Posted: Fri Jan 13, 2006 3:24 am Post subject: Global or Local
Master
Joined: 10 Nov 2005 Posts: 217 Location: London, UK
Hi,
In previous roles I have always secured MQ on Windows 2000 using local groups that have global groups inserted into them.
I'm wondering whether this is entirely necessary and whether I can authorise global groups directly to have access to MQ objects (via setmqaut). The reason I'm asking the question is my current workplace do not like local groups on machines at all.
The Security manual just mentions "groups" but does not specify whether they can be merely global.
I have tried authorising a global group with access to an MQ object but the command fails..
If you are going after global groups (domain groups) the user running MQ must have priviledge to query group membership on the domain... otherwise this will fail...
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum