Closed ly123-liu closed 2 years ago
This issue has been automatically marked as stale because it has been open 90 days with no activity. Remove stale label or comment or this issue will be closed in 30 days
This issue has been automatically marked as stale because it has been open 90 days with no activity. Remove stale label or comment or this issue will be closed in 30 days
This issue was automatically closed because of stale in 30 days
Describe the bug
we use fluent to consume kafka messages with ssl cert , fluent start with error below:
2022-01-12 15:00:45 +0800 [error]: #0 unexpected error error_class=OpenSSL::SSL::SSLError error="SSL_CTX_use_certificate: ca md too weak" 2022-01-12 15:00:45 +0800 [error]: #0 /usr/local/bundle/gems/ruby-kafka-1.3.0/lib/kafka/ssl_socket_with_timeout.rb:59:in'
2022-01-12 15:00:45 +0800 [error]: #0 unexpected error error_class=OpenSSL::SSL::SSLError error="SSL_CTX_use_certificate: ca md too weak"
2022-01-12 15:00:45 +0800 [error]: #0 suppressed same stacktrace
initialize' 2022-01-12 15:00:45 +0800 [error]: #0 /usr/local/bundle/gems/ruby-kafka-1.3.0/lib/kafka/ssl_socket_with_timeout.rb:59:in
new' 2022-01-12 15:00:45 +0800 [error]: #0 /usr/local/bundle/gems/ruby-kafka-1.3.0/lib/kafka/ssl_socket_with_timeout.rb:59:ininitialize' 2022-01-12 15:00:45 +0800 [error]: #0 /usr/local/bundle/gems/ruby-kafka-1.3.0/lib/kafka/connection.rb:130:in
new' 2022-01-12 15:00:45 +0800 [error]: #0 /usr/local/bundle/gems/ruby-kafka-1.3.0/lib/kafka/connection.rb:130:inopen' 2022-01-12 15:00:45 +0800 [error]: #0 /usr/local/bundle/gems/ruby-kafka-1.3.0/lib/kafka/connection.rb:101:in
block in send_request' 2022-01-12 15:00:45 +0800 [error]: #0 /usr/local/bundle/gems/ruby-kafka-1.3.0/lib/kafka/instrumenter.rb:23:ininstrument' 2022-01-12 15:00:45 +0800 [error]: #0 /usr/local/bundle/gems/ruby-kafka-1.3.0/lib/kafka/connection.rb:100:in
send_request' 2022-01-12 15:00:45 +0800 [error]: #0 /usr/local/bundle/gems/ruby-kafka-1.3.0/lib/kafka/broker.rb:200:insend_request' 2022-01-12 15:00:45 +0800 [error]: #0 /usr/local/bundle/gems/ruby-kafka-1.3.0/lib/kafka/broker.rb:44:in
fetch_metadata' 2022-01-12 15:00:45 +0800 [error]: #0 /usr/local/bundle/gems/ruby-kafka-1.3.0/lib/kafka/cluster.rb:427:inblock in fetch_cluster_info' 2022-01-12 15:00:45 +0800 [error]: #0 /usr/local/bundle/gems/ruby-kafka-1.3.0/lib/kafka/cluster.rb:422:in
each' 2022-01-12 15:00:45 +0800 [error]: #0 /usr/local/bundle/gems/ruby-kafka-1.3.0/lib/kafka/cluster.rb:422:infetch_cluster_info' 2022-01-12 15:00:45 +0800 [error]: #0 /usr/local/bundle/gems/ruby-kafka-1.3.0/lib/kafka/cluster.rb:402:in
cluster_info' 2022-01-12 15:00:45 +0800 [error]: #0 /usr/local/bundle/gems/ruby-kafka-1.3.0/lib/kafka/cluster.rb:102:inrefresh_metadata!' 2022-01-12 15:00:45 +0800 [error]: #0 /usr/local/bundle/gems/ruby-kafka-1.3.0/lib/kafka/cluster.rb:106:in
refresh_metadata_if_necessary!' 2022-01-12 15:00:45 +0800 [error]: #0 /usr/local/bundle/gems/ruby-kafka-1.3.0/lib/kafka/cluster.rb:452:inrandom_broker' 2022-01-12 15:00:45 +0800 [error]: #0 /usr/local/bundle/gems/ruby-kafka-1.3.0/lib/kafka/cluster.rb:382:in
list_topics' 2022-01-12 15:00:45 +0800 [error]: #0 /usr/local/bundle/gems/ruby-kafka-1.3.0/lib/kafka/consumer.rb:634:incluster_topics' 2022-01-12 15:00:45 +0800 [error]: #0 /usr/local/bundle/gems/ruby-kafka-1.3.0/lib/kafka/consumer.rb:614:in
subscribe_to_regex' 2022-01-12 15:00:45 +0800 [error]: #0 /usr/local/bundle/gems/ruby-kafka-1.3.0/lib/kafka/consumer.rb:606:inblock in scan_for_subscribing' 2022-01-12 15:00:45 +0800 [error]: #0 /usr/local/bundle/gems/ruby-kafka-1.3.0/lib/kafka/consumer.rb:601:in
each' 2022-01-12 15:00:45 +0800 [error]: #0 /usr/local/bundle/gems/ruby-kafka-1.3.0/lib/kafka/consumer.rb:601:inscan_for_subscribing' 2022-01-12 15:00:45 +0800 [error]: #0 /usr/local/bundle/gems/ruby-kafka-1.3.0/lib/kafka/consumer.rb:118:in
subscribe' 2022-01-12 15:00:45 +0800 [error]: #0 /usr/local/bundle/gems/fluent-plugin-kafka-0.16.0/lib/fluent/plugin/in_kafka_group.rb:229:inblock in setup_consumer' 2022-01-12 15:00:45 +0800 [error]: #0 /usr/local/bundle/gems/fluent-plugin-kafka-0.16.0/lib/fluent/plugin/in_kafka_group.rb:221:in
each' 2022-01-12 15:00:45 +0800 [error]: #0 /usr/local/bundle/gems/fluent-plugin-kafka-0.16.0/lib/fluent/plugin/in_kafka_group.rb:221:insetup_consumer' 2022-01-12 15:00:45 +0800 [error]: #0 /usr/local/bundle/gems/fluent-plugin-kafka-0.16.0/lib/fluent/plugin/in_kafka_group.rb:202:in
start' 2022-01-12 15:00:45 +0800 [error]: #0 /usr/local/bundle/gems/fluentd-1.9.1/lib/fluent/compat/call_super_mixin.rb:42:instart' 2022-01-12 15:00:45 +0800 [error]: #0 /usr/local/bundle/gems/fluentd-1.9.1/lib/fluent/root_agent.rb:200:in
block in start' 2022-01-12 15:00:45 +0800 [error]: #0 /usr/local/bundle/gems/fluentd-1.9.1/lib/fluent/root_agent.rb:189:inblock (2 levels) in lifecycle' 2022-01-12 15:00:45 +0800 [error]: #0 /usr/local/bundle/gems/fluentd-1.9.1/lib/fluent/root_agent.rb:188:in
each' 2022-01-12 15:00:45 +0800 [error]: #0 /usr/local/bundle/gems/fluentd-1.9.1/lib/fluent/root_agent.rb:188:inblock in lifecycle' 2022-01-12 15:00:45 +0800 [error]: #0 /usr/local/bundle/gems/fluentd-1.9.1/lib/fluent/root_agent.rb:175:in
each' 2022-01-12 15:00:45 +0800 [error]: #0 /usr/local/bundle/gems/fluentd-1.9.1/lib/fluent/root_agent.rb:175:inlifecycle' 2022-01-12 15:00:45 +0800 [error]: #0 /usr/local/bundle/gems/fluentd-1.9.1/lib/fluent/root_agent.rb:199:in
start' 2022-01-12 15:00:45 +0800 [error]: #0 /usr/local/bundle/gems/fluentd-1.9.1/lib/fluent/engine.rb:248:instart' 2022-01-12 15:00:45 +0800 [error]: #0 /usr/local/bundle/gems/fluentd-1.9.1/lib/fluent/engine.rb:147:in
run' 2022-01-12 15:00:45 +0800 [error]: #0 /usr/local/bundle/gems/fluentd-1.9.1/lib/fluent/supervisor.rb:590:inblock in run_worker' 2022-01-12 15:00:45 +0800 [error]: #0 /usr/local/bundle/gems/fluentd-1.9.1/lib/fluent/supervisor.rb:825:in
main_process' 2022-01-12 15:00:45 +0800 [error]: #0 /usr/local/bundle/gems/fluentd-1.9.1/lib/fluent/supervisor.rb:584:inrun_worker' 2022-01-12 15:00:45 +0800 [error]: #0 /usr/local/bundle/gems/fluentd-1.9.1/lib/fluent/command/fluentd.rb:338:in
<top (required)>' 2022-01-12 15:00:45 +0800 [error]: #0 /usr/local/lib/ruby/2.6.0/rubygems/core_ext/kernel_require.rb:54:inrequire' 2022-01-12 15:00:45 +0800 [error]: #0 /usr/local/lib/ruby/2.6.0/rubygems/core_ext/kernel_require.rb:54:in
require' 2022-01-12 15:00:45 +0800 [error]: #0 /usr/local/bundle/gems/fluentd-1.9.1/bin/fluentd:8:in<top (required)>' 2022-01-12 15:00:45 +0800 [error]: #0 /usr/local/bundle/bin/fluentd:23:in
load' 2022-01-12 15:00:45 +0800 [error]: #0 /usr/local/bundle/bin/fluentd:23:in `To Reproduce
since we generate kafka cert without set message digest, default message digest seems sha1WithRSAEncryption , is there fluent-kafka-input plugin can check tls with sha1 and continue to work ?
Expected behavior
1
Your Environment
Your Configuration
Your Error Log
Additional context
No response