ASG
IBM
Zystems
Cressida
Icon
Netflexity
 
  MQSeries.net
Search  Search       Tech Exchange      Education      Certifications      Library      Info Center      SupportPacs      LinkedIn  Search  Search                                                                   FAQ  FAQ   Usergroups  Usergroups
 
Register  ::  Log in Log in to check your private messages
 
RSS Feed - WebSphere MQ Support RSS Feed - Message Broker Support

MQSeries.net Forum Index » General IBM MQ Support » Is it possible to stop WMQ Tool from having mqm status?

Post new topic  Reply to topic
 Is it possible to stop WMQ Tool from having mqm status? « View previous topic :: View next topic » 
Author Message
qwerty
PostPosted: Mon Jun 22, 2009 10:30 pm    Post subject: Is it possible to stop WMQ Tool from having mqm status? Reply with quote

Apprentice

Joined: 22 Jun 2009
Posts: 37

Hi, we have a problem.

We try to active the OAM, as security and some of us use the WMQ Tool.
This Tool always has mqm status and so I can´t protect queues, qmgrs etc.

Is it possible to unable the mqm status for this tool?

or is it possible to take away the rights of mqm (only the rights which aren´t necessary) and make a new user with all the abilities?

The big question is: How can we take away the access of this Tool to queues, qmgrs, chls, ect within mqs?

Thanks
qwerty
Back to top
View user's profile Send private message
jon
PostPosted: Mon Jun 22, 2009 11:01 pm    Post subject: Reply with quote

Apprentice

Joined: 17 May 2009
Posts: 32

Hi qwerty,

I too faced the same problem, there should be some way to limit authority level on this tool.
Back to top
View user's profile Send private message
qwerty
PostPosted: Mon Jun 22, 2009 11:15 pm    Post subject: Reply with quote

Apprentice

Joined: 22 Jun 2009
Posts: 37

Hi jon,

i hope so too.

Do you have any clues for me?
Back to top
View user's profile Send private message
zpat
PostPosted: Mon Jun 22, 2009 11:25 pm    Post subject: Reply with quote

Jedi Council

Joined: 19 May 2001
Posts: 5866
Location: UK

It's not the WMQ tool as such, it's the fact that you allow MQ client based programs to connect without authentication as mqm.

Check out BlockIP2 or use SSL.
Back to top
View user's profile Send private message
qwerty
PostPosted: Mon Jun 22, 2009 11:30 pm    Post subject: Reply with quote

Apprentice

Joined: 22 Jun 2009
Posts: 37

can you please discribe this a bit easier for me.

we try to avoid to use SSL.

What can we do to to avoid login as mqm without authentication?
Back to top
View user's profile Send private message
Pavan Kumar PNV
PostPosted: Mon Jun 22, 2009 11:50 pm    Post subject: Reply with quote

Acolyte

Joined: 03 Feb 2007
Posts: 66

BlockIP2 is a security exit that you need to deploy the SVRCONN channel - more details on the use can be found here - http://mrmq.dk/index.htm?BlockIP2.htm
_________________
_____________
Pavan Pendyala
http://pavanz.blogspot.com
Back to top
View user's profile Send private message Visit poster's website Yahoo Messenger
qwerty
PostPosted: Mon Jun 22, 2009 11:58 pm    Post subject: Reply with quote

Apprentice

Joined: 22 Jun 2009
Posts: 37

is there no other possibility?
Back to top
View user's profile Send private message
zpat
PostPosted: Tue Jun 23, 2009 12:16 am    Post subject: Reply with quote

Jedi Council

Joined: 19 May 2001
Posts: 5866
Location: UK

Don't leave the MCAUSER on SVRCONN channels blank (and don't set it to mqm).

BlockIP2 is fairly easy and doesn't just work on IP addresses - it can be used in various ways. For example it can block the use of mqm ids but allow other ids to flow through.

These other ids could be members of the mqm group - not perfect but better than nothing.
Back to top
View user's profile Send private message
qwerty
PostPosted: Wed Jul 01, 2009 10:24 pm    Post subject: Reply with quote

Apprentice

Joined: 22 Jun 2009
Posts: 37

at the moment i am testing BlockIP2 and I am a bit confused

how can I create a Configuration file?
i am logged in with mqm
mqm has the ability to read and write in the exits folder
I untar´d BlockIP2.tar
and now?
I can do some specifications in my SVRCONN an so I tried this

alt chl(MQT2.TCP.MQT1) chltype(SVRCONN) +
SCYDATA('FN=/var/mqm/exits/Blockspec.txt;') +
scyexit('BlockIP2(BlockExit)')

but it doesn´t work
can somebody tell me why?
Back to top
View user's profile Send private message
Vitor
PostPosted: Wed Jul 01, 2009 10:34 pm    Post subject: Reply with quote

Grand High Poobah

Joined: 11 Nov 2005
Posts: 26093
Location: Texas, USA

qwerty wrote:
at the moment i am testing BlockIP2 and I am a bit confused

how can I create a Configuration file?
i am logged in with mqm
mqm has the ability to read and write in the exits folder
I untar´d BlockIP2.tar
and now?
I can do some specifications in my SVRCONN an so I tried this

alt chl(MQT2.TCP.MQT1) chltype(SVRCONN) +
SCYDATA('FN=/var/mqm/exits/Blockspec.txt;') +
scyexit('BlockIP2(BlockExit)')

but it doesn´t work
can somebody tell me why?


for this thread, and a double post of this!

Double posting is considered rude.
_________________
Honesty is the best policy.
Insanity is the best defence.
Back to top
View user's profile Send private message
qwerty
PostPosted: Wed Jul 01, 2009 10:43 pm    Post subject: Reply with quote

Apprentice

Joined: 22 Jun 2009
Posts: 37

omg...
Back to top
View user's profile Send private message
qwerty
PostPosted: Wed Jul 01, 2009 11:20 pm    Post subject: Reply with quote

Apprentice

Joined: 22 Jun 2009
Posts: 37

plz close =)
Back to top
View user's profile Send private message
gbaddeley
PostPosted: Thu Jul 02, 2009 4:42 pm    Post subject: Reply with quote

Jedi Knight

Joined: 25 Mar 2003
Posts: 2538
Location: Melbourne, Australia

qwerty wrote:
plz close =)


Threads don't close, they remain active for eternity, unless deleted by the forum administrators. Someone can read and comment on a thread that is many years old.
_________________
Glenn
Back to top
View user's profile Send private message
Vitor
PostPosted: Fri Jul 03, 2009 12:50 am    Post subject: Reply with quote

Grand High Poobah

Joined: 11 Nov 2005
Posts: 26093
Location: Texas, USA

gbaddeley wrote:
Someone can read and comment on a thread that is many years old.


Though (for the record) it's probably better in that sense to start a new thread which has a link back to the previous one. It's unlikely (given the change in software levels) that an old thread is exactly relevant, but is certainly a worthwhile start.
_________________
Honesty is the best policy.
Insanity is the best defence.
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic  Reply to topic Page 1 of 1

MQSeries.net Forum Index » General IBM MQ Support » Is it possible to stop WMQ Tool from having mqm status?
Jump to:  



You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Protected by Anti-Spam ACP
 
 


Theme by Dustin Baccetti
Powered by phpBB © 2001, 2002 phpBB Group

Copyright © MQSeries.net. All rights reserved.