|
RSS Feed - WebSphere MQ Support
|
RSS Feed - Message Broker Support
|
 |
|
MQ AMS - enabling AMS on a single queue manager in a cluster |
« View previous topic :: View next topic » |
Author |
Message
|
subhmq |
Posted: Wed Oct 18, 2017 11:31 am Post subject: MQ AMS - enabling AMS on a single queue manager in a cluster |
|
|
Newbie
Joined: 01 Jul 2014 Posts: 3
|
Hello MQ Security Gurus,
I am new to MQ AMS and looking for answers for below questions.
Basically I am creating a new queue manager and clustering with existing queue managers. I would like to enable MQ AMS only on this new queue manager and receive messages from existing queue managers in the cluster and others via cluster queues and queue manager hopping.
1. Is it possible to setup security policies to encrypt data only on cluster local queues on a queue manager and put messages from other queue managers in the cluster. I tried this and got the error 'AMQ9034: Message does not have a valid protection type.'.
To rephrase my question,
I could setup policies for java clients without enabling AMS on java clients by using MCA interception. I would like to know if MCA interception can be setup for messages coming via cluster channels without enabling AMS on remote queue managers.
Note:- New queue manager will be using MQ V9.
Thanks in advance for any feedback or suggestions. |
|
Back to top |
|
 |
Vitor |
Posted: Wed Oct 18, 2017 12:01 pm Post subject: Re: MQ AMS - enabling AMS on a single queue manager in a clu |
|
|
 Grand High Poobah
Joined: 11 Nov 2005 Posts: 26093 Location: Texas, USA
|
subhmq wrote: |
1. Is it possible to setup security policies to encrypt data only on cluster local queues on a queue manager and put messages from other queue managers in the cluster. I tried this and got the error 'AMQ9034: Message does not have a valid protection type.'. |
No. AMS protects messages end to end; that's the point. If it's unprotected when it's put, then it can't be considered protected (from an MQ software point of view) when it arrives.
subhmq wrote: |
I could setup policies for java clients without enabling AMS on java clients by using MCA interception. I would like to know if MCA interception can be setup for messages coming via cluster channels without enabling AMS on remote queue managers. |
No, so far as I'm aware. Someone may know better than me.
More generally, what's the requirement here? How is a message sensitive enough to be protected by AMS when it's delivered to a queue, but not sensitive when it's in transit? _________________ Honesty is the best policy.
Insanity is the best defence. |
|
Back to top |
|
 |
subhmq |
Posted: Wed Oct 18, 2017 12:33 pm Post subject: |
|
|
Newbie
Joined: 01 Jul 2014 Posts: 3
|
Vitor,
Thanks a lot for your quick response.
More generally, what's the requirement here?
My requirement is to encrypt the messages at rest.
Basically, we are setting up the new queue manager as a multi-instance,
so the queue manager uses NFS storage for encryption. So, requirement is to encrypt anything that gets stored on network storage. That is why I would like to enable AMS only for the queues on new multi-instance queue manager.
How is a message sensitive enough to be protected by AMS when it's delivered to a queue, but not sensitive when it's in transit?
For encrypting the data in transit, we have SSL enabled on all the channels.
Please suggest if you can think of any alternatives to AMS for encrypting queue data at rest.
Hello everyone,
Please share if any of you have come across similar requirement. Thanks. |
|
Back to top |
|
 |
Vitor |
Posted: Wed Oct 18, 2017 12:48 pm Post subject: |
|
|
 Grand High Poobah
Joined: 11 Nov 2005 Posts: 26093 Location: Texas, USA
|
subhmq wrote: |
My requirement is to encrypt the messages at rest. |
If it was me (and obviously it's not) I'd encrypt the contact admin disk itself through hardware / firmware. _________________ Honesty is the best policy.
Insanity is the best defence. |
|
Back to top |
|
 |
RogerLacroix |
Posted: Thu Oct 26, 2017 3:30 pm Post subject: |
|
|
 Jedi Knight
Joined: 15 May 2001 Posts: 3264 Location: London, ON Canada
|
subhmq wrote: |
Please suggest if you can think of any alternatives to AMS for encrypting queue data at rest. |
You should have a look at MQ Message Encryption.
Regards,
Roger Lacroix
Capitalware Inc. _________________ Capitalware: Transforming tomorrow into today.
Connected to MQ!
Twitter |
|
Back to top |
|
 |
|
|
 |
|
Page 1 of 1 |
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
|
|
|