【问题标题】:Java Spring Boot connection to Artemis with SSL enabled启用 SSL 的 Java Spring Boot 连接到 Artemis
【发布时间】:2020-02-03 14:51:10
【问题描述】:

我正在尝试使用 SSL 在客户端和 Artemis 之间建立连接。

我创建了客户端和代理密钥库和信任库。所以经纪人受到 SSL 的保护,并且可以相互通信,但与客户端我遇到了问题

@Bean
public ActiveMQConnectionFactory jmsFactory(@Value("${artemis.client.truststore}") String trustStorePath, @Value("${artemis.client.keystore}") String keyStorePath) {
    ActiveMQConnectionFactory factory = new ActiveMQConnectionFactory(
            "(tcp://192.168.2.101:61616,tcp://192.168.2.102:61616,tcp://192.168.2.103:61616)?ha=true" +
                    "sslEnabled=true&" +
                    "trustStorePath="+ trustStorePath + "&trustStorePassword=artemis&keyStorePath="+ keyStorePath +"&keyStorePassword=artemis");
    factory.setRetryInterval(1000);
    factory.setRetryIntervalMultiplier(1.0);
    factory.setReconnectAttempts(-1);
    factory.setConfirmationWindowSize(10);
    return factory;
}

application.properties

artemis.client.truststore=client_ts.p12
artemis.client.keytstore=client_ks.p12

这是我的 broker.xml:

<?xml version='1.0'?>

<configuration xmlns="urn:activemq"
               xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
               xmlns:xi="http://www.w3.org/2001/XInclude"
               xsi:schemaLocation="urn:activemq /schema/artemis-configuration.xsd">

   <core xmlns="urn:activemq:core" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
         xsi:schemaLocation="urn:activemq:core ">

      <name>0.0.0.0</name>

      <persistence-enabled>true</persistence-enabled>

      <journal-type>ASYNCIO</journal-type>

      <paging-directory>data/paging</paging-directory>

      <bindings-directory>data/bindings</bindings-directory>

      <journal-directory>data/journal</journal-directory>

      <large-messages-directory>data/large-messages</large-messages-directory>

      <journal-datasync>true</journal-datasync>

      <journal-min-files>2</journal-min-files>

      <journal-pool-files>10</journal-pool-files>

      <journal-device-block-size>4096</journal-device-block-size>

      <journal-file-size>10M</journal-file-size>

      <journal-buffer-timeout>28000</journal-buffer-timeout>

      <journal-max-io>4096</journal-max-io>

      <disk-scan-period>5000</disk-scan-period>

      <max-disk-usage>100</max-disk-usage>

      <critical-analyzer>true</critical-analyzer>

      <critical-analyzer-timeout>120000</critical-analyzer-timeout>

      <critical-analyzer-check-period>60000</critical-analyzer-check-period>

      <critical-analyzer-policy>HALT</critical-analyzer-policy>

      <page-sync-timeout>1628000</page-sync-timeout>

      <global-max-size>204Mb</global-max-size>

      <connectors>
         <connector name="netty-connector">tcp://amq1:61616?sslEnabled=true;keyStorePath=client_ks.p12;keyStorePassword=artemis;trustStorePath=client_ts.p12;trustStorePassword=artemis</connector>
      </connectors>
      <acceptors>
         <acceptor name="netty-acceptor">tcp://amq1:61616?sslEnabled=true;keyStorePath=broker_ks.p12;keyStorePassword=artemis;trustStorePath=broker_ts.p12;trustStorePassword=artemis;needClientAuth=true</acceptor>
      </acceptors>

      <cluster-connections>
         <cluster-connection name="my-cluster">
            <address>amq</address>
            <connector-ref>netty-connector</connector-ref>
            <retry-interval>1000</retry-interval>
            <retry-interval-multiplier>3</retry-interval-multiplier>
            <use-duplicate-detection>true</use-duplicate-detection>
            <message-load-balancing>STRICT</message-load-balancing>
            <discovery-group-ref discovery-group-name="my-discovery-group"/>
         </cluster-connection>
      </cluster-connections>

      <broadcast-groups>
         <broadcast-group name="my-broadcast-group">
            <local-bind-address>amq1</local-bind-address>
            <local-bind-port>9876</local-bind-port>
            <group-address>231.7.7.7</group-address>
            <group-port>9876</group-port>
            <broadcast-period>2000</broadcast-period>
            <connector-ref>netty-connector</connector-ref>
         </broadcast-group>
      </broadcast-groups>   

      <discovery-groups>
         <discovery-group name="my-discovery-group">
            <local-bind-address>amq1</local-bind-address>
            <local-bind-port>9876</local-bind-port>
             <group-address>231.7.7.7</group-address>
             <group-port>9876</group-port>
             <refresh-timeout>10000</refresh-timeout>
         </discovery-group>
      </discovery-groups>

      <network-check-list>amq1,amq2,amq3</network-check-list>   
      <network-check-period>5000</network-check-period>
      <network-check-timeout>1000</network-check-timeout>
      <network-check-ping-command>ping -c 1 -t %d %s</network-check-ping-command>
      <network-check-ping6-command>ping6 -c 1 %2$s</network-check-ping6-command>

      <!-- Other config -->
      <ha-policy>
        <replication>
          <master>
            <check-for-live-server>true</check-for-live-server>
          </master>
        </replication>
      </ha-policy>

      <security-settings>
         <security-setting match="#">
            <permission type="createNonDurableQueue" roles="amq"/>
            <permission type="deleteNonDurableQueue" roles="amq"/>
            <permission type="createDurableQueue" roles="amq"/>
            <permission type="deleteDurableQueue" roles="amq"/>
            <permission type="createAddress" roles="amq"/>
            <permission type="deleteAddress" roles="amq"/>
            <permission type="consume" roles="amq"/>
            <permission type="browse" roles="amq"/>
            <permission type="send" roles="amq"/>
            <!-- we need this otherwise ./artemis data imp wouldn't work -->
            <permission type="manage" roles="amq"/>
         </security-setting>
      </security-settings>

      <addresses>
         <address name="exampleQueue">
            <anycast>
               <queue name="exampleQueue"/>
            </anycast>
         </address>
         <address name="DLQ">
            <anycast>
               <queue name="DLQ" />
            </anycast>
         </address>
         <address name="ExpiryQueue">
            <anycast>
               <queue name="ExpiryQueue" />
            </anycast>
         </address>
      </addresses>

      <address-settings>
         <!-- if you define auto-create on certain queues, management has to be auto-create -->
         <address-setting match="activemq.management#">
            <dead-letter-address>DLQ</dead-letter-address>
            <expiry-address>ExpiryQueue</expiry-address>
            <redelivery-delay>0</redelivery-delay>
            <!-- with -1 only the global-max-size is in use for limiting -->
            <max-size-bytes>-1</max-size-bytes>
            <message-counter-history-day-limit>10</message-counter-history-day-limit>
            <address-full-policy>PAGE</address-full-policy>
            <auto-create-queues>true</auto-create-queues>
            <auto-create-addresses>true</auto-create-addresses>
            <auto-create-jms-queues>true</auto-create-jms-queues>
            <auto-create-jms-topics>true</auto-create-jms-topics>
         </address-setting>
         <!--default for catch all-->
         <address-setting match="#">
            <dead-letter-address>DLQ</dead-letter-address>
            <expiry-address>ExpiryQueue</expiry-address>
            <redelivery-delay>0</redelivery-delay>
            <!-- with -1 only the global-max-size is in use for limiting -->
            <max-size-bytes>-1</max-size-bytes>
            <message-counter-history-day-limit>10</message-counter-history-day-limit>
            <address-full-policy>PAGE</address-full-policy>
            <auto-create-queues>true</auto-create-queues>
            <auto-create-addresses>true</auto-create-addresses>
            <auto-create-jms-queues>true</auto-create-jms-queues>
            <auto-create-jms-topics>true</auto-create-jms-topics>
         </address-setting>
         <address-setting match="exampleQueue">            
            <dead-letter-address>DLQ</dead-letter-address>                      
            <redelivery-delay>1000</redelivery-delay>    
            <max-delivery-attempts>3</max-delivery-attempts>
            <max-size-bytes>-1</max-size-bytes>
            <page-size-bytes>1048576</page-size-bytes>
            <message-counter-history-day-limit>10</message-counter-history-day-limit>
            <address-full-policy>PAGE</address-full-policy>
        </address-setting>
      </address-settings>
   </core>
</configuration>

当我启动向 ActiveMQ Artemis 发送消息的 Java 客户端时,没有任何反应,几秒钟后我的代理抛出错误:

2020-02-03 15:50:18,091 ERROR [org.apache.activemq.artemis.core.server] AMQ224088: Timeout (10 seconds) on acceptor "netty-acceptor" during protocol handshake with /192.168.2.105:42942 has occurred.

Java 客户端正在192.168.2.105 上运行。

【问题讨论】:

  • 您真的要使用双向(即 2-way)SSL 吗?这种配置非常少见。
  • 您为什么使用&lt;address&gt;amq&lt;/address&gt; 作为您的cluster-connection?您没有配置任何名为 amq 的地址,这意味着实际上不会对任何地址进行集群。
  • @JustinBertram 你是对的。我可能是从一些例子中得到的,并没有真正理解这部分。可以扔掉没有问题吗?
  • what 可以毫无问题地扔掉吗?您是在询问相互 SSL 还是您的 cluster-connectionaddress
  • 您可以在cluster-connection 中省略address 元素,这将被解释为所有 地址。这是正常的配置。这也包含在documentation 中。

标签: spring-boot spring-jms activemq-artemis


【解决方案1】:

您的连接工厂代码在 URL 中似乎存在语法错误。这是您正在使用的代码:

ActiveMQConnectionFactory factory = new ActiveMQConnectionFactory(
            "(tcp://192.168.2.101:61616,tcp://192.168.2.102:61616,tcp://192.168.2.103:61616)?ha=true" +
                    "sslEnabled=true&" +
                    "trustStorePath="+ trustStorePath + "&trustStorePassword=artemis&keyStorePath="+ keyStorePath +"&keyStorePassword=artemis");

这将产生一个这样的 URL:

(tcp://192.168.2.101:61616,tcp://192.168.2.102:61616,tcp://192.168.2.103:61616)?ha=truesslEnabled=true&trustStorePath=/some/path&trustStorePassword=artemis&keyStorePath=/some/other/path&keyStorePassword=artemis

注意,sslEnabled=true 之前没有 &amp; 分隔符。试试这个:

ActiveMQConnectionFactory factory = new ActiveMQConnectionFactory(
            "(tcp://192.168.2.101:61616,tcp://192.168.2.102:61616,tcp://192.168.2.103:61616)?ha=true&" +
                    "sslEnabled=true&" +
                    "trustStorePath="+ trustStorePath + "&trustStorePassword=artemis&keyStorePath="+ keyStorePath +"&keyStorePassword=artemis");

【讨论】:

  • 该死的。感谢您指出我这一点。制片人现在工作。关于相互 SSL,你能举一些例子吗?
猜你喜欢
  • 1970-01-01
  • 2020-11-01
  • 1970-01-01
  • 2019-06-12
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
相关资源
最近更新 更多