IBM Support

IT36926: ACE V11 DOESNT ALLOW WEBUSER WITH A ROLE AS CHARACTER '*' (STAR)

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • In IIB, a webuser can be created with the role as '*' in order
    to use the login username as the role. The mqsiwebuseradmin
    command is run as below
    
    
    mqsiwebuseradmin Node -c -u * -x -r *
    
    
    This would mean that every user is authenticated against the
    LDAP and the successfully authenticated username will be used as
    the role of the user. All authorization checks, whether its MQ
    or FIle, will be done against the logged-in username.
    
    
    However, ACE V11 doesnt allow running the command like above,
    and neither it treats the role '*' with any special meaning.
    

Local fix

  • -
    

Problem summary

  • ****************************************************************
    USERS AFFECTED:
    All users of IBM App Connect Enterprise V11 and V12  using MQ or
    File based authorization for administration security.
    
    
    Platforms affected:
    MultiPlatform
    
    ****************************************************************
    PROBLEM DESCRIPTION:
    In the earlier version of the product, such as IBM Integration
    Bus V10, a webuser can be created with the role as '*' in order
    to use the login username as the role. For this, the
    mqsiwebuseradmin command is run as below
    
      mqsiwebuseradmin Node -c -u * -x -r *
    
    The (above command) would mean that every user is authenticated
    against the LDAP and the successfully authenticated username
    will be used as the role of the user. All authorization checks,
    whether MQ or File, will be done against the logged-in username.
    
    However, ACE V11 and V12 do not allow running the command as
    above and do not treat the role '*' with any special meaning.
    

Problem conclusion

  • The product is fixed to allow the character star(*) to be
    specified as the role of a user in <span
    style="background-color:rgb(255, 255, 255)">mqsiwebuseradmin
    </span>comand.
    
    ---------------------------------------------------------------
    The fix is targeted for delivery in the following PTFs:
    
    Version    Maintenance Level
    v11.0      11.0.0.14
    v12.0      12.0.2.0
    
    The latest available maintenance can be obtained from:
    http://www-01.ibm.com/support/docview.wss?rs=849&uid=swg27006041
    
    If the maintenance level is not yet available,information on
    its planned availability can be found on:
    http://www-1.ibm.com/support/docview.wss?rs=849&uid=swg27006308
    ---------------------------------------------------------------
    

Temporary fix

Comments

APAR Information

  • APAR number

    IT36926

  • Reported component name

    APP CONNECT ENT

  • Reported component ID

    5724J0550

  • Reported release

    B00

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2021-06-04

  • Closed date

    2021-08-26

  • Last modified date

    2021-10-04

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    APP CONNECT ENT

  • Fixed component ID

    5724J0550

Applicable component levels

[{"Line of Business":{"code":"LOB45","label":"Automation"},"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSDR5J","label":"IBM App Connect Enterprise"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"B00"}]

Document Information

Modified date:
05 October 2021