MQ

 View Only
  • 1.  Protecting data-encryption key for MQ AMS

    Posted Thu March 21, 2024 12:50 PM

    Dear all,

    due to data protection regulations it is required to protect our MQ 9.3 AMS data-encryption key with a separately stored key-encryption key.

    The default setup - as far we understand it - stashes the password in the same folder as the key repository.

    The requirement is to protect the key with some sort of password management solution or a vault - that provides an equally strong security from an external location.

    We'd be grateful if you could share your experiences / best practices for this.

    Best regards,

    Peter



    ------------------------------
    Péter Bősze
    Swisscom (Schweiz) AG
    ------------------------------


  • 2.  RE: Protecting data-encryption key for MQ AMS

    IBM Champion
    Posted Fri March 22, 2024 07:16 AM

    Hi Péter,

    I tried replying about 12 hours ago, but for some reason my reply has never showed up so I will try again now.

    Have you read about this: https://www.ibm.com/docs/en/ibm-mq/9.3?topic=mq-protecting-passwords-in-component-configuration-files

    This was a feature added fairly recently, so you might not be aware of it.

    I think it might be what you need.

    Cheers,
    Morag



    ------------------------------
    Morag Hughson
    MQ Technical Education Specialist
    MQGem Software Limited
    Website: https://www.mqgem.com
    ------------------------------



  • 3.  RE: Protecting data-encryption key for MQ AMS

    Posted Fri March 22, 2024 11:37 AM

    Hi Morag,

    thank you, no, we haven't seen this addition yet.

    Will check it out!

    Cheers,

    Péter



    ------------------------------
    Péter Bősze
    Swisscom (Schweiz) AG
    ------------------------------



  • 4.  RE: Protecting data-encryption key for MQ AMS

    Posted Thu March 28, 2024 04:00 AM

    Hi Morag,

    we had a look at runamscred and it looks really promising - one could use a HW-Box to store the protected key.

    The original enquiry was triggered by the requirements of PCI DSS Compliance, and it seems our biggest issue is the strength of encryption on the key:

    https://www.ibm.com/docs/en/ibm-mq/9.3?topic=files-limits-protection-through-password-encryption

    Do you think raising a PMR on IBM on this matter would lead to a result here?

    Cheers,

    Peter



    ------------------------------
    Péter Bősze
    Swisscom (Schweiz) AG
    ------------------------------



  • 5.  RE: Protecting data-encryption key for MQ AMS

    Posted Tue April 02, 2024 04:01 AM

    I'm not sure that this is a subject suited to a support request.

    However, you could use https://bigblue.aha.io/products/MESNS/ideas_overview to request improvements to the encryption mechanism.



    ------------------------------
    Mark Bluemel
    Software Engineer
    IBM
    mbluemel@uk.ibm.com
    ------------------------------



  • 6.  RE: Protecting data-encryption key for MQ AMS

    IBM Champion
    Posted Fri April 05, 2024 12:44 AM

    I agree with Mark's reply. To consider the strength of the encryption key to be too weak is not a defect. The key strength is working exactly as documented. So raising a PMR/case with IBM is not the correct route to take as that is for reporting things that do not work as advertised.

    To ask for a functional enhancement, that is a new feature, to make the encryption key strength stronger than that documented, you should raise what used to be known as an RFE (Request For Enhancement) which is now called an Idea. The link for non-IBMers to submit an Idea is here.

    Cheers,
    Morag



    ------------------------------
    Morag Hughson
    MQ Technical Education Specialist
    MQGem Software Limited
    Website: https://www.mqgem.com
    ------------------------------



  • 7.  RE: Protecting data-encryption key for MQ AMS

    Posted Wed April 17, 2024 03:01 AM

    Thank you Morag and Mark,

    I have created the idea MESNS-I-700, let's hope it'll fly.

    Have a great day,

    Peter



    ------------------------------
    Péter Bősze
    Swisscom (Schweiz) AG
    ------------------------------