Java通过SSL连接IBM MQ失败:MQJE001(CC=2,RC=2397)排查求助
IBM MQ SSL连接失败排查指南
客户端错误堆栈
com.ibm.mq.MQException: MQJE001: Completion Code '2', Reason '2397'. at com.ibm.mq.MQManagedConnectionJ11.<init>(MQManagedConnectionJ11.java:251) at com.ibm.mq.MQClientManagedConnectionFactoryJ11._createManagedConnection(MQClientManagedConnectionFactoryJ11.java:449) at com.ibm.mq.MQClientManagedConnectionFactoryJ11.createManagedConnection(MQClientManagedConnectionFactoryJ11.java:486) at com.ibm.mq.StoredManagedConnection.<init>(StoredManagedConnection.java:97) at com.ibm.mq.MQSimpleConnectionManager.allocateConnection(MQSimpleConnectionManager.java:194) at com.ibm.mq.MQQueueManagerFactory.obtainBaseMQQueueManager(MQQueueManagerFactory.java:870) at com.ibm.mq.MQQueueManagerFactory.procure(MQQueueManagerFactory.java:818) at com.ibm.mq.MQQueueManagerFactory.constructQueueManager(MQQueueManagerFactory.java:760) at com.ibm.mq.MQQueueManagerFactory.createQueueManager(MQQueueManagerFactory.java:200) at com.ibm.mq.MQQueueManager.<init>(MQQueueManager.java:893) at MQUtility.main(MQUtility.java:405) Caused by: com.ibm.mq.jmqi.JmqiException: CC=2;RC=2397;AMQ9204: Connection to host 'server.ip.address.number(1919)' rejected. [1=com.ibm.mq.jmqi.JmqiException[CC=2;RC=2397;AMQ9771: SSL handshake failed. [1=javax.net.ssl.SSLHandshakeException[Remote host terminated the handshake],3=MQServer_Name/server.ip.address.number:1919 (MQServer_Name),4=SSLSocket.startHandshake,5=default]],3=server.ip.address.number(1919),4=,5=RemoteTCPConnection.protocolConnect] at com.ibm.mq.jmqi.remote.api.RemoteFAP$Connector.jmqiConnect(RemoteFAP.java:13635) at com.ibm.mq.jmqi.remote.api.RemoteFAP$Connector.access$100(RemoteFAP.java:13175) at com.ibm.mq.jmqi.remote.api.RemoteFAP.jmqiConnect(RemoteFAP.java:1449) at com.ibm.mq.jmqi.remote.api.RemoteFAP.jmqiConnect(RemoteFAP.java:1390) at com.ibm.mq.ese.jmqi.InterceptedJmqiImpl.jmqiConnect(InterceptedJmqiImpl.java:377) at com.ibm.mq.ese.jmqi.ESEJMQI.jmqiConnect(ESEJMQI.java:562) at com.ibm.mq.MQSESSION.MQCONNX_j(MQSESSION.java:916) at com.ibm.mq.MQManagedConnectionJ11.<init>(MQManagedConnectionJ11.java:236) ... 10 more Caused by: com.ibm.mq.jmqi.JmqiException: CC=2;RC=2397;AMQ9771: SSL handshake failed. [1=javax.net.ssl.SSLHandshakeException[Remote host terminated the handshake],3=MQServer_Name/server.ip.address.number:1919 (MQServer_Name),4=SSLSocket.startHandshake,5=default] at com.ibm.mq.jmqi.remote.impl.RemoteTCPConnection.protocolConnect(RemoteTCPConnection.java:1493) at com.ibm.mq.jmqi.remote.impl.RemoteConnection.connect(RemoteConnection.java:1011) at com.ibm.mq.jmqi.remote.impl.RemoteConnectionSpecification.getNewConnection(RemoteConnectionSpecification.java:688) at com.ibm.mq.jmqi.remote.impl.RemoteConnectionSpecification.getSessionFromNewConnection(RemoteConnectionSpecification.java:282) at com.ibm.mq.jmqi.remote.impl.RemoteConnectionSpecification.getSession(RemoteConnectionSpecification.java:181) at com.ibm.mq.jmqi.remote.impl.RemoteConnectionPool.getSession(RemoteConnectionPool.java:127) at com.ibm.mq.jmqi.remote.api.RemoteFAP$Connector.jmqiConnect(RemoteFAP.java:13375) ... 17 more Caused by: javax.net.ssl.SSLHandshakeException: Remote host terminated the handshake at sun.security.ssl.SSLSocketImpl.handleEOF(Unknown Source) at sun.security.ssl.SSLSocketImpl.decode(Unknown Source) at sun.security.ssl.SSLSocketImpl.readHandshakeRecord(Unknown Source) at sun.security.ssl.SSLSocketImpl.startHandshake(Unknown Source) at sun.security.ssl.SSLSocketImpl.startHandshake(Unknown Source) at com.ibm.mq.jmqi.remote.impl.RemoteTCPConnection$6.run(RemoteTCPConnection.java:1460) at com.ibm.mq.jmqi.remote.impl.RemoteTCPConnection$6.run(RemoteTCPConnection.java:1452) at java.security.AccessController.doPrivileged(Native Method) at com.ibm.mq.jmqi.remote.impl.RemoteTCPConnection.protocolConnect(RemoteTCPConnection.java:1452) ... 23 more Caused by: java.io.EOFException: SSL peer shut down incorrectly at sun.security.ssl.SSLSocketInputRecord.read(Unknown Source) at sun.security.ssl.SSLSocketInputRecord.readHeader(Unknown Source) at sun.security.ssl.SSLSocketInputRecord.decode(Unknown Source) at sun.security.ssl.SSLTransport.decode(Unknown Source) ... 31 more
服务端错误日志
日志路径:C:\ProgramData\IBM\MQ\qmgrs\<mq-manager-name>\errors
----- amqrmrsa.c : 938 -------------------------------------------------------- 9/22/2023 16:56:09 - Process(1532.229) User(SYSTEM) Program(amqrmppa.exe) Host(MQSERVER_NAME) Installation(Installation1) VRMF(9.0.3.0) QMgr(MQManager_Name) Time(2023-09-22T21:56:09.933Z) AMQ9620: Internal error on call to SSL function on channel '????' to host 'client_host_name (server.ip.number)'. EXPLANATION: An error indicating a software problem was returned from a function which is used to provide SSL or TLS support. The error code returned was '14'. The function call was 'gsk_secure_soc_init'. The channel is '????'; in some cases its name cannot be determined and so is shown as '????'. The channel did not start. The remote host name is 'client_host_name (server.ip.number)'. ACTION: Collect the items listed in the 'Problem determination' section of the System Administration manual and use either the MQ Support site: http://www.ibm.com/software/integration/wmq/support/, or IBM Support Assistant (ISA): http://www.ibm.com/software/support/isa/, to see whether a solution is already available. If you are unable to find a match, contact your IBM support center. ----- amqccisa.c : 7846 ------------------------------------------------------- 9/22/2023 16:56:09 - Process(1532.229) User(SYSTEM) Program(amqrmppa.exe) Host(MQSERVER_NAME) Installation(Installation1) VRMF(9.0.3.0) QMgr(MQManager_Name) Time(2023-09-22T21:56:09.933Z) AMQ9999: Channel '????' to host 'client_host_name (server.ip.number)' ended abnormally. EXPLANATION: The channel program running under process ID 1532(1188) for channel '????' ended abnormally. The host name is 'client_host_name (server.ip.number)'; in some cases the host name cannot be determined and so is shown as '????'. ACTION: Look at previous error messages for the channel program in the error logs to determine the cause of the failure. Note that this message can be excluded completely or suppressed by tuning the "ExcludeMessage" or "SuppressMessage" attributes under the "QMErrorLog" stanza in qm.ini. Further information can be found in the System Administration Guide. ----- amqrmrsa.c : 938 --------------------------------------------------------
问题排查步骤
一、验证Java客户端密钥文件(怀疑证书过期)
Java客户端通常使用JKS或PKCS12格式的密钥库/信任库,可通过以下命令验证:
查看密钥库中证书有效期
JKS格式:keytool -list -v -keystore <你的密钥库路径> -storepass <密钥库密码>PKCS12格式:
keytool -list -v -keystore <你的密钥库路径> -storetype PKCS12 -storepass <密钥库密码>输出中找到
Valid from和Valid until字段,确认证书是否过期。检查信任库中的服务器证书
若客户端使用独立信任库,执行相同命令检查信任库内的服务器证书:keytool -list -v -keystore <信任库路径> -storepass <信任库密码>导出证书查看详情
先导出证书再查看更直观的信息:# 导出密钥库中的证书 keytool -exportcert -alias <证书别名> -keystore <密钥库路径> -file exported_cert.cer -storepass <密钥库密码> # 查看导出的证书详情 keytool -printcert -file exported_cert.cer
二、IBM MQ服务端配置检查
1. 检查通道SSL配置
- 连接到目标队列管理器:
runmqsc <MQManager_Name> - 查询通道SSL参数(替换
<通道名称>,不确定则执行DISPLAY CHANNEL(*)查看所有通道):
重点关注:DISPLAY CHANNEL(<通道名称>) SSLCIPH SSLCAUTH SSLPEERSSLCIPH:确认加密套件与客户端配置一致(如TLS1.2对应TLS_RSA_WITH_AES_256_CBC_SHA256)SSLCAUTH:REQUIRED表示需验证客户端证书,OPTIONAL则不需要SSLPEER:若配置,确认客户端证书DN是否匹配
2. 检查队列管理器SSL密钥库
在runmqsc中执行:
DISPLAY QMGR SSLKEYR查看
SSLKEYR的值,指向服务端.kdb格式密钥库文件。验证服务端密钥库有效性:
runmqakm -cert -list -db <SSLKEYR路径>.kdb -pw <密钥库密码>确认服务端证书未过期,且包含客户端信任的根证书。
3. 解读服务端错误码
日志中gsk_secure_soc_init错误码14对应GSK_ERROR_BAD_CERTIFICATE,通常原因:
- 服务端无法验证客户端证书(过期、未信任、格式错误)
- 服务端自身证书过期或配置错误
4. 确认通道状态
- 查看通道状态:
DISPLAY CHANNEL(<通道名称>) STATUS - 若通道为
STOPPED,手动启动:START CHANNEL(<通道名称>)
内容的提问来源于stack exchange,提问作者tarekahf
相关产品推荐
相关产品推荐

