ASG
IBM
Zystems
Cressida
Icon
Netflexity
 
  MQSeries.net
Search  Search       Tech Exchange      Education      Certifications      Library      Info Center      SupportPacs      LinkedIn  Search  Search                                                                   FAQ  FAQ   Usergroups  Usergroups
 
Register  ::  Log in Log in to check your private messages
 
RSS Feed - WebSphere MQ Support RSS Feed - Message Broker Support

MQSeries.net Forum Index » IBM MQ Security » security - channel (SVRCONN)

Post new topic  Reply to topic
 security - channel (SVRCONN) « View previous topic :: View next topic » 
Author Message
Elayaraja
PostPosted: Fri Oct 29, 2010 4:39 pm    Post subject: security - channel (SVRCONN) Reply with quote

Newbie

Joined: 27 Oct 2010
Posts: 4

Hi,

We are implementing security for SVRCONN channel for particular user (non-mq group user). When we create channel, we had given MCAUSER as 'wasadmin' and executed setmqaut for wasadmin to connect the qmgr and channel.

Question 1.
When we create the QCF, we had given wrong password of 'wasadmin' user. Still we are able to connect the queue manager.

Is that correct scenario?
Back to top
View user's profile Send private message
mqjeff
PostPosted: Fri Oct 29, 2010 5:02 pm    Post subject: Re: security - channel (SVRCONN) Reply with quote

Grand Master

Joined: 25 Jun 2008
Posts: 17447

Elayaraja wrote:
Hi,

We are implementing security for SVRCONN channel for particular user (non-mq group user). When we create channel, we had given MCAUSER as 'wasadmin' and executed setmqaut for wasadmin to connect the qmgr and channel.

Question 1.
When we create the QCF, we had given wrong password of 'wasadmin' user. Still we are able to connect the queue manager.

Is that correct scenario?


Yes.

MCAUSER and MQ in general does not make regard to the password.

If you wish to control whether some particular OS level user can connect to the channel vs some other OS level user that can't, you either need an Exit or you need to use SSL and SSLPEER.
Back to top
View user's profile Send private message
Elayaraja
PostPosted: Fri Oct 29, 2010 5:26 pm    Post subject: Reply with quote

Newbie

Joined: 27 Oct 2010
Posts: 4

Thanks for the clarification. It's very difficult to explain to non technical managers. Their question is "then what is the purpose of user authentication issue setmquat"
Back to top
View user's profile Send private message
Vitor
PostPosted: Fri Oct 29, 2010 5:37 pm    Post subject: Reply with quote

Grand High Poobah

Joined: 11 Nov 2005
Posts: 26093
Location: Texas, USA

Elayaraja wrote:
Their question is "then what is the purpose of user authentication issue setmquat"


Point out that setmqaut (as described here) is an authorization service not an authentication service.

Hence the lack of facilities to authenticate users. Because that's not what it does.
_________________
Honesty is the best policy.
Insanity is the best defence.
Back to top
View user's profile Send private message
mqjeff
PostPosted: Sat Oct 30, 2010 3:13 am    Post subject: Reply with quote

Grand Master

Joined: 25 Jun 2008
Posts: 17447

Vitor wrote:
Elayaraja wrote:
Their question is "then what is the purpose of user authentication issue setmquat"


Point out that setmqaut (as described here) is an authorization service not an authentication service.


And if you can't make them understand that difference, then you need to make them understand that they are paying you to be technical for them.
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic  Reply to topic Page 1 of 1

MQSeries.net Forum Index » IBM MQ Security » security - channel (SVRCONN)
Jump to:  



You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Protected by Anti-Spam ACP
 
 


Theme by Dustin Baccetti
Powered by phpBB © 2001, 2002 phpBB Group

Copyright © MQSeries.net. All rights reserved.