.NET 8用IBMMQDotnetClient通过SSL连IBM MQ遇2059错误求助
IBM MQ .NET客户端SSL连接返回2059错误问题
我正在使用.NET 8和IBMMQDotnetClient 9.3.5.1 NuGet包,尝试连接本地Docker Linux容器中运行的IBM MQ队列(基于公司提供的安全MQ开发镜像),但C#程序无法通过SSL连接队列,持续返回2059错误。
连接队列的方法代码
/// <summary> /// Connects to the IBM MQ queue using the given parameters. /// </summary> /// <param name="connectionType">One of the MQC.TRANSPORT_MQSERIES_values</param> /// <param name="hostName">The host name for the queue</param> /// <param name="channelName">The channel name for the queue</param> /// <param name="queueManagerName">The queue manager name</param> /// <param name="queueName">The queue name</param> /// <param name="queueManager">Output parameter representing connection to MQ Queue Manager.</param> /// <param name="isSsl">Flag indicating where to use SSL connection to queue.</param> /// <returns>An <see cref="MQQueue"/> object representing the queue connection.</returns> private static MQQueue GetConnectionToQueue( string connectionType, string hostName, string channelName, string queueManagerName, string queueName, out MQQueueManager queueManager, bool isSsl) { var connectionProperties = new Hashtable { // Add the connection type { MQC.TRANSPORT_PROPERTY, connectionType } }; // Set up the rest of the connection properties, based on the // connection type requested switch (connectionType) { case MQC.TRANSPORT_MQSERIES_BINDINGS: break; case MQC.TRANSPORT_MQSERIES_CLIENT: case MQC.TRANSPORT_MQSERIES_XACLIENT: case MQC.TRANSPORT_MQSERIES_MANAGED: connectionProperties.Add(MQC.HOST_NAME_PROPERTY, hostName); connectionProperties.Add(MQC.CHANNEL_PROPERTY, channelName); break; } // SSL stuff if (isSsl) { connectionProperties.Add(MQC.SSL_CERT_STORE_PROPERTY, "*USER"); connectionProperties.Add(MQC.SSL_CIPHER_SUITE_PROPERTY, "SSL_RSA_WITH_AES_128_CBC_SHA256"); // I also tried it with this CIPHER, but it doesn't work either //connectionProperties.Add(MQC.SSL_CIPHER_SUITE_PROPERTY, "TLS_RSA_WITH_AES_256_CBC_SHA256"); connectionProperties.Add(MQC.MQCA_CERT_LABEL, "ibmwebspheremquf8472v"); //connectionProperties.Add(MQC.SSL_CIPHER_SPEC_PROPERTY, "TLS_RSA_WITH_AES_128_CBC_SHA256"); } // Create a connection to the queue manager using the connection // properties just defined queueManager = new MQQueueManager(queueManagerName, connectionProperties); // Set up the options on the queue we want to open int openOptions = MQC.MQOO_INPUT_AS_Q_DEF | MQC.MQOO_OUTPUT; // Now specify the queue that we want to open,and the open options var queue = queueManager.AccessQueue(queueName, openOptions); return queue; }
调用该方法时,传入MQC.TRANSPORT_MQSERIES_MANAGED作为connectionType参数。
已做排查操作
- Docker容器的MQ实例通道已配置SSL证书,公司其他程序可正常通过SSL向队列发送消息
- 已将证书导入Windows个人证书库
- 开启日志后仅得到如下底层日志信息,无有效排查线索:
0000024C 16:49:17.457614 14024.1 Constructing IBM.WMQ.MQERD#005DDE0E MQMBID sn=p935-001-240405 su=_o1_M5vNNEe6mUKqTP0CEtw pn=basedotnet/nmqi/MQERD.cs 0000024D 16:49:17.458034 14024.1 -------------{ MQERD.ReadStruct(Byte [ ],int) inputs [System.Byte[]] [28] 0000024E 16:49:17.458172 14024.1 -------------} MQERD.ReadStruct(Byte [ ],int) rc=OK returns [8] 0000024F 16:49:17.459110 14024.1 New MQException CompCode: 2 Reason: 2059
更新排查进展
- 使用IBM MQ客户端自带的SimplePut程序(路径为
C:\Program Files\IBM\MQ\tools\dotnet\samples\cs\base\SimplePut,已通过Visual Studio编译)测试,结果相同:非SSL通道可正常连接,SSL通道仍出现2059错误,说明端口、主机名、队列管理器名称等配置均正确,问题可能出在IBM MQ代码无法找到证书或证书格式不符 - 导入的是p7b格式证书(ibmwebspheremquf8472v.p7b),暂未在IBM文档中找到相关格式支持说明
- 查看Linux容器的AMQERR01.LOG文件,发现服务器端存在证书未找到的问题
内容的提问来源于stack exchange,提问作者dcp
相关产品推荐
相关产品推荐

