首页 > 解决方案 > 带有 AWS 开发工具包 Node.js 的自定义 S3 服务器的自签名证书错误

问题描述

我正在尝试连接到自定义 S3 服务器(不是基于 AWS)并创建存储桶。

在 Python 中使用以下代码有效:

session = boto3.session.Session()
s3res = session.resource(service_name='s3',
  use_ssl=True,
  verify=False,
  aws_access_key_id='xxx',
  aws_secret_access_key='xxx',
  endpoint_url='https://xxx',
  config=botocore_client_config)

但是,Node.js 中的以下代码不会:

const AWS = require("aws-sdk");
const https = require('https');

const S3 = new AWS.S3({
  accessKeyId: 'xxx',
  secretAccessKey: 'xxx',
  endpoint: 'https://xxx/',
  s3ForcePathStyle: true,
  httpOptions: {
    agent: new https.Agent({ rejectUnauthorized: false })
  }
});

实际上,它在尝试创建存储桶时会导致以下错误:

{ NetworkingError: Protocol "http:" not supported. Expected "https:"
    at new ClientRequest (_http_client.js:109:11)
    at Object.request (http.js:41:10)
    at features.constructor.handleRequest (/home/ec2-user/s3-tests/node_modules/aws-sdk/lib/http/node.js:42:23)

如果我删除自定义 https 代理,我会收到以下错误:

{ Error: self signed certificate
    at TLSSocket.onConnectSecure (_tls_wrap.js:1048:34)

此外,设置process.env.NODE_TLS_REJECT_UNAUTHORIZED = "0";也无济于事。

标签: node.jssslamazon-s3aws-sdkboto3

解决方案


那是因为当您在 中指定agenthttpOptions,您使用了https

const https = require('https');

如果您不想要 ssl 版本,请http改用:

const http = require('http');

const S3 = new AWS.S3({
  accessKeyId: 'xxx',
  secretAccessKey: 'xxx',
  endpoint: 'https://xxx/',
  s3ForcePathStyle: true,
  httpOptions: {
    agent: new http.Agent({ rejectUnauthorized: false })
  }
});

推荐阅读