You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ActiveMQ Artemis JMX带认证连接报错及空账号可连接问题排查

解答

一、第一个代码连接报错的原因

你的报错栈核心是JMS连接失败(ActiveMQNotConnectedException),和JMX认证逻辑无关,问题出在JMS连接环节:

  1. 两段代码的JMS连接逻辑完全一致(均调用createQueueConnection()无参方法),但第一段报错、第二段正常,大概率是传入的brokerUrl参数不一致——比如第一段传入的是需要认证的JMS连接地址,而第二段用的是无需认证的地址;或者第一段的brokerUrl存在拼写错误(如端口、IP不对)。
  2. 关于账号密码:amq/amq是否有效,取决于broker的用户配置:
    • 检查etc/artemis-users.properties中是否存在amq=amq的配置;
    • 检查etc/artemis-roles.properties中是否存在amq=amq(或其他匹配management.xml中角色的配置)。
      如果这两个配置都存在,账号密码本身没问题,报错和JMX认证无关。

二、空账号密码仍能连接JMX的原因

你的management.xml仅配置了JMX的角色授权规则(限制不同角色能执行的操作),但未开启JMX的认证机制。默认情况下,ActiveMQ Artemis的JMX连接允许匿名访问,因此即使传入空用户名和密码,也能成功建立连接。

要开启JMX认证,需要完成以下配置:

  1. 在etc/login.config中添加JMX登录模块:
artemis-jmx {
    org.apache.activemq.artemis.spi.core.security.jaas.PropertiesLoginModule required
        debug=false
        reload=true
        org.apache.activemq.jaas.properties.user="artemis-users.properties"
        org.apache.activemq.jaas.properties.role="artemis-roles.properties";
};
  1. 在broker启动脚本(如etc/artemis.profile)中添加JVM参数,启用JMX认证:
-Djava.security.auth.login.config=${ARTEMIS_INSTANCE_URI}/etc/login.config
-Dcom.sun.management.jmxremote.authenticate=true
-Dcom.sun.management.jmxremote.login.config=artemis-jmx
  1. 确保artemis-users.properties和artemis-roles.properties中存在对应的用户和角色配置,且角色匹配management.xml中的授权规则。

内容的提问来源于stack exchange,提问作者user21859885

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.22 10:17:02