ASG
IBM
Zystems
Cressida
Icon
Netflexity
 
  MQSeries.net
Search  Search       Tech Exchange      Education      Certifications      Library      Info Center      SupportPacs      LinkedIn  Search  Search                                                                   FAQ  FAQ   Usergroups  Usergroups
 
Register  ::  Log in Log in to check your private messages
 
RSS Feed - WebSphere MQ Support RSS Feed - Message Broker Support

MQSeries.net Forum Index » IBM MQ Installation/Configuration Support » Enqueuing across domains

Post new topic  Reply to topic
 Enqueuing across domains « View previous topic :: View next topic » 
Author Message
klamerus
PostPosted: Tue Nov 13, 2007 9:02 am    Post subject: Enqueuing across domains Reply with quote

Disciple

Joined: 05 Jul 2004
Posts: 199
Location: Detroit, MI

We have the following security related question.

Our environment is WebSphere MQ 5.x on Windows 2003. We'll get to WebSphere v6 eventually.

In the meantime, we want to send messages from one Windows domain (the client application) to a queue hosted on a server in another domain.

There is no trust between these domains.

So far as we know, there is no way to do this. It is not possible to pass domain/username/password data as parameters in a connection to the server from the sending application.

In the Windows world, the account that is running the sending application must be given permission to the queue on the server and since the server is in a different domain, we're out of luck.

Can anyone confirm or provide information on how to do this? We have the ability to change the code to provide a domain/username/password if that's something we've just overlooked, but we asked this question before and the answer we got was that this wasn't available.

Thanks,
_________________
Careful with that VAX Eugene
Back to top
View user's profile Send private message Send e-mail AIM Address Yahoo Messenger MSN Messenger
jefflowrey
PostPosted: Tue Nov 13, 2007 9:54 am    Post subject: Reply with quote

Grand Poobah

Joined: 16 Oct 2002
Posts: 19981

MCAUser on the client channel.
_________________
I am *not* the model of the modern major general.
Back to top
View user's profile Send private message
klamerus
PostPosted: Tue Nov 13, 2007 7:08 pm    Post subject: Is that a sentence? Reply with quote

Disciple

Joined: 05 Jul 2004
Posts: 199
Location: Detroit, MI

Sorry, but that's pretty terse. A few more words might help
_________________
Careful with that VAX Eugene
Back to top
View user's profile Send private message Send e-mail AIM Address Yahoo Messenger MSN Messenger
RogerLacroix
PostPosted: Tue Nov 13, 2007 8:18 pm    Post subject: Reply with quote

Jedi Knight

Joined: 15 May 2001
Posts: 3264
Location: London, ON Canada

Hi,

Terse - short in both words and any security for that channel. Setting a UserId in the MCAUSER field means any and all connections would be running under that UserId. Hence, a free for all.

Regards,
Roger Lacroix
Capitalware Inc.
_________________
Capitalware: Transforming tomorrow into today.
Connected to MQ!
Twitter
Back to top
View user's profile Send private message Visit poster's website
Vitor
PostPosted: Wed Nov 14, 2007 1:39 am    Post subject: Re: Is that a sentence? Reply with quote

Grand High Poobah

Joined: 11 Nov 2005
Posts: 26093
Location: Texas, USA

klamerus wrote:
Sorry, but that's pretty terse. A few more words might help


Use the MCAUser parameter to supply the credentials to the target domain.

Which, as Roger correctly points out, allows anyone to access the target domain queue manager with the authorities given to the id in MCAUser. So make sure it's locked down.

Or do a search in the forum for the many discussions on client security, and security in general, for further information.
_________________
Honesty is the best policy.
Insanity is the best defence.
Back to top
View user's profile Send private message
fjb_saper
PostPosted: Wed Nov 14, 2007 2:32 am    Post subject: Reply with quote

Grand High Poobah

Joined: 18 Nov 2003
Posts: 20756
Location: LI,NY

RogerLacroix wrote:
Hi,

Terse - short in both words and any security for that channel. Setting a UserId in the MCAUSER field means any and all connections would be running under that UserId. Hence, a free for all.

Regards,
Roger Lacroix
Capitalware Inc.


Roger, I thought that would only happen if you had it also as a default channel to the target qm. To be a free for all others would have to know the Xmitq when it is not part of a default path...
_________________
MQ & Broker admin
Back to top
View user's profile Send private message Send e-mail
Vitor
PostPosted: Wed Nov 14, 2007 2:36 am    Post subject: Reply with quote

Grand High Poobah

Joined: 11 Nov 2005
Posts: 26093
Location: Texas, USA

fjb_saper wrote:
To be a free for all others would have to know the Xmitq when it is not part of a default path...


When did client connections start using xmitqs? Have I missed a tech note? Or has someone spiked my coffee with ProPlus? Again?
_________________
Honesty is the best policy.
Insanity is the best defence.
Back to top
View user's profile Send private message
fjb_saper
PostPosted: Wed Nov 14, 2007 2:49 am    Post subject: Reply with quote

Grand High Poobah

Joined: 18 Nov 2003
Posts: 20756
Location: LI,NY

Missed the fact that he was talking about a client conn. I thought he was going for qmgr to qmgr conn across domains...
_________________
MQ & Broker admin
Back to top
View user's profile Send private message Send e-mail
Vitor
PostPosted: Wed Nov 14, 2007 2:53 am    Post subject: Reply with quote

Grand High Poobah

Joined: 11 Nov 2005
Posts: 26093
Location: Texas, USA

But on the plus side, this means my coffee is chemically safe!
_________________
Honesty is the best policy.
Insanity is the best defence.
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic  Reply to topic Page 1 of 1

MQSeries.net Forum Index » IBM MQ Installation/Configuration Support » Enqueuing across domains
Jump to:  



You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Protected by Anti-Spam ACP
 
 


Theme by Dustin Baccetti
Powered by phpBB © 2001, 2002 phpBB Group

Copyright © MQSeries.net. All rights reserved.