使用pymqi通过SSL连接远程IBM MQ遇2035授权错误,应添加什么参数?
问题
使用Python的pymqi库通过SSL连接远程IBM MQ队列管理器时,遇到错误:pymqi.MQMIError: MQI Error. Comp: 2, Reason 2035: FAILED: MQRC_NOT_AUTHORIZED
MQ日志给出的解释:
AMQ9777E: Channel was blocked
EXPLANATION:
The inbound channel 'MY.SSL.CHL' was blocked from address 'xx.xx.xx.xx'
because the active values of the channel matched a record configured with
USERSRC(NOACCESS). The active values of the channel were 'CLNTUSER(mysysusrid).'
发现代码中定义的用户未被使用,连接时自动采用了系统用户ID,代码如下:
queue_manager = 'MY.DEV.IN.QM' channel = b'MY.SSL.CHL' host = 'xx.xx.xx.xx' port = '1414' queue_name = 'MY.Q' conn_info = f'{host}({port})' conn_info = conn_info.encode('utf-8') ssl_cipher_spec = b'TLS_RSA_WITH_AES_256_CBC_SHA256' key_repo_location = b'key' certificate_label = b'certificate_label ' user = 'user' password = 'password' message = 'Hello from Python!' cd = pymqi.CD() cd.ChannelName = channel cd.ConnectionName = conn_info cd.ChannelType = pymqi.CMQC.MQCHT_CLNTCONN cd.TransportType = pymqi.CMQC.MQXPT_TCP cd.SSLCipherSpec = ssl_cipher_spec cd.CertificateLabel = certificate_label sco = pymqi.SCO() sco.KeyRepository = key_repo_location sco.CertificateLabel = certificate_label kwargs = { 'user': user, 'password': password, 'cd': cd, 'sco': sco } qmgr = pymqi.QueueManager(None) qmgr.connect_with_options(queue_manager, **kwargs)
请问需要添加什么参数来解决该错误?
解决方案
问题根源是pymqi默认会将本地系统用户ID作为CLNTUSER传递给MQ队列管理器,而你需要强制指定自定义用户ID。只需在CD(通道定义)对象中设置UserIdentifier属性即可。
修改步骤
- 在创建
cd对象后,添加一行代码指定用户ID(注意需转为字节类型,匹配pymqi的属性要求):
cd.UserIdentifier = user.encode('utf-8')
- 确保MQ端通道配置允许该用户访问,对应的通道记录未将该用户设置为
USERSRC(NOACCESS)。
修改后的完整代码片段
cd = pymqi.CD() cd.ChannelName = channel cd.ConnectionName = conn_info cd.ChannelType = pymqi.CMQC.MQCHT_CLNTCONN cd.TransportType = pymqi.CMQC.MQXPT_TCP cd.SSLCipherSpec = ssl_cipher_spec cd.CertificateLabel = certificate_label # 强制指定连接使用的用户ID cd.UserIdentifier = user.encode('utf-8')
修改后,连接时会使用你定义的user作为CLNTUSER,避免使用系统用户ID,从而解决2035授权错误导致的通道被阻止问题。
内容的提问来源于stack exchange,提问作者K Ashish
相关产品推荐
相关产品推荐

