ASG
IBM
Zystems
Cressida
Icon
Netflexity
 
  MQSeries.net
Search  Search       Tech Exchange      Education      Certifications      Library      Info Center      SupportPacs      LinkedIn  Search  Search                                                                   FAQ  FAQ   Usergroups  Usergroups
 
Register  ::  Log in Log in to check your private messages
 
RSS Feed - WebSphere MQ Support RSS Feed - Message Broker Support

MQSeries.net Forum Index » General IBM MQ Support » MCA User does not match to User ID attribute ?

Post new topic  Reply to topic
 MCA User does not match to User ID attribute ? « View previous topic :: View next topic » 
Author Message
rcp_mq
PostPosted: Wed Jul 02, 2014 4:20 am    Post subject: MCA User does not match to User ID attribute ? Reply with quote

Centurion

Joined: 13 Dec 2011
Posts: 133

I have SVRCONN channel in an MQ6 installation on a remote unix machine. It has an MCAUSER "xyz". From my local windows desktop with MQ7.5 explorer, I'm able to connect to the remote Queue manager with User ID attribute set to "abc". I was expecting a 2035.
Could anyone suggest what I'm missing?
Back to top
View user's profile Send private message
PeterPotkay
PostPosted: Wed Jul 02, 2014 5:05 am    Post subject: Reply with quote

Poobah

Joined: 15 May 2001
Posts: 7722

Why were you expecting a 2035?
_________________
Peter Potkay
Keep Calm and MQ On
Back to top
View user's profile Send private message
rcp_mq
PostPosted: Wed Jul 02, 2014 10:22 pm    Post subject: Reply with quote

Centurion

Joined: 13 Dec 2011
Posts: 133

If connecting to an untrusted domain, shouldn't there be an access denied error?
Perhaps, i'm too dumb to understand the info center definitions.
Could you tell me why it should not cause a 2035?
Back to top
View user's profile Send private message
PeterPotkay
PostPosted: Thu Jul 03, 2014 4:05 am    Post subject: Reply with quote

Poobah

Joined: 15 May 2001
Posts: 7722

I didn't say whether it should or should not cause a 2035. Without knowing what authority abc and xyz have to the Queue Manager its impossible to say.

But with xyz in the MCAUSER field of the SVRCONN channel, and assuming there is no Security Exit in play, it doesn't matter what abc, def or 123 has - all connections over that channel will be authorized as xyz.
_________________
Peter Potkay
Keep Calm and MQ On
Back to top
View user's profile Send private message
bruce2359
PostPosted: Thu Jul 03, 2014 4:20 am    Post subject: Reply with quote

Poobah

Joined: 05 Jan 2008
Posts: 9469
Location: US: west coast, almost. Otherwise, enroute.

So, what authority do abc and xyz have? Are they in the mqm group?
_________________
I like deadlines. I like to wave as they pass by.
ב''ה
Lex Orandi, Lex Credendi, Lex Vivendi. As we Worship, So we Believe, So we Live.
Back to top
View user's profile Send private message
JosephGramig
PostPosted: Thu Jul 03, 2014 5:06 am    Post subject: Reply with quote

Grand Master

Joined: 09 Feb 2006
Posts: 1244
Location: Gold Coast of Florida, USA

And you realize IBM MQ V6.?.?.? is beyond "End of Support" (EOS) for a long time, right?

You need to upgrade and before you do that, research all the requirements of equipment, OS and other software.
Back to top
View user's profile Send private message AIM Address
rcp_mq
PostPosted: Sun Jul 06, 2014 10:49 pm    Post subject: Reply with quote

Centurion

Joined: 13 Dec 2011
Posts: 133

@bruce xyz and abc are random and not part of mqm.
Thanks for the advice Joseph. We do use 7.5, this is an old test machine.
Back to top
View user's profile Send private message
smdavies99
PostPosted: Sun Jul 06, 2014 11:02 pm    Post subject: Reply with quote

Jedi Council

Joined: 10 Feb 2003
Posts: 6076
Location: Somewhere over the Rainbow this side of Never-never land.

rcp_mq wrote:
@bruce xyz and abc are random and not part of mqm.
Thanks for the advice Joseph. We do use 7.5, this is an old test machine.


so why don't you install V7.5 or even V8 on it instead of faffing around with an obsolete version of the product?

The WMQ (sorry IBM MQ) security model changed a lot with V7.1. There are more changes in V8. It is a lot easier to resolve this type of problem with V7.1 onwards.
_________________
WMQ User since 1999
MQSI/WBI/WMB/'Thingy' User since 2002
Linux user since 1995

Every time you reinvent the wheel the more square it gets (anon). If in doubt think and investigate before you ask silly questions.
Back to top
View user's profile Send private message
mqjeff
PostPosted: Mon Jul 07, 2014 5:29 am    Post subject: Reply with quote

Grand Master

Joined: 25 Jun 2008
Posts: 17447

Look, aside from all the blather about what version you're running - and it does make a difference and it is important, but it's still mostly blather.

It's not clear that you understand MCAUSER.

IF there is an MCAUSER in effect, and none of the other rules introduced in v7.1 and v8 apply, then the only ID that makes any difference to MQ security is the MCAUSER.

That's the whole point of the MCAUSER.
Back to top
View user's profile Send private message
JosephGramig
PostPosted: Tue Jul 08, 2014 4:45 am    Post subject: Reply with quote

Grand Master

Joined: 09 Feb 2006
Posts: 1244
Location: Gold Coast of Florida, USA

To get a better idea of the permission, dump what has been granted in the OAM.
Code:
amqoamd -s -m <QmgrName>|grep -v 'g mqm'

First part dumps all permissions and the second part filters out the group mqm's permission (which are full permissions).

You might choose to view only specific groups and I'm only mentioning groups because you indicated this is Unix, which only uses groups (if you specify a principle, the grant goes to the primary group of that principle).
Back to top
View user's profile Send private message AIM Address
Display posts from previous:   
Post new topic  Reply to topic Page 1 of 1

MQSeries.net Forum Index » General IBM MQ Support » MCA User does not match to User ID attribute ?
Jump to:  



You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Protected by Anti-Spam ACP
 
 


Theme by Dustin Baccetti
Powered by phpBB © 2001, 2002 phpBB Group

Copyright © MQSeries.net. All rights reserved.