APAR status
Closed as program error.
Error description
This happens if the queue manager has been started automatically at the time the appliance is rebooted. The internal ID mqsystem is incorrectly being looked up via LDAP. The runmqsc program abends with a not-authorized error message to the screen and AMQ5531 in the error logs. AMQ8135 Not authorized AMQ5531: Error locating user or group in LDAP The LDAP authentication and authorization service has failed in the ldap_search call while trying to find user or group 'mqsystem'
Local fix
Restart the queue manager manually using the strmqm command.
Problem summary
**************************************************************** USERS AFFECTED: Users of the MQ Appliance where the queue manager is configured to start automatically at boot time. Platforms affected: MultiPlatform **************************************************************** PROBLEM DESCRIPTION: The early part of queue manager startup establishes some records in the OAM for the user that has started the queue manager. When strmqm is run manually from the mqcli, this user is "mqsystem". When strmqm is run automatically during system boot, then this user is "root". Accordingly the queue manager's OAM has different records, depending upon whether the queue manager was started manually or automatically. In the automatic case, the OAM has no records for "mqsystem" at a later moment when the queue manager switches over to using LDAP for its user/group repository. At this time, when runmqsc is run from the mqcli, it runs as user mqsystem, and the queue manager queries the LDAP repository for a user of this name. Normally such a user does not exist in the user's LDAP repository, and the search correctly fails, leading to the abend of runmqsc. The queue manager should not have queried LDAP for the user "mqsystem", as this is an ID internal to the MQ Appliance.
Problem conclusion
The queue manager code has been corrected so that it will not query the LDAP repository for the username "mqsystem". --------------------------------------------------------------- The fix is targeted for delivery in the following PTFs: Version Maintenance Level v8.0 8.0.0.11 v9.1 CD 9.1.1 v9.1 LTS 9.1.0.1 The latest available maintenance can be obtained from 'WebSphere MQ Recommended Fixes' http://www-1.ibm.com/support/docview.wss?rs=171&uid=swg27006037 If the maintenance level is not yet available information on its planned availability can be found in 'WebSphere MQ Planned Maintenance Release Dates' http://www-1.ibm.com/support/docview.wss?rs=171&uid=swg27006309 ---------------------------------------------------------------
Temporary fix
Comments
APAR Information
APAR number
IT25172
Reported component name
IBM MQ APPL M20
Reported component ID
5725Z0900
Reported release
800
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt / Xsystem
Submitted date
2018-05-25
Closed date
2018-06-28
Last modified date
2018-07-19
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
IBM MQ APPL M20
Fixed component ID
5725Z0900
Applicable component levels
[{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SS5K6E","label":"IBM MQ Appliance"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"8.0","Edition":"","Line of Business":{"code":"LOB36","label":"IBM Automation"}}]
Document Information
Modified date:
19 July 2018