MQAUSX Security Bulletin

Yesterday, it was discovered that MQAUSX has a security issue of a high priority. If your IniFile is using UseAuthOrder and AuthOrder keywords and if the any of the parameters of AuthOrder keyword are disabled then all incoming connections are allowed.
i.e.

UseAuthOrder = Y
AuthOrder = ldap files mqausx
UseLDAP = N

A fix is available for this bug. Please contact Capitalware Support immediately for the fix. For an interim fix, either disable UseAuthOrder or make sure none of the authentication components listed in AuthOrder are disabled.

Regards,
Roger Lacroix
Capitalware Inc.

Capitalware, IBM i (OS/400), Linux, MQ Authenticate User Security Exit, Security, Unix, Windows, z/OS Comments Off on MQAUSX Security Bulletin

MQ queue managers should not be allowed to create CCDT files

In my opinion, IBM should drop the feature that allows a user to create a CCDT (Client Channel Definition Table) via a queue manager. Here is my logic to my idea:

  • The queue manager stores the CCDT information in 2 places that sometimes becomes out of sync. This desynchronization makes the CCDT file useless
  • CCDT files hold the CLNTCONN channel information which is not by the queue manager itself. The CCDT file is used by client applications (running on another server)
  • In order to be used by the client applications, the CCDT file(s) must be copied from the server where the queue manager is running and transferred to another server where the CCDT file(s) are actually required

What should IBM do? Include Paul Clarke’s SupportPac MO72 into the base MQ product.
http://www.ibm.com/support/docview.wss?uid=swg24007769

  • SupportPac MO72 is a great product that allows a user to create a CCDT file without requiring MQ to be installed on that server
  • SupportPac MO72 can create CCDT files for different versions of MQ (i.e. v5.3, v6.0, v7.0, etc..)
  • SupportPac MO72 can be installed and used on application servers where the CCDT file will be used. Hence, no need to copy CCDT file(s) between servers

Food for thought. 🙂

Regards,
Roger Lacroix
Capitalware Inc.

IBM MQ 1 Comment

ProGuard v4.6 Released

Eric Lafortune has just released ProGuard v4.6.
http://proguard.sourceforge.net/

ProGuard is a free Java class file shrinker, optimizer, obfuscator, and preverifier. It detects and removes unused classes, fields, methods, and attributes. It optimizes bytecode and removes unused instructions. It renames the remaining classes, fields, and methods using short meaningless names. Finally, it preverifies the processed code for Java 6 or for Java Micro Edition.

Regards,
Roger Lacroix
Capitalware Inc.

Java, Open Source, Programming Comments Off on ProGuard v4.6 Released

OpenOffice v3.3 Released

OpenOffice has just released OpenOffice v3.3.
http://www.openoffice.org

OpenOffice.org 3 is the leading open-source office software suite for word processing, spreadsheets, presentations, graphics, databases and more. It is available in many languages and works on all common computers. It stores all your data in an international open standard format and can also read and write files from other common office software packages. It can be downloaded and used completely free of charge for any purpose.

Regards,
Roger Lacroix
Capitalware Inc.

Linux, macOS (Mac OS X), Open Source, Windows Comments Off on OpenOffice v3.3 Released

Nokia: going, going, …

Just when you thought Nokia couldn’t make any more mistakes, today they decided to dump Symbian and MeeGo and go with Microsoft’s Windows Phone 7. You have got to be kidding me! At first I thought it was a joke but it isn’t:
http://www.infoworld.com/t/mobile-platforms/nokia-jumps-the-windows-phone-abyss-250

And the cherry on top: Nokia will not support Qt on Windows Phone 7. You must use the Microsoft Windows Phone 7 developer kit.

I have been a long, long time Nokia smartphone user. I guess it is time for me to look at other smartphones.

Speaking of truly stupid ideas, I also just read that RIM’s Playbook will get Android apps support.
http://www.theinquirer.net/inquirer/news/2025857/rim-s-playbook-android-apps-support

Don’t people take history anymore at school, college or university? What was one of the top reasons why OS/2 died? OS/2 could run Windows applications in a Windows VM under OS/2. Why did this lead to the death of OS/2? Developers decided that there was no point in porting their Windows applications to OS/2 because OS/2 could run them under the Windows VM.

If the Playbook will be able to run Android apps then developers will not port their apps to the Playbook. Hence, this will definitely be a nail in Playbook’s coffin.

Regards,
Roger Lacroix
Capitalware Inc.

Mobile Comments Off on Nokia: going, going, …

New: MQ Auditor v1.2.0

Capitalware Inc. would like to announce the official release of MQ Auditor v1.2.0. This is a FREE upgrade for ALL licensed users of MQ Auditor. MQ Auditor is a solution that allows a company to audit/track all MQ API calls performed by MQ applications that are connected to a queue manager.

For more information about MQ Auditor go to:
https://www.capitalware.com/mqa_overview.html

    Changes for MQ Auditor v1.2.0:

  • Fixed an issue with vsnprintf/vfprintf on Linux 64-bit servers.
  • Enhanced the PCF message handling process
  • Improved the speed of the writing the Audit record to a file or queue

Regards,
Roger Lacroix
Capitalware Inc.

Capitalware, IBM i (OS/400), IBM MQ, Linux, MQ Auditor, Unix, Windows Comments Off on New: MQ Auditor v1.2.0

WebSphere MQ v7.0.1.4 Fix Pack

IBM has released WebSphere MQ Fix Pack 7.0.1.4 for AIX, HP-UX, Linux, Solaris and Windows:
http://www.ibm.com/support/docview.wss?rs=171&uid=swg24028106

IBM has released WebSphere MQ Fix Pack 7.0.1.4 for IBM i (OS/400):
http://www.ibm.com/support/docview.wss?rs=171&uid=swg24028106

Regards,
Roger Lacroix
Capitalware Inc.

IBM i (OS/400), IBM MQ, Linux, Unix, Windows Comments Off on WebSphere MQ v7.0.1.4 Fix Pack

LibreOffice 3.3 Released

LibreOffice has just released LibreOffice v3.3.
http://www.libreoffice.org

LibreOffice is a comprehensive, professional-quality productivity suite that you can download and install for free. There is a large base of satisfied LibreOffice users worldwide, and it’s available in more than 30 languages and for all major operating systems, including Microsoft Windows, Mac OS X and Linux (Debian, Ubuntu, Fedora, Mandriva, Suse, …).

Regards,
Roger Lacroix
Capitalware Inc.

Linux, macOS (Mac OS X), Open Source, Windows Comments Off on LibreOffice 3.3 Released

New: MQ File Mover v3.2.1.1

Capitalware is pleased to announce that starting with v3.2.1.1 MQ File Mover is now supported on IBM i (OS/400).

MQ File Mover is a software package that is designed to move files using WebSphere MQ (aka MQSeries). MQFM processes “Action” commands which are controlled through an MQFM Workflow XML file. The user combines a series of Action commands to create the MQFM Workflow XML file.

For more information on MQ File Mover, please go to:
http://www.capitalware.biz/mqfm_overview.html

Regards,
Roger Lacroix
Capitalware Inc.

Capitalware, IBM i (OS/400), IBM MQ, Java, Linux, macOS (Mac OS X), MQ File Mover, Open Source, Unix, Windows 4 Comments

Apache Tomcat 7.0.6 Released

The Apache Tomcat Project has announced the release of version 7.0.6 of Apache Tomcat. This is the first stable release of the Tomcat 7 branch. For more information about Tomcat v7, go to http://tomcat.apache.org/index.html

Regards,
Roger Lacroix
Capitalware Inc.

Java, JMS, Open Source Comments Off on Apache Tomcat 7.0.6 Released