ASG
IBM
Zystems
Cressida
Icon
Netflexity
 
  MQSeries.net
Search  Search       Tech Exchange      Education      Certifications      Library      Info Center      SupportPacs      LinkedIn  Search  Search                                                                   FAQ  FAQ   Usergroups  Usergroups
 
Register  ::  Log in Log in to check your private messages
 
RSS Feed - WebSphere MQ Support RSS Feed - Message Broker Support

MQSeries.net Forum Index » IBM MQ Security » BlockIP2 vs. Channel Auth Records

Post new topic  Reply to topic
 BlockIP2 vs. Channel Auth Records « View previous topic :: View next topic » 
Author Message
oli
PostPosted: Tue Jun 09, 2015 10:58 pm    Post subject: BlockIP2 vs. Channel Auth Records Reply with quote

Acolyte

Joined: 14 Jul 2006
Posts: 68
Location: Germany

Hi all,

with MQ 7 we were using BlockIP2 and used a configuration to allow access for specific user from specific IPs. I wonder if it's possible to use MQ 8's Channel Auth Records to do the same thing: Allow access from specific IPs only for specific users.

Can anybody answer this question?

Thanks, Oli
Back to top
View user's profile Send private message
Skalli
PostPosted: Wed Jun 10, 2015 3:37 am    Post subject: Reply with quote

Newbie

Joined: 08 Jun 2015
Posts: 5

Yep. "SET CHLAUTH() TYPE(ADRESSMAP) ADDRESS(...)"

See the following, which is the best descirption I know of how to use CHLAUTH: http://www.mqug.org.uk/downloads/201207/201207%20-%20WMQ02%20-%20WMQ%20Channel%20Authentication.pdf
Back to top
View user's profile Send private message
Vitor
PostPosted: Wed Jun 10, 2015 4:33 am    Post subject: Reply with quote

Grand High Poobah

Joined: 11 Nov 2005
Posts: 26093
Location: Texas, USA

Skalli wrote:
See the following, which is the best descirption I know of how to use CHLAUTH: http://www.mqug.org.uk/downloads/201207/201207%20-%20WMQ02%20-%20WMQ%20Channel%20Authentication.pdf


Or any of the links Morag (the author) has posted on this forum to her other materials. Which are universally excellent on this subject.
_________________
Honesty is the best policy.
Insanity is the best defence.
Back to top
View user's profile Send private message
oli
PostPosted: Wed Jun 10, 2015 9:10 am    Post subject: Reply with quote

Acolyte

Joined: 14 Jul 2006
Posts: 68
Location: Germany

But as far as I see the type ADDRESSMAP only takes into account the IP address from where the connection is initiated, not the IP address in combination with the provided user id. In BlockIP2 I can map an IP/user combination to an MCA user ...

Am I wrong?
Back to top
View user's profile Send private message
Vitor
PostPosted: Wed Jun 10, 2015 9:27 am    Post subject: Reply with quote

Grand High Poobah

Joined: 11 Nov 2005
Posts: 26093
Location: Texas, USA

oli wrote:
In BlockIP2 I can map an IP/user combination to an MCA user ...


And you can do the same with channel authority records. Maybe not a single record.....

Question - why would you test a user again an IP address? Is it not restrictive given that many users will be using dynamic IP addresses? What has led you to this choice over (for example) SSL?

I'm wondering if there's another way to achieve your requirement more simply.
_________________
Honesty is the best policy.
Insanity is the best defence.
Back to top
View user's profile Send private message
fjb_saper
PostPosted: Wed Jun 10, 2015 9:48 am    Post subject: Reply with quote

Grand High Poobah

Joined: 18 Nov 2003
Posts: 20696
Location: LI,NY

oli wrote:
But as far as I see the type ADDRESSMAP only takes into account the IP address from where the connection is initiated, not the IP address in combination with the provided user id. In BlockIP2 I can map an IP/user combination to an MCA user ...

Am I wrong?

In the usermap specify an IP or IP range. This should do it for you.
_________________
MQ & Broker admin
Back to top
View user's profile Send private message Send e-mail
oli
PostPosted: Wed Jun 10, 2015 10:10 am    Post subject: Reply with quote

Acolyte

Joined: 14 Jul 2006
Posts: 68
Location: Germany

@Vitor
SSL is not really an option in our environment. The user/IP check is sufficient for us as it is not a production environment.

@fjb_saper
I will check this.

Thanks
Back to top
View user's profile Send private message
Vitor
PostPosted: Wed Jun 10, 2015 10:39 am    Post subject: Reply with quote

Grand High Poobah

Joined: 11 Nov 2005
Posts: 26093
Location: Texas, USA

oli wrote:
@Vitor
SSL is not really an option in our environment. The user/IP check is sufficient for us as it is not a production environment.


SSL is easier if it's non-Prod; you can create your own CA....

...but whatever works for you....
_________________
Honesty is the best policy.
Insanity is the best defence.
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic  Reply to topic Page 1 of 1

MQSeries.net Forum Index » IBM MQ Security » BlockIP2 vs. Channel Auth Records
Jump to:  



You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Protected by Anti-Spam ACP
 
 


Theme by Dustin Baccetti
Powered by phpBB © 2001, 2002 phpBB Group

Copyright © MQSeries.net. All rights reserved.