ActiveMQ Artemis 2.27.0 HTTP本地管理员控制台登录失败问题
问题描述
ActiveMQ Artemis 2.27.0版本中,通过SSL结合Active Directory账号登录Web控制台可正常访问;但使用HTTP协议搭配本地管理员账号登录时,系统无任何错误提示,仅返回登录页面,不过日志与审计记录显示用户已完成认证。
相关配置信息
bootstrap.xml
<web path="web"> <binding uri="https://host1:sslport" keyStorePath="XXXXX" keyStorePassword="xxxxx"> <app url="activemq-branding" war="activemq-branding.war"/> <app url="artemis-plugin" war="artemis-plugin.war"/> <app url="console" war="console.war"/> </binding> <binding uri="http://host1:port"> <app url="activemq-branding" war="activemq-branding.war"/> <app url="artemis-plugin" war="artemis-plugin.war"/> <app url="console" war="console.war"/> </binding> </web>
login.config
activemq { org.apache.activemq.artemis.spi.core.security.jaas.PropertiesLoginModule sufficient debug=false reload=true org.apache.activemq.jaas.properties.user="artemis-users.properties" org.apache.activemq.jaas.properties.role="artemis-roles.properties"; org.apache.activemq.artemis.spi.core.security.jaas.LDAPLoginModule sufficient -- 剩余内容为敏感信息 -- }
artemis.profile(默认配置外的自定义项)
HAWTIO_ROLE='amq,LDAP_artemis_instance_admin,LDAP_artemis_admin'
日志与审计记录
- 日志信息:
2022-12-20 14:52:53,822 INFO [io.hawt.web.auth.LoginServlet] Logging in user: user1 - 审计记录:
2022-12-20 14:52:53,824 AUDIT AMQ601715: User user1(LDAP_Application_Artemis_Admin)@xx.x.xx.xx:xxxxx successfully authenticated
问题原因
这种现象是Hawtio(Artemis Web控制台基于Hawtio构建)的Cookie安全配置导致的:当控制台同时配置HTTPS和HTTP绑定,Hawtio默认会将会话Cookie标记为Secure(仅在HTTPS连接下传递)。使用HTTP登录时,浏览器不会将带Secure属性的Cookie回传给服务器,导致服务器无法识别已认证的会话,因此返回登录页面,但认证过程本身是成功的(所以日志和审计记录正常)。
解决方法
修改artemis.profile,添加以下配置项,禁用Hawtio Cookie的Secure属性,适配HTTP连接的会话传递:
# 禁用Cookie的Secure属性,允许HTTP连接传递会话Cookie HAWTIO_COOKIE_SECURE=false # 确保Cookie路径匹配控制台上下文 HAWTIO_COOKIE_PATH=/console # 保留HttpOnly属性提升安全性 HAWTIO_COOKIE_HTTPONLY=true
修改完成后重启ActiveMQ Artemis服务,再通过HTTP使用本地管理员账号登录即可正常进入控制台。
内容的提问来源于stack exchange,提问作者user7403308
相关产品推荐
相关产品推荐

