.Net连接MQ 9.2 SSL遇0x80090327错误的排查与解决
连接IBM MQ 9.2时2393错误的排查与解决
问题场景
- 分别使用.Net Framework对应的
amqmdnet.dll和.Net 6.0对应的amqmdnetstd.dll连接MQ 9.2服务器,均出现相同错误 - 服务器要求TLS 1.2连接,指定密码套件为
TLS_RSA_WITH_AES_256_GCM_SHA384,且需验证客户端证书 - 客户端证书由.kdb文件导出为.p12格式,已导入用户个人证书存储;通过gpedit将目标密码套件设置为Windows SSL密码套件顺序首位
客户端代码(.Net 6 amqmdnetstd.dll)
Hashtable properties = new Hashtable(); properties.Add(MQC.TRANSPORT_PROPERTY, MQC.TRANSPORT_MQSERIES_MANAGED); properties.Add(MQC.HOST_NAME_PROPERTY, SERVER_IP); properties.Add(MQC.PORT_PROPERTY, SERVER_PORT); properties.Add(MQC.CHANNEL_PROPERTY, SERVER_CHANNEL); properties.Add(MQC.SSL_CERT_STORE_PROPERTY, "*USER"); properties.Add(MQC.SSL_CIPHER_SPEC_PROPERTY, "TLS_RSA_WITH_AES_256_GCM_SHA384"); properties.Add(MQC.CERT_LABEL_PROPERTY, "ibmwebspheremqmyuser"); MQQueueManager _mqmgmt = new MQQueueManager(SERVER_QUEUEMNG, properties);
错误日志(返回码2393)
0000018C 08:13:12.004980 436.1 Created an instance of SSLStreams 0000018D 08:13:12.005002 436.1 Setting current certificate store as 'User' 0000018E 08:13:12.005010 436.1 Windows/Mac so use My Store & CurrentStore 0000018F 08:13:12.005043 436.1 Created store object to access certificates 00000190 08:13:12.009208 436.1 Opened store 00000191 08:13:12.009230 436.1 Accessing certificate - ibmwebspheremqmyuser 00000192 08:13:12.009736 436.1 Adding certificate with FriendlyName - ibmwebspheremqmyuser 00000193 08:13:12.009770 436.1 Number of certificates in the store:1 00000194 08:13:12.010241 436.1 TLS12 supported - True 00000195 08:13:12.010262 436.1 TLS13 supported - True 00000196 08:13:12.010456 436.1 Cipherspec protocol version:TLS 1.2 00000197 08:13:12.010745 436.1 Setting SslProtol as Tls12 00000198 08:13:12.010760 436.1 Starting SSL Authentication 00000199 08:13:12.011550 436.1 Server name is set to XXX 0000019A 08:13:12.013051 436.1 ------------{ MQEncryptedSocket.FixClientCertificate(Object,String,X509CertificateCollection,X509Certificate,String[]) 0000019B 08:13:12.013086 436.1 Client callback has been invoked to find client certificate 0000019C 08:13:12.013112 436.1 ------------} MQEncryptedSocket.FixClientCertificate(Object,String,X509CertificateCollection,X509Certificate,String[]) rc=OK 0000019D 08:13:12.043400 436.1 ------------{ MQEncryptedSocket.FixClientCertificate(Object,String,X509CertificateCollection,X509Certificate,String[]) 0000019E 08:13:12.043430 436.1 Client callback has been invoked to find client certificate 0000019F 08:13:12.043436 436.1 Use the first certificate that is from an acceptable issuer. 000001A0 08:13:12.043579 436.1 ------------} MQEncryptedSocket.FixClientCertificate(Object,String,X509CertificateCollection,X509Certificate,String[]) rc=OK 000001A1 08:13:12.090685 436.1 System.Security.Authentication.AuthenticationException: Authentication failed, see inner exception. ---> System.ComponentModel.Win32Exception (0x80090327): An unknown error occurred while processing the certificate. --- End of inner exception stack trace --- at System.Net.Security.SslStream.ForceAuthenticationAsync[TIOAdapter](Boolean receiveFirst, Byte[] reAuthenticationData, CancellationToken cancellationToken) at System.Net.Security.SslStream.AuthenticateAsClient(SslClientAuthenticationOptions sslClientAuthenticationOptions) at IBM.WMQ.Nmqi.MQEncryptedSocket.MakeSecuredConnection() 000001A2 08:13:12.091000 436.1 New MQException CompCode: 2 Reason: 2393
排查与解决
- 尝试使用虚拟证书连接,能建立连接但返回2540错误,推测该虚拟证书关联用户无对应通道权限
- 排查后确认客户端配置与代码均无问题,问题根源为MQ服务端配置错误:客户端证书关联的用户未正确配置
- 修正服务端用户配置后,问题解决
内容的提问来源于stack exchange,提问作者Julien
相关产品推荐
相关产品推荐

