You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用pymqi库连接IBM MQ Qmgr双向SSL失败求助

Pymqi双向SSL连接IBM MQ失败问题排查与解决

问题概述

在IBM MQ服务器本地运行Python脚本,已实现单向SSL连接队列管理器,但使用pymqi库建立双向SSL连接时失败,推测未向Qmgr发送客户端证书,需明确配置方法。

当前代码

cd = pymqi.CD()
cd.ChannelName = channel
cd.ConnectionName = conn_info
cd.ChannelType = pymqi.CMQC.MQCHT_CLNTCONN
cd.TransportType = pymqi.CMQC.MQXPT_TCP
cd.SSLCipherSpec = ssl_cipher_spec
sco = pymqi.SCO()
sco.KeyRepository = key_repo_location
qmgr = pymqi.QueueManager(None)
qmgr.connect_with_options(queue_manager, cd, sco)
queue = pymqi.Queue(qmgr, queue_name)

环境信息

  • MQ版本:v9.2
  • Python版本:3.6
  • 操作系统:RHELinux

已执行操作

使用runmqakm工具创建客户端密钥库client.kdb并生成证书,将Qmgr公钥证书导入client.kdb,同时将客户端公钥证书导入Qmgr的key.kdb密钥库。密钥库列表如下:

客户端密钥库client.kdb:

runmqakm -cert -list -db client.kdb -stashed
Certificates found
* default, - personal, ! trusted, # secret key
!   ibmwebspheremqqm1
*-  ibmwebspheremqapp

Qmgr密钥库key.kdb:

runmqakm -cert -list -db key.kdb -stashed
Certificates found
* default, - personal, ! trusted, # secret key
!   "cn=signer-cert"
!   ibmwebspheremqapp
-   ibmwebspheremqqm1

报错信息

Python脚本报错

Traceback (most recent call last):
File "ssl-mq.py", line 32, in 
qmgr.connect_with_options(queue_manager, cd, sco)
File "/root/.local/lib/python3.6/site-packages/pymqi-1.12.10-py3.6-linux-x86_64.egg/pymqi/__init__.py", line 1747, in connect_with_options
raise MQMIError(rv[1], rv[2])
pymqi.MQMIError: MQI Error. Comp: 2, Reason 2393: FAILED: MQRC_SSL_INITIALIZATION_ERROR

MQ端报错

AMQ9633E: Bad SSL certificate for channel 'TEST1'.

The details of the certificate which could not be validated are '[Class=]GSKVALMethod::X509 The certificate validation error was 575010

ACTION: Check which of the possible causes applies on your system. Correct the error, and restart the channel. This error might indicate that the remote end of the channel is configured to send the wrong certificate. Check the certificate label configuration at the remote end of the channel and ensure that the local key repository contains all of the necessary CA certificates.

解决方案

要实现双向SSL连接,需在pymqi配置中明确指定客户端证书相关参数,具体修改如下:

  1. 启用客户端身份验证
    在CD(Channel Definition)对象中添加SSLClientAuth配置,要求客户端提供证书:
cd.SSLClientAuth = pymqi.CMQC.MQSCA_REQUIRED
  1. 指定客户端证书标签
    如果客户端证书的标签不是MQ默认的ibmwebspheremq<小写操作系统用户名>,需要在SCO(SSL Configuration Options)对象中明确指定证书标签:
sco.SSLCertLabel = "ibmwebspheremqapp"
  1. 验证MQ通道配置
    确保队列管理器的通道(TEST1)的SSLCAUTH参数已设置为REQUIRED,强制要求客户端提供证书:
ALTER CHANNEL(TEST1) CHLTYPE(SVRCONN) SSLCAUTH(REQUIRED)

修改后的完整代码示例:

cd = pymqi.CD()
cd.ChannelName = channel
cd.ConnectionName = conn_info
cd.ChannelType = pymqi.CMQC.MQCHT_CLNTCONN
cd.TransportType = pymqi.CMQC.MQXPT_TCP
cd.SSLCipherSpec = ssl_cipher_spec
# 启用客户端身份验证
cd.SSLClientAuth = pymqi.CMQC.MQSCA_REQUIRED

sco = pymqi.SCO()
sco.KeyRepository = key_repo_location
# 指定客户端证书标签
sco.SSLCertLabel = "ibmwebspheremqapp"

qmgr = pymqi.QueueManager(None)
qmgr.connect_with_options(queue_manager, cd, sco)
queue = pymqi.Queue(qmgr, queue_name)

内容的提问来源于stack exchange,提问作者Vishnu

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.02 15:00:54