Category Archives: WMQ Security

WebSphere MQ Security-related posts.

Managing CA-signed certificates

MQ Admins are getting serious about TLS channels these days, but it isn’t always easy because there’s a fairly steep learning curve.  Though there is plenty of documentation for the MQ aspects, and for X.509 and TLS itself, very little … Continue reading

Posted in Security, WMQ, WMQ Security | Tagged , , , , , , , | 9 Comments

MQ V8 Certification

Would it surprise you to know there’s an MQ V8 System Administration certification?  Normally I run down and take the test as soon as it’s available but this one has been out since January 14th and somehow I missed the … Continue reading

Posted in News, Security, WMQ, WMQ AMS, WMQ ESE, WMQ FTE, WMQ Security | Tagged , , , , , , , , | 22 Comments

Avoiding reputational damage

Everyone knows that data breaches are expensive.  Security venders never tire of telling us exactly how expensive breaches are, on a per-incident or per-record basis.  In the case of a large retail brand, a breach can make a significant dent … Continue reading

Posted in Security, WMQ, WMQ Security | Tagged , , , , , , | 2 Comments

Configuration backups: the forgotten WMQ security control

Update: IBM has reconsidered and has announced that dmpmqcfg will be fixed as a defect! Subscribe if you would like a notification when the fix is announced. But please do read the post, especially if you are using amqoamd for … Continue reading

Posted in Fail, General, IIB, Security, WMQ, WMQ AMS, WMQ ESE, WMQ FTE, WMQ Security | Tagged , , , , , , , | Leave a comment

Cluster security

Well, the residency to write the new WebSphere MQ Security book is past the halfway point and we are working diligently to finish up on time. I’m happy to say that one of my favorite new security topics is covered … Continue reading

Posted in Events, News, Publications, WMQ, WMQ Security | Tagged , , , , , , , , , , | 1 Comment

Thoughts on certificate sharing

The topic of certificate sharing keeps popping up as of late so I wanted to address it here.  The main objection to certificate-based crypto seems to be the administrative overhead.  After having scripted up certificate management for several customers, I … Continue reading

Posted in WMQ, WMQ AMS, WMQ Security | Tagged , , , , , , , , , , , | Leave a comment

PCI zone and non PCI zone in same DataPower box

I’ve been having PCI Déjà vu lately.  It seems the same questions keep coming up over and over.  One strategy for compliance that is nearly ubiquitous is to segregate the PCI data from the rest of the network.  In practical terms, … Continue reading

Posted in General, WMQ Security | Tagged , , , , , , | 4 Comments