<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
	>
<channel>
	<title>Comments for Store and Forward</title>
	<atom:link href="http://t-rob.net/comments/feed/" rel="self" type="application/rss+xml" />
	<link>https://t-rob.net</link>
	<description>A blog about securing and using WebSphere MQ</description>
	<lastBuildDate>Wed, 14 Dec 2011 16:15:24 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>Comment on Credit card security fail by Doug</title>
		<link>https://t-rob.net/2011/11/02/credit-card-security-fail/#comment-120</link>
		<dc:creator>Doug</dc:creator>
		<pubDate>Wed, 14 Dec 2011 16:15:24 +0000</pubDate>
		<guid isPermaLink="false">https://t-rob.net/?p=479#comment-120</guid>
		<description>I was 45 minutes into talking to someone at my local bank branch when we shifted over to the topic of security. I asked if they were improving the online security, perhaps to some sort of two-factor authentication device like the RSA Key. (Answer: No.)   I made an offhanded comment that their security was annoying lax. She asked &quot;what do you mean?&quot;

I pointed out:  We&#039;ve been making all sorts of changes to my personal account, and yet you haven&#039;t even asked me for ID.

She turned red, and stammered briefly.

&quot;And THAT&#039;s why I&#039;m asking for better security for my online bank access.&quot; I told her.
(And I&#039;m not getting it, because apparently nobody asks these obvious questions.)</description>
		<content:encoded><![CDATA[<p>I was 45 minutes into talking to someone at my local bank branch when we shifted over to the topic of security. I asked if they were improving the online security, perhaps to some sort of two-factor authentication device like the RSA Key. (Answer: No.)   I made an offhanded comment that their security was annoying lax. She asked &#8220;what do you mean?&#8221;</p>
<p>I pointed out:  We&#8217;ve been making all sorts of changes to my personal account, and yet you haven&#8217;t even asked me for ID.</p>
<p>She turned red, and stammered briefly.</p>
<p>&#8220;And THAT&#8217;s why I&#8217;m asking for better security for my online bank access.&#8221; I told her.<br />
(And I&#8217;m not getting it, because apparently nobody asks these obvious questions.)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Encrypting passwords in config files &#8211; secure or not? by T.Rob</title>
		<link>https://t-rob.net/2011/10/24/encrypting-passwords-in-config-files-secure-or-not/#comment-101</link>
		<dc:creator>T.Rob</dc:creator>
		<pubDate>Thu, 03 Nov 2011 17:33:42 +0000</pubDate>
		<guid isPermaLink="false">https://t-rob.net/?p=475#comment-101</guid>
		<description>@Gustav - We actually found a bug this way at WSTC Berlin.  The WMQ Security Lab has a note that one should make keystores read-only at run time and never world or group readable.  One of the students misunderstood and set the keystore perms to read-only *before* generating the Cert Signing Request.  The iKeyman GUI was obviously unable to write the keystore but never raised an error!

So, yes absolutely, I&#039;m trying to get information added to the docs about things that are not strictly WMQ configuration, including making keystores and configuration files private to the owner.  I already mention this in the security presentations and articles so the word is starting to get out.  Of course, we also raised a defect for iKeyman to throw an error for non-writable keystores.

Hope to see you at the next WSTC and keep those comments and suggestions coming.  They help me justify the changes to the docs and feature requests - and they keep me on my toes!</description>
		<content:encoded><![CDATA[<p>@Gustav &#8211; We actually found a bug this way at WSTC Berlin.  The WMQ Security Lab has a note that one should make keystores read-only at run time and never world or group readable.  One of the students misunderstood and set the keystore perms to read-only *before* generating the Cert Signing Request.  The iKeyman GUI was obviously unable to write the keystore but never raised an error!</p>
<p>So, yes absolutely, I&#8217;m trying to get information added to the docs about things that are not strictly WMQ configuration, including making keystores and configuration files private to the owner.  I already mention this in the security presentations and articles so the word is starting to get out.  Of course, we also raised a defect for iKeyman to throw an error for non-writable keystores.</p>
<p>Hope to see you at the next WSTC and keep those comments and suggestions coming.  They help me justify the changes to the docs and feature requests &#8211; and they keep me on my toes!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Encrypting passwords in config files &#8211; secure or not? by Gustav</title>
		<link>https://t-rob.net/2011/10/24/encrypting-passwords-in-config-files-secure-or-not/#comment-98</link>
		<dc:creator>Gustav</dc:creator>
		<pubDate>Tue, 25 Oct 2011 18:54:33 +0000</pubDate>
		<guid isPermaLink="false">https://t-rob.net/?p=475#comment-98</guid>
		<description>Thanks for the interesting article Rob, I commented on this at one of your sessions at the Düsseldorf WebSphere conference last year :)
The obfuscated stash file may give the administrator a false sense of security and I think an important security reminder could be to always make it mq service user readable only.</description>
		<content:encoded><![CDATA[<p>Thanks for the interesting article Rob, I commented on this at one of your sessions at the Düsseldorf WebSphere conference last year <img src='https://t-rob.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
The obfuscated stash file may give the administrator a false sense of security and I think an important security reminder could be to always make it mq service user readable only.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on WMQ Security in v7.1 by Kalpana</title>
		<link>https://t-rob.net/2011/10/18/wmq-security-in-v7-1/#comment-96</link>
		<dc:creator>Kalpana</dc:creator>
		<pubDate>Wed, 19 Oct 2011 06:51:59 +0000</pubDate>
		<guid isPermaLink="false">https://t-rob.net/?p=471#comment-96</guid>
		<description>Informative crisp article for WMQ 7.1 security features. Very nice.</description>
		<content:encoded><![CDATA[<p>Informative crisp article for WMQ 7.1 security features. Very nice.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Hang on &#8211; switching hosting providers by T.Rob</title>
		<link>https://t-rob.net/2011/04/23/hang-on-switching-hosting-providers/#comment-88</link>
		<dc:creator>T.Rob</dc:creator>
		<pubDate>Wed, 20 Jul 2011 17:48:36 +0000</pubDate>
		<guid isPermaLink="false">https://t-rob.net/?p=422#comment-88</guid>
		<description>Hi Dave - The move was just a bit rocky but successful in the end.  The Archives page was supposed to have an index of posts but I was unable to get it to work after the move.  I&#039;m not sure whether it had to do with the WordPress upgrade conflicting with the theme I&#039;m using, something with the new hosting platform (not likely, I think) or something altogether different.  In any case, I&#039;ve been so caught up in the transition at work (more on that in the next post) that I just nixed the page from the menu and moved on.  Also, the email list which was powered by Mailman at Webzpro was a complete loss.  I hope to have a replacement sometime in August or September.  On a positive note, I did get SSL set up on the new host site.</description>
		<content:encoded><![CDATA[<p>Hi Dave &#8211; The move was just a bit rocky but successful in the end.  The Archives page was supposed to have an index of posts but I was unable to get it to work after the move.  I&#8217;m not sure whether it had to do with the WordPress upgrade conflicting with the theme I&#8217;m using, something with the new hosting platform (not likely, I think) or something altogether different.  In any case, I&#8217;ve been so caught up in the transition at work (more on that in the next post) that I just nixed the page from the menu and moved on.  Also, the email list which was powered by Mailman at Webzpro was a complete loss.  I hope to have a replacement sometime in August or September.  On a positive note, I did get SSL set up on the new host site.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Hang on &#8211; switching hosting providers by David Awerbuch</title>
		<link>https://t-rob.net/2011/04/23/hang-on-switching-hosting-providers/#comment-87</link>
		<dc:creator>David Awerbuch</dc:creator>
		<pubDate>Wed, 20 Jul 2011 14:54:13 +0000</pubDate>
		<guid isPermaLink="false">https://t-rob.net/?p=422#comment-87</guid>
		<description>Hi T.Rob,

So .... did the rehosting cutover succeed?   you never updated the home page after what was supposed to be the April move.


Also,what happened to your page http://t-rob.net/archives  ?? 

Thanks, 
Dave</description>
		<content:encoded><![CDATA[<p>Hi T.Rob,</p>
<p>So &#8230;. did the rehosting cutover succeed?   you never updated the home page after what was supposed to be the April move.</p>
<p>Also,what happened to your page <a href="http://t-rob.net/archives" rel="nofollow">http://t-rob.net/archives</a>  ?? </p>
<p>Thanks,<br />
Dave</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Handy IMPACT conference cross reference by T.Rob</title>
		<link>https://t-rob.net/2011/03/29/handy-impact-conference-cross-reference/#comment-81</link>
		<dc:creator>T.Rob</dc:creator>
		<pubDate>Sat, 02 Apr 2011 04:46:39 +0000</pubDate>
		<guid isPermaLink="false">https://t-rob.net/?p=409#comment-81</guid>
		<description>Sorry Andy!  I saw it listed that way somewhere and thought you had a dedicated handle just for WebSphere stuff.  I&#039;ve corrected it and if I find where I got that, I&#039;ll let you know.</description>
		<content:encoded><![CDATA[<p>Sorry Andy!  I saw it listed that way somewhere and thought you had a dedicated handle just for WebSphere stuff.  I&#8217;ve corrected it and if I find where I got that, I&#8217;ll let you know.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Handy IMPACT conference cross reference by andy piper</title>
		<link>https://t-rob.net/2011/03/29/handy-impact-conference-cross-reference/#comment-80</link>
		<dc:creator>andy piper</dc:creator>
		<pubDate>Fri, 01 Apr 2011 23:43:49 +0000</pubDate>
		<guid isPermaLink="false">https://t-rob.net/?p=409#comment-80</guid>
		<description>hey T.Rob. Nice guide - you&#039;ve managed to mangle my Twitter handle somehow though :-)</description>
		<content:encoded><![CDATA[<p>hey T.Rob. Nice guide &#8211; you&#8217;ve managed to mangle my Twitter handle somehow though <img src='https://t-rob.net/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on WMQ File Transfer Edition launched by Kim</title>
		<link>https://t-rob.net/2008/12/07/wmq-file-transfer-edition-launched/#comment-56</link>
		<dc:creator>Kim</dc:creator>
		<pubDate>Wed, 09 Feb 2011 01:46:05 +0000</pubDate>
		<guid isPermaLink="false">http://t-rob.net/?p=191#comment-56</guid>
		<description>Probably worth noting that when the agent starts up, it needs to read the agent.properties file and others in the coordination queue manager config directory as well as write out a file to that directory. So if you have installed as another user, and wish to run as a different user, then need to ensure the different user has permissions to read and write to the config directories!</description>
		<content:encoded><![CDATA[<p>Probably worth noting that when the agent starts up, it needs to read the agent.properties file and others in the coordination queue manager config directory as well as write out a file to that directory. So if you have installed as another user, and wish to run as a different user, then need to ensure the different user has permissions to read and write to the config directories!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Mission:Messaging: Migration, failover, and scaling in a WebSphere MQ cluster by T.Rob</title>
		<link>https://t-rob.net/2008/12/02/missionmessaging-migration-failover-and-scaling-in-a-websphere-mq-cluster/#comment-55</link>
		<dc:creator>T.Rob</dc:creator>
		<pubDate>Sat, 15 Jan 2011 18:23:09 +0000</pubDate>
		<guid isPermaLink="false">http://t-rob.net/?p=177#comment-55</guid>
		<description>Hi Hatcher,

Yes, Fix Packs are cumulative.  If you have any version of v7 you can apply v7.0.1.3 over top of it.</description>
		<content:encoded><![CDATA[<p>Hi Hatcher,</p>
<p>Yes, Fix Packs are cumulative.  If you have any version of v7 you can apply v7.0.1.3 over top of it.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

