You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ActiveMQ Artemis SSL握手失败:No available authentication scheme求助

解决ActiveMQ Artemis SSL握手失败问题

问题根源

服务器端的JKS密钥库仅导入了服务器证书,缺少对应的私钥。SSL握手时服务器无法提供私钥完成身份验证,导致出现No available authentication scheme错误,客户端因此触发handshake_failure。

修复步骤

1. 将私钥与证书打包为PKCS12格式

使用OpenSSL把生成的私钥activemq.key和服务器证书my-cer.cer合并成PKCS12文件(Java密钥工具可识别的包含私钥的格式):

openssl pkcs12 -export -in my-cer.cer -inkey activemq.key -out server.p12 -name server

执行时会提示设置导出密码,记录该密码,后续步骤需要使用。

2. 导入PKCS12文件到JKS密钥库

将生成的PKCS12文件导入到JKS密钥库(也可以直接将PKCS12作为Artemis的密钥库使用,只需修改acceptor配置中的keyStoreType为PKCS12):

keytool -importkeystore -srckeystore server.p12 -srcstoretype PKCS12 -destkeystore server-keystore.jks -deststoretype JKS

按提示输入:

  • 源密钥库密码(即步骤1设置的PKCS12密码)
  • 目标密钥库密码(需与Artemis acceptor配置中的keyStorePassword一致)
  • 密钥密码(建议与密钥库密码保持一致)

3. 验证密钥库内容

执行以下命令确认密钥库中包含私钥条目:

keytool -list -v -keystore server-keystore.jks -alias server

查看输出,若显示Entry type: PrivateKeyEntry则说明私钥已成功导入;若为trustedCertEntry则表示导入未成功,需重新执行上述步骤。

4. 其他检查项

  • 确认客户端信任库truststore.jks中已正确导入CA根证书CA.cer,确保客户端能信任服务器证书
  • 核对Artemis acceptor配置中的keyStorePassword与JKS密钥库密码完全一致
  • Java 17默认兼容sha256WithRSAEncryption签名算法,无需额外调整加密策略

内容的提问来源于stack exchange,提问作者Subhidh Agarwal

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.24 14:32:33