Skip to main content

Security considerations for distributed queuing (using CICS ISC) - Middleware News

Security considerations for distributed queuing (using CICS ISC) - Middleware News



This section discusses security considerations for the "CICS mover".

When defining and starting channels for the CICS mover, the transactions used require access to certain WebSphere MQ and CICS resources. The list below shows the transactions that are used for the CICS mover and the access requirements that might be needed. Security is not a mandatory requirement and these examples are only relevant where you are using resource security.

CKMC

This transaction requires RACF UPDATE access to the following resources:

* The CSQKCDF VSAM file in CICS
* The SYSTEM.CHANNEL.SEQNO local queue in WebSphere MQ
* The SYSTEM.CHANNEL.COMMAND local queue in WebSphere MQ

The CKMC transaction only needs RACF UPDATE access to the above resources under certain conditions:

* For the CSQKCDF file, only when the following functions are performed:
o CREATE a channel
o COPY a channel
o DELETE a channel
o ALTER a channel
* For the SYSTEM.CHANNEL.SEQNO local queue, only when the following functions are performed:
o RESYNC a channel
o RESET a channel
o RESOLVE a channel
* For the system.channel.command local queue when requesting stop for a channel.

All other functions only require RACF READ access.

CKSG

This transaction requires RACF READ access to the following resources:

* The CSQKCDF VSAM file in CICS

RACF UPDATE access to the following resources:

* The SYSTEM.CHANNEL.SEQNO local queue in WebSphere MQ
* The SYSTEM.CHANNEL.COMMAND local queue in WebSphere MQ
* The dead-letter queue (see Dead-letter queue security for information about how to achieve this)

and RACF ALTER access to the following resources:

* The transmission queue specified in the channel definition in WebSphere MQ

CKSV

This transaction requires RACF READ access to the following resources:

* The CSQKCDF VSAM file in WebSphere MQ

RACF UPDATE access to the following resources:

* The SYSTEM.CHANNEL.SEQNO local queue in WebSphere MQ
* The SYSTEM.CHANNEL.COMMAND local queue in WebSphere MQ
* The dead-letter queue (see Dead-letter queue security for information about how to achieve this)

and RACF ALTER access to the following resources:

* The transmission queue specified in the channel definition in WebSphere MQ

CKRQ


This transaction requires RACF READ access to the following resources:

* The CSQKCDF VSAM file in CICS

and RACF UPDATE access to the following resources:

* The SYSTEM.CHANNEL.SEQNO local queue in WebSphere MQ
* In WebSphere MQ, either
o The object name passed in the RemoteQName field of the MQXQH structure, or
o The transmission queue representing the remote queue manager, if the value in the RemoteQMgrName field of the MQXQH structure does not match the local queue manager name.
* In WebSphere MQ the SYSTEM.CHANNEL.COMMAND local queue
* The dead-letter queue (see Dead-letter queue security for information about how to achieve this)

CKRC

This transaction requires RACF READ access to the following resources:

* The CSQKCDF VSAM file in CICS

and RACF UPDATE access to the following resources:

* The SYSTEM.CHANNEL.SEQNO local queue in WebSphere MQ
* The SYSTEM.CHANNEL.COMMAND local queue
* In WebSphere MQ, either
o The object name passed in the RemoteQName field of the MQXQH structure, or
o The transmission queue representing the remote queue manager, if the value in the RemoteQmgrName field of the MQXQH structure does not match the local queue manager name

* The dead-letter queue (see Dead-letter queue security for information about how to achieve this)

Comments

adsrerrapop

Popular posts from this blog

Troubleshooting Java/JMS SSL Configurations - Middleware News

 This document is intended to help diagnose WebSphere MQ V7 Java™ or JMS SSL setup errors. It lists most of the common configuration errors that can cause an SSL connection from a Java/JMS client to a queue manager to fail, and gives the course of action to resolve the problem. In each case the error can be diagnosed by a combination of the error seen in the client log - either a console output, trace file or SystemOut.log file - and the queue manager's error logs. The document is quite long, so the easiest way to find the potential error is to search for one of the errors seen in this list, then filter this list using the error from the opposite end of the channel. All cases here assume that 2-way authentication is being attempted (SSLCAUTH set to REQUIRED on the queue manager's SVRCONN channel). This is the default, and the errors are very similar for 1-way authentication (SSLCAUTH set to OPTIONAL). Symptom Instructions on collecting documentation...

Using telnet to test connectivity between IBM Websphere MQ Client and MQ server - Middleware News

You are having trouble connecting a WebSphere MQ client to a MQ server, receiving errors that you can not connect to the MQ queue manager. One of the first things to determine is if the two machines can communicate, and using the telnet tool is one way to accomplish it. Symptom Receiving errors which state that a queue manager is not found or not available. Connection errors. For example: AMQ9213, AMQ9524, AMQ9202 or AMQ9508 or MQRC =2059 0x0000080b MQRC_Q_MGR_NOT_AVAILABLE. Please note, this is by no means an exclusive list of errors related to this type a problem but just a sample of some of the more common error messages and codes that might occur. Cause One possible cause is that the two machines can not communicate. May be the IP address or hostname was not properly specified by the MQ client. The port number might be incorrect. A queue manager is not running at the desired host. The queue manager could be running, but the corresponding listener is not runnin...

IBM Websphere MQ interview Questions Part 5

MQ Series: - It is an IBM web sphere product which is evolved in 1990’s. MQ series does transportation from one point to other. It is an EAI tool (Middle ware) VERSIONS:-5.0, 5.1, 5.3, 6.0, 7.0(new version). The currently using version is 6.2 Note: – MQ series supports more than 35+ operating systems. It is platform Independent. For every OS we have different MQ series software’s. But the functionality of MQ series Default path for installing MQ series is:- C: programfiles\BM\clipse\SDK30 C: programfiles\IBM\WebsphereMQ After installation it will create a group and user. Some middleware technologies are Tibco, SAP XI. MQ series deals with two things, they are OBJECTS, SERVICES. In OBJECTS we have • QUEUES • CHANNELS • PROCESS • AUTHENTICATION • QUERY MANAGER. In SERVICES we have LISTENERS. Objects: – objects are used to handle the transactions with the help of services. QUEUE MANAGER maintains all the objects and services. QUEUE: – it is a database structure ...