ssl - 客户端无法通过 SSL 连接到 Apache Artemis
问题描述
我在服务器上使用 SSL 配置了单个独立的 Artemis。
我生成了 trustStore 和 keyStore
openssl genrsa -des3 -out brokerRoot.key 4096
openssl req -newkey rsa:2048 -nodes -keyout brokerRoot.key -x509 -days 3600 -out brokerRoot.pem -subj "/C=US/ST=Maryland/L=Aberdeen/O=Company/OU=IT/CN=company/emailAddress=test@test.de" -passin pass:passphrase
openssl pkcs12 -inkey brokerRoot.key -in brokerRoot.pem -export -out broker_ks.p12 -password pass:keyStorePassword
//Create a truststore for the client
keytool -import -alias broker -keystore client_ts.p12 -file brokerRoot.pem -deststoretype pkcs12 -storepass trustStorePassword -noprompt
经纪人.xml
<?xml version='1.0'?>
<configuration xmlns="urn:activemq"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xmlns:xi="http://www.w3.org/2001/XInclude"
xsi:schemaLocation="urn:activemq /schema/artemis-configuration.xsd">
<core xmlns="urn:activemq:core" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:schemaLocation="urn:activemq:core ">
<name>0.0.0.0</name>
<persistence-enabled>true</persistence-enabled>
<journal-type>ASYNCIO</journal-type>
<paging-directory>data/paging</paging-directory>
<bindings-directory>data/bindings</bindings-directory>
<journal-directory>data/journal</journal-directory>
<large-messages-directory>data/large-messages</large-messages-directory>
<journal-datasync>true</journal-datasync>
<journal-min-files>2</journal-min-files>
<journal-pool-files>10</journal-pool-files>
<journal-device-block-size>4096</journal-device-block-size>
<journal-file-size>10M</journal-file-size>
<journal-buffer-timeout>28000</journal-buffer-timeout>
<journal-max-io>4096</journal-max-io>
<disk-scan-period>5000</disk-scan-period>
<max-disk-usage>100</max-disk-usage>
<critical-analyzer>true</critical-analyzer>
<critical-analyzer-timeout>120000</critical-analyzer-timeout>
<critical-analyzer-check-period>60000</critical-analyzer-check-period>
<critical-analyzer-policy>HALT</critical-analyzer-policy>
<page-sync-timeout>1628000</page-sync-timeout>
<global-max-size>204Mb</global-max-size>
<!-- Connectors -->
<connectors>
<connector name="netty-connector">tcp://hostname:61616?sslEnabled=true;trustStorePath=/home/artemis/client_ts.p12;trustStorePassword=trustStorePassword</connector>
</connectors>
<acceptors>
<acceptor name="netty-acceptor">tcp://hostname:61616?sslEnabled=true;keyStorePath=/home/artemis/broker_ks.p12;keyStorePassword=keyStorePassword</acceptor>
</acceptors>
<cluster-connections>
<cluster-connection name="my-cluster">
<connector-ref>netty-connector</connector-ref>
<retry-interval>1000</retry-interval>
<retry-interval-multiplier>3</retry-interval-multiplier>
<use-duplicate-detection>true</use-duplicate-detection>
<message-load-balancing>STRICT</message-load-balancing>
</cluster-connection>
</cluster-connections>
<security-settings>
<security-setting match="#">
<permission type="createNonDurableQueue" roles="amq"/>
<permission type="deleteNonDurableQueue" roles="amq"/>
<permission type="createDurableQueue" roles="amq"/>
<permission type="deleteDurableQueue" roles="amq"/>
<permission type="createAddress" roles="amq"/>
<permission type="deleteAddress" roles="amq"/>
<permission type="consume" roles="amq"/>
<permission type="browse" roles="amq"/>
<permission type="send" roles="amq"/>
<!-- we need this otherwise ./artemis data imp wouldn't work -->
<permission type="manage" roles="amq"/>
</security-setting>
</security-settings>
<addresses>
<address name="exampleQueue">
<anycast>
<queue name="exampleQueue"/>
</anycast>
</address>
<address name="DLQ">
<anycast>
<queue name="DLQ" />
</anycast>
</address>
<address name="ExpiryQueue">
<anycast>
<queue name="ExpiryQueue" />
</anycast>
</address>
</addresses>
<address-settings>
<!-- if you define auto-create on certain queues, management has to be auto-create -->
<address-setting match="activemq.management#">
<dead-letter-address>DLQ</dead-letter-address>
<expiry-address>ExpiryQueue</expiry-address>
<redelivery-delay>0</redelivery-delay>
<!-- with -1 only the global-max-size is in use for limiting -->
<max-size-bytes>-1</max-size-bytes>
<message-counter-history-day-limit>10</message-counter-history-day-limit>
<address-full-policy>PAGE</address-full-policy>
<auto-create-queues>true</auto-create-queues>
<auto-create-addresses>true</auto-create-addresses>
<auto-create-jms-queues>true</auto-create-jms-queues>
<auto-create-jms-topics>true</auto-create-jms-topics>
</address-setting>
<!--default for catch all-->
<address-setting match="#">
<dead-letter-address>DLQ</dead-letter-address>
<expiry-address>ExpiryQueue</expiry-address>
<redelivery-delay>0</redelivery-delay>
<!-- with -1 only the global-max-size is in use for limiting -->
<max-size-bytes>-1</max-size-bytes>
<message-counter-history-day-limit>10</message-counter-history-day-limit>
<address-full-policy>PAGE</address-full-policy>
<auto-create-queues>true</auto-create-queues>
<auto-create-addresses>true</auto-create-addresses>
<auto-create-jms-queues>true</auto-create-jms-queues>
<auto-create-jms-topics>true</auto-create-jms-topics>
</address-setting>
<address-setting match="exampleQueue">
<dead-letter-address>DLQ</dead-letter-address>
<redelivery-delay>1000</redelivery-delay>
<max-delivery-attempts>3</max-delivery-attempts>
<max-size-bytes>-1</max-size-bytes>
<page-size-bytes>1048576</page-size-bytes>
<message-counter-history-day-limit>10</message-counter-history-day-limit>
<address-full-policy>PAGE</address-full-policy>
</address-setting>
</address-settings>
</core>
</configuration>
引导程序.xml
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<broker xmlns="http://activemq.org/schema">
<jaas-security domain="activemq"/>
<server configuration="file:/home/artemis-broker/etc//broker.xml"/>
<web bind="https://0.0.0.0:8161" path="web" keyStorePath="/home/artemis_certs/broker_ks.p12" keyStorePassword="keyStorePassword" trustStorePath="/home/artemis_certs/client_ts.p12" trustStorePassword="trustStorePassword">
<app url="activemq-branding" war="activemq-branding.war"/>
<app url="artemis-plugin" war="artemis-plugin.war"/>
<app url="console" war="console.war"/>
</web>
</broker>
我的 Java 客户端试图与 Artemis 建立连接坏了我收到错误 无效的密钥库格式 jms 配置看起来像这样
jms.artemis.broker.url=tcp://hostname:61616?sslEnabled=true&trustStorePath=./certs/client_ts.p12&trustStorePassword=trustStorePassword
jms.artemis.user=admin
jms.artemis.password=admin
有人可以帮我解决这个问题吗?可能是我配置错了吗?
解决方案
我们有一个使用 artemis 运行的 docker 容器。我们使用 Java 版本的 OpenJDK 11.0.12 (A) 生成了密钥库。在我们的 docker 容器中,我们有版本 1.8.0._302 (B)。
从版本 A 生成的密钥库与版本 B 不匹配。在我们发现这一点后,我们在 Dock-Container 中生成了版本 B 的密钥库,一切运行正常。
推荐阅读
- php - 如何在分页后将 ACF 字段挂钩到 Woocommerce 类别页面的“after_shop_loop”部分的底部
- sql - 表“tableName”包含列“columnName”的约束定义,该列不在 Java Derby 表中
- python - Python RegEx:如何单独替换每个匹配项
- json - 如何解析 APEX REST 服务的 JSON 响应
- html - 内容安全策略 .htaccess 框架祖先
- php - PHP循环遍历数组并执行语句
- c# - c#一次从数据库中删除多个数据
- android - 切换到暗模式时是否有数据丢失
- c# - SignalR AccessTokenProvider 适用于 TypeScript 客户端,但不适用于 .NET 客户端
- c# - 使用 ActivatorUtilities 确定在运行时注入哪个实现