ASG
IBM
Zystems
Cressida
Icon
Netflexity
 
  MQSeries.net
Search  Search       Tech Exchange      Education      Certifications      Library      Info Center      SupportPacs      LinkedIn  Search  Search                                                                   FAQ  FAQ   Usergroups  Usergroups
 
Register  ::  Log in Log in to check your private messages
 
RSS Feed - WebSphere MQ Support RSS Feed - Message Broker Support

MQSeries.net Forum Index » IBM MQ Security » Securing MQ with Active Directory

Post new topic  Reply to topic
 Securing MQ with Active Directory « View previous topic :: View next topic » 
Author Message
RocknRambo
PostPosted: Fri Jun 03, 2011 7:28 am    Post subject: Securing MQ with Active Directory Reply with quote

Partisan

Joined: 24 Sep 2003
Posts: 355

Can anyone point me to the documentation/article on securing WMQ with Active Directory.

Installs and configuration are complete, I'm assuming we still can secure the environment such as access control with Active Directory

environment:
Windows 2008 server
WMQ v7.x

we are getting push back on not use OAM.

Thanks for the help

-RR
Back to top
View user's profile Send private message
mqjeff
PostPosted: Fri Jun 03, 2011 7:43 am    Post subject: Reply with quote

Grand Master

Joined: 25 Jun 2008
Posts: 17447

There is not, AFAIK, an out of the box way to configure ActiveDirectory to act as an Authorization Service so that you can use it INSTEAD of OAM - that is so that AD would "know" what a queue was, and know that user A could PUT or GET from that queue.

You can certainly configure AD to act as a user repository so that the OAM knows that user A can PUT or GET from a given queue.

Which are you trying to do?
Back to top
View user's profile Send private message
RocknRambo
PostPosted: Fri Jun 03, 2011 8:59 am    Post subject: Reply with quote

Partisan

Joined: 24 Sep 2003
Posts: 355

Thanks Jeff,

yes, I'm looking to achieve what said

Quote:
You can certainly configure AD to act as a user repository so that the OAM knows that user A can PUT or GET from a given queue.


can you point me put some instructions, like what's needs to be done on AD and details we need on MQ in order complete the configuration.

Thanks
--
RR
Back to top
View user's profile Send private message
bruce2359
PostPosted: Fri Jun 03, 2011 9:03 am    Post subject: Reply with quote

Poobah

Joined: 05 Jan 2008
Posts: 9400
Location: US: west coast, almost. Otherwise, enroute.

Google wmq+active+directory
_________________
I like deadlines. I like to wave as they pass by.
ב''ה
Lex Orandi, Lex Credendi, Lex Vivendi. As we Worship, So we Believe, So we Live.
Back to top
View user's profile Send private message
RocknRambo
PostPosted: Fri Jun 03, 2011 9:24 am    Post subject: Reply with quote

Partisan

Joined: 24 Sep 2003
Posts: 355

Yes, I kinda did some home work via googling .. (may be not enough) , and tht's where need some additional help & thoughts

the best matching link, i found.

http://publib.boulder.ibm.com/infocenter/wmqv7/v7r0/index.jsp?topic=/com.ibm.mq.amqtan.doc/wc14250_.htm


anyone aware of any redbook/manual/developerswork with additional details

--RR
Back to top
View user's profile Send private message
mqjeff
PostPosted: Fri Jun 03, 2011 10:36 am    Post subject: Reply with quote

Grand Master

Joined: 25 Jun 2008
Posts: 17447

RocknRambo wrote:
the best matching link, i found.

http://publib.boulder.ibm.com/infocenter/wmqv7/v7r0/index.jsp?topic=/com.ibm.mq.amqtan.doc/wc14250_.htm


That page describes how to retrieve information about what queue manager and queues an application should access. It does not describe how to configure AD to store information about what users can access what queues or queue managers, nor how to configure the OAM to know what groups a user belongs to.

RocknRambo wrote:
Yes, I kinda did some home work via googling .. (may be not enough) , and tht's where need some additional help & thoughts



If you want to know how to enable the OAM to talk to AD, so that it can verify that AD has authenticated a given user and find out what ids it belongs to, then start here
http://publib.boulder.ibm.com/infocenter/wmqv7/v7r0/index.jsp?topic=/com.ibm.mq.amqtac.doc/wq10820_.htm

If you want to configure MQ to ask AD what users are allowed to PUT or GET to a given queue, you're on your own.
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic  Reply to topic Page 1 of 1

MQSeries.net Forum Index » IBM MQ Security » Securing MQ with Active Directory
Jump to:  



You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Protected by Anti-Spam ACP
 
 


Theme by Dustin Baccetti
Powered by phpBB © 2001, 2002 phpBB Group

Copyright © MQSeries.net. All rights reserved.