T.Rob Wyatt of IoPT Consulting will be giving a webinar on issues/problems with/using CONNAUTH and CHLAUTH:
https://www.imwuc.org/p/ca/vi/sid=435
Date: November 30, 2016 at 01:00 PM EST
Description:
Native MQ password authentication (CONNAUTH) introduced in IBM MQ v8.0 has gotten off to a rough start. As of Fix Pack 8.0.0.5, the interaction between CONNAUTH and CHLAUTH has exhibited 5 distinct behaviors. After applying Fix Packs some of these cause hard failures while others silently over-authorize client users, leaving the queue manager exposed. This webcast will present findings from our CONNAUTH/CHLAUTH security research as well as recommendations for MQ users and the audit community.
I STRONGLY recommend all MQAdmins attend this webinar.
Regards,
Roger Lacroix
Capitalware Inc.