Author |
Message |
Topic: Authentication Records Displaying on Read Only Group |
myip
Replies: 11 Views: 14872
|
Forum: IBM MQ Security Posted: Thu Mar 01, 2018 2:49 pm Subject: Authentication Records Displaying on Read Only Group |
Look at Table 2 here:
https://www.ibm.com/support/knowledgecenter/SSFKSJ_8.0.0/com.ibm.mq.ref.adm.doc/q083500_.htm
Notice CHLAUTH records don't have their own column.
Guess which column IBM uses ... |
Topic: Authentication Records Displaying on Read Only Group |
myip
Replies: 11 Views: 14872
|
Forum: IBM MQ Security Posted: Wed Feb 21, 2018 7:03 am Subject: Authentication Records Displaying on Read Only Group |
What groups is the user a member of?
only it-read |
Topic: Authentication Records Displaying on Read Only Group |
myip
Replies: 11 Views: 14872
|
Forum: IBM MQ Security Posted: Mon Feb 19, 2018 12:11 pm Subject: Authentication Records Displaying on Read Only Group |
Then you have not taken away access to that queue.
Start again and don't grant access to all queues (**).
I have again, deleted the QMGR and created a new one, then I only granted the read only ... |
Topic: Authentication Records Displaying on Read Only Group |
myip
Replies: 11 Views: 14872
|
Forum: IBM MQ Security Posted: Mon Feb 19, 2018 11:11 am Subject: Authentication Records Displaying on Read Only Group |
Did you refresh security?
yes, I even restarted the QM |
Topic: Authentication Records Displaying on Read Only Group |
myip
Replies: 11 Views: 14872
|
Forum: IBM MQ Security Posted: Mon Feb 19, 2018 8:53 am Subject: Authentication Records Displaying on Read Only Group |
Guess where MQ stores the chlauth mapping info?
SYSTEM.CHLAUTH.DATA.QUEUE
Don't grant read access to this queue if you want to hide it.
However hiding it is not really a substitute for proper ... |
Topic: Authentication Records Displaying on Read Only Group |
myip
Replies: 11 Views: 14872
|
Forum: IBM MQ Security Posted: Mon Feb 19, 2018 7:33 am Subject: Authentication Records Displaying on Read Only Group |
Hi team,
The MQ version is 7.5.0.0.3
I want to setup a Read Only group ('it-read') that can only display QUEUES and TOPICS using MQ Explorer.
These are the script:
SET AUTHREC OBJTYPE(QM ... |