MQ Authenticate User Security Exit Overview
The MQ Authenticate User Security Exit v1.2.3 is a new solution that allows a company to fully authenticate a user who is accessing a WebSphere MQ resource. It verifies the User's UserID and Password (and possibly Domain Name) against the server's native OS system (or domain controller) or a remote LDAP server.
The security exit will operate with WebSphere MQ v5.3 and v6.0 (and MQSeries v5.2) in Windows, Unix and Linux environments. It works with the Server Connection Channels and / or Client Connection Channels of WebSphere MQ queue manager.
The MQ Authenticate User Security Exit solution is comprised of 2 components: client-side security exit and server-side security exit.
Client-Side Security Exit Summary
- The client-side security exit is available in 3 forms:
- Windows DLL
- Java JAR
- Non-GUI shared library for AIX, HP-UX, Linux and Solaris
- The client-side security exit has been tested against the following MQ client programs:
- IBM's MQ Explorer
- SupportPac MO71 (MQMon)
- IBM's WBIMB Eclipse Tool Kit
- Mercury's SiteScope
- Capitalware's MQ Visual Edit, MQ Visual Browse & MQ Batch Toolkit
- Any program that uses Client Channel Tables (i.e. SupportPac MS03, WatchQ, etc.)
Server-Side Security Exit Summary
- The server-side security exit is available in 2 forms:
- Windows DLL
- Non-GUI shared library for AIX, HP-UX, Linux and Solaris
- The server-side security exit major features are:
- Authenticate a user against the server's native OS (or against a File) or a remote LDAP server
- Support for Proxy UserIDs
- Allow or restrict the incoming IP address against a regular expression pattern
- Limit the number of incoming channel connections on a SVRCONN channel.
- Allow or restrict the use of 'mqm', 'MUSER_MQADMIN' or 'mqm' UserIDs
- Ability to turn off server-side authentication
- Allow or restrict the incoming UserID against a regular expression pattern when authentication is off
- Provides logging capability for all connecting client applications regardless if they were successful or not.
- Server-Side Security Exit has been tested against and is supported for the following LDAP servers:
- Microsoft's Active Directory for Windows 2000 Server or higher
- Novell's eDirectory v8 or higher
- OpenLDAP v2.1 or higher
- z/OS Integrated Security Services LDAP Server v1.6 or higher
Pricing
- The client-side security exits are included for FREE and can be distributed to an unlimited number of remote servers or PCs with MQ client applications (the user only pays for the server-side licenses).
- The server-side security exits are provided in the format of a native DLL / shared library and are currently available for AIX, HP-UX, Linux, Solaris and Windows. The pricing of Capitalware's MQ Authenticate User Security Exit solution is on a 'per queue manager' basis.
| Operating System | MQ v5.3 | MQ v6.0 |
| AIX v5.1, v5.2 & v5.3 | 32-bit | 64-bit |
| HP-UX RISC v11.00 & v11.11 | 32-bit | 64-bit |
| Linux x86 | 32-bit | 32-bit |
| Linux x86_64 | n/a | 64-bit |
| Linux on POWER | n/a | 64-bit |
| Linux on zSeries | 32-bit | 32-bit & 64-bit |
| Solaris SPARC v8, v9 & v10 | 32-bit | 64-bit |
| Solaris x86_64 v10 | n/a | 64-bit |
| Windows NT, 2000, 2003 & XP Pro | 32-bit | 32-bit |
| Product | Price (USD) * | Ordering |
| MQ Authenticate User Security Exit (per license**) | $499.00 | |
| Yearly maintenance and support fee | 15% | |
| Total | $574.00 | Order Now |
* Volume discounts available for as low as $299.00 USD per license plus 15% yearly maintenance and support fee.
** MQ Authenticate User Security Exit is licensed on a per queue manager basis.
- Each licensed user will receive:
- Full version of MQ Authenticate User Security Exit
- Free updates / upgrades to any version 1.x release.
- Free email support
- Free forum support
| Enterprise License for MQ Authenticate User Security Exit: |
| Enterprise License for MQ Authenticate User Security Exit sells for a MSRP of $90,000 USD plus 15% yearly maintenance and support fee. An enterprise license will allow a company to have unlimited number of queue managers use MQ Authenticate User Security Exit at an unlimited number of locations. |
