go
auth_error
ai_generated
true
rpc error: code = Unavailable desc = connection error: desc = "transport: authentication handshake failed: tls: first record does not look like a TLS handshake"
ID: go/grpc-permission-denied-tls-mismatch
80%Fix Rate
88%Confidence
0Evidence
2024-11-05First Seen
Version Compatibility
| Version | Status | Introduced | Deprecated | Notes |
|---|---|---|---|---|
| 1.40+ | active | — | — | — |
Root Cause
The client is attempting TLS but the server is serving plaintext (or vice versa). Common when mixing grpc.WithInsecure() with a TLS server or dialing a plaintext port with credentials.
generic中文
客户端尝试使用 TLS,但服务端提供明文(或反之)。常见于将 grpc.WithInsecure() 与 TLS 服务端混用,或使用凭证拨号明文端口时。
Workarounds
-
93% success
// TLS server creds, _ := credentials.NewServerTLSFromFile("server.crt", "server.key") s := grpc.NewServer(grpc.Creds(creds)) // TLS client creds, _ := credentials.NewClientTLSFromFile("ca.crt", "") conn, _ := grpc.Dial(addr, grpc.WithTransportCredentials(creds)) -
90% success
import "google.golang.org/grpc/credentials/insecure" conn, _ := grpc.Dial(addr, grpc.WithTransportCredentials(insecure.NewCredentials()))
Dead Ends
Common approaches that don't work:
-
80% fail
Silences TLS but breaks against a TLS-only server; also disables security in production
-
85% fail
Does not help when the server isn't speaking TLS at all; and it weakens security