ASG
IBM
Zystems
Cressida
Icon
Netflexity
 
  MQSeries.net
Search  Search       Tech Exchange      Education      Certifications      Library      Info Center      SupportPacs      LinkedIn  Search  Search                                                                   FAQ  FAQ   Usergroups  Usergroups
 
Register  ::  Log in Log in to check your private messages
 
RSS Feed - WebSphere MQ Support RSS Feed - Message Broker Support

MQSeries.net Forum Index » General IBM MQ Support » Authorization

Post new topic  Reply to topic
 Authorization « View previous topic :: View next topic » 
Author Message
cturner
PostPosted: Mon Aug 18, 2003 9:20 am    Post subject: Authorization Reply with quote

Newbie

Joined: 21 Aug 2002
Posts: 9
Location: Apex, NC

I have a customer that is asking if they can set security on a channel to only access certain queues/objects. Initially, I told them it wasn't possible but now they read something and seem to think it is possible.

Basically, they will have about 7 sender/receiver channels coming from 7 different places and they want to secure the connections and queus so that the 7 different places will not be able to see or access each others queues and channels.

Any help appreciated, thanks.
Back to top
View user's profile Send private message
Reconda
PostPosted: Mon Aug 18, 2003 12:48 pm    Post subject: Reply with quote

Apprentice

Joined: 20 Jun 2002
Posts: 40

Hi,

You can accomplish this by using our QN-AppWatch for MQ product. QN-AppWatch provides highly secure customized views so that users only see/touch what you want them to see/touch. This level of granularity goes down to the channel and message level. You can visit our website at www.reconda.com to learn more.
Back to top
View user's profile Send private message Send e-mail Visit poster's website
interactivechannel
PostPosted: Wed Aug 20, 2003 12:16 am    Post subject: Reply with quote

Voyager

Joined: 20 May 2003
Posts: 94
Location: uk

Set the MCAUSER on the channel.
Back to top
View user's profile Send private message
jefflowrey
PostPosted: Wed Aug 20, 2003 11:11 am    Post subject: Re: Authorization Reply with quote

Grand Poobah

Joined: 16 Oct 2002
Posts: 19981

cturner wrote:
I have a customer that is asking if they can set security on a channel to only access certain queues/objects. Initially, I told them it wasn't possible but now they read something and seem to think it is possible.

Basically, they will have about 7 sender/receiver channels coming from 7 different places and they want to secure the connections and queus so that the 7 different places will not be able to see or access each others queues and channels.

This is basic MQSeries security. MQSeries objects have permissions on them, and those permissions are granted to defined users. If each of the 7 different places are running their applications as different users, then use setmqaut or dspmqaut to manage the permissions for each of those users.

If each of those 7 different places aren't running their apps as different users, and you aren't otherwise authenicating them, then you could set the MCAUser on the channel as someone else suggested and then assign priviledges for each of those users. However, all that means is that anyone who connects to that channel has the rights assigned to the user defined to the channel.
Back to top
View user's profile Send private message
EddieA
PostPosted: Wed Aug 20, 2003 11:27 am    Post subject: Reply with quote

Jedi

Joined: 28 Jun 2001
Posts: 2453
Location: Los Angeles

Quote:
This is basic MQSeries security. MQSeries objects have permissions on them, and those permissions are granted to defined users. If each of the 7 different places are running their applications as different users, then use setmqaut or dspmqaut to manage the permissions for each of those users.


If you do this for the local queues where the messages will arrive, then don't forget to change the Receiver channel to use Put Authority = Context.

Cheers,
_________________
Eddie Atherton
IBM Certified Solution Developer - WebSphere Message Broker V6.1
IBM Certified Solution Developer - WebSphere Message Broker V7.0
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic  Reply to topic Page 1 of 1

MQSeries.net Forum Index » General IBM MQ Support » Authorization
Jump to:  



You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Protected by Anti-Spam ACP
 
 


Theme by Dustin Baccetti
Powered by phpBB © 2001, 2002 phpBB Group

Copyright © MQSeries.net. All rights reserved.