使用pymqi库连接IBM MQ Qmgr双向SSL失败求助
Pymqi双向SSL连接IBM MQ失败问题排查与解决
问题概述
在IBM MQ服务器本地运行Python脚本,已实现单向SSL连接队列管理器,但使用pymqi库建立双向SSL连接时失败,推测未向Qmgr发送客户端证书,需明确配置方法。
当前代码
cd = pymqi.CD() cd.ChannelName = channel cd.ConnectionName = conn_info cd.ChannelType = pymqi.CMQC.MQCHT_CLNTCONN cd.TransportType = pymqi.CMQC.MQXPT_TCP cd.SSLCipherSpec = ssl_cipher_spec sco = pymqi.SCO() sco.KeyRepository = key_repo_location qmgr = pymqi.QueueManager(None) qmgr.connect_with_options(queue_manager, cd, sco) queue = pymqi.Queue(qmgr, queue_name)
环境信息
- MQ版本:v9.2
- Python版本:3.6
- 操作系统:RHELinux
已执行操作
使用runmqakm工具创建客户端密钥库client.kdb并生成证书,将Qmgr公钥证书导入client.kdb,同时将客户端公钥证书导入Qmgr的key.kdb密钥库。密钥库列表如下:
客户端密钥库client.kdb:
runmqakm -cert -list -db client.kdb -stashed Certificates found * default, - personal, ! trusted, # secret key ! ibmwebspheremqqm1 *- ibmwebspheremqapp
Qmgr密钥库key.kdb:
runmqakm -cert -list -db key.kdb -stashed Certificates found * default, - personal, ! trusted, # secret key ! "cn=signer-cert" ! ibmwebspheremqapp - ibmwebspheremqqm1
报错信息
Python脚本报错
Traceback (most recent call last): File "ssl-mq.py", line 32, in qmgr.connect_with_options(queue_manager, cd, sco) File "/root/.local/lib/python3.6/site-packages/pymqi-1.12.10-py3.6-linux-x86_64.egg/pymqi/__init__.py", line 1747, in connect_with_options raise MQMIError(rv[1], rv[2]) pymqi.MQMIError: MQI Error. Comp: 2, Reason 2393: FAILED: MQRC_SSL_INITIALIZATION_ERROR
MQ端报错
AMQ9633E: Bad SSL certificate for channel 'TEST1'. The details of the certificate which could not be validated are '[Class=]GSKVALMethod::X509 The certificate validation error was 575010 ACTION: Check which of the possible causes applies on your system. Correct the error, and restart the channel. This error might indicate that the remote end of the channel is configured to send the wrong certificate. Check the certificate label configuration at the remote end of the channel and ensure that the local key repository contains all of the necessary CA certificates.
解决方案
要实现双向SSL连接,需在pymqi配置中明确指定客户端证书相关参数,具体修改如下:
- 启用客户端身份验证
在CD(Channel Definition)对象中添加SSLClientAuth配置,要求客户端提供证书:
cd.SSLClientAuth = pymqi.CMQC.MQSCA_REQUIRED
- 指定客户端证书标签
如果客户端证书的标签不是MQ默认的ibmwebspheremq<小写操作系统用户名>,需要在SCO(SSL Configuration Options)对象中明确指定证书标签:
sco.SSLCertLabel = "ibmwebspheremqapp"
- 验证MQ通道配置
确保队列管理器的通道(TEST1)的SSLCAUTH参数已设置为REQUIRED,强制要求客户端提供证书:
ALTER CHANNEL(TEST1) CHLTYPE(SVRCONN) SSLCAUTH(REQUIRED)
修改后的完整代码示例:
cd = pymqi.CD() cd.ChannelName = channel cd.ConnectionName = conn_info cd.ChannelType = pymqi.CMQC.MQCHT_CLNTCONN cd.TransportType = pymqi.CMQC.MQXPT_TCP cd.SSLCipherSpec = ssl_cipher_spec # 启用客户端身份验证 cd.SSLClientAuth = pymqi.CMQC.MQSCA_REQUIRED sco = pymqi.SCO() sco.KeyRepository = key_repo_location # 指定客户端证书标签 sco.SSLCertLabel = "ibmwebspheremqapp" qmgr = pymqi.QueueManager(None) qmgr.connect_with_options(queue_manager, cd, sco) queue = pymqi.Queue(qmgr, queue_name)
内容的提问来源于stack exchange,提问作者Vishnu
相关产品推荐
相关产品推荐

