ASG
IBM
Zystems
Cressida
Icon
Netflexity
 
  MQSeries.net
Search  Search       Tech Exchange      Education      Certifications      Library      Info Center      SupportPacs      LinkedIn  Search  Search                                                                   FAQ  FAQ   Usergroups  Usergroups
 
Register  ::  Log in Log in to check your private messages
 
RSS Feed - WebSphere MQ Support RSS Feed - Message Broker Support

MQSeries.net Forum Index » IBM MQ Installation/Configuration Support » Anonymous User authentication for MQ servers...

Post new topic  Reply to topic
 Anonymous User authentication for MQ servers... « View previous topic :: View next topic » 
Author Message
dude1
PostPosted: Mon Jun 09, 2008 9:06 am    Post subject: Anonymous User authentication for MQ servers... Reply with quote

Novice

Joined: 20 Feb 2007
Posts: 10

Hello there.....

I am not a great MQ person... But i need some information...
I searched this forum... but i want to make sure if my understanding is correct... if not hoping one u experts can throw some knowledge on me about this.

We have a IBM MQ server... Windows box, V6.0


we have a different company (client) who wants to connect to our server...and get the message...
They have a UNIX box............... everything went fine... untill the authentication issue poped up..........

They have a system which cannot enter user name n password... so they need to access our MQ server anonymously.........

My Q manager settings...
Q manager is set with just one server connection channel.........
Two local Q........ and the client access us over the Internet
My MCA user is blank in the Server-Connection channel property page..
This means the channel does not have any authetication.........

As far as my knowledge goes... for MQ server... it authenticates with the system logged in username n password... (windows log in info)

but they diff need anonymous authentication..........

I read that if we buy and install Security exit for the MQ server... it gives the capability to allow anonymous authentication..... but is there any way we can do so .. without buying this capitalware product...??


Any help is appreciated...
Back to top
View user's profile Send private message
fjb_saper
PostPosted: Mon Jun 09, 2008 1:49 pm    Post subject: Reply with quote

Grand High Poobah

Joined: 18 Nov 2003
Posts: 20756
Location: LI,NY

Use SSL and set an MCAUser on the channel.
This will restrict what they can do to the MCAUser on the channel. All svrconn channels on that box need to be secured...

You can also choose to use MQIPT. Same deal about SSL and an MCAUser on the channel.

Enjoy
_________________
MQ & Broker admin
Back to top
View user's profile Send private message Send e-mail
RogerLacroix
PostPosted: Wed Jun 11, 2008 8:31 pm    Post subject: Re: Anonymous User authentication for MQ servers... Reply with quote

Jedi Knight

Joined: 15 May 2001
Posts: 3264
Location: London, ON Canada

Hi,
dude1 wrote:
As far as my knowledge goes... for MQ server... it authenticates with the system logged in username n password... (windows log in info)

This is not correct. The default setup of MQ does NOT authenticate a connection.

dude1 wrote:
I read that if we buy and install Security exit for the MQ server... it gives the capability to allow anonymous authentication..... but is there any way we can do so .. without buying this capitalware product...??

You could buy Primeur's product or IBM ESE product or use SSL.

Regards,
Roger Lacroix
Capitalware Inc.
_________________
Capitalware: Transforming tomorrow into today.
Connected to MQ!
Twitter
Back to top
View user's profile Send private message Visit poster's website
vinbud117
PostPosted: Thu Jun 12, 2008 4:36 am    Post subject: Reply with quote

Acolyte

Joined: 22 Jul 2005
Posts: 61

Until you set up the MQIPT or SSL, I would suggest you set the MCAUSER and use setmqaut to provide necessary access to the MCAUSER id.
Back to top
View user's profile Send private message
RogerLacroix
PostPosted: Thu Jun 12, 2008 9:07 am    Post subject: Reply with quote

Jedi Knight

Joined: 15 May 2001
Posts: 3264
Location: London, ON Canada

Hi,
vinbud117 wrote:
set the MCAUSER and use setmqaut to provide necessary access to the MCAUSER id.

People suggest this all the time but it is NOT security.

I.e. Default MQ security is like having all the doors and windows in your house wide open. Now you decide to close all the windows / doors that face North.

Anyone, anytime, can access those queues and do whatever they want and nobody will know.

Regards,
Roger Lacroix
Capitalware Inc.
_________________
Capitalware: Transforming tomorrow into today.
Connected to MQ!
Twitter
Back to top
View user's profile Send private message Visit poster's website
HubertKleinmanns
PostPosted: Thu Jun 12, 2008 11:19 pm    Post subject: Reply with quote

Shaman

Joined: 24 Feb 2004
Posts: 732
Location: Germany

RogerLacroix wrote:
Hi,
vinbud117 wrote:
set the MCAUSER and use setmqaut to provide necessary access to the MCAUSER id.

People suggest this all the time but it is NOT security.

I.e. Default MQ security is like having all the doors and windows in your house wide open. Now you decide to close all the windows / doors that face North.

Anyone, anytime, can access those queues and do whatever they want and nobody will know.

Regards,
Roger Lacroix
Capitalware Inc.


Roger,

very nice explanation .

Dude1,

securing a door without buying a lock is very difficult .
_________________
Regards
Hubert
Back to top
View user's profile Send private message Visit poster's website
frodon
PostPosted: Fri Jun 20, 2008 1:06 pm    Post subject: Reply with quote

Newbie

Joined: 06 Jun 2008
Posts: 4
Location: Luxemburg

setting MCAUSER to a dedicated user and giving appropriate authorities via setmqaut to restrict access to lonely queues needed is the right approch ! ... but only if you are using
1) SSL wich permit to certify and authenticate the connecting partner
2) Using SSLPEER to restrict the use of only one certificate being able to be used to access this channel.

Then you garanteed that the user/application using the channel is the authorised one and no other one can access the same channel.

Regards.
Back to top
View user's profile Send private message
PeterPotkay
PostPosted: Fri Jun 20, 2008 1:15 pm    Post subject: Reply with quote

Poobah

Joined: 15 May 2001
Posts: 7722

frodon wrote:
setting MCAUSER to a dedicated user and giving appropriate authorities via setmqaut to restrict access to lonely queues needed is the right approch ! ... but only if you are using
1) SSL wich permit to certify and authenticate the connecting partner
2) Using SSLPEER to restrict the use of only one certificate being able to be used to access this channel.


3) or you use a Security Exit instead of SSL.
_________________
Peter Potkay
Keep Calm and MQ On
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic  Reply to topic Page 1 of 1

MQSeries.net Forum Index » IBM MQ Installation/Configuration Support » Anonymous User authentication for MQ servers...
Jump to:  



You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Protected by Anti-Spam ACP
 
 


Theme by Dustin Baccetti
Powered by phpBB © 2001, 2002 phpBB Group

Copyright © MQSeries.net. All rights reserved.