ASG
IBM
Zystems
Cressida
Icon
Netflexity
 
  MQSeries.net
Search  Search       Tech Exchange      Education      Certifications      Library      Info Center      SupportPacs      LinkedIn  Search  Search                                                                   FAQ  FAQ   Usergroups  Usergroups
 
Register  ::  Log in Log in to check your private messages
 
RSS Feed - WebSphere MQ Support RSS Feed - Message Broker Support

MQSeries.net Forum Index » IBM MQ Security » MQexplorer read only user group -AMQ4036

Post new topic  Reply to topic Goto page Previous  1, 2
 MQexplorer read only user group -AMQ4036 « View previous topic :: View next topic » 
Author Message
amitjain
PostPosted: Wed Apr 22, 2015 7:17 am    Post subject: Reply with quote

Apprentice

Joined: 14 Jan 2015
Posts: 39

Thanks mqjeff.

Thanks exerk for Morag Hughson's various blogs

Now I understand the purpose of AUTHINFO objects.

After defining authinfo properly I am able to connect to LDAP from MQ and also able to connect MQ explorer using my windows credential.
Back to top
View user's profile Send private message
amitjain
PostPosted: Wed Apr 29, 2015 4:02 am    Post subject: AMQ4401 - MQ explorer issue Reply with quote

Apprentice

Joined: 14 Jan 2015
Posts: 39

Hi,

I have defined the group unx-appsupp on windows and on linux when I execute below command I get the proper output.

~/mq_scripts ] $ getent group unx-appsupp
unx-appsupp:*:111515:ajain

I have given setmqaut to this group and those commands get executed successfully.

Also I have defined
DEFINE AUTHINFO for LDAP and it shows connected in below command

DIS QMSTATUS ALL


But when I try to acess through MQ explorer on windows it gives me AMQ4401 error and AMQERR01.log suggest my userid ajain does not have permission on

SYSTEM.MQEXPLORER.REPLY.MODEL
SYSTEM.ADMIN.COMMAND.QUEUE

But I have given the permission to the group unx-appsupp to which I belong.

setmqaut -n SYSTEM.MQEXPLORER.REPLY.MODEL -t q -g "unx-appsupp" +dsp +inq +get
setmqaut -n SYSTEM.ADMIN.COMMAND.QUEUE -t q -g "unx-appsupp" +dsp +inq +put

If i give setmqaut to -p ajain it works.

Please help me to understand what I am doing wrong while doing setmqaut at group level. I don't want to give individual person setmqaut.

One more thing , If I create local unix group and add my id to that group and give setmqaut to local unix group it works fine.

I am not able to make it work with only windows group.
Back to top
View user's profile Send private message
amitjain
PostPosted: Wed Apr 29, 2015 4:14 am    Post subject: Reply with quote

Apprentice

Joined: 14 Jan 2015
Posts: 39

:~/mq_scripts ] $ groups ajain
ajain : unx-is splunk unx-appsupp
Back to top
View user's profile Send private message
amitjain
PostPosted: Wed Apr 29, 2015 5:38 am    Post subject: Reply with quote

Apprentice

Joined: 14 Jan 2015
Posts: 39

Don't know but it started working fine now.

In windows AD I have changed my unix primary group id to unx-appsupp and it started working fine.

I am again perform all steps from beginning for new group and new queue manager and check how it works.
Back to top
View user's profile Send private message
mqjeff
PostPosted: Wed Apr 29, 2015 5:41 am    Post subject: Reply with quote

Grand Master

Joined: 25 Jun 2008
Posts: 17447

amitjain wrote:
unix primary group id
Back to top
View user's profile Send private message
amitjain
PostPosted: Wed Apr 29, 2015 5:46 am    Post subject: Reply with quote

Apprentice

Joined: 14 Jan 2015
Posts: 39

Could you please point me to some documentation to understand how primary group things work in context of MQ.

I was thinking it will check what all groups I am member of and according pick matching profile of setmqaut.

Thanks.
Back to top
View user's profile Send private message
amitjain
PostPosted: Wed Apr 29, 2015 5:47 am    Post subject: Reply with quote

Apprentice

Joined: 14 Jan 2015
Posts: 39

:~/mq_scripts ] $ groups ajain
ajain : unx-appsupp splunk tg dev all unx-beauchamp


peviously unx-is was primary and now I have unx-appsupp as primary.
Back to top
View user's profile Send private message
fjb_saper
PostPosted: Wed Apr 29, 2015 7:27 am    Post subject: Reply with quote

Grand High Poobah

Joined: 18 Nov 2003
Posts: 20696
Location: LI,NY

Well it depends on multiple factors.
Say you have just been added to a group. Before that change becomes effective you have to:
  • run refresh security on the qmgr (mqsc)
  • log out and log back in on the server

So really there is no easy way to tell why something works or does not.
_________________
MQ & Broker admin
Back to top
View user's profile Send private message Send e-mail
Display posts from previous:   
Post new topic  Reply to topic Goto page Previous  1, 2 Page 2 of 2

MQSeries.net Forum Index » IBM MQ Security » MQexplorer read only user group -AMQ4036
Jump to:  



You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Protected by Anti-Spam ACP
 
 


Theme by Dustin Baccetti
Powered by phpBB © 2001, 2002 phpBB Group

Copyright © MQSeries.net. All rights reserved.