ASG
IBM
Zystems
Cressida
Icon
Netflexity
 
  MQSeries.net
Search  Search       Tech Exchange      Education      Certifications      Library      Info Center      SupportPacs      LinkedIn  Search  Search                                                                   FAQ  FAQ   Usergroups  Usergroups
 
Register  ::  Log in Log in to check your private messages
 
RSS Feed - WebSphere MQ Support RSS Feed - Message Broker Support

MQSeries.net Forum Index » WebSphere Message Broker (ACE) Support » User with restricted broker access rights

Post new topic  This topic is locked: you cannot edit posts or make replies.
 User with restricted broker access rights « View previous topic :: View next topic » 
Author Message
oli
PostPosted: Mon Jul 02, 2012 9:56 pm    Post subject: User with restricted broker access rights Reply with quote

Acolyte

Joined: 14 Jul 2006
Posts: 68
Location: Germany

Hi all,

we are using WMB 7.0, OS is AIX 6.1.

We currently face the problem that we need special users that have broker admin rights only for specific brokers or execution groups. So putting such a user into mqbrkrs group is not a solution.

Is there a way to achieve this other than using the method described here: http://www.mqseries.net/phpBB2/viewtopic.php?t=57058

We already have setup users and groups to be used for connecting from Toolkit or MQ Explorer but we need users to be used for ssh connections ...


Thanks,

Oli
Back to top
View user's profile Send private message
jackson456
PostPosted: Sat Jul 14, 2012 1:55 am    Post subject: Reply with quote

Newbie

Joined: 12 Jul 2012
Posts: 1

hi, your post is really nice.

EDIT by exerk: This post has all the hallmarks of a spam first post, so it has been reported to site admin.
Back to top
View user's profile Send private message
fjb_saper
PostPosted: Sat Jul 14, 2012 9:11 am    Post subject: Re: User with restricted broker access rights Reply with quote

Grand High Poobah

Joined: 18 Nov 2003
Posts: 20756
Location: LI,NY

oli wrote:
Hi all,

we are using WMB 7.0, OS is AIX 6.1.

We currently face the problem that we need special users that have broker admin rights only for specific brokers or execution groups. So putting such a user into mqbrkrs group is not a solution.

Is there a way to achieve this other than using the method described here: http://www.mqseries.net/phpBB2/viewtopic.php?t=57058

We already have setup users and groups to be used for connecting from Toolkit or MQ Explorer but we need users to be used for ssh connections ...


Thanks,

Oli

Oli, can you please be a little bit more specific in your last sentence?
Your whole writeup has nothing to do with ssh or telnet... so how does that figure into the picture now?
By the way you do realize you can setup the MQ Channel to force the need for an SSL connection right?. Toolkit and WMBE will communicate via a svrconn channel. This channel should be made secure (SSL).

Have fun
_________________
MQ & Broker admin
Back to top
View user's profile Send private message Send e-mail
oli
PostPosted: Sun Jul 15, 2012 9:10 pm    Post subject: Reply with quote

Acolyte

Joined: 14 Jul 2006
Posts: 68
Location: Germany

I try to describe a little bit more in detail. We have already set up users and groups that have the desired access rightss to brokers and execution groups when using Message Broker Toolkit. In addition to that we use BlockIP2.

Now we like to have OS users/groups that also have limited access to Message Broker objects when connecting through SSH and using command line tools on the AIX machine.

I hope it's clearer now what we like to have

Thanks, Oli
Back to top
View user's profile Send private message
fjb_saper
PostPosted: Mon Jul 16, 2012 7:02 am    Post subject: Reply with quote

Grand High Poobah

Joined: 18 Nov 2003
Posts: 20756
Location: LI,NY

Assign the users to the same groups you already use for the toolkit...
I expect that you turned security on for the broker
_________________
MQ & Broker admin
Back to top
View user's profile Send private message Send e-mail
bruce2359
PostPosted: Tue Jul 17, 2012 1:12 pm    Post subject: Reply with quote

Poobah

Joined: 05 Jan 2008
Posts: 9469
Location: US: west coast, almost. Otherwise, enroute.

Moved to Message Broker forum.
_________________
I like deadlines. I like to wave as they pass by.
ב''ה
Lex Orandi, Lex Credendi, Lex Vivendi. As we Worship, So we Believe, So we Live.
Back to top
View user's profile Send private message
lancelotlinc
PostPosted: Wed Jul 18, 2012 5:26 am    Post subject: Reply with quote

Jedi Knight

Joined: 22 Mar 2010
Posts: 4941
Location: Bloomington, IL USA

For V8, sudo is used extensively. With the help from advice from an IBM PMR, you could potentially move that direction for later V7 fixpacks.
_________________
http://leanpub.com/IIB_Tips_and_Tricks
Save $20: Coupon Code: MQSERIES_READER
Back to top
View user's profile Send private message Send e-mail
Display posts from previous:   
Post new topic  This topic is locked: you cannot edit posts or make replies. Page 1 of 1

MQSeries.net Forum Index » WebSphere Message Broker (ACE) Support » User with restricted broker access rights
Jump to:  



You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Protected by Anti-Spam ACP
 
 


Theme by Dustin Baccetti
Powered by phpBB © 2001, 2002 phpBB Group

Copyright © MQSeries.net. All rights reserved.