APAR status
Closed as program error.
Error description
Unable to connect to local queue manager with AzureAD domain user account. An AzureAD domain user (in the mqm group) executing runmqsc.exe results in "AMQ8135: Not authorized." message at command prompt. FFST files are produced with Errorcode: MQRC_NOT_AUTHORIZED and (for example) ProbeID: PU821050 with MQM Function Stack: fcxControlProcessMain fmxInitialize fmiSubscribeStreams fmiMakeStreamSupportedSubscription Queue manager error logs show AMQ8075 errors with the text: "AMQ8075: Authorization failed because the SID for entity '<first 12 characters of username>' cannot be obtained."
Local fix
Use a locally-defined account to connect to the queue manager
Problem summary
**************************************************************** USERS AFFECTED: Users with an Azure Active Directory (AzureAD) domain user account Platforms affected: Windows **************************************************************** PROBLEM DESCRIPTION: A programming error caused the AzureAD user's SID to be corrupted whilst stored in memory and passed between MQ processes, causing an authentication failure.
Problem conclusion
The programming error has been resolved to correctly pass the user's SID between processes. --------------------------------------------------------------- The fix is targeted for delivery in the following PTFs: Version Maintenance Level v8.0 8.0.0.9 v9.0 CD 9.0.5 v9.0 LTS 9.0.0.3 The latest available maintenance can be obtained from 'WebSphere MQ Recommended Fixes' http://www-1.ibm.com/support/docview.wss?rs=171&uid=swg27006037 If the maintenance level is not yet available information on its planned availability can be found in 'WebSphere MQ Planned Maintenance Release Dates' http://www-1.ibm.com/support/docview.wss?rs=171&uid=swg27006309 ---------------------------------------------------------------
Temporary fix
Comments
APAR Information
APAR number
IT21988
Reported component name
WMQ BASE MULTIP
Reported component ID
5724H7251
Reported release
800
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt / Xsystem
Submitted date
2017-08-11
Closed date
2017-10-20
Last modified date
2018-06-28
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
WMQ BASE MULTIP
Fixed component ID
5724H7251
Applicable component levels
[{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSYHRD","label":"IBM MQ"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"8.0.0.0","Edition":"","Line of Business":{"code":"LOB45","label":"Automation"}}]
Document Information
Modified date:
28 June 2018