Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 6003461
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 23, 20262026-05-23T01:07:30+00:00 2026-05-23T01:07:30+00:00

Has anyone experienced an issue where WAS does not use the Windows username when

  • 0

Has anyone experienced an issue where WAS does not use the Windows username when connecting to a Websphere MQ resource? None of our developer boxes have ever experienced this problem in the past, they’ve been able to send the username through for MQ to do authorization. But we have a new developer machine that does not appear to be sending the username, and thus the connection to MQ can’t be made.

We tried specifying a J2C authentication alias to the QCF with a DefaultPrincipalMapping, but that didn’t work.

SOLUTION: Found out that the problem was that the server was installed and running as a Windows service. When we created a new server profile which was run by the user and not as a service, it used the Windows username when connecting to MQ.

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-23T01:07:30+00:00Added an answer on May 23, 2026 at 1:07 am

    I suspect the problem might actually be the opposite of what you are describing. In older versions of WAS if the User ID field of the Connection Factory panel was left blank, WAS would send a blank ID. WebSphere MQ would have no value to pass along to the Object Authority Manager and so the channel would run under authority of the Message Channel Agent’s process – which is always administrative. Thus, older versions of WAS commonly ran with administrative rights, although this was not widely recognized as such. You can verify this by looking at the status of the running channel and see if the MCAUSER field is blank.

    Newer versions of WAS now try a bit harder to find an ID to send to WMQ if the configuration panel is blank. Because of this new installations and upgrades of existing installations often fail to authorize to WMQ using the same channel that previously worked.

    The interesting part of all this is that the only way this is an issue is if the QMgr has a blank value on the MCAUSER channel attribute. If the QMgr has a blank MCAUSER and no exit is setting MCAUSER at CONNECT time, then the channel allows administrative access. If the channel does not have SSL with SSLPEER set or an exit to authenticate the connection then that administrative access is available to anonymous users. Why is this an issue? Because WebSphere MQ comes with the ability to initiate OS commands based on arrival of a message. This means that any user with WMQ admin rights can remotely execute arbitrary OS commands as a feature of the software. It follows that this capability MUST be locked down, even from legitimate applications if there is to be any accountability of the messages flowing through the network.

    The fact that your app is able to present an ID that succeeds and another ID that fails would seem to indicate that the QMgr is allowing administrative access and, I would wager, doing so for anonymous connections. D’oh! MUCH better to fix the QMgr’s security than to fix the connection problem by setting the “right” ID in WAS. For more on this, see the Hardening WebSphere MQ presentation from the IMPACT conference.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

Has anyone had experience using these two technologies in tandem? What are (if any)
Has anyone had experience taking a full-fledged Java desktop application and replicating the functionality
Has anyone had any experience targetting WSH in the way that VBScript , JScript
Has anyone got much experience deploying applications to Amazons EC2? I am considering doing
Has anyone had any experience in building a 'real world' application with the Smart
Has anyone had any experience scaling out SQL Server in a multi reader single
I read somewhere that snprintf is faster than ostringstream. Has anyone has any experiences
Has anyone built a website with IronPython and ASP.NET. What were your experiences and
I am wondering if anyone has any experience using a JQuery plugin that converts
I'm wondering if anyone has any experience using log4net in a multi-threaded environment like

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.