13.07.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

The authority service component provided with <strong>WebSphere</strong> MQ is called theObject Authority Manager (OAM). The OAM is automatically enabled for eachqueue manager. If you do not want any authority checks, you can disable theOAM.The OAM maintains an access control list (ACL) for each <strong>WebSphere</strong> MQ objectit is controlling access to. On UNIX systems only group IDs can appear in anACL. This means that all members of a group have the same authority. OnWindows, both user IDs and group IDs can appear in an ACL. This means thatauthorities can be granted to individual users as well as groups. The controlcommand setmqaut grants and revokes authorities and is used to maintain ACL.You can specify any number of authorizations in a single command. Forexample, the list of authorizations permits a user or group to put messages onthe queue and to browse them, but to revoke access to get messages thefollwing is used:+put +browse -getThe following example shows how to use the setmqaut command to grant andrevoke permissions to use an object.setmqaut -m QM1 -t queue -n ITSO.QUEUE -g ITSOGROUP +put +browse -getIn this example:► QM1 is the Queue Manager.► queue is the object type.► ITSO.QUEUE is the object name.► ITSOGROUP is the identifier of the group whose authorizations are to change.► +put +browse -get is the authorization list for the specified queue:– +put adds authorization to put (MQPUT) messages on the queue– +browse adds the authorization to browse messages on the queue (toissue MQGET with the browse option)– -get removes authorization to get (MQGET) messages from the queueSSL SupportMany times, it is required to secure data transmitting over an insecure network.<strong>WebSphere</strong> MQ supports SSL Version 3.0 on UNIX (installed with <strong>WebSphere</strong>MQ), Windows (Windows 200 has SSL support integral to the operatingsystems) and z/OS (SSL support is integral to the z/OS operating system).168 <strong>IBM</strong> <strong>WebSphere</strong> <strong>V5.0</strong> <strong>Security</strong> Handbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!