Posted: Sun Dec 20, 2015 11:36 pm Post subject: Readonly & remote & secure access to queue managers
Newbie
Joined: 18 Dec 2015 Posts: 2
Dear all,
I`m trying to find a way to give a group of people read only access to queue managers. I used "Add role based authentication" wizard to grant readonly authorization to a local account (let`s call it ROUSER).
Queue managers (MQ 8.0.0.3) are installed on Windows 2012 R2 servers and run under local account. Servers do not have terminal role, so there`s limitation to only 2 RDP sessions.
Therefore remote access through MQ Explorer seems to be a good idea for me. I created SVRCONN channel and assigned ROUSER as MCA.
Now I`m struggling with channel security. I`d like only authorized people to have access to my queue managers. I don`t like the idea to create local account for every person on every mq server.
These people already have Active Directory accounts and I`d like to use them for authentication.
How can I do that? I didn`t find any good documentation on that topic. I think I have to create new user repository, so I click Authentication Information in MQ explorer, then New, and then "LDAP User ID + Password Authentication Information...". And this is the place when I don`t know what to do next. I don`t quite understand what should I put in "User object class", "Qualifying user filed" etc.
you need to talk to your window domain administrator. Your LDAP access needs to be set up at the domain level. You can then talk to your admin and they will tell you what you need to populate there.
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum