You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Java通过SSL连接IBM MQ失败:MQJE001(CC=2,RC=2397)排查求助

IBM MQ SSL连接失败排查指南

客户端错误堆栈

com.ibm.mq.MQException: MQJE001: Completion Code '2', Reason '2397'.
        at com.ibm.mq.MQManagedConnectionJ11.<init>(MQManagedConnectionJ11.java:251)
        at com.ibm.mq.MQClientManagedConnectionFactoryJ11._createManagedConnection(MQClientManagedConnectionFactoryJ11.java:449)
        at com.ibm.mq.MQClientManagedConnectionFactoryJ11.createManagedConnection(MQClientManagedConnectionFactoryJ11.java:486)
        at com.ibm.mq.StoredManagedConnection.<init>(StoredManagedConnection.java:97)
        at com.ibm.mq.MQSimpleConnectionManager.allocateConnection(MQSimpleConnectionManager.java:194)
        at com.ibm.mq.MQQueueManagerFactory.obtainBaseMQQueueManager(MQQueueManagerFactory.java:870)
        at com.ibm.mq.MQQueueManagerFactory.procure(MQQueueManagerFactory.java:818)
        at com.ibm.mq.MQQueueManagerFactory.constructQueueManager(MQQueueManagerFactory.java:760)
        at com.ibm.mq.MQQueueManagerFactory.createQueueManager(MQQueueManagerFactory.java:200)
        at com.ibm.mq.MQQueueManager.<init>(MQQueueManager.java:893)
        at MQUtility.main(MQUtility.java:405)
Caused by: com.ibm.mq.jmqi.JmqiException: CC=2;RC=2397;AMQ9204: Connection to host 'server.ip.address.number(1919)' rejected. [1=com.ibm.mq.jmqi.JmqiException[CC=2;RC=2397;AMQ9771: SSL handshake failed. [1=javax.net.ssl.SSLHandshakeException[Remote host terminated the handshake],3=MQServer_Name/server.ip.address.number:1919 (MQServer_Name),4=SSLSocket.startHandshake,5=default]],3=server.ip.address.number(1919),4=,5=RemoteTCPConnection.protocolConnect]
        at com.ibm.mq.jmqi.remote.api.RemoteFAP$Connector.jmqiConnect(RemoteFAP.java:13635)
        at com.ibm.mq.jmqi.remote.api.RemoteFAP$Connector.access$100(RemoteFAP.java:13175)
        at com.ibm.mq.jmqi.remote.api.RemoteFAP.jmqiConnect(RemoteFAP.java:1449)
        at com.ibm.mq.jmqi.remote.api.RemoteFAP.jmqiConnect(RemoteFAP.java:1390)
        at com.ibm.mq.ese.jmqi.InterceptedJmqiImpl.jmqiConnect(InterceptedJmqiImpl.java:377)
        at com.ibm.mq.ese.jmqi.ESEJMQI.jmqiConnect(ESEJMQI.java:562)
        at com.ibm.mq.MQSESSION.MQCONNX_j(MQSESSION.java:916)
        at com.ibm.mq.MQManagedConnectionJ11.<init>(MQManagedConnectionJ11.java:236)
        ... 10 more
Caused by: com.ibm.mq.jmqi.JmqiException: CC=2;RC=2397;AMQ9771: SSL handshake failed. [1=javax.net.ssl.SSLHandshakeException[Remote host terminated the handshake],3=MQServer_Name/server.ip.address.number:1919 (MQServer_Name),4=SSLSocket.startHandshake,5=default]
        at com.ibm.mq.jmqi.remote.impl.RemoteTCPConnection.protocolConnect(RemoteTCPConnection.java:1493)
        at com.ibm.mq.jmqi.remote.impl.RemoteConnection.connect(RemoteConnection.java:1011)
        at com.ibm.mq.jmqi.remote.impl.RemoteConnectionSpecification.getNewConnection(RemoteConnectionSpecification.java:688)
        at com.ibm.mq.jmqi.remote.impl.RemoteConnectionSpecification.getSessionFromNewConnection(RemoteConnectionSpecification.java:282)
        at com.ibm.mq.jmqi.remote.impl.RemoteConnectionSpecification.getSession(RemoteConnectionSpecification.java:181)
        at com.ibm.mq.jmqi.remote.impl.RemoteConnectionPool.getSession(RemoteConnectionPool.java:127)
        at com.ibm.mq.jmqi.remote.api.RemoteFAP$Connector.jmqiConnect(RemoteFAP.java:13375)
        ... 17 more
Caused by: javax.net.ssl.SSLHandshakeException: Remote host terminated the handshake
        at sun.security.ssl.SSLSocketImpl.handleEOF(Unknown Source)
        at sun.security.ssl.SSLSocketImpl.decode(Unknown Source)
        at sun.security.ssl.SSLSocketImpl.readHandshakeRecord(Unknown Source)
        at sun.security.ssl.SSLSocketImpl.startHandshake(Unknown Source)
        at sun.security.ssl.SSLSocketImpl.startHandshake(Unknown Source)
        at com.ibm.mq.jmqi.remote.impl.RemoteTCPConnection$6.run(RemoteTCPConnection.java:1460)
        at com.ibm.mq.jmqi.remote.impl.RemoteTCPConnection$6.run(RemoteTCPConnection.java:1452)
        at java.security.AccessController.doPrivileged(Native Method)
        at com.ibm.mq.jmqi.remote.impl.RemoteTCPConnection.protocolConnect(RemoteTCPConnection.java:1452)
        ... 23 more
Caused by: java.io.EOFException: SSL peer shut down incorrectly
        at sun.security.ssl.SSLSocketInputRecord.read(Unknown Source)
        at sun.security.ssl.SSLSocketInputRecord.readHeader(Unknown Source)
        at sun.security.ssl.SSLSocketInputRecord.decode(Unknown Source)
        at sun.security.ssl.SSLTransport.decode(Unknown Source)
        ... 31 more

服务端错误日志

日志路径:C:\ProgramData\IBM\MQ\qmgrs\<mq-manager-name>\errors

----- amqrmrsa.c : 938 --------------------------------------------------------
9/22/2023 16:56:09 - Process(1532.229) User(SYSTEM) Program(amqrmppa.exe)
                      Host(MQSERVER_NAME) Installation(Installation1)
                      VRMF(9.0.3.0) QMgr(MQManager_Name)
                      Time(2023-09-22T21:56:09.933Z)
                     
AMQ9620: Internal error on call to SSL function on channel '????' to host
'client_host_name (server.ip.number)'.

EXPLANATION:
An error indicating a software problem was returned from a function which is
used to provide SSL or TLS support. The error code returned was '14'. The
function call was 'gsk_secure_soc_init'. 

The channel is '????'; in some cases its name cannot be determined and so is
shown as '????'. The channel did not start. 

The remote host name is 'client_host_name (server.ip.number)'.
ACTION:
Collect the items listed in the 'Problem determination' section of the System
Administration manual and use either the MQ Support site:
http://www.ibm.com/software/integration/wmq/support/, or IBM Support Assistant
(ISA): http://www.ibm.com/software/support/isa/, to see whether a solution is
already available.  If you are unable to find a match, contact your IBM support
center. 
----- amqccisa.c : 7846 -------------------------------------------------------
9/22/2023 16:56:09 - Process(1532.229) User(SYSTEM) Program(amqrmppa.exe)
                      Host(MQSERVER_NAME) Installation(Installation1)
                      VRMF(9.0.3.0) QMgr(MQManager_Name)
                      Time(2023-09-22T21:56:09.933Z)
                     
AMQ9999: Channel '????' to host 'client_host_name (server.ip.number)' ended abnormally.

EXPLANATION:
The channel program running under process ID 1532(1188) for channel '????'
ended abnormally. The host name is 'client_host_name (server.ip.number)'; in some cases
the host name cannot be determined and so is shown as '????'.
ACTION:
Look at previous error messages for the channel program in the error logs to
determine the cause of the failure. Note that this message can be excluded
completely or suppressed by tuning the "ExcludeMessage" or "SuppressMessage"
attributes under the "QMErrorLog" stanza in qm.ini. Further information can be
found in the System Administration Guide. 
----- amqrmrsa.c : 938 --------------------------------------------------------

问题排查步骤

一、验证Java客户端密钥文件(怀疑证书过期)

Java客户端通常使用JKS或PKCS12格式的密钥库/信任库,可通过以下命令验证:

  • 查看密钥库中证书有效期
    JKS格式:

    keytool -list -v -keystore <你的密钥库路径> -storepass <密钥库密码>
    

    PKCS12格式:

    keytool -list -v -keystore <你的密钥库路径> -storetype PKCS12 -storepass <密钥库密码>
    

    输出中找到Valid from和Valid until字段,确认证书是否过期。

  • 检查信任库中的服务器证书
    若客户端使用独立信任库,执行相同命令检查信任库内的服务器证书:

    keytool -list -v -keystore <信任库路径> -storepass <信任库密码>
    
  • 导出证书查看详情
    先导出证书再查看更直观的信息:

    # 导出密钥库中的证书
    keytool -exportcert -alias <证书别名> -keystore <密钥库路径> -file exported_cert.cer -storepass <密钥库密码>
    # 查看导出的证书详情
    keytool -printcert -file exported_cert.cer
    

二、IBM MQ服务端配置检查

1. 检查通道SSL配置

  • 连接到目标队列管理器:
    runmqsc <MQManager_Name>
    
  • 查询通道SSL参数(替换<通道名称>,不确定则执行DISPLAY CHANNEL(*)查看所有通道):
    DISPLAY CHANNEL(<通道名称>) SSLCIPH SSLCAUTH SSLPEER
    
    重点关注:
    • SSLCIPH:确认加密套件与客户端配置一致(如TLS1.2对应TLS_RSA_WITH_AES_256_CBC_SHA256)
    • SSLCAUTH:REQUIRED表示需验证客户端证书,OPTIONAL则不需要
    • SSLPEER:若配置,确认客户端证书DN是否匹配

2. 检查队列管理器SSL密钥库

  • 在runmqsc中执行:

    DISPLAY QMGR SSLKEYR
    

    查看SSLKEYR的值,指向服务端.kdb格式密钥库文件。

  • 验证服务端密钥库有效性:

    runmqakm -cert -list -db <SSLKEYR路径>.kdb -pw <密钥库密码>
    

    确认服务端证书未过期,且包含客户端信任的根证书。

3. 解读服务端错误码

日志中gsk_secure_soc_init错误码14对应GSK_ERROR_BAD_CERTIFICATE,通常原因:

  • 服务端无法验证客户端证书(过期、未信任、格式错误)
  • 服务端自身证书过期或配置错误

4. 确认通道状态

  • 查看通道状态:
    DISPLAY CHANNEL(<通道名称>) STATUS
    
  • 若通道为STOPPED,手动启动:
    START CHANNEL(<通道名称>)
    

内容的提问来源于stack exchange,提问作者tarekahf

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.10 10:25:53