ASG
IBM
Zystems
Cressida
Icon
Netflexity
 
  MQSeries.net
Search  Search       Tech Exchange      Education      Certifications      Library      Info Center      SupportPacs      LinkedIn  Search  Search                                                                   FAQ  FAQ   Usergroups  Usergroups
 
Register  ::  Log in Log in to check your private messages
 
RSS Feed - WebSphere MQ Support RSS Feed - Message Broker Support

MQSeries.net Forum Index » IBM MQ Security » unable to setmqaut

Post new topic  Reply to topic
 unable to setmqaut « View previous topic :: View next topic » 
Author Message
Felix
PostPosted: Wed Mar 14, 2012 6:50 am    Post subject: unable to setmqaut Reply with quote

Newbie

Joined: 18 Jan 2012
Posts: 9
Location: Bangalore

Hi,

I am having issue while authenticating a user from another machine on the mq-server.

I have 2 Linux machines with different logins on each of them.
1. Machine1 [MQ server is installed here, and my Queue Manager is created here] with mqBox as userid
2. machine2 [MQ client is installed here] with myuser as userid

When I try to setmqaut on Machine1 for machine2, I see this error:
Code:

bin$] setmqaut -m my_qm -t qmgr  -p myuser +all
AMQ7026: A principal or group name was invalid.

bin$] setmqaut -m my_qm -t qmgr  -p Machine2:myuser +all
AMQ7026: A principal or group name was invalid.

bin$] setmqaut -m my_qm -t qmgr  -p myuser@Machine2 +all
AMQ7026: A principal or group name was invalid.

I get the error - "AMQ7026: A principal or group name was invalid."

I saw the IBM public library, but could not make out much from it.

Please let me know if I am missing something here.
_________________
-
Felix
Back to top
View user's profile Send private message
bruce2359
PostPosted: Wed Mar 14, 2012 7:01 am    Post subject: Reply with quote

Poobah

Joined: 05 Jan 2008
Posts: 9469
Location: US: west coast, almost. Otherwise, enroute.

Did you do some research on the AMQ7026 error? On google, for example?
_________________
I like deadlines. I like to wave as they pass by.
ב''ה
Lex Orandi, Lex Credendi, Lex Vivendi. As we Worship, So we Believe, So we Live.
Back to top
View user's profile Send private message
mqjeff
PostPosted: Wed Mar 14, 2012 7:05 am    Post subject: Reply with quote

Grand Master

Joined: 25 Jun 2008
Posts: 17447

What have you done on box 1 to make it aware of the ids that exist on box 2?

Why do you expect that you can trust the userid that is presented by a remote application? How do you know that the machine in question is not compromised, and someone has now created a userid called 'mqm' on that box?
Back to top
View user's profile Send private message
exerk
PostPosted: Wed Mar 14, 2012 7:26 am    Post subject: Reply with quote

Jedi Council

Joined: 02 Nov 2006
Posts: 6339

And it is NOT A GOOD IDEA to use principals on *nix-based systems.
_________________
It's puzzling, I don't think I've ever seen anything quite like this before...and it's hard to soar like an eagle when you're surrounded by turkeys.
Back to top
View user's profile Send private message
fjb_saper
PostPosted: Wed Mar 14, 2012 8:45 am    Post subject: Reply with quote

Grand High Poobah

Joined: 18 Nov 2003
Posts: 20756
Location: LI,NY

Authorize the group, set a member of the group on the MCAUser of the channel and use SSL to secure the channel (don't forget to set the peer values)

Have fun
_________________
MQ & Broker admin
Back to top
View user's profile Send private message Send e-mail
Display posts from previous:   
Post new topic  Reply to topic Page 1 of 1

MQSeries.net Forum Index » IBM MQ Security » unable to setmqaut
Jump to:  



You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Protected by Anti-Spam ACP
 
 


Theme by Dustin Baccetti
Powered by phpBB © 2001, 2002 phpBB Group

Copyright © MQSeries.net. All rights reserved.