|
RSS Feed - WebSphere MQ Support
|
RSS Feed - Message Broker Support
|
 |
|
MQ Advance Message Security |
« View previous topic :: View next topic » |
Author |
Message
|
mq__quest |
Posted: Thu Nov 02, 2017 8:56 pm Post subject: MQ Advance Message Security |
|
|
Apprentice
Joined: 21 Aug 2017 Posts: 49
|
KC says AMS is available with MQ Client, can a ams enabled mq client be used to send and receive encrypted messages to/from non ams enabled mq server component? |
|
Back to top |
|
 |
exerk |
Posted: Fri Nov 03, 2017 12:09 am Post subject: |
|
|
 Jedi Council
Joined: 02 Nov 2006 Posts: 6339
|
If you mean AMS-encrypted, no. _________________ It's puzzling, I don't think I've ever seen anything quite like this before...and it's hard to soar like an eagle when you're surrounded by turkeys. |
|
Back to top |
|
 |
mq__quest |
Posted: Fri Nov 03, 2017 5:25 am Post subject: |
|
|
Apprentice
Joined: 21 Aug 2017 Posts: 49
|
exerk wrote: |
If you mean AMS-encrypted, no. |
Yes, AMS encryption. If it can't then what is the purpose of having AMS included in client? SSL already does the encryption right? |
|
Back to top |
|
 |
Vitor |
Posted: Fri Nov 03, 2017 5:28 am Post subject: |
|
|
 Grand High Poobah
Joined: 11 Nov 2005 Posts: 26093 Location: Texas, USA
|
mq__quest wrote: |
exerk wrote: |
Yes, AMS encryption. If it can't then what is the purpose of having AMS included in client? SSL already does the encryption right? |
|
AMS requires a specific client that can prove it's allowed to receive the decrypted data. If you could retrieve the data from an encrypted queue by connecting with a normal client, that devalues the protection AMS provides. _________________ Honesty is the best policy.
Insanity is the best defence. |
|
Back to top |
|
 |
RogerLacroix |
Posted: Fri Nov 03, 2017 12:40 pm Post subject: |
|
|
 Jedi Knight
Joined: 15 May 2001 Posts: 3264 Location: London, ON Canada
|
Vitor wrote: |
If you could retrieve the data from an encrypted queue by connecting with a normal client, that devalues the protection AMS provides. |
Be careful with that line. The queue is not encrypted but rather the message and anyone with the correct OAM permission can get the message. The difference is that one user may not be able to decrypt the message, hence, they will receive a buffer of what appears to be crap.
i.e. An MQAmin that uses 'mqm' on Linux/Unix can browse/read all messages on a queue. The difference is that AMS will not decrypt if 'mqm' is not on the recipients list. Hence, 'mqm' will get the raw encrypted data.
Regards,
Roger Lacroix
Capitalware Inc. _________________ Capitalware: Transforming tomorrow into today.
Connected to MQ!
Twitter |
|
Back to top |
|
 |
|
|
 |
|
Page 1 of 1 |
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
|
|
|