ASG
IBM
Zystems
Cressida
Icon
Netflexity
 
  MQSeries.net
Search  Search       Tech Exchange      Education      Certifications      Library      Info Center      SupportPacs      LinkedIn  Search  Search                                                                   FAQ  FAQ   Usergroups  Usergroups
 
Register  ::  Log in Log in to check your private messages
 
RSS Feed - WebSphere MQ Support RSS Feed - Message Broker Support

MQSeries.net Forum Index » WebSphere Message Broker (ACE) Support » Policy set to enforce username and password

Post new topic  Reply to topic
 Policy set to enforce username and password « View previous topic :: View next topic » 
Author Message
BrianR
PostPosted: Tue Sep 09, 2008 12:08 am    Post subject: Policy set to enforce username and password Reply with quote

Novice

Joined: 04 Nov 2005
Posts: 12
Location: London

Can anyone tell me how to configure a policy set to enforce the presence of both a username and password token?

I have tried using the WSS10Default which does enforce the presence of a username token but when no password is present the webservice runs. When a password is present then the security manager is called.

I am using broker 6.1 fixpack 2
Back to top
View user's profile Send private message
sridhsri
PostPosted: Tue Sep 09, 2008 6:05 pm    Post subject: Reply with quote

Master

Joined: 19 Jun 2008
Posts: 297

What are you using for authentication ? I remember when I used a LDAP a blank password still gave me exceptions.
Back to top
View user's profile Send private message
BrianR
PostPosted: Tue Sep 09, 2008 10:28 pm    Post subject: Reply with quote

Novice

Joined: 04 Nov 2005
Posts: 12
Location: London

We are using OID (Oracle Internet Directory) which claims to be LDAP 3 compliant.

Also, if you enter a non-existent user and no password the web service executes which does imply that either:-

- The authorisation service is not being called when no password is present
or
- The authorisation service ignores the userid UNLESS a password is also present
Back to top
View user's profile Send private message
mqjeff
PostPosted: Wed Sep 10, 2008 1:51 am    Post subject: Reply with quote

Grand Master

Joined: 25 Jun 2008
Posts: 17447

You need to always create your own profile. The default should not be used.
Back to top
View user's profile Send private message
BrianR
PostPosted: Wed Sep 10, 2008 2:32 am    Post subject: Reply with quote

Novice

Joined: 04 Nov 2005
Posts: 12
Location: London

mqjeff

I have created security profile which points at the OID LDAP server, this part is working fine as long as the message includes both a userid and password, if the password is correct the service runs, if the password is wrong an error is returned.

My question was to do the the presence/absence of the password in the input message, for SOAP nodes if the password tag is not present OR the password tag is present but empty the the service runs (even if the userid does not exist). For HTTPInput node, if the password tag is missing then an error is reported, if the password tag is present but empty then the service runs.

It would appear that the bind to the LDAP server is being done as anonymous unless both the userid and password tags are present AND contain a value
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic  Reply to topic Page 1 of 1

MQSeries.net Forum Index » WebSphere Message Broker (ACE) Support » Policy set to enforce username and password
Jump to:  



You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Protected by Anti-Spam ACP
 
 


Theme by Dustin Baccetti
Powered by phpBB © 2001, 2002 phpBB Group

Copyright © MQSeries.net. All rights reserved.