mqsicreateaclentry command

Start of change

Supported platforms

  • Windows 2000, Windows XP
  • UNIX platforms
  • z/OS
End of change
Start of change

Purpose

Use the mqsicreateaclentry command to create or modify the Configuration Manager database table relating to the group or user access control lists that you have defined.

End of change

Syntax

Windows and UNIX platforms

z/OS

Start of change

Parameters

You must select either -f or
  • -g or -u, and
  • -x, and
  • -b or -e or -s or -r or -t or -p

If you select -u you must select either -m or -a

-f FileName
(Optional) File from which to import the configuration. The output of the mqsilistaclentry command is the correct format.
-g GroupName
(Optional) Local group to which this entry refers. For this reason, the name must adhere to the standard platform convention for group names.

To add a domain group, grant authority to a local group and then add the domain group, or groups, that you want to authorize into that local group. Any members of those domain groups obtain the permissions of the local group indirectly.

-u UserName
(Optional) User name to which this entry refers, for example, TEST\ANOTHER.
Note: -u and -g in this command refer to users and groups within the domain that the Configuration Manager uses for its security. This domain is by default the machine on which the Configuration Manager resides.
-m MachineName
(Optional) The name of the machine from which a specified user can connect. This option can not be used with -a.
-a
(Optional) This signifies that the specified user name can be on any machine. This option can not be used with -m.
Note: If you select -u, you must select either -a or -m.
-x AccessLevel
(Optional) The required access level given for this group. This can be any combination of the letters FDEV, where:
F
Full control
D
Deploy
E
Edit
V
View
-b Broker
(Optional) The object is a broker object, and its name is specified as a parameter.
-e ExeGroup
(Optional) The object is an execution group and its name is specified as a parameter of the form Broker\ExeGroup.
-s Subscription
(Optional) The object is a subscription object, and its name is specified as a parameter.
-r
(Optional) The object refers to the root topic.
-t
(Optional) The object refers to the main topology.
-p
(Optional) The object refers to the "allresources" resource type. The authority that the principal has for this object applies to all objects, including the mqsicreateaclentry, mqsideleteaclentry, and mqsilistaclentry commands themselves.
End of change
Start of change

Authorization

The user ID used to invoke this command must have appropriate Access Control List (ACL) permissions set for the "allresources" resource type.

End of change
Start of change

Examples

mqsicreateaclentry -f c:\test\mylist 
mqsicreateaclentry -g GROUPA -x F -b MYBROKER
Related concepts
Security
Related tasks
Database security
End of change