Extensions
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

IBM MQ Extension

mindscratch
Newcomer

Updating IBM MQ Extension to the latest version - 4.3.4

We are getting this Error Message

Endpoints OK: 0 WARNING: 0 ERROR: 1 Unhealthy endpoints: <Queue Manager> - GENERIC_ERROR DEC:159 Failed to communicate with tenant https://127.0.0.1:9999/e/<Tenant ID>/api/v2/settings/objects. HTTPSConnectionPool(host='127.0.0.1', port=9999): Max retries exceeded with url: /e/<Tenant ID>/api/v2/settings/objects (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: self-signed certificate (_ssl.c:1081)')))

3 REPLIES 3

t_pawlak
DynaMight Leader
DynaMight Leader

Hi,
It looks like the issue is not directly related to the IBM MQ connection itself.

The error occurs when the extension tries to communicate with the Dynatrace Environment API through the local ActiveGate endpoint.

CERTIFICATE_VERIFY_FAILED: self-signed certificate

this looks more like a certificate trust issue between the extension and the local ActiveGate, or potentially a regression introduced with IBM MQ Extension 4.3.4 if the previous version worked with exactly the same configuration.

If the previous IBM MQ Extension version worked on the same ActiveGate without any certificate changes, I would suspect an issue introduced in 4.3.4 and recommend opening a Dynatrace Support case.

 

sia_h
Dynatrace Champion
Dynatrace Champion

You could try and disable Use SSL in the monitoring configuration.

sujit_k_singh
Leader

Hi @mindscratch 

This is a known issue with extensions running on ActiveGate, the extension process tries to call the local ActiveGate API (127.0.0.1:9999) but fails SSL verification because ActiveGate uses a self-signed certificate by default.
Reason
The IBM MQ extension communicates with the local ActiveGate REST API on https://127.0.0.1:9999 to push settings/objects. When ActiveGate is using a self-signed certificate, the Python SSL layer inside the extension rejects it with CERTIFICATE_VERIFY_FAILED. This is typically triggered or exposed after upgrading to 4.3.4 if that version introduced a new API call to /api/v2/settings/objects.

Solution: Replace the ActiveGate self-signed cert with a trusted certificate.

Thanks,

Sujit

Dynatrace Professional Certified

Featured Posts