9616] Trying to authenticate using Tls12
[2026.01.23 19:41:58.9629] Checking certificate validation results:
[2026.01.23 19:41:58.9630] Certificate error: RemoteCertificateChainErrors
[2026.01.23 19:41:58.9630] unable to get certificate CRL
[2026.01.23 19:41:58.9630] unable to get certificate CRL
[2026.01.23 19:41:58.9630] Cert details:
[2026.01.23 19:41:58.9631] issued to CN=cr16.northeurope1-a.control.database.windows.net, O=Microsoft Corporation, L=Redmond, S=WA, C=US
[2026.01.23 19:41:58.9631] valid from 1/16/2026 1:53:03 PM until 7/15/2026 1:53:03 PM
[2026.01.23 19:41:58.9631] issued from CN=Microsoft Azure RSA TLS Issuing CA 07, O=Microsoft Corporation, C=US
[2026.01.23 19:41:58.9632] thumbprint E191BAEA456729A409E3A08C7CFDF49E6D75A01A
[2026.01.23 19:42:13.9680] valid: False
[2026.01.23 19:42:13.9685] key usages: KeyEncipherment, DigitalSignature
[2026.01.23 19:42:13.9685] intended purposes: TLS Web Client Authentication, TLS Web Server Authentication
[2026.01.23 19:42:13.9685] Cert details:
[2026.01.23 19:42:13.9690] issued to CN=Microsoft Azure RSA TLS Issuing CA 07, O=Microsoft Corporation, C=US
[2026.01.23 19:42:13.9690] valid from 6/8/2023 12:00:00 AM until 8/25/2026 11:59:59 PM
[2026.01.23 19:42:13.9691] issued from CN=DigiCert Global Root G2, OU=[www.digicert.com](https://www.digicert.com/), O=DigiCert Inc, C=US
[2026.01.23 19:42:13.9691] thumbprint 3382517058A0C20228D598EE7501B61256A76442
[2026.01.23 19:42:14.2904] valid: False
[2026.01.23 19:42:14.2906] this cert is CertificateAuthority
[2026.01.23 19:42:14.2906] key usages: CrlSign, KeyCertSign, DigitalSignature
[2026.01.23 19:42:14.2906] intended purposes: TLS Web Server Authentication, TLS Web Client Authentication
[2026.01.23 19:42:14.2906] Cert details:
[2026.01.23 19:42:14.2907] issued to CN=DigiCert Global Root G2, OU=[www.digicert.com](https://www.digicert.com/), O=DigiCert Inc, C=US
[2026.01.23 19:42:14.2907] valid from 8/1/2013 12:00:00 PM until 1/15/2038 12:00:00 PM
[2026.01.23 19:42:14.2907] issued from CN=DigiCert Global Root G2, OU=[www.digicert.com](https://www.digicert.com/), O=DigiCert Inc, C=US
[2026.01.23 19:42:14.2907] thumbprint DF3C24F9BFD666761B268073FE06D1CC8D4F82A4
[2026.01.23 19:42:14.2916] valid: True
[2026.01.23 19:42:14.2916] this cert is CertificateAuthority
[2026.01.23 19:42:14.2916] key usages: CrlSign, KeyCertSign, DigitalSignature
[2026.01.23 19:42:28.9659] Enabling encryption operation was not completed and cancelled at client side after 30 seconds, it should be done under 5 seconds.
[2026.01.23 19:42:28.9660] SNI timeout detected, PreLogin phase was not complete after 30025 milliseconds.
[2026.01.23 19:42:28.9661] Error
Exception:Enabling encryption operation was not completed and cancelled at client side after 30 seconds, it should be done under 5 seconds.
[2026.01.23 19:42:28.9678] Disconnect initiated.
[2026.01.23 19:42:28.9679] Disconnect done.
```
贡献指南
这个仓库没有索引到贡献指南
调研方向
从 SQL Connectivity Checker PowerShell 脚本开始,跟踪日志中显示的 PreLogin/TLS 证书验证路径。在网络隔离的 Azure Container App 中针对 Azure SQL 重现该故障,然后验证被阻止的 CRL 端点不再导致 30 秒超时,并且握手能在预期的五秒内完成。
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- azure, csharp, powershell, sql
- 领域
- cloud, networking, security
- Issue 类型
- 缺陷
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 活跃度
- 停滞
- 描述清晰度
- 需要澄清
- 新手友好度
- 35/100