ASG
IBM
Zystems
Cressida
Icon
Netflexity
 
  MQSeries.net
Search  Search       Tech Exchange      Education      Certifications      Library      Info Center      SupportPacs      LinkedIn  Search  Search                                                                   FAQ  FAQ   Usergroups  Usergroups
 
Register  ::  Log in Log in to check your private messages
 
RSS Feed - WebSphere MQ Support RSS Feed - Message Broker Support

MQSeries.net Forum Index » WebSphere Message Broker (ACE) Support » mqsicredentials conectivity to LDAP

Post new topic  Reply to topic
 mqsicredentials conectivity to LDAP « View previous topic :: View next topic » 
Author Message
Lone_Wanderer
PostPosted: Mon May 06, 2024 6:54 am    Post subject: mqsicredentials conectivity to LDAP Reply with quote

Novice

Joined: 16 Jan 2017
Posts: 10

Hi all,

We migrated to ACE12 from IIB and I'm reviewing some of our old installation scripts.

One of them states: mqsisetdbparms $IIBname -n ldap::LDAP -u "$LDAPaccount" -p "$LDAPaccountPwd"

Which stored credentials to be used anytime we wanted to access LDAP. Now, with ACE, I would like to use a Vault for those creds, but that has me little cofused. The command would be:

mqsicredentials $IIBname --create --credential-type ldap --credential-name $LDAPaccount --password $LDAPaccountPwd

However, now the real confusion sets in. We Use LDAP for Authorization and Authentication of incoming requests via our SOAPInput nodes. We had a security profile, which referred to a set of LDAP groups, that authenticated and authorized the user and this profile (along with policy sets and bindings) was referenced in the SOAPInput node.

But, when using the mqsicredentials command, it's not clear to me if ACE will "just use it" when trying to access LDAP, like it did with aforementioned mqsisetdbparms command. The old command was set up in a way, that any connection to any LDAP will use those credentials, however no such behaviour is documented with mqsicredentials.

Do I need to use mqsicredentials along with Security Profile? If so, how do I reffer it and from where?

The goal is the move those credentials to a Vault, but from documentation, it's not clear to me how to do it in this specific case.

Kind Regards

I also found this: https://www.ibm.com/docs/en/app-connect/12.0?topic=authorization-configuring-ldap
which clearly instructs to use mqsisetdbparms. This is disappointing.
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic  Reply to topic Page 1 of 1

MQSeries.net Forum Index » WebSphere Message Broker (ACE) Support » mqsicredentials conectivity to LDAP
Jump to:  



You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Protected by Anti-Spam ACP
 
 


Theme by Dustin Baccetti
Powered by phpBB © 2001, 2002 phpBB Group

Copyright © MQSeries.net. All rights reserved.