ASG
IBM
Zystems
Cressida
Icon
Netflexity
 
  MQSeries.net
Search  Search       Tech Exchange      Education      Certifications      Library      Info Center      SupportPacs      LinkedIn  Search  Search                                                                   FAQ  FAQ   Usergroups  Usergroups
 
Register  ::  Log in Log in to check your private messages
 
RSS Feed - WebSphere MQ Support RSS Feed - Message Broker Support

MQSeries.net Forum Index » WebSphere Message Broker (ACE) Support » Prevent deleting broker from the toolkit

Post new topic  Reply to topic
 Prevent deleting broker from the toolkit « View previous topic :: View next topic » 
Author Message
NewMB
PostPosted: Thu May 26, 2005 9:29 am    Post subject: Prevent deleting broker from the toolkit Reply with quote

Apprentice

Joined: 05 Jan 2005
Posts: 42

Is it possible to restrict users accidentally delete broker from the toolkit? I found out a command "mqsicreateaclgroup" can set user access control to broker but I am not sure it is what I am looking for.

Thanks!
Back to top
View user's profile Send private message
jefflowrey
PostPosted: Thu May 26, 2005 9:47 am    Post subject: Reply with quote

Grand Poobah

Joined: 16 Oct 2002
Posts: 19981

Don't put them in the ops group.
_________________
I am *not* the model of the modern major general.
Back to top
View user's profile Send private message
ydsk
PostPosted: Thu May 26, 2005 10:38 am    Post subject: Reply with quote

Chevalier

Joined: 23 May 2005
Posts: 410

That would restrict the users from adding brokers to the domain...even from connecting to the domain. Right ?
Back to top
View user's profile Send private message
jefflowrey
PostPosted: Thu May 26, 2005 10:45 am    Post subject: Reply with quote

Grand Poobah

Joined: 16 Oct 2002
Posts: 19981

ydsk wrote:
That would restrict the users from adding brokers to the domain...even from connecting to the domain. Right ?

Developers shouldn't need to add or delete brokers. Operational Staff should know not to delete brokers from the Toolkit.

With the Access Control Lists, you can give users different permissions on the Topology than on Brokers. You can not give them different permissions to create a broker than to delete it.
_________________
I am *not* the model of the modern major general.
Back to top
View user's profile Send private message
ydsk
PostPosted: Thu May 26, 2005 2:08 pm    Post subject: Reply with quote

Chevalier

Joined: 23 May 2005
Posts: 410

I am not talking about the real create with the 'mqsicreatebroker' command. Not adding a user to mqbrops on the ConfigMgr box would restrict the user from connecting to the domain through a toolkit on his desktop. Right ?
Back to top
View user's profile Send private message
jefflowrey
PostPosted: Thu May 26, 2005 2:41 pm    Post subject: Reply with quote

Grand Poobah

Joined: 16 Oct 2002
Posts: 19981

ydsk wrote:
I am not talking about the real create with the 'mqsicreatebroker' command. Not adding a user to mqbrops on the ConfigMgr box would restrict the user from connecting to the domain through a toolkit on his desktop. Right ?

I've forgotten. I dug through the infocenter stuff on security earlier, and didn't find the stuff I remember seeing where it spelled out what the classical groups were and what permissions they gave.

It did say that ACLs were used if the user WASN'T found in the groups, or didn't have the permission from the groups they were asking for.

Regardless... I'm not positive that developers need to connect to the domain, except in dev.

And even then, they can be told 'Don't delete the broker!'.
_________________
I am *not* the model of the modern major general.
Back to top
View user's profile Send private message
ydsk
PostPosted: Tue May 31, 2005 6:27 am    Post subject: Reply with quote

Chevalier

Joined: 23 May 2005
Posts: 410

Jeff,

I don't know much about ACLs. Do you know if both the mqb*** groups and ACLs can be used for security ? We have a similar situation...we informed the developers not to delete the brokers through a toolkit. They were added to the mqbrops group in the dev environment as they needed it.

Though we told the developers not to delete the brokers from toolkit we can't stop them technically from doing so. Do you know how we can achieve this through ACLs or a combination of both mq**** groups and ACLs. ?

Appreciate any explanation.

Thanks.
Back to top
View user's profile Send private message
jefflowrey
PostPosted: Tue May 31, 2005 6:37 am    Post subject: Reply with quote

Grand Poobah

Joined: 16 Oct 2002
Posts: 19981

Developers don't need the ability to change the topology.

The Topology is a different object in the ACLs than the Brokers are. You can use the ACLs to deny the ability to change the topology (prevent them from deleting AND creating brokers) without affecting their ability to use the brokers.

The ACLs are checked only if the user is not in the traditional groups, according to the documentation.
_________________
I am *not* the model of the modern major general.
Back to top
View user's profile Send private message
ydsk
PostPosted: Tue May 31, 2005 6:46 am    Post subject: Reply with quote

Chevalier

Joined: 23 May 2005
Posts: 410

Jeff,
Thanks for the information. I know the developers don't need to modify topology. But a developer can't see the brokers in the domain unless he is in mqbrops group on the configmgr ( I am sure of it as I saw it myself).

As you said, we might have to do away with the mq**** groups completely to implement security with ACLs.

Anyone has any different experiences ? Pls let me know.

Thanks.
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic  Reply to topic Page 1 of 1

MQSeries.net Forum Index » WebSphere Message Broker (ACE) Support » Prevent deleting broker from the toolkit
Jump to:  



You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Protected by Anti-Spam ACP
 
 


Theme by Dustin Baccetti
Powered by phpBB © 2001, 2002 phpBB Group

Copyright © MQSeries.net. All rights reserved.