apache / apache/pulsar-client-node

不使用证书的情况下调用ssl的url,服务无法连接

オープン
#382 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
主要言語
C++
スター
164
フォーク
98
PR マージ指標
30日以内にマージされた PR はありません

説明

以下是node代码,在java中是可以通过```
PulsarClient client = PulsarClient.builder().serviceUrl(brokerServerUrl).allowTlsInsecureConnection(true)
.authentication(new IoTAuthentication(iotAccessId, iotSecretKey)).build();
Consumer consumer = client.newConsumer(Schema.STRING).topic(String.format("%s/iot/event", iotAccessId))
.subscriptionName(subscriptionName).subscriptionType(SubscriptionType.Failover)
.autoUpdatePartitions(Boolean.FALSE).subscribe();
```
这种方式来跳过ssl证书的,在下面node中我也加入了tlsAllowInsecureConnection: true,
tlsValidateHostname: false,这两个参数但是无法连接到服务

`const Pulsar = require('pulsar-client');
const crypto = require('crypto');
const iotAccessId = "yGmZyJnpqPPIGwzj1564";
const iotSecretKey="b9fab8817fa64f4ab6424d6a7035d2e7";
const brokerSSLServerUrl = "pulsar+ssl://iot-north-mq.heclouds.com:6651/";
const iotSubscriptionName="yGmZyJnpqPPIGwzj1564-sub";

const token = JSON.stringify({
tenant: iotAccessId,
password: sha256(iotAccessId + sha256(iotSecretKey)).substring(4, 20)
});

(async () => {
try {
console.log("token:", token);
// Create a client
let authenticationToken = new Pulsar.AuthenticationToken({
token: token
});

Pulsar.Client.setLogHandler((level, file, line, message) => {
console.log('[%s][%s:%d] %s', Pulsar.LogLevel.toString(level), file, line, message);
});

const client = new Pulsar.Client({
serviceUrl: brokerSSLServerUrl,
authentication: authenticationToken,
tlsAllowInsecureConnection: true,
tlsValidateHostname: false,
});

console.log("client:", client);

// Create a consumer
const consumer = await client.subscribe({
topic: `${iotAccessId}/iot/event`,
// topic: 'persistent://yGmZyJnpqPPIGwzj1564/iot/event-partition-0',
subscription: iotSubscriptionName,
subscriptionType: 'Failover'
});

console.log("consumer:", consumer);

// Receive the message
const msg = await consumer.receive();
console.log(msg.getData().toString());
consumer.acknowledge(msg);

await consumer.close();
await client.close();
} catch (error) {
console.error("An error occurred:", error.message);
console.error(error.stack);
}
})();

function sha256(data) {
return crypto.createHash('sha256').update(data, 'utf8').digest('hex');
}`

最下面是报错信息```
[INFO][Client:86] Subscribing on Topic :yGmZyJnpqPPIGwzj1564/iot/event
[INFO][ClientConnection:187] [ -> pulsar+ssl://iot-north-mq.heclouds.com:6651] Create ClientConnection, timeout=10000
[INFO][ConnectionPool:124] Created connection for pulsar+ssl://iot-north-mq.heclouds.com:6651-pulsar+ssl://iot-north-mq.heclouds.com:6651-0
[INFO][ClientConnection:403] [10.10.80.213:63773 -> 218.201.45.7:6651] Connected to broker
[ERROR][ClientConnection:1318] [10.10.80.213:63773 -> 218.201.45.7:6651] Connection closed with ConnectError (refCnt: 2)
[INFO][ConnectionPool:141] Remove connection for pulsar+ssl://iot-north-mq.heclouds.com:6651-pulsar+ssl://iot-north-mq.heclouds.com:6651-0
[ERROR][ClientImpl:507] Error Checking/Getting Partition Metadata while Subscribing on persistent://yGmZyJnpqPPIGwzj1564/iot/event -- ConnectError
[INFO][ClientConnection:275] [10.10.80.213:63773 -> 218.201.45.7:6651] Destroyed connection to pulsar+ssl://iot-north-mq.heclouds.com:6651-0
An error occurred: Failed to create consumer: ConnectError
Error: Failed to create consumer: ConnectError
```

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

調査の方向性

Node クライアントのコンストラクターと、その tlsAllowInsecureConnection および tlsValidateHostname オプションから始め、次にクライアントのロギングを有効にして、提供されたサブスクリプション例を pulsar+ssl サービス URL に対して再現します。接続の失敗とパーティションメタデータの失敗を Java の動作と比較します。証明書の検証を無効にした状態で、Node クライアントが接続し、ConnectError なしでコンシューマーを作成できれば完了です。

索引モデルが issue の本文から書いたものです。

評価

技術スタック
javascript, node.js
領域
distributed-systems
issue の種類
バグ
難易度
3/5
見積もり時間
1〜2日
活発さ
停滞
明瞭さ
おおむね明確
初心者へのやさしさ
35/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。