|
RSS Feed - WebSphere MQ Support
|
RSS Feed - Message Broker Support
|
 |
|
setmqaut fails with AUTHENMD(PAM) |
« View previous topic :: View next topic » |
Author |
Message
|
LavMQ1980 |
Posted: Wed Dec 25, 2024 6:35 am Post subject: setmqaut fails with AUTHENMD(PAM) |
|
|
Apprentice
Joined: 08 Mar 2022 Posts: 33
|
Hello,
We have a linux server configured with active directory through SSSD and when we try to set permissions with "setmqaut" to AD user, we get:
"AMQ7026E: A principal or group name was invalid."
If AUTHENMD(OS) is set, it works, but then login fails, because MQ does not reach AD for authemtication .... With AUTHENMD(PAM), it doesn't recognize the user.
If we first set AUTHENMD(OS) and issue "setmqaut" it works, and then change to AUTHENMD(PAM), then everything works, but this is not a way to do it.
What are we missing?
Thank you in advance. |
|
Back to top |
|
 |
fjb_saper |
Posted: Thu Dec 26, 2024 10:04 am Post subject: Re: setmqaut fails with AUTHENMD(PAM) |
|
|
 Grand High Poobah
Joined: 18 Nov 2003 Posts: 20756 Location: LI,NY
|
LavMQ1980 wrote: |
Hello,
We have a linux server configured with active directory through SSSD and when we try to set permissions with "setmqaut" to AD user, we get:
"AMQ7026E: A principal or group name was invalid."
If AUTHENMD(OS) is set, it works, but then login fails, because MQ does not reach AD for authemtication .... With AUTHENMD(PAM), it doesn't recognize the user.
If we first set AUTHENMD(OS) and issue "setmqaut" it works, and then change to AUTHENMD(PAM), then everything works, but this is not a way to do it.
What are we missing?
Thank you in advance. |
It really depends on how you set up your authentication in the OS.
Usually using AUTHENMD(PAM) means that at the OS level you are using a plugable authentication module, and as such that if you issue an OS authentication call it will succeed.
Again depending on your OS setup, for AD you'd either use AUTHENMD(PAM) or authtype(IDPWOS | IDPWLDAP)
Hope it helps  _________________ MQ & Broker admin |
|
Back to top |
|
 |
hughson |
Posted: Mon Dec 30, 2024 2:58 am Post subject: |
|
|
 Padawan
Joined: 09 May 2013 Posts: 1959 Location: Bay of Plenty, New Zealand
|
You don't say what AUTHTYPE you are using?
Cheers,
Morag _________________ Morag Hughson @MoragHughson
IBM MQ Technical Education Specialist
Get your IBM MQ training here!
MQGem Software |
|
Back to top |
|
 |
|
|
 |
|
Page 1 of 1 |
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
|
|
|