TLS with Rabbitmq Docker-Image: handshake_failure

Viewed 46

I am running rabbitmq:3.10.7-management for AMQPS on a VM and I am using chained TLS-Certificates. When I configure Rabbitmq according to the How-To-TLS website from Rabbitmq I get no errors starting the container but I can't connect via TLS and get an immediate Connection-Error. Depending on which Tool I use or where I use it I get a connection reset by peer. But it seems like the handshake does not work at all. When I enable TCP I can just connect fine with a non-TLS-client.

The Rabbitmq part of the Docker-Compose looks like this:

  rabbitmq:
    restart: unless-stopped
    hostname: rabbitmq
    image: rabbitmq:3.10.7-management
    networks:
      - traefik
    ports:
      - "5672:5672"
      - "5671:5671"
    logging:
      options:
        max-size: "10m"
        max-file: "3"
    volumes: 
      - ./rabbitmq.conf:/etc/rabbitmq/rabbitmq.conf
      - ./certs:/certs
      - /data/rabbitmq_data:/var/lib/rabbitmq
    labels:
      - "traefik.enable=true"
      - "traefik.http.routers.rabbitmq-secure.priority=150"
      - "traefik.http.services.rabbitmq-secure.loadbalancer.server.port=15672"
      - "traefik.http.routers.rabbitmq-secure.rule=Host(`<myDomain>`) && PathPrefix(`/`)"
      - "traefik.http.routers.rabbitmq-secure.entrypoints=web-secure"
      - "traefik.http.routers.rabbitmq-secure.tls=true"
      - "traefik.http.routers.rabbitmq-secure.tls.options=myTLSOptions@file"
      - "traefik.http.routers.rabbitmq.rule=Host(`<myDomain>`) && PathPrefix(`/`)"
      - "traefik.http.routers.rabbitmq.entrypoints=web"

I am using the same certs to serve the management frontend with no problems.

ca_certificate.pem ->

  • CN=T-TeleSec GlobalRoot Class 2, OU=T-Systems Trust Center, O=T-Systems Enterprise Services GmbH, C=DE
  • Chain-Cert 1
  • Chain-Cert 2

server_certificate.pem ->

  • Wild-Card-Cert

server_key.pem ->

  • Key for Wild-Card-Cert

I think I tried almost every other configuration as well, for which part goes where.

RabbitMQ-Conf:

log.console.level = debug

listeners.ssl.default = 5671

listeners.tcp = none

ssl_options.cacertfile = /certs/ca_certificate.pem
ssl_options.certfile   = /certs/server_certificate.pem
ssl_options.keyfile    = /certs/server_key.pem
ssl_options.verify     = verify_none
ssl_options.fail_if_no_peer_cert = false

ssl_options.versions.1 = tlsv1.3
ssl_options.versions.2 = tlsv1.2

ssl_options.honor_cipher_order = false
ssl_options.honor_ecc_order    = false
ssl_handshake_timeout = 10000

ssl_options.ciphers.1 = ECDHE-ECDSA-AES256-GCM-SHA384
ssl_options.ciphers.2 = ECDHE-RSA-AES256-GCM-SHA384
ssl_options.ciphers.3 = ECDHE-ECDSA-AES128-GCM-SHA256
ssl_options.ciphers.4 = ECDHE-RSA-AES128-GCM-SHA256
ssl_options.ciphers.5 = ECDHE-ECDSA-CHACHA20-POLY1305
ssl_options.ciphers.6 = ECDHE-RSA-CHACHA20-POLY1305
ssl_options.ciphers.7 = DHE-RSA-AES128-GCM-SHA256
ssl_options.ciphers.8 = DHE-RSA-AES256-GCM-SHA384

Logs seem to be OK:

...
2022-09-06 14:42:22.024539+00:00 [info] <0.615.0> started TLS (SSL) listener on [::]:5671
...

Going through "Troubleshooting TLS-enabled Connections" I can check all the boxes I can find up until connecting with TLS:

Check Listeners:

rabbitmq@rabbitmq:/$ rabbitmq-diagnostics listeners
Asking node rabbit@rabbitmq to report its protocol listeners ...
Interface: [::], port: 15672, protocol: http, purpose: HTTP API
Interface: [::], port: 15692, protocol: http/prometheus, purpose: Prometheus exporter API over HTTP
Interface: [::], port: 25672, protocol: clustering, purpose: inter-node and CLI tool communication
Interface: [::], port: 5671, protocol: amqp/ssl, purpose: AMQP 0-9-1 and AMQP 1.0 over TLS

Check permissions:

rabbitmq@rabbitmq:/certs$ ls -ll
total 20
-rw-r--r-- 1 rabbitmq rabbitmq 1366 Sep  6 14:39 ca_certificate.pem
-rw-r--r-- 1 rabbitmq rabbitmq 6943 Sep  6 14:39 server_certificate.pem
-rw-r--r-- 1 rabbitmq rabbitmq 3275 Sep  5 13:20 server_key.pem

Check TLS-support in erlang:

rabbitmq@rabbitmq:/certs$ rabbitmq-diagnostics --silent tls_versions
tlsv1.3
tlsv1.2
tlsv1.1
tlsv1

Attempt TLS-Connection with openssl

rabbitmq@rabbitmq:/certs$ openssl s_client -connect localhost:5671
CONNECTED(00000003)
write:errno=104
---
no peer certificate available
---
No client certificate CA names sent
---
SSL handshake has read 0 bytes and written 293 bytes
Verification: OK
---
New, (NONE), Cipher is (NONE)
Secure Renegotiation IS NOT supported
Compression: NONE
Expansion: NONE
No ALPN negotiated
Early data was not sent
Verify return code: 0 (ok)
---

The debug logs don't even show any error when trying to connect. Trying to connect with TLS to TCP throws an error, though. Somehow the listener does not accept connections at all.

Maybe someone experienced something similar already or I am just dumb overlooking the obvious. But for everything else the VM and the certs work just fine (e.g. Mosquitto-MQTTS). Help would be really appreciated.

0 Answers
Related