关于无需凭证访问前缀为queue.的ActiveMQ队列的配置问询
Absolutely, you can configure ActiveMQ to let unauthenticated (anonymous) clients access queues starting with queue.. Here's the step-by-step modification for your activemq.xml:
1. Enable Anonymous Authentication
First, you need to allow unauthenticated connections by adding or updating the AnonymousAuthenticationPlugin in the plugins section of your config. This plugin assigns a default identity to users who connect without credentials.
Find the <plugins> block in activemq.xml and add this plugin if it's not already present:
<plugins> <!-- Keep existing authentication plugins (like JaasAuthenticationPlugin) if you still need them for other destinations --> <anonymousAuthenticationPlugin username="anonymous" group="users" /> <!-- Your existing AuthorizationPlugin configuration goes here --> </plugins>
The username and group values define the identity unauthenticated connections will use—anonymous/users is a common, safe default, but you can adjust these to match your setup.
2. Update the Authorization Entry
Next, modify your existing authorizationEntry to grant the necessary permissions to the anonymous identity for the queue.> destinations.
Option 1: Keep existing test user access + add anonymous access
If you want to retain the original permissions for the test user while allowing anonymous access, update your entry like this:
<authorizationEntry queue="queue.>" read="test,anonymous" write="test,anonymous" admin="test,anonymous" />
Option 2: Allow only anonymous access
If you no longer need the test user restrictions for these queues, simplify it to:
<authorizationEntry queue="queue.>" read="anonymous" write="anonymous" admin="anonymous" />
Option 3: Use the anonymous group instead
If you set group="users" in the anonymous plugin, you can grant permissions to the entire group (useful if you have other users in this group):
<authorizationEntry queue="queue.>" read="users" write="users" admin="users" />
3. Verify No Conflicting Rules
Double-check that there aren't any catch-all authorization entries (like queue=">") that might override your queue.> rule. ActiveMQ applies more specific rules first, so your queue.> entry should take precedence, but it's good to confirm.
Also, ensure the AnonymousAuthenticationPlugin is listed before other authentication plugins in the <plugins> block—this ensures unauthenticated connections are handled correctly.
Final Steps
- Save your modified
activemq.xml - Restart the ActiveMQ broker for changes to take effect
- Test connecting to a
queue.*destination without credentials to confirm it works
内容的提问来源于stack exchange,提问作者Santosh Kumar

