# rpc error: code = Unavailable desc = 连接错误：传输：认证握手失败：tls: 第一条记录看起来不像 TLS 握手

- **ID:** `go/grpc-permission-denied-tls-mismatch`
- **领域:** go
- **类别:** auth_error
- **验证级别:** ai_generated
- **修复率:** 80%

## 根因

客户端尝试使用 TLS，但服务端提供明文（或反之）。常见于将 grpc.WithInsecure() 与 TLS 服务端混用，或使用凭证拨号明文端口时。

## 版本兼容性

| 版本 | 状态 | 引入 | 弃用 |
|------|------|------|------|
| 1.40+ | active | — | — |

## 解决方案

1. **** (93% 成功率)
   ```
   // TLS server
creds, _ := credentials.NewServerTLSFromFile("server.crt", "server.key")
s := grpc.NewServer(grpc.Creds(creds))
// TLS client
creds, _ := credentials.NewClientTLSFromFile("ca.crt", "")
conn, _ := grpc.Dial(addr, grpc.WithTransportCredentials(creds))
   ```
2. **** (90% 成功率)
   ```
   import "google.golang.org/grpc/credentials/insecure"
conn, _ := grpc.Dial(addr, grpc.WithTransportCredentials(insecure.NewCredentials()))
   ```

## 无效尝试

- **** — Silences TLS but breaks against a TLS-only server; also disables security in production (80% 失败率)
- **** — Does not help when the server isn't speaking TLS at all; and it weakens security (85% 失败率)
