|  | 
 
  
    | RSS Feed - WebSphere MQ Support | RSS Feed - Message Broker Support |  
 
  
	|    |  |  
  
	| Separating authorizations for operators and admins (NT) | « View previous topic :: View next topic » |  
  	| 
		
		
		  | Author | Message |  
		  | royr | 
			  
				|  Posted: Mon Aug 06, 2001 1:49 am    Post subject: |   |  |  
		  |  Acolyte
 
 
 Joined: 30 Jun 2001Posts: 65
 Location: Israel
 
 | 
			  
				| I need to set MQ authorizations for a group of NT operators. They should not have any access to messages on queues, but they should be able to start and stop MQ processes: The various services, channel initiators, specific channels, and so on. Also, they need authorizations to update attributes of some of the objects. 
 The problem is that there seems to be no separation of admins and operators in the OAM. An operator has to be in the mqm or administrators groups in order to start/stop channels, and this gives her complete authority on all the queue manager objects.
 
 This is from the "Programmable System Management" book:
 
 
   
	| Quote: |  
	| To process any of the following commands the user ID must belong to group mqm. Note: For Windows NT only the user ID may belong to group Administrators or group mqm.
 
 Change Channel
 Copy Channel
 Create Channel
 Delete Channel
 Ping Channel
 Reset Channel
 Start Channel
 Stop Channel
 Start Channel Initiator
 Start Channel Listener
 Resolve Channel
 
 |  |  |  
		  | Back to top |  |  
		  |  |  
		  | kolban | 
			  
				|  Posted: Mon Aug 06, 2001 4:46 am    Post subject: |   |  |  
		  |  Grand Master
 
 
 Joined: 22 May 2001Posts: 1072
 Location: Fort Worth, TX, USA
 
 | 
			  
				| This is a really good question.  I don't yet have a good answer but a thought struck me and I quickly killed it because it is a disasterous idea. 
 Once upon a time, I removed the group mqm from the authorization list because I didn't want the default security settings.  I broke my queue manager solidly.  Please don't ever think you can remove this group.
 |  |  
		  | Back to top |  |  
		  |  |  
		  | Reddiough | 
			  
				|  Posted: Mon Aug 06, 2001 5:02 am    Post subject: |   |  |  
		  | Novice
 
 
 Joined: 27 Jun 2001Posts: 23
 
 
 | 
			  
				| Have a look at supportpac MSOE. 
 I haven't used it myself but it looks like the sort of thing you're after.
 
 Regards,
 Tony.
 |  |  
		  | Back to top |  |  
		  |  |  
		  |  |  |  
  
	|    |  | Page 1 of 1 |  
 
 
  
  	| 
		
		  | 
 
 | You cannot post new topics in this forum You cannot reply to topics in this forum
 You cannot edit your posts in this forum
 You cannot delete your posts in this forum
 You cannot vote in polls in this forum
 
 |  |  |  |