Original Message:
Sent: Thu February 09, 2023 05:15 AM
From: Morag Hughson
Subject: Message Encryption on queue data files
An IBM Official performance report for some of AMS, specifically the new Confidentially policy can be read here. That particular policy was designed for people who were put off by the cost of the gold standard, single use encryption keys. It will certainly give you a flavour as it does show the costs of each of the different policy types.
Cheers,
Morag
------------------------------
Morag Hughson
MQ Technical Education Specialist
MQGem Software Limited
Website: https://www.mqgem.com
Original Message:
Sent: Thu February 09, 2023 05:10 AM
From: Sebastian Wilk
Subject: Message Encryption on queue data files
Hey Morag,
thank you for the quick reply, that seems to be exactly what I was looking for. I'll install it and play around.
Do you, by chance, have any performance reports or presentations that cover that aspect?
------------------------------
Sebastian Wilk
Original Message:
Sent: Thu February 09, 2023 04:38 AM
From: Morag Hughson
Subject: Message Encryption on queue data files
Hi Sebastian,
They are if you tell MQ that is what you want. You may have heard of a feature called Advanced Message Security (AMS). If this feature is used, then message data is encrypted before it leaves the putting application process, and thus remains encrypted when in queue manager buffers, in queue data files, and everywhere in between until the message reaches an authorised getting application process, and at that point it is decrypted. Even if the queue manager is stopped and restarted.
To read more about AMS, this is a good starting point in IBM Docs:-
Hope that helps.
Cheers,
Morag
------------------------------
Morag Hughson
MQ Technical Education Specialist
MQGem Software Limited
Website: https://www.mqgem.com
Original Message:
Sent: Thu February 09, 2023 04:33 AM
From: Sebastian Wilk
Subject: Message Encryption on queue data files
Hey there MQ people,
we recently had a discussion about security. I have browsed the documenation but I was unable to find a definitive answer.
Are messages, which are stored in so called queue data files (?) encrypted? Especially in a scenario e.g.
Persistent messages put into a queue, the queuemanager bounces or has a scheduled maintenance, are the stored messages encrypted?
Kind regards
------------------------------
Sebastian Wilk
------------------------------