【问题标题】:How to connect from client to IBM WebSphere Queue Manager using SSL Connection如何使用 SSL 连接从客户端连接到 IBM WebSphere Queue Manager
【发布时间】:2015-01-19 11:59:26
【问题描述】:

我已经非常严格地按照所有步骤创建密钥库、客户端证书、服务器
在以下视频的帮助下使用证书:

**"Configuring WMQ Explorer for TLS (Part1, Part2, Part3, Part4) as below".**
Part 1: WMQ Explorer TLS 1 of 4: Create the QMgr's KDB and certificate**
Part 2: WMQ Explorer TLS 2 of 4: Create the user's JKS and certificate
Part 3: WMQ Explorer TLS 3 of 4: Configure WMQ Explorer preferences
Part 4: WMQ Explorer TLS 4 of 4: Connecting 

现在,我正在尝试从 IBM Websphere MQ 客户端 (V7.5.0.3) 连接到 IBM WebSphere MQ
服务器 (V7.5.0.2) 使用 SSL 的服务器队列管理器。

From the IBM WebSphere MQ Explorer (Client Side) : 

a) Provided the Queue Manager Name : jmsdemo
b) Selected the radio-button "Connect directly"
c) Hostname or IP Address :  Server IP
d) Port number : Server Port of the Queue Manager that i am trying to connect.
e) Server-connection channel : Server Connection Channel 
  (This server connection channel has below parameters
  MCA --> MUSR_MQADMIN
  SSL --> SSL Cipher Spec : "TLS_RSA_WITH_AES_128_CBC_SHA256"
  SSL Authentication : Required

f) After finishing all the steps, when i press the "Finish" Button. I am getting the below    
errors.

Please let me know if i missing/doing something wrong in-order to connect to SSL? 

参考文献:

a) UI 中的以下错误(IBM WebSphere MQ Explorer 客户端):

由于 SSL 配置错误,队列管理器 jmsdemo 无法用于客户端连接。
(AMQ4199) 由于 SSL
,队列管理器 jmsdemo 不可用于客户端连接 配置错误。 (AMQ4199) 严重性:30(严重错误) 说明: 用户正在尝试使用安全连接连接到远程队列管理器。 响应:检查目标队列管理器的 SSL 配置和本地 SSL 信任库。

b) 下面的错误信息是提取“AMQERR01”错误文件(来自服务器端)

https://docs.google.com/document/d/19b-N4qc0zXw4HiwZv5pmmeixqeClDDHgWpylalkHhqY/edit#

谢谢 JK

【问题讨论】:

    标签: ssl ibm-mq


    【解决方案1】:

    此错误AMQ9660: SSL key repository: password stash file absent or unusable 可能是由损坏的存储文件引起的。存储文件包含密钥存储库的密码。我建议您尝试以下步骤:

    1) 转到队列管理器的密钥存储库(.kdb 文件)所在的文件夹。

    2) 找到密钥存储库的 stash (.sth) 文件并将其删除。

    3) 然后用当前密码在“IBM Key Management Tool”中打开.kdb文件。

    4) 打开 kdb 文件后,单击“Key Database File -> Stash Password”菜单。这将再次创建存储文件。

    5)(可能需要):然后为runmqsc 中的队列管理器执行REFRESH SECURITY TYPE(SSL)。

    然后尝试连接。

    【讨论】:

    • 感谢Shashi,您的帮助。我按照您的步骤操作,能够通过 IBM MQ Explorer(从客户端)连接到服务器端。
    • 好的。如果你能接受我的回答,我会很高兴:)
    猜你喜欢
    • 2017-04-30
    • 1970-01-01
    • 2011-03-04
    • 2011-02-09
    • 1970-01-01
    • 1970-01-01
    • 2015-01-09
    • 1970-01-01
    • 2017-06-05
    相关资源
    最近更新 更多