|
RSS Feed - WebSphere MQ Support
|
RSS Feed - Message Broker Support
|
 |
|
Need Secutriy Exit |
« View previous topic :: View next topic » |
Author |
Message
|
aditya.aggarwal |
Posted: Sun Jan 18, 2009 1:51 am Post subject: Need Secutriy Exit |
|
|
 Master
Joined: 13 Jan 2009 Posts: 252
|
How to write and use security exit for users?
I want to use mqsecid file to allow the user to connect with queue managers and queues. |
|
Back to top |
|
 |
Vitor |
Posted: Sun Jan 18, 2009 5:52 am Post subject: Re: Need Secutriy Exit |
|
|
 Grand High Poobah
Joined: 11 Nov 2005 Posts: 26093 Location: Texas, USA
|
aditya.aggarwal wrote: |
How to write and use security exit for users? |
Very, very carefully, after many years of programming experience and with a lot of testing!
Exits are an advanced WMQ topic, and there's no simple answer to your question. There's a great thread from Roger on the subject of exits you should read, and obviously the IBM documentation.
You'll also find a number of posts from me warning on the dangers on exits, which I stand by. Think seriously if you really need an exit solution, or if something like SSL will meet your needs.
Also seriously consider a purchased security solution if you're committed to this path. TCO is likely to be much lower. _________________ Honesty is the best policy.
Insanity is the best defence. |
|
Back to top |
|
 |
PeterPotkay |
Posted: Sun Jan 18, 2009 7:43 am Post subject: |
|
|
 Poobah
Joined: 15 May 2001 Posts: 7722
|
I would recomend the Capitalware MQ Security Exit.
http://www.capitalware.biz/mqausx_overview.html
It works very well, support is excellent, and its a lot cheaper than trying to figure out writing your own. Unless you are a security expert, the security exit you finally do get working is unlikely to meet requirements and pass all security tests. A common one I love to hear is "Look at my new Security Exit, it works great!" Um, you are passing the ID and password over the wire in plain text.
A commercial security exit is officially supported by people whose sole job is security. And its tested by hundreds if not thousands of other customers so you can be sure it works well. Do you really want to be responsible for breaches in your companies security because of a hole in the design or coding your first security exit? _________________ Peter Potkay
Keep Calm and MQ On |
|
Back to top |
|
 |
|
|
 |
|
Page 1 of 1 |
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
|
|
|