Skip to main content

WebSphere MQ 8.0 LDAP Authorization - Middleware News

LDAP Authorization

The V8.0.0 Connection Authentication feature which checked your user ID and password has been extended in V8.0.0.2 to allow LDAP authorization as well. The new fields that allow you to configure this on an AUTHTYPE(IDPWLDAP) Authentication Information object are protected by the 801 Command Level.
New Attribute MQSC name
See DEF AUTHINFO
Look for
PCF constant and values
See Create Authentication Information
Look for
LDAP Auth Method
AUTHORMD
  • OS
  • SEARCHGRP
  • SEARCHUSR
MQIA_LDAP_AUTHORMD (263)
  • MQLDAP_AUTHORMD_OS (0)
  • MQLDAP_AUTHORMD_SEARCHGRP (1)
  • MQLDAP_AUTHORMD_SEARCHUSR (2)
LDAP Group Object Class CLASSGRP
MQCA_LDAP_GROUP_OBJECT_CLASS (2133)
  • String of length MQ_LDAP_CLASS_LENGTH (128)
LDAP Base DN Group BASEDNG
MQCA_LDAP_BASE_DN_GROUPS (2132)
  • String of length MQ_LDAP_BASE_DN_LENGTH (1024)
LDAP Group Attr Field GRPFIELD
MQCA_LDAP_GROUP_ATTR_FIELD (2134)
  • String of length MQ_LDAP_FIELD_LENGTH (128)
LDAP Find Group FINDGRP
MQCA_LDAP_FIND_GROUP_FIELD (2135)
  • String of length MQ_LDAP_FIELD_LENGTH (128)
LDAP Group Nesting
NESTGRP
  • NO
  • YES
MQIA_LDAP_NESTGRP (264)
  • MQLDAP_NESTGRP_NO (0)
  • MQLDAP_NESTGRP_YES (1)

Channel Status

Channels now show the security protocol in use – helping those people who were unsure how to answer the oft-asked question after the POODLE vulnerability, “are you still using an SSL CipherSpec?” Now instead of looking up your CipherSpec in the table in Knowledge Center, you can instead see this information output in the channel status display. Read more about this in Know your protocol.
New Attribute MQSC name PCF constant and values
Security Protocol
SECPROT
  • NONE
  • SSLV3
  • TLSV1
  • TLSV12
MQIACH_SECURITY_PROTOCOL (1645)
  • MQSECPROT_NONE (0)
  • MQSECPROT_SSLV30 (1)
  • MQSECPROT_TLSV10 (2)
  • MQSECPROT_TLSV12 (4)

AMQP Channel

In support of the MQLight in IBM MQ Beta, there is a whole new channel type with an associated set of channel attributes added. This is not yet documented in Knowledge Center but is visible when operating a queue manager at Command Level 801, and in the header files for PCF applications. Along with the Beta download that enables some of these attributes, there is a PDF of instructions on how to use the attributes available at the above link for the Beta. Be aware that although you can view and set all these attributes, not all of them are implemented by the current Beta. Get involved with the Beta program and read the PDF file mentioned above to see which attributes are currently usable.
New Attribute MQSC name PCF constant and values
Channel Type
CHLTYPE
  • AMQP
MQIACH_CHANNEL_TYPE (1511)
  • MQCHT_AMQP (11)
Description DESCR
MQCACH_DESC (3502)
  • String of length MQ_CHANNEL_DESC_LENGTH
Port PORT
MQIACH_PORT (1522)
  • Value in the range 1 – 65335
Local Address LOCLADDR
MQCACH_LOCAL_ADDRESS (3520)
  • String of length MQ_LOCAL_ADDRESS_LENGTH
SSL/TLS Certificate Label CERTLABL
MQCA_CERT_LABEL (2121)
  • String of length MQ_CERT_LABEL_LENGTH
SSL/TLS Cipher Spec SSLCIPH
MQCACH_SSL_CIPHER_SPEC (3544)
  • String of length MQ_SSL_CIPHER_SPEC_LENGTH
SSL/TLS Client Auth SSLCAUTH
MQIACH_SSL_CLIENT_AUTH (1568)
  • String of length MQ_SSL_CIPHER_SPEC_LENGTH
SSL/TLS Peer Name SSLPEER
MQCACH_SSL_PEER_NAME (3545)
  • String of length MQ_SSL_PEER_NAME_LENGTH
Alteration Date ALTDATE
MQCA_ALTERATION_DATE (2027)
  • String of length MQ_DATE_LENGTH
Alteration Time ALTTIME
MQCA_ALTERATION_TIME (2028)
  • String of length MQ_TIME_LENGTH
AMQP Keep Alive AMQPKA
MQIACH_AMQP_KEEP_ALIVE (1644)
  • Values in the range 0 – 99 999
  • MQKAI_AUTO
Use Client Identifier
USECLTID
  • YES
  • NO
MQIACH_USE_CLIENT_ID (1629)
  • MQUCI_YES (1)
  • MQUCI_NO (0)
Max Message Length MAXMSGL
MQIACH_MAX_MSG_LENGTH (1510)
  • Values in the range 0 – 100MB
MCA UserId MCAUSER
MQCACH_MCA_USER_ID (3527)
  • String of length MQ_MCA_USER_ID_LENGTH
Max Instances MAXINST
MQIACH_MAX_INSTANCES (1618)
  • Values in the range 0 – 999 999 999

Display Connection

With the introduction of the AMQP channel in CommandLevel 801, there is also a new attribute returned when you display application connections.
New Attribute MQSC name PCF constant and values
AMQP Client ID CLIENTID
MQCACF_AMQP_CLIENT_ID (3207)
  • String of length MQ_AMQP_CLIENT_ID_LENGTH (256)

Comments

adsrerrapop

Popular posts from this blog

Troubleshooting Java/JMS SSL Configurations - Middleware News

 This document is intended to help diagnose WebSphere MQ V7 Java™ or JMS SSL setup errors. It lists most of the common configuration errors that can cause an SSL connection from a Java/JMS client to a queue manager to fail, and gives the course of action to resolve the problem. In each case the error can be diagnosed by a combination of the error seen in the client log - either a console output, trace file or SystemOut.log file - and the queue manager's error logs. The document is quite long, so the easiest way to find the potential error is to search for one of the errors seen in this list, then filter this list using the error from the opposite end of the channel. All cases here assume that 2-way authentication is being attempted (SSLCAUTH set to REQUIRED on the queue manager's SVRCONN channel). This is the default, and the errors are very similar for 1-way authentication (SSLCAUTH set to OPTIONAL). Symptom Instructions on collecting documentation...

Using telnet to test connectivity between IBM Websphere MQ Client and MQ server - Middleware News

You are having trouble connecting a WebSphere MQ client to a MQ server, receiving errors that you can not connect to the MQ queue manager. One of the first things to determine is if the two machines can communicate, and using the telnet tool is one way to accomplish it. Symptom Receiving errors which state that a queue manager is not found or not available. Connection errors. For example: AMQ9213, AMQ9524, AMQ9202 or AMQ9508 or MQRC =2059 0x0000080b MQRC_Q_MGR_NOT_AVAILABLE. Please note, this is by no means an exclusive list of errors related to this type a problem but just a sample of some of the more common error messages and codes that might occur. Cause One possible cause is that the two machines can not communicate. May be the IP address or hostname was not properly specified by the MQ client. The port number might be incorrect. A queue manager is not running at the desired host. The queue manager could be running, but the corresponding listener is not runnin...

IBM Websphere MQ interview Questions Part 5

MQ Series: - It is an IBM web sphere product which is evolved in 1990’s. MQ series does transportation from one point to other. It is an EAI tool (Middle ware) VERSIONS:-5.0, 5.1, 5.3, 6.0, 7.0(new version). The currently using version is 6.2 Note: – MQ series supports more than 35+ operating systems. It is platform Independent. For every OS we have different MQ series software’s. But the functionality of MQ series Default path for installing MQ series is:- C: programfiles\BM\clipse\SDK30 C: programfiles\IBM\WebsphereMQ After installation it will create a group and user. Some middleware technologies are Tibco, SAP XI. MQ series deals with two things, they are OBJECTS, SERVICES. In OBJECTS we have • QUEUES • CHANNELS • PROCESS • AUTHENTICATION • QUERY MANAGER. In SERVICES we have LISTENERS. Objects: – objects are used to handle the transactions with the help of services. QUEUE MANAGER maintains all the objects and services. QUEUE: – it is a database structure ...