Posted: Mon May 15, 2006 4:47 am Post subject: Bit of a strange one - ISeries WMQ Level of access
Knight
Joined: 14 Jul 2004 Posts: 550
Been reading up on several areas with regards to this for a client
Judging by what I have read levels of access on WMQ on Iseries is all or nothing BUT you can control this from ISeries
Not being an ISeries boffin (I can use it more than normal I suppose) does anyone have any ideas / exposure / examples to this sort of problem.
In other words the clients Admins will have full on access on ISeries but support people will only have read access etc and any changes will be made by admin etc
On iSeries (or System i as IBM is calling it now) there are group profiles, similar to windows groups. Typically (I guess to avoid complexity and work) I have seen any and all MQ users on iSeries to be attached with QMQMADM group profile. Which, like you pointed out, gives them ALL auth. to do as they please.
A slightly different approach could be to have 3-4 (or as many as needed) group profiles created and users assigned to them based on their requirements. As an example you could have a group profile called TELLERS with Connect, INQ to the QM and appropriate GET/Browse/Put to the queues, and so on and on ....
I did assume that WMQ seurity/access was all that you were talking about and not native OS sec. which can also be addressed in a similar fashion.
Does this help?
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum