Failed to connect to all addresses - gRPC with Go and NodeJS

Viewed 149

"Failed to connect to all addresses" occurs while adding TLS certs to envoy.yaml, full error:

code: 14,
  metadata: Metadata { _internal_repr: {}, flags: 0 },
  details: 'failed to connect to all addresses'

Envoy config (Envoy is running on port 50000, and itemService on 50052):

transport_socket:
        name: envoy.transport_sockets.tls
        typed_config:
          "@type": type.googleapis.com/envoy.extensions.transport_sockets.tls.v3.DownstreamTlsContext
          common_tls_context:
            tls_certificates:
              - certificate_chain:
                  filename: server.cert
                private_key:
                  filename: server.key

Client code Nodejs - (NextJS on server side - getServerSideProps)

options = {
  key: readFileSync("certs/client.key"),
  cert: readFileSync("certs/ca.crt"),
  csr: readFileSync("certs/client.crt"),
};

const creds = credentials.createSsl(
  options.cert,
  options.key,
  options.csr
);

grpcServer.servicesList.itemsService = new ItemsServiceClient(
  "localhost:50000",
  creds,
  {
    "grpc.ssl_target_name_override": "localhost",
    "grpc.default_authority": "localhost",
  }
);

Request works normally when removing TLS certs from envoy.yaml.

Error I get from grpcurl tool: Failed to dial target host "localhost:50000" x509: certificate relies on legacy Common Name field, use SANs instead. When I set GODEBUG=x509ignoreCN=0, seems like error stays same.

0 Answers
Related