ASG
IBM
Zystems
Cressida
Icon
Netflexity
 
  MQSeries.net
Search  Search       Tech Exchange      Education      Certifications      Library      Info Center      SupportPacs      LinkedIn  Search  Search                                                                   FAQ  FAQ   Usergroups  Usergroups
 
Register  ::  Log in Log in to check your private messages
 
RSS Feed - WebSphere MQ Support RSS Feed - Message Broker Support

MQSeries.net Forum Index » General IBM MQ Support » Originator IP address for inbound messages

Post new topic  Reply to topic
 Originator IP address for inbound messages « View previous topic :: View next topic » 
Author Message
npvmq
PostPosted: Tue Apr 20, 2004 1:28 pm    Post subject: Originator IP address for inbound messages Reply with quote

Novice

Joined: 20 Feb 2004
Posts: 10
Location: US

Hi,

In my case, I have messages coming from a 3rd party queue manager on to our local queue. Before processing the message, I want to validate the originator IP address from our list of 3rd party IP addresses. We want to discard the message if the IP address does not belong to the list. I am not able to figure out how to get hold of the originator IP address for inbound messages.

Please let me know if it is possible or how.

Thx in advance.
-npvmq
Back to top
View user's profile Send private message
jefflowrey
PostPosted: Tue Apr 20, 2004 1:32 pm    Post subject: Reply with quote

Grand Poobah

Joined: 16 Oct 2002
Posts: 19981

Actually, I don't think you want to validate the IP address on a message by message basis.

I think you want to make sure that the connections are validated.

SSL is one way to do this.
_________________
I am *not* the model of the modern major general.
Back to top
View user's profile Send private message
npvmq
PostPosted: Tue Apr 20, 2004 3:32 pm    Post subject: Reply with quote

Novice

Joined: 20 Feb 2004
Posts: 10
Location: US

Jeff, As u said I can use the SSL but what if another 3rd party QMB (Assuming QMA is the first 3rd party qmgr and both have SSL channel connection with us) tries to spoof as if it is sending message as QMA.

Our objective is to prevent QMA spoofing as QMB and viceversa. Hence we thought if we had a control on the originator IP address we could control the spoofing.

Thx
-npvmq
Back to top
View user's profile Send private message
PeterPotkay
PostPosted: Tue Apr 20, 2004 3:41 pm    Post subject: Reply with quote

Poobah

Joined: 15 May 2001
Posts: 7722

An IP address can be spoofed also, so thats not really a 100% sure way if authenticating the other side.


SSL is better. QMA at third party #1 has one SSL certificate, QMB at third party #2 has a different one. That keeps each one from being able to impersonate the other, as long as you keep the certificates secure.
_________________
Peter Potkay
Keep Calm and MQ On
Back to top
View user's profile Send private message
jefflowrey
PostPosted: Tue Apr 20, 2004 5:47 pm    Post subject: Reply with quote

Grand Poobah

Joined: 16 Oct 2002
Posts: 19981

Just to clarify a little (hopefully) what Peter is saying.

QMGRA talks to one channel using one certificate.

QMGRB talks to a different channel using a different certificate.

Even if QMGRB learns about QMGRA's channel, as long as he doesn't have the right certificate, he can't connect to it.
_________________
I am *not* the model of the modern major general.
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic  Reply to topic Page 1 of 1

MQSeries.net Forum Index » General IBM MQ Support » Originator IP address for inbound messages
Jump to:  



You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Protected by Anti-Spam ACP
 
 


Theme by Dustin Baccetti
Powered by phpBB © 2001, 2002 phpBB Group

Copyright © MQSeries.net. All rights reserved.