You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Python 3.10中Qpid Proton SSL连接ActiveMQ Artemis问题排查

问题描述

我想要创建一个带SSL的AMQP客户端,以连接ActiveMQ Artemis代理。为此我从Qpid Proton仓库获取示例项目并稍作修改,代码如下:

def on_start(self, event):
        ssl_domain = SSLDomain(SSLDomain.MODE_CLIENT)
        ssl_domain.set_credentials(cert_file=str('./ssl/cert.pem'),
                                   key_file=str('./ssl/key.pem'),
                                   password=str('QWErty123'))
        ssl_domain.set_trusted_ca_db(certificate_db=str('./ssl/ca.pem'))
        ssl_domain.set_peer_authentication(SSLDomain.VERIFY_PEER_NAME)

        self.container = event.container
        self.conn = event.container.connect(self.url, ssl_domain=ssl_domain, allowed_mechs="EXTERNAL")
        self.server = event.container.create_sender(self.url)

cert.pem和ca.pem包含BEGIN/END CERTIFICATE,key.pem包含BEGIN/END PRIVATE KEY,连接URL为:

amqps://localhost:61616/Server.RQ

Windows 10运行错误

Traceback (most recent call last):
  File "C:\Users\Daemon2017\PycharmProjects\python-server\server\client.py", line 43, in <module>
    Container(Send("amqps://localhost:61616/Server.RQ", "Client.RQ")).run()
  File "C:\Program Files\Python310\lib\site-packages\proton\_reactor.py", line 197, in run
    while self.process():
  File "C:\Program Files\Python310\lib\site-packages\proton\_reactor.py", line 260, in process
    event.dispatch(handler)
  File "C:\Program Files\Python310\lib\site-packages\proton\_events.py", line 161, in dispatch
    self.dispatch(h, type)
  File "C:\Program Files\Python310\lib\site-packages\proton\_events.py", line 158, in dispatch
    _dispatch(handler, type.method, self)
  File "C:\Program Files\Python310\lib\site-packages\proton\_events.py", line 129, in _dispatch
    m(*args)
  File "C:\Program Files\Python310\lib\site-packages\proton\_handlers.py", line 753, in on_reactor_init
    self.on_start(event)
  File "C:\Users\Daemon2017\PycharmProjects\python-server\server\client.py", line 16, in on_start
    ssl_domain.set_credentials(cert_file=str('./ssl/cert.pem'),
  File "C:\Program Files\Python310\lib\site-packages\proton\_transport.py", line 755, in set_credentials
    return self._check(pn_ssl_domain_set_credentials(self._domain,
  File "C:\Program Files\Python310\lib\site-packages\proton\_transport.py", line 725, in _check
    raise exc("SSL failure.")
proton._exceptions.Timeout: SSL failure.

Ubuntu运行错误

Traceback (most recent call last):
  File "/home/daemon2017/python-server/server/client.py", line 43, in <module>
    Container(Send("amqps://localhost:61616/Server.RQ", "Client.RQ")).run()
  File "/home/daemon2017/.local/lib/python3.10/site-packages/proton/_reactor.py", line 197, in run
    while self.process():
  File "/home/daemon2017/.local/lib/python3.10/site-packages/proton/_reactor.py", line 260, in process
    event.dispatch(handler)
  File "/home/daemon2017/.local/lib/python3.10/site-packages/proton/_events.py", line 161, in dispatch
    self.dispatch(h, type)
  File "/home/daemon2017/.local/lib/python3.10/site-packages/proton/_events.py", line 158, in dispatch
    _dispatch(handler, type.method, self)
  File "/home/daemon2017/.local/lib/python3.10/site-packages/proton/_events.py", line 129, in _dispatch
    m(*args)
  File "/home/daemon2017/.local/lib/python3.10/site-packages/proton/_handlers.py", line 753, in on_reactor_init
    self.on_start(event)
  File "/home/daemon2017/python-server/server/client.py", line 15, in on_start
    ssl_domain = SSLDomain(SSLDomain.MODE_CLIENT)
  File "/home/daemon2017/.local/lib/python3.10/site-packages/proton/_transport.py", line 720, in __init__
    raise SSLUnavailable()
proton._exceptions.SSLUnavailable

版本信息

  • Python 3.10.0
  • python-qpid-proton 0.38.0

解决方案

Ubuntu下的SSLUnavailable问题

该错误表明你的Qpid Proton安装未启用SSL支持。python-qpid-proton依赖底层Proton C库,默认pip安装的版本可能不含SSL组件,处理步骤如下:

  1. 卸载当前python-qpid-proton:
pip uninstall python-qpid-proton
  1. 安装系统级SSL依赖和Proton开发库:
sudo apt-get install libssl-dev libqpid-proton11-dev
  1. 重新编译安装python-qpid-proton,确保链接SSL库:
pip install python-qpid-proton --no-binary :all:

Windows下的Timeout: SSL failure问题

该错误多与证书配置或SSL握手失败相关,按以下步骤排查:

  1. 修正证书路径:Windows相对路径解析可能异常,改用绝对路径指定证书文件,示例:
ssl_domain.set_credentials(cert_file=str('C:/Users/Daemon2017/PycharmProjects/python-server/ssl/cert.pem'),
                           key_file=str('C:/Users/Daemon2017/PycharmProjects/python-server/ssl/key.pem'),
                           password=str('QWErty123'))
ssl_domain.set_trusted_ca_db(certificate_db=str('C:/Users/Daemon2017/PycharmProjects/python-server/ssl/ca.pem'))
  1. 验证证书有效性:
    • 检查key.pem密码是否正确或未加密:
    openssl rsa -in key.pem -check
    
    • 验证cert.pem是否由ca.pem签发:
    openssl verify -CAfile ca.pem cert.pem
    
  2. 检查ActiveMQ Artemis配置:
    • 确认代理SSL端口(61616)已正确配置,且信任你的ca.pem证书。
    • 若代理不要求客户端证书认证,可移除allowed_mechs="EXTERNAL",并将set_peer_authentication改为SSLDomain.VERIFY_PEER。
  3. 临时关闭防火墙/杀毒软件:Windows防火墙或杀毒软件可能拦截SSL握手连接,关闭后测试是否恢复正常。

内容的提问来源于stack exchange,提问作者Daemon2017

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.25 03:05:40