ASG
IBM
Zystems
Cressida
Icon
Netflexity
 
  MQSeries.net
Search  Search       Tech Exchange      Education      Certifications      Library      Info Center      SupportPacs      LinkedIn  Search  Search                                                                   FAQ  FAQ   Usergroups  Usergroups
 
Register  ::  Log in Log in to check your private messages
 
RSS Feed - WebSphere MQ Support RSS Feed - Message Broker Support

MQSeries.net Forum Index » General Discussion » Why does MQ series require 777 permission for its in unix?

Post new topic  Reply to topic
 Why does MQ series require 777 permission for its in unix? « View previous topic :: View next topic » 
Author Message
rabdul
PostPosted: Thu Dec 02, 2004 4:00 am    Post subject: Why does MQ series require 777 permission for its in unix? Reply with quote

Newbie

Joined: 02 Dec 2004
Posts: 2

Hi,
I would like to know why MQ series has a restiction in unix to have 777 permissions for some of its files? as MQ process runs with a specific ID can't it be made to have only 755 permissions?

Thanks
Abdul.
Back to top
View user's profile Send private message Yahoo Messenger
Nigelg
PostPosted: Thu Dec 02, 2004 5:13 am    Post subject: Reply with quote

Grand Master

Joined: 02 Aug 2004
Posts: 1046

Because WMQ applications can run as any user ID.
Back to top
View user's profile Send private message
dgolding
PostPosted: Thu Dec 02, 2004 6:42 am    Post subject: Reply with quote

Yatiri

Joined: 16 May 2001
Posts: 668
Location: Switzerland

Usually it's only the error log directories that have such open permissions - because ANYBODY may have to write an error report.

Queues and other sensitive files are normally protected "mqm" read-write only (unless you change it, NOT A GOOD IDEA IN ANY CIRCUMSTANCES).

I'm not sure but I think the "partner" process you get when you connect to MQM (the zlaa process), as it is running as MQM, does the writing (after doing some safety checks). If you use MQCONNX to connect (not using a partner process) then you MUST be in the MQM group.

HTH
Back to top
View user's profile Send private message Visit poster's website
rabdul
PostPosted: Thu Dec 02, 2004 10:11 pm    Post subject: Thanks a lot. Reply with quote

Newbie

Joined: 02 Dec 2004
Posts: 2

Thanks
Back to top
View user's profile Send private message Yahoo Messenger
Tibor
PostPosted: Fri Dec 03, 2004 12:59 am    Post subject: Reply with quote

Grand Master

Joined: 20 May 2001
Posts: 1033
Location: Hungary

You find a good description in this link to lift up the security on these directories:

http://publib.boulder.ibm.com/infocenter/wasinfo/topic/com.ibm.websphere.base.doc/info/aes/ae/tmj_secmqm.html

Tibor
Back to top
View user's profile Send private message
Tibor
PostPosted: Fri Dec 03, 2004 1:01 am    Post subject: Reply with quote

Grand Master

Joined: 20 May 2001
Posts: 1033
Location: Hungary

Tibor wrote:
You find a good description in this link to lift up the security on these directories:

http://publib.boulder.ibm.com/infocenter/wasinfo/topic/com.ibm.websphere.base.doc/info/aes/ae/tmj_secmqm.html

and

http://www-1.ibm.com/support/docview.wss?rs=171&context=SSFKSJ&q1=%40ipcc&uid=swg21051945&loc=en_US&cs=utf-8&lang=en+en
http://www-1.ibm.com/support/docview.wss?rs=171&context=SSFKSJ&q1=%2fvar%2fmqm&q2=permission&uid=swg21109491&loc=en_US&cs=utf-8&lang=en

Tibor
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic  Reply to topic Page 1 of 1

MQSeries.net Forum Index » General Discussion » Why does MQ series require 777 permission for its in unix?
Jump to:  



You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Protected by Anti-Spam ACP
 
 


Theme by Dustin Baccetti
Powered by phpBB © 2001, 2002 phpBB Group

Copyright © MQSeries.net. All rights reserved.