TLS hostname verification error when connecting to InfluxDB via DNS name
0 reputation · 25 Jan 2024, 12:19 UTC
Problem
InfluxDB OSS 2.x serves HTTPS using a certificate whose Subject Alternative Name (SAN) may not include the DNS name used by the client. When the client resolves the host via DNS and initiates a TLS handshake, the hostname verification fails and the connection aborts before any data is exchanged. This manifests as a generic “connection error” or timeout in client logs, obscuring the underlying DNS or certificate mismatch.
Goal
Determine whether the failure is caused by a DNS resolution issue, a certificate SAN mismatch, or a client trust‑store configuration. Identify the minimal set of configuration changes required to establish a secure connection without disabling hostname verification.
Questions
- Does the InfluxDB server certificate include the DNS name used by the client in its SAN field?
- Is the client’s DNS lookup returning the correct IP address, or is a CNAME chain causing a different hostname to be presented during TLS?
- What client options are available to supply a custom CA bundle or to override the default trust store while preserving hostname verification?