You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

.Net连接MQ 9.2 SSL遇0x80090327错误的排查与解决

连接IBM MQ 9.2时2393错误的排查与解决

问题场景

  • 分别使用.Net Framework对应的amqmdnet.dll和.Net 6.0对应的amqmdnetstd.dll连接MQ 9.2服务器,均出现相同错误
  • 服务器要求TLS 1.2连接,指定密码套件为TLS_RSA_WITH_AES_256_GCM_SHA384,且需验证客户端证书
  • 客户端证书由.kdb文件导出为.p12格式,已导入用户个人证书存储;通过gpedit将目标密码套件设置为Windows SSL密码套件顺序首位

客户端代码(.Net 6 amqmdnetstd.dll)

Hashtable properties = new Hashtable();
properties.Add(MQC.TRANSPORT_PROPERTY, MQC.TRANSPORT_MQSERIES_MANAGED);
properties.Add(MQC.HOST_NAME_PROPERTY, SERVER_IP);
properties.Add(MQC.PORT_PROPERTY, SERVER_PORT);
properties.Add(MQC.CHANNEL_PROPERTY, SERVER_CHANNEL);
properties.Add(MQC.SSL_CERT_STORE_PROPERTY, "*USER");
properties.Add(MQC.SSL_CIPHER_SPEC_PROPERTY, "TLS_RSA_WITH_AES_256_GCM_SHA384");
properties.Add(MQC.CERT_LABEL_PROPERTY, "ibmwebspheremqmyuser");

MQQueueManager _mqmgmt = new MQQueueManager(SERVER_QUEUEMNG, properties);

错误日志(返回码2393)

0000018C 08:13:12.004980   436.1       Created an instance of SSLStreams
0000018D 08:13:12.005002   436.1       Setting current certificate store as 'User'
0000018E 08:13:12.005010   436.1       Windows/Mac so use My Store  & CurrentStore
0000018F 08:13:12.005043   436.1       Created store object to access certificates
00000190 08:13:12.009208   436.1       Opened store
00000191 08:13:12.009230   436.1       Accessing certificate - ibmwebspheremqmyuser
00000192 08:13:12.009736   436.1       Adding certificate with FriendlyName - ibmwebspheremqmyuser
00000193 08:13:12.009770   436.1       Number of certificates in the store:1
00000194 08:13:12.010241   436.1       TLS12 supported - True
00000195 08:13:12.010262   436.1       TLS13 supported - True
00000196 08:13:12.010456   436.1       Cipherspec protocol version:TLS 1.2
00000197 08:13:12.010745   436.1       Setting SslProtol as Tls12
00000198 08:13:12.010760   436.1       Starting SSL Authentication
00000199 08:13:12.011550   436.1       Server name is set to XXX
0000019A 08:13:12.013051   436.1      ------------{  MQEncryptedSocket.FixClientCertificate(Object,String,X509CertificateCollection,X509Certificate,String[])
0000019B 08:13:12.013086   436.1       Client callback has been invoked to find client certificate
0000019C 08:13:12.013112   436.1      ------------}  MQEncryptedSocket.FixClientCertificate(Object,String,X509CertificateCollection,X509Certificate,String[]) rc=OK
0000019D 08:13:12.043400   436.1      ------------{  MQEncryptedSocket.FixClientCertificate(Object,String,X509CertificateCollection,X509Certificate,String[])
0000019E 08:13:12.043430   436.1       Client callback has been invoked to find client certificate
0000019F 08:13:12.043436   436.1       Use the first certificate that is from an acceptable issuer.
000001A0 08:13:12.043579   436.1      ------------}  MQEncryptedSocket.FixClientCertificate(Object,String,X509CertificateCollection,X509Certificate,String[]) rc=OK
000001A1 08:13:12.090685   436.1       System.Security.Authentication.AuthenticationException: Authentication failed, see inner exception.
 ---> System.ComponentModel.Win32Exception (0x80090327): An unknown error occurred while processing the certificate.
   --- End of inner exception stack trace ---
   at System.Net.Security.SslStream.ForceAuthenticationAsync[TIOAdapter](Boolean receiveFirst, Byte[] reAuthenticationData, CancellationToken cancellationToken)
   at System.Net.Security.SslStream.AuthenticateAsClient(SslClientAuthenticationOptions sslClientAuthenticationOptions)
   at IBM.WMQ.Nmqi.MQEncryptedSocket.MakeSecuredConnection()
000001A2 08:13:12.091000   436.1       New MQException CompCode: 2 Reason: 2393

排查与解决

  • 尝试使用虚拟证书连接,能建立连接但返回2540错误,推测该虚拟证书关联用户无对应通道权限
  • 排查后确认客户端配置与代码均无问题,问题根源为MQ服务端配置错误:客户端证书关联的用户未正确配置
  • 修正服务端用户配置后,问题解决

内容的提问来源于stack exchange,提问作者Julien

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.04 01:49:52