Professional Documents
Culture Documents
Agenda
Highlights of WMB 7.0 security
WMB 7.0 and earlier components
Broker administration security
Activating
Authorization queues
Authorization levels
Examples
Deactivating
Command changes
Migration – Configmgr ACLs and WMB v7 support
General debugging techniques
Summary
MQ MQ
Configuration
Manager
Toolkit, CMP API
Apps, IS02, Brokers
deploy commands
MQ
Broker commands
MQ
MQ
Broker commands
Examples:
Command changes
-s option added to
mqsicreatebroker
• Security is disabled by default
mqsichangebroker
• -s values = active, inactive
mqsideletebroker
• -s option optionally deletes
SYSTEM.BROKER.AUTH.* queues
Principals
WMB ACLs (prior to v7) WMB v7 support
Username Yes
Group name yes
Machine/domain name SSL/exits
All machines Yes
Principal type
WMB ACLs (prior to v7) WMB v7 support
User Yes
Group Yes
Object type
WMB ACLs (prior to v7) WMB v7 support
ConfigManagerProxy NA
PubSubTopology NA
Broker Yes
ExecutionGroup Yes
Subscription NA
TopicRoot NA
Permissions
WMB ACLs (prior to v7) WMB v7 support
V - View access read
F – Full control Read,write,execute
NA Execute
Summary
W MB 7.0 security
Simplified
Relies on W MQ security model
Configmgr and user name server removed in W MB 7.0
W MB 7.0 broker administration security can be activated/
deactivated
mqsicreatebroker, mqsichangebroker, and
mqsideletebroker command changed to include –s option
Migration of Configmgr ACLs is manual
Use mqsilistaclentry output and tables to migrate ACLs
View a webcast replay with step-by-step instructions for using the Service Request (SR)
tool for submitting problems electronically:
http://www.ibm.com/software/websphere/support/d2w.html
Sign up to receive weekly technical My Notifications emails:
http://www.ibm.com/software/support/einfo.html