QuestionQ45

Manage Security

Following an upgrade to WebSphere Application Server ND 9.0.5, a JMS application that uses an indirect JNDI lookup cannot connect to the MQ Queue Manager and receives an MQRC_NOT_AUTHORIZED exception.

Which Queue Connection Factory property can be set to fix the error?

Explanation

WebSphere Application Server only flows the credentials from a J2C authentication alias configured on a Queue Connection Factory when the application obtains the connection through an indirect JNDI lookup - that is, the application looks up a resource-reference name (java:comp/env/...) that the deployment descriptor maps to the real connection factory, with the resource-reference's res-auth setting configured for container sign-on. In that indirect-lookup scenario it is specifically the Container-managed authentication alias on the connection factory that WebSphere applies to authenticate to the queue manager; for a direct JNDI lookup of the connection factory's own JNDI name, WebSphere deliberately ignores the configured alias for security reasons and instead flows the identity of the user that started the server, which is what produces MQRC_NOT_AUTHORIZED after an upgrade changes this behavior or exposes a previously-masked misconfiguration. The Component-managed authentication alias only comes into play for res-auth=Application (component-managed) connections, and XA recovery alias and username/password fields address XA recovery and application-supplied credentials respectively, not the indirect-lookup case described here.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!