1 Feb 2012 19:24
Re: MQ V7.1 CHLAUTH Odd Behaviour
now I seem to have an issue with "older" MQ Clients -- apps using MQ V7.0.1.2 clients connecting to MQ V7.1 seem to work OK as long as I don't try to apply channel authentication mapping rules.... the client authentication mapping rules seem to be completely ignored when an app connects with the "older" client versions. I wonder if T. Rob or Roger have seen this problem?
From: "Derek" <dhornby5-Bhb0V27niACOppBP9C4UkQ@public.gmane.org>
To: MQSERIES-0lvw86wZMd9k/bWDasg6f+2wyY2g16FtwPuJ0ROkVbw@public.gmane.org
Sent: Thursday, January 26, 2012 7:08:40 AM
Subject: Re: Fw: MQ V7.1 CHLAUTH Odd Behaviour
I guess, but these are "single app usage" servers, so it would be
reasonable to accept almost any Id from them.... I don't think I am
willing to tighten up the requirements any more than I have now, given
that I would be causing conflict with all the app managers
On 1/26/2012 6:50 AM, David C. Partridge wrote:
> You can't trust the ID that a client presents to the channel - it is so easy to fake it - if necessary using a security exit at the client end. SSL authorisation with SSLCAUTH only I hope!
>
> Dave
>
> ________________________________
>
> From: MQSeries List [mailto:MQSERIES <at> LISTSERV.MEDUNIWIEN.AC.AT] On Behalf Of Derek
> Sent: 26 January 2012 11:22
> To: MQSERIES-0lvw86wZMd9k/bWDasg6f+2wyY2g16FtwPuJ0ROkVbw@public.gmane.org
> Subject: Re: Fw: MQ V7.1 CHLAUTH Odd Behaviour
>
>
> not bad Morag but you left out the IP addresses on the rules.... When the client IP addresses are used, I am then pretty sure that client1 and client2 are on servers that are locked in a data center and protected by the OS authentication (which actually uses Centrify and AD, but that's another story....)
>
> To unsubscribe, write to LISTSERV-0lvw86wZMd9k/bWDasg6f+2wyY2g16FtwPuJ0ROkVbw@public.gmane.org and,
> in the message body (not the subject), write: SIGNOFF MQSERIES
> Instructions for managing your mailing list subscription are provided in
> the Listserv General Users Guide available at http://www.lsoft.com
> Archive: http://listserv.meduniwien.ac.at/archives/mqser-l.html
>
To unsubscribe, write to LISTSERV-0lvw86wZMd9k/bWDasg6f+2wyY2g16FtwPuJ0ROkVbw@public.gmane.org and,
in the message body (not the subject), write: SIGNOFF MQSERIES
Instructions for managing your mailing list subscription are provided in
the Listserv General Users Guide available at http://www.lsoft.com
Archive: http://listserv.meduniwien.ac.at/archives/mqser-l.html
From: "Derek" <dhornby5-Bhb0V27niACOppBP9C4UkQ@public.gmane.org>
To: MQSERIES-0lvw86wZMd9k/bWDasg6f+2wyY2g16FtwPuJ0ROkVbw@public.gmane.org
Sent: Thursday, January 26, 2012 7:08:40 AM
Subject: Re: Fw: MQ V7.1 CHLAUTH Odd Behaviour
I guess, but these are "single app usage" servers, so it would be
reasonable to accept almost any Id from them.... I don't think I am
willing to tighten up the requirements any more than I have now, given
that I would be causing conflict with all the app managers
On 1/26/2012 6:50 AM, David C. Partridge wrote:
> You can't trust the ID that a client presents to the channel - it is so easy to fake it - if necessary using a security exit at the client end. SSL authorisation with SSLCAUTH only I hope!
>
> Dave
>
> ________________________________
>
> From: MQSeries List [mailto:MQSERIES <at> LISTSERV.MEDUNIWIEN.AC.AT] On Behalf Of Derek
> Sent: 26 January 2012 11:22
> To: MQSERIES-0lvw86wZMd9k/bWDasg6f+2wyY2g16FtwPuJ0ROkVbw@public.gmane.org
> Subject: Re: Fw: MQ V7.1 CHLAUTH Odd Behaviour
>
>
> not bad Morag but you left out the IP addresses on the rules.... When the client IP addresses are used, I am then pretty sure that client1 and client2 are on servers that are locked in a data center and protected by the OS authentication (which actually uses Centrify and AD, but that's another story....)
>
> To unsubscribe, write to LISTSERV-0lvw86wZMd9k/bWDasg6f+2wyY2g16FtwPuJ0ROkVbw@public.gmane.org and,
> in the message body (not the subject), write: SIGNOFF MQSERIES
> Instructions for managing your mailing list subscription are provided in
> the Listserv General Users Guide available at http://www.lsoft.com
> Archive: http://listserv.meduniwien.ac.at/archives/mqser-l.html
>
To unsubscribe, write to LISTSERV-0lvw86wZMd9k/bWDasg6f+2wyY2g16FtwPuJ0ROkVbw@public.gmane.org and,
in the message body (not the subject), write: SIGNOFF MQSERIES
Instructions for managing your mailing list subscription are provided in
the Listserv General Users Guide available at http://www.lsoft.com
Archive: http://listserv.meduniwien.ac.at/archives/mqser-l.html
List Archive - Manage Your List Settings - Unsubscribe
Instructions for managing your mailing list subscription are provided in the Listserv General Users Guide available at http://www.lsoft.com
RSS Feed