.NET6 XMS客户端连接MQ TLS通道报CWSMQ0006E(2538)问题排查与解决
问题背景
运行一台MQ服务器,使用基于.NET6的XMS组件连接时,非安全通道可正常连接并读取消息,但安全通道连接失败。已通过MMC将有效证书导入Windows证书存储,服务器使用的CipherSpec为TLS_RSA_WITH_AES_256_GCM_SHA384。
初始连接代码
XMSFactoryFactory xff = XMSFactoryFactory.GetInstance(XMSC.CT_WMQ); IBM.XMS.IConnectionFactory cf = xff.CreateConnectionFactory(); cf.SetStringProperty(XMSC.WMQ_HOST_NAME, "hostname"); cf.SetIntProperty(XMSC.WMQ_PORT, 1414); cf.SetStringProperty(XMSC.WMQ_CHANNEL, "channelname"); cf.SetIntProperty(XMSC.WMQ_CONNECTION_MODE, XMSC.WMQ_CM_CLIENT); cf.SetStringProperty(XMSC.WMQ_QUEUE_MANAGER, "manager"); cf.SetIntProperty(XMSC.WMQ_BROKER_VERSION, XMSC.WMQ_BROKER_V1); cf.SetStringProperty(XMSC.WMQ_SSL_CIPHER_SPEC, "TLS_AES_256_GCM_SHA384"); IConnection conn = cf.CreateConnection();
初始报错信息
客户端报错
IBM.XMS.XMSException: 'CWSMQ0006E with reason 2538. Linked exception is MQRC_HOST_NOT_AVAILABLE
MQ服务器日志
The SSL or TLS connection was closed by the remote host '255.255.255.255' during
the secure socket handshake. The channel is '????'; in some cases its name
cannot be determined and so is shown as '????'. The channel did not start.
ACTION:
Check the remote end of the channel for SSL and TLS errors. Fix them and
restart the channel.
虽已指定CipherSpec且证书有效,但尝试多种CipherSpec均无法连接,怀疑是证书未被识别或CipherSpec不匹配。
排查过程
假设问题出在证书环节,且服务器仅支持TLS 1.2/1.3,尝试通过命令创建kdb文件并导入个人证书:
"C:\Program Files (x86)\ibm\gsk8\bin\gsk8capicmd.exe" -cert -add -db test.kdb -type kdb -label ibmwebspheremqusername -trust enable -file personal.cer
验证证书时出现错误:
CTGSK2146W An invalid certificate chain was found. Additional untranslated info: GSKKM_LAST_VALIDATION_ERROR: No certificate chain built
将签名信任证书添加到同一kdb存储后,信任证书验证通过,但个人证书仍报错:
CTGSK2052W An invalid basic constraint extension was found. Additional untranslated info: GSKKM_LAST_VALIDATION_ERROR: GSKVAL_ERR_CA_MISSING_CRITICAL_BASIC_CONSTRAINT (575051)
此时运行代码报错:
{"CWSMQ0006E: An exception was received during the call to the method ConnectionFactory.CreateConnection: CompCode: 2, Reason: 2381. During execution of the specified method an exception was thrown by another component. See the linked exception for more information."}
关联异常为MQRC_KEY_REPOSITORY_ERROR,符合证书验证失败的预期。
最终解决方案
问题根源是Windows证书存储中的证书导入方式错误,正确步骤如下:
- 创建p12证书存储文件
- 导入证书和密钥文件,并指定
ibmwebspheremq+用户名格式的标签 - 将该p12文件导入Windows证书存储
调整后的最终连接代码(核心配置无需修改,仅修正证书导入环节即可):
XMSFactoryFactory xff = XMSFactoryFactory.GetInstance(XMSC.CT_WMQ); IBM.XMS.IConnectionFactory cf = xff.CreateConnectionFactory(); cf.SetStringProperty(XMSC.WMQ_HOST_NAME, "hostname"); cf.SetIntProperty(XMSC.WMQ_PORT, 1414); cf.SetStringProperty(XMSC.WMQ_CHANNEL, "channelname"); cf.SetIntProperty(XMSC.WMQ_CONNECTION_MODE, XMSC.WMQ_CM_CLIENT); cf.SetStringProperty(XMSC.WMQ_QUEUE_MANAGER, "manager"); cf.SetStringProperty(XMSC.WMQ_SSL_CIPHER_SPEC, "TLS_AES_256_GCM_SHA384");
内容的提问来源于stack exchange,提问作者user9671207

