You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

IBM MQ通道AMQ9638/AMQ9716错误排查求助

IBM MQ SSL通道启动失败(AMQ9638/AMQ9716)问题排查方案

问题详情

本地通道频繁抛出AMQ9638 SSL通信错误,通道无法启动:

AMQ9638: SSL communications error for channel 'xxxx'.

EXPLANATION:
An unexpected SSL communications error occurred for a channel, as reported in
the preceding messages. The channel is 'xxxx'; in some cases its
name cannot be determined and so is shown as '????'. The channel did not start.
ACTION:
Investigate the problem reported in the preceding messages. Review the local
and remote console logs for reports of network errors. Correct the errors and
restart the channel.

已完成验证:

  • 发送端与接收端SSL证书均有效
  • 未对SSL密钥库key.kdb做任何修改

远程端日志抛出AMQ9716E证书吊销状态检查失败:

AMQ9716E: Remote SSL certificate revocation status check failed for channel
'????'.

EXPLANATION:
IBM MQ failed to determine the revocation status of the remote SSL certificate
for one of the following reasons:
(a) The channel was unable to contact any of the CRL servers or OCSP responders
  for the certificate.
(b) None of the OCSP responders contacted knows the revocation status of the
  certificate.
(c) An OCSP response was received, but the digital signature of the response
  could not be verified.

The details of the certificate in question are
'xxxxx'.

The channel name is '????'. In some cases the channel name cannot be determined
and so is shown as '????'. The channel did not start.

IBM MQ does not allow the channel to start unless the certificate revocation
status can be determined.
ACTION:
If the certificate contains an AuthorityInfoAccess extension, ensure that the
OCSP server named in the certificate extension is available and is correctly
configured.

If the certificate contains a CrlDistributionPoint extension, ensure that the
CRL server named in the certificate extension is available and is correctly
configured.

If you have specified any CRL or OCSP servers to IBM MQ, check that those
servers are available and are correctly configured.

Ensure that the local key repository has the necessary SSL certificates to
verify the digital signature of the response from the OCSP server.

AMQ9999E: Channel '????' to host 'xxxx' ended abnormally.

当前队列管理器qm.ini的SSL核心配置:

SSL:
   MinimumRSAKeySize=2048$
   OCSPAuthentication=OPTIONAL$
   OCSPCheckExtensions=NO$
   AllowWeakCipherSpec=TLS_RSA_WITH_NULL_SHA256$

已执行refresh security type(SSL)操作,但问题未解决。

完整qm.ini配置:

qm.ini file data

#*******************************************************************#$
#* Module Name: qm.ini                                             *#$
#* Type       : IBM MQ queue manager configuration file            *#$
#  Function   : Define the configuration of a single queue manager *#$
#*                                                                 *#$
#*******************************************************************#$
#* Notes      :                                                    *#$
#* 1) This file defines the configuration of the queue manager     *#$
#*                                                                 *#$
#*******************************************************************#$
ExitPath:$
   ExitsDefaultPath=/var/mqm/exits$
   ExitsDefaultPath64=/var/mqm/exits64$
#*                                                                 *#$
#*                                                                 *#$
Log:$
   LogPrimaryFiles=10$
   LogSecondaryFiles=10$
   LogFilePages=32768$
   LogType=LINEAR$
   LogBufferPages=2048$
   LogPath=/var/mqm/log/<QM Name>/$
   LogWriteIntegrity=TripleWrite$
   LogManagement=Automatic$
Service:$
   Name=AuthorizationService$
   EntryPoints=14$
ServiceComponent:$
   Service=AuthorizationService$
   Name=MQSeries.UNIX.auth.service$
   Module=amqzfu$
   ComponentDataSize=0$
TCP:$
   KeepAlive=Yes$
   ListenerBacklog=400$
   SndBuffSize=0$
   RcvBuffSize=0$
   RcvSndBuffSize=0$
   RcvRcvBuffSize=0$
   ClntSndBuffSize=0$
   ClntRcvBuffSize=0$
   SvrSndBuffSize=0$
   SvrRcvBuffSize=0$
Channels:$
   ChlauthEarlyAdopt=Y$
   MaxChannels=400$
   StopEvent=ALWAYS$
   AdoptNewMCA=ALL$
   AdoptNewMCATimeOut=60$
   AdoptNewMCACheck=ALL$
$
QMErrorLog:$
   ErrorLogSize=4194304$
#   ExcludeMessage=7234$
   SuppressMessage=9001,9002,9202$
   SuppressInterval=30$
$
# PMR (pub/sub) 33868,070,724 zisSPIInquirePubSubStatus rc=MQRC_INSUFFICIENT_BUFFER$
#Connection:$
#   DefaultBindTYPE=ISOLATED$
SSL:$
   MinimumRSAKeySize=2048$
   OCSPAuthentication=OPTIONAL$
   OCSPCheckExtensions=NO$
   AllowWeakCipherSpec=TLS_RSA_WITH_NULL_SHA256$
$
#ApiExitLocal:$
#   Name=MessageTracker$
#   Sequence=100$
#   Function=EntryPoint$
#   Module=mtxapi$
$
# Special Tuning for Queue creation. Needs qmgr restart$
TuningParameters:$
#   DefaultQBufferSize=256000$
   TolerateRepositoryFailure=TRUE$
$

IBM MQ版本信息:

Name:        IBM MQ
Version:     9.3.0.5
Level:       p930-005-230413
BuildType:   IKAP - (Production)
Platform:    IBM MQ for Linux (x86-64 platform)
Mode:        64-bit
O/S:         Linux 4.12.14-122.159-default
O/S Details: SLES 12-SP5
InstName:    Installation2
InstDesc:
Primary:     Yes
InstPath:    /opt/mqm930
DataPath:    /var/mqm
MaxCmdLevel: 930
LicenseType: Production

Name:        IBM MQ
Version:     9.1.0.8
InstName:    Installation1
InstDesc:
InstPath:    /opt/mqm910
Primary:     No

问题分析

AMQ9716E明确指出MQ无法确定证书吊销状态,即使配置了OCSPAuthentication=OPTIONAL仍出现拦截,核心原因包括:

  1. OCSPAuthentication=OPTIONAL的逻辑是仅当成功获取吊销状态时才验证,获取失败则允许启动,但如果MQ获取状态时遇到签名验证失败(如错误原因c),仍会拒绝通道启动
  2. OCSPCheckExtensions=NO仅忽略证书内置的OCSP/CRL扩展,若MQ配置了全局OCSP服务器(当前qm.ini未体现),仍会尝试连接
  3. refresh security type(SSL)仅能刷新密钥库和证书,无法加载qm.ini中OCSP相关的配置变更,此类参数需重启队列管理器生效
  4. 多版本MQ共存环境下,需确认队列管理器关联的是9.3版本的安装路径与配置文件

修复步骤

1. 重启队列管理器使OCSP配置生效

执行以下命令重启队列管理器:

endmqm <QM_NAME>
strmqm <QM_NAME>

2. 临时禁用OCSP验证(紧急恢复)

若需快速恢复通道,修改qm.ini的SSL节:

SSL:
   OCSPAuthentication=DISABLED

修改后必须重启队列管理器,待问题排查完成后再恢复原配置。

3. 排查OCSP响应签名验证问题

若错误原因是(c),需确认本地密钥库是否包含OCSP响应服务器的根/中间证书:

  • 使用runmqckm列出密钥库证书:
    runmqckm -cert -list -db key.kdb -stashed
    
  • 对比证书详情中的OCSP服务器信息,确保对应CA证书已导入密钥库

4. 验证OCSP/CRL服务器连通性

针对错误原因(a),检查远程端是否能访问证书指定的服务器:

  • 使用openssl测试OCSP连通性:
    openssl ocsp -issuer <CA_CERT.pem> -cert <TARGET_CERT.pem> -url <OCSP_URL> -text
    
  • 确认防火墙、代理未阻塞MQ与服务器的通信端口(通常为80/443)

5. 检查通道级SSL配置

部分通道可能单独配置SSL参数覆盖全局设置,执行以下命令检查:

dis chl(<CHANNEL_NAME>) SSLCIPH SSLCAUTH OCSPCLIENTAUTH OCSPAUTHENTICATION

若通道级设置OCSPAUTHENTICATION=REQUIRED,需修改为OPTIONAL或DISABLED,并执行:

refresh chl(<CHANNEL_NAME>)

6. 确认MQ版本关联有效性

检查队列管理器关联的安装路径:

dspmq -n

输出中的InstPath需指向/opt/mqm930,若不符,需重新关联队列管理器到9.3版本。


内容的提问来源于stack exchange,提问作者Karthik B P

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.08 23:35:58