SV-89575r1_rule
V-74901
SRG-APP-000177-AS-000126
MQMH-AS-001020
CAT II
10
Specify LDAP as the authentication method for each queue manager.
To access the MQ Appliance CLI, enter:
mqcli
runmqsc [queue manager name]
DEFINE AUTHINFO('[Object name e.g., USE.CRLLDAP]')
AUTHTYPE(CRLLDAP)
CONNAME('[LDAPhost1(port)]') REPLACE
Type "end" to exit runmqsc mode.
To access the MQ Appliance CLI, for each queue manager, enter:
mqcli
To identify the queue managers, enter:
dspmq
For each queue manager identified, run the command:
runmqsc [queue name]
DIS AUTHINFO(*) AUTHTYPE(CRLLDAP) CONNAME
Verify that an "AUTHINFO" definition of "AUTHTYPE(CRLLDAP)" is displayed and that the CONNAME in parenthesis is the host name or IPv4 dotted decimal address of an organizationally approved LDAP server.
If the "AUTHINFO" definition is not equal to "AUTHTYPE(CRLLDAP)", this is a finding.
V-74901
False
MQMH-AS-001020
To access the MQ Appliance CLI, for each queue manager, enter:
mqcli
To identify the queue managers, enter:
dspmq
For each queue manager identified, run the command:
runmqsc [queue name]
DIS AUTHINFO(*) AUTHTYPE(CRLLDAP) CONNAME
Verify that an "AUTHINFO" definition of "AUTHTYPE(CRLLDAP)" is displayed and that the CONNAME in parenthesis is the host name or IPv4 dotted decimal address of an organizationally approved LDAP server.
If the "AUTHINFO" definition is not equal to "AUTHTYPE(CRLLDAP)", this is a finding.
M
3239