MQ

MQ

Join this online group to communicate across IBM product users and experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Message Encryption on queue data files

    Posted Thu February 09, 2023 04:34 AM

    Hey there MQ people,

    we recently had a discussion about security. I have browsed the documenation but I was unable to find a definitive answer.

    Are messages, which are stored in so called queue data files (?) encrypted? Especially in a scenario e.g.

    Persistent messages put into a queue, the queuemanager bounces or has a scheduled maintenance, are the stored messages encrypted?

    Kind regards



    ------------------------------
    Sebastian Wilk
    ------------------------------


  • 2.  RE: Message Encryption on queue data files

    Posted Thu February 09, 2023 04:39 AM

    Hi Sebastian,

    They are if you tell MQ that is what you want. You may have heard of a feature called Advanced Message Security (AMS). If this feature is used, then message data is encrypted before it leaves the putting application process, and thus remains encrypted when in queue manager buffers, in queue data files, and everywhere in between until the message reaches an authorised getting application process, and at that point it is decrypted. Even if the queue manager is stopped and restarted.

    To read more about AMS, this is a good starting point in IBM Docs:-

    Hope that helps.

    Cheers,
    Morag



    ------------------------------
    Morag Hughson
    MQ Technical Education Specialist
    MQGem Software Limited
    Website: https://www.mqgem.com
    ------------------------------



  • 3.  RE: Message Encryption on queue data files

    Posted Thu February 09, 2023 05:11 AM

    Hey Morag,

    thank you for the quick reply, that seems to be exactly what I was looking for. I'll install it and play around.

    Do you, by chance, have any performance reports or presentations that cover that aspect?



    ------------------------------
    Sebastian Wilk
    ------------------------------



  • 4.  RE: Message Encryption on queue data files

    Posted Thu February 09, 2023 05:15 AM

    An IBM Official performance report for some of AMS, specifically the new Confidentially policy can be read here. That particular policy was designed for people who were put off by the cost of the gold standard, single use encryption keys. It will certainly give you a flavour as it does show the costs of each of the different policy types.

    Cheers,
    Morag



    ------------------------------
    Morag Hughson
    MQ Technical Education Specialist
    MQGem Software Limited
    Website: https://www.mqgem.com
    ------------------------------



  • 5.  RE: Message Encryption on queue data files

    Posted Thu February 09, 2023 06:22 AM

    Blimey! That is plentiful, much appreciated



    ------------------------------
    Sebastian Wilk
    ------------------------------



  • 6.  RE: Message Encryption on queue data files

    Posted Fri February 10, 2023 03:47 PM

    Hello Sebastian,

    MQ/AMS is a licensed IBM product (i.e. you have to pay to use it).  If you want a cheaper vendor alternative, you should look at Capitalware's MQ Message Encryption. The end-user can select which queues should have their messages encrypted, and all queue files and transactional log files for those "protected queues" will have the message data encrypted.

    Regards,
    Roger Lacroix
    Capitalware Inc.



    ------------------------------
    Roger Lacroix
    CTO
    Capitalware Inc.
    London ON Canada
    https://capitalware.com
    ------------------------------



  • 7.  RE: Message Encryption on queue data files

    Posted Thu February 16, 2023 02:00 AM

    if u using MQ Appliance, u can encrypt the filesystem. Distributed would need something like AMS.



    ------------------------------
    om prakash
    ------------------------------