Home

 

Changing and revoking access to a WebSphere MQ object

 

To change the level of access that a user or group has to an object, use the setmqaut command. To revoke the access of a particular user that is a member of a group that has authorization, remove the user from the group, as described in Creating and managing groups.

The user ID that creates a WebSphere MQ object is granted full control authorities to that object. If you remove this user ID from the local mqm group (or the Administrators group on Windows systems) these authorities are not revoked. Use the setmqaut control command or the MQCMD_DELETE_AUTH_REC PCF command to revoke access to an object for the user ID that created it, after removing it from the mqm or Administrators group. For a full definition of the setmqaut control command and its syntax, see setmqaut (grant or revoke authority), and for a full definition of the MQCMD_INQUIRE_ENTITY_AUTH PCF command and its syntax, see the WebSphere MQ Programmable Command Formats and Administration Interface book.

 

Parent topic:

Using the OAM to control access to objects


fa13250_


 

Home