ASG
IBM
Zystems
Cressida
Icon
Netflexity
 
  MQSeries.net
Search  Search       Tech Exchange      Education      Certifications      Library      Info Center      SupportPacs      LinkedIn  Search  Search                                                                   FAQ  FAQ   Usergroups  Usergroups
 
Register  ::  Log in Log in to check your private messages
 
RSS Feed - WebSphere MQ Support RSS Feed - Message Broker Support

MQSeries.net Forum Index » General IBM MQ Support » MSA User ID Behavior

Post new topic  Reply to topic
 MSA User ID Behavior « View previous topic :: View next topic » 
Author Message
klobubj
PostPosted: Fri May 18, 2007 3:42 am    Post subject: MSA User ID Behavior Reply with quote

Newbie

Joined: 18 May 2007
Posts: 4
Location: Pittsburgh Pa

I'm in the process of setting up intercommunication between our organization and a business partner. In the interest of conntrolling the access to a specific QManager and Queue in our environment, I flipped the Put Authority to Context on our recieve channel and Set the MCA User Id to a internally known account. Subsequently, I've secured the Qmanager and Queue as tightly as resonable using this account.

The channel starts fine...presumably in the context of our known account. However, when our business partner sends a message it goes to dead letter in the context of an account they are using basically because it's not secured to put on the application queue. My expectation was that the context would change to the MCA user...even on the put.

Am I all wet? Do I need to create a mirrored account and secure it? Any other suggestions?

P.S. I am also implementing BlockIP as a security exit.
Back to top
View user's profile Send private message
Michael Dag
PostPosted: Fri May 18, 2007 3:46 am    Post subject: Reply with quote

Jedi Knight

Joined: 13 Jun 2002
Posts: 2607
Location: The Netherlands (Amsterdam)

if you set the channel putaut to ctx (context) like you did, this is exactly what happens,
the userid in the mqmd of the message is used to put to the queue and since it doesn't exist in your environment it is not authorised to do so.

setting the MCAUSER on the channel has no effect in this situation.
_________________
Michael



MQSystems Facebook page
Back to top
View user's profile Send private message Visit poster's website MSN Messenger
klobubj
PostPosted: Wed May 23, 2007 10:28 am    Post subject: Still confused Reply with quote

Newbie

Joined: 18 May 2007
Posts: 4
Location: Pittsburgh Pa

I'm not sure I understand why MCA User ID has nothing to do with it. The Message was ultimately put to the Dead letter queue in the context of my MCA user ID. Nowhere else is that account configured.
Back to top
View user's profile Send private message
fjb_saper
PostPosted: Wed May 23, 2007 12:52 pm    Post subject: Re: Still confused Reply with quote

Grand High Poobah

Joined: 18 Nov 2003
Posts: 20756
Location: LI,NY

klobubj wrote:
I'm not sure I understand why MCA User ID has nothing to do with it. The Message was ultimately put to the Dead letter queue in the context of my MCA user ID. Nowhere else is that account configured.


What Michael is trying to diplomatically tell you is that in order for it to work as you expect you do not want the channel putaut set to ctx.

Working as designed. Moving on...
_________________
MQ & Broker admin
Back to top
View user's profile Send private message Send e-mail
Display posts from previous:   
Post new topic  Reply to topic Page 1 of 1

MQSeries.net Forum Index » General IBM MQ Support » MSA User ID Behavior
Jump to:  



You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Protected by Anti-Spam ACP
 
 


Theme by Dustin Baccetti
Powered by phpBB © 2001, 2002 phpBB Group

Copyright © MQSeries.net. All rights reserved.