The main components ofGlobal Mailboxand the architecture for the components to work together
High availability inGlobal Mailboxis based on specific availability principles. There are some limitations to the high availability properties of Global Mailbox.
- High availability
The high availability mailboxing capability enables you to deploy a B2B platform that can minimize downtime plus offer disaster recovery capabilities. - Global Mailbox system principles
Global Mailboxsolution is designed around some specific availability principles for trading partner connections, user actions, and message processing. - High availability properties and limitations of Global Mailbox
High availability of Global Mailboxis limited during some situations, for example when a data center goes down or when one or more nodes in a data center are not operational. - Global Mailbox deployment considerations
When deploying Global Mailbox, you must consider a few items due to various factors such as, limitations of the supported topology and limitations of the components supporting Global Mailbox.
Global Mailboxis a facility for creating a directory of mailboxes with submailboxes and hosting them across multiple data centers. Messages are created by Global Mailboxfor applications (on behalf of trading partners, as application users) and stored in mailboxes.
A mailbox is a secure document payload repository. Mailboxes are secure because there is a permission model that controls who can access which mailbox.
By creating a network of multiple data centers that host mailboxes, the mailboxes can be available even if a data center is not operational. Other data centers in the network continue to perform the transactions. Data, including metadata, is replicated between the data centers.
Mailboxes are have the following features:
- Mailboxes are organized in a hierarchical tree structure.
- There is a root mailbox at the highest level in the directory structure.
- Each mailbox can have only one parent.
- Mailboxes can be created without an owner, until users or groups and permissions are assigned to them.
- Mailboxes can contain the following items:
- Messages
- Other mailboxes
- Permission information for specific users
- Mailbox types
Mailboxes are a point of integration for applications to access the same message.
- Traditional mailboxes -Sterling B2B Integratormailboxes that are in one node, or instance of Sterling B2B Integrator.
- Sterling File Gatewaymailboxes are traditional mailboxes with advanced routing and visibility that is enabled by Sterling File Gateway
- Global Mailboxcan be configured in multiple data centers with replication of the data so that messages are stored in multiple data centers and are available even when one data center is offline or has an interruption in communication. Global Mailboxis an optional feature of Sterling B2B Integratorthat enables mailboxes that can be distributed across multiple data centers.
- Messages
A message consists of a payload and metadata.
Message metadata includes message name (file name), size of the file (that is the size of the payload), payload type (inline storage or shared file system storage), and depending on the payload type, the payload itself (inline) or a payload reference identifier. The metadata is stored in Cassandra. The payload is an actual business document or file. A message can have only one payload.
InGlobal Mailbox, you can configure a threshold for payload size. If the size of the payload is more than the threshold, the payload is stored in a shared file system storage. If the size is less than the threshold size, it is stored inline with the metadata in Cassandra, as a blob.
Message replication is the replication of both the message metadata and the message payload. Cassandra handles the metadata replication transparently. If the payload of a message is inline, replication of payload is handled by Cassandra. If the payload is not inline, its replication is performed by a replication server.
Global Mailboxadministrators can manage messages from the Mailbox Explorerpage. Global Mailboxadministrators can delete messages or view all messages that a specific Global Mailboxcontains.
- Virtual roots
Each user must be assigned a virtual root to accessGlobal Mailbox.
The virtual root is the first level of the directory path for a user when they are navigating the mailbox navigation pane.
To support limited visibility into the mailbox hierarchy, mailboxes are visible to the user as a relative path, while administrators see the mailbox in an absolute or full path. This concept is referred to as the virtual root .
An administrator user always has a virtual root of / (slash). If a standard user is changed to an admin user, that user is assigned a virtual root value of / (slash). No default virtual root is assigned to users. An admin must assign a virtual root before users can accessGlobal Mailbox.
- Dead Letter mailbox
A Dead Letter mailbox is a mailbox that contains AS2 messages that might not be routed for some reason. The Dead Letter mailbox is available by default inGlobal Mailboxunder the rootmailbox as /DeadLetter. A Dead Letter mailbox cannot be deleted or renamed.
If you already have a mailbox that is called Dead Letter in your setup, you must delete or rename the mailbox before you upgrade to v6.0.1 or later. Otherwise, the existing Dead Letter mailbox is overwritten with the new Dead Letter mailbox and your existing messages are lost.
You can create submailboxes under the Dead Letter mailbox. You can also move messages from the Dead Letter mailbox or delete them. While moving messages to a target mailbox, if the target mailbox has an event rule that matches the messages, events are generated and the files are routed.
An administrator can check the messages in the Dead Letter mailbox periodically for the messages that are not routed correctly and resolve them.
- Duplicate messages
TheGlobal Mailboxsupports uploading and downloading of messages with same names (duplicate) through SFTP and FTP.
Duplicate message support is case insensitive. For example, if you have a message with name
To upload or download a duplicate message, you must set thecom.ibm.mailbox.messages.allowDuplicatesproperty to true when you register Sterling B2B Integratorwith Global Mailbox. If com.ibm.mailbox.messages.allowDuplicatesproperty is set to false, and you upload a message with the same name, the new message overwrites the existing message. Important:If you set com.ibm.mailbox.messages.allowDuplicatesto true and upload files with same name, duplicate files with different timestamp are created. Later if you set com.ibm.mailbox.messages.allowDuplicatesto false, then every time a business process runs, a file with the duplicate name is deleted until the data in the mailbox aligns with the configuration of the com.ibm.mailbox.messages.allowDuplicatesproperty.test, and another one withTESTorteSTthen the messages are considered as duplicate of each other. When you download a message with duplicate name, the newest extractable message is downloaded. If extraction count is configured for the newest file, and if the extraction count of the file reaches 0 remaining extractions, then the next download fetches the next newest duplicate file.The
listDuplicatesproperty in the ftpserver.propertiesand sftpserver.propertiesfiles controls how the FTP Server adapter and the SFTP Server adapter handle presence of multiple files with same name in a mailbox. When the property is set totrue, the FTP and SFTP Server adapters list all the duplicate messages. When the property is set tofalse, only the newest file is shown in the list.Additionally, for FTP and SFTP transfers, you can configure theSupport for concurrent duplicate named file transfersparameter, which is available in the FTP and SFTP Server adapter configuration wizards. Currently, Limitedand Full (resume of file transfers not supported)options are supported for Global Mailbox. For more information about the parameter and supported options, see the FTP Server Adaptertopic.
For FTP and SFTP transfers, if you configure the FTP or SFTP Server adapter to enableGlobal Mailbox, and also select the option Full, concatenate duplicate-named files on a GET (resume of file transfers not supported), the adapter ignores the concatenation request when operating on Global Mailbox. Instead, the adapter returns the newest message with the name that is specified in the request. If you enable Global Mailboxand concatenation, a warning message, stating that the concatenation setting is ignored, is printed in the adapter logs.
- Message collections
Multiple messages with the same message name are processed to present the correct message or messages to the user.
When multiple messages with the same message name are received intoGlobal Mailbox, how they are handled depends on the following criteria:- Which application created this mailbox
- Whether that application supports duplicate messages (a setting in the application)
- If yes, lists all messages that match that message name, in the default order
- If no, lists the most recently created message with the message name
- If switched to No after previously setting Yes, lists the most recently created message with the message name
To support the feature of having messages with the same names, set the property
com.ibm.mailbox.messages.allowDuplicates. This property is specified per application. Valid values aretrueandfalse(default). To specify a value for the property, use the command-line application registration utility. By default the property is set to false during installation. You can update the configuration later as required.To update the property, enter the following command:
./appConfigUtility.sh updateAppConfig --appName=Sterling Integrator Instance 1 --Pcom.ibm.mailbox.messages.allowDuplicates=true
(Linux® or UNIX)
appConfigUtility.bat updateAppConfig --appName=Sterling Integrator Instance 1 --Pcom.ibm.mailbox.messages.allowDuplicates=true
Global Mailboxadministrators can manage mailboxes, messages, permissions, virtual roots, and event rules in the Global Mailboxmanagement tool.
- MAILBOX
- Deployment
- Mailbox Administrators
- Sterling B2B Integrator Admin
- Mailbox Explorer
- User Explorer
- Event Explorer
Mailbox Explorer
From theMailbox Explorerpage, Global Mailboxadministrators can manage all messages, submailboxes, permissions, and event rules for all mailboxes in the Global Mailboxsystem. The mailbox navigation tree allows Global Mailboxadministrators to view all mailboxes and submailboxes on the Mailbox Explorerpage.
- Create and delete mailboxes and submailboxes
- View information about each message, including the message creation date, the message creator, and payload size
- View and modify extraction criteria for individual messages
- View and modify user permissions for a mailbox
- View and resend all events that are generated by a message
- View and modify all event rules that apply to the mailbox
- Create or delete an event rule
- Enable or disable event rules
User Explorer
- Create or remove all mailbox permissions
- View and modify all mailbox permissions
- View the existing virtual root
- Set a new virtual root
- View the application that the user belongs to
Event Explorer
- View all event rules that exist for the application
- Modify event rules, such as updating the Message Name Filter criteria
- Evaluate an event rule
- Create or delete an event rule
- Enable or disable event rules
With theEventstab on the Event Explorerpage, Global Mailboxadministrators can resend all events by application that match the filter criteria that is specified. For example, if one or more events were unsuccessfully processed, Global Mailboxadministrators can resend events for processing by specifying filter criteria that matches the unsuccessfully processed events.
Administrative users inSterling B2B Integrator(admins) are granted all permissions in Global Mailbox.
When a service or adapter is configured with a repository type ofGlobal Mailbox, a user designated as a Sterling B2B Integratoradministrator is granted all rights and permissions to Global Mailboxresources, without having to specifically add them. There is no scenario whereby a Sterling B2B Integratoradministrator gets a permission denied or authorization exception type error because they have all permissions within Global Mailbox.
The virtual root must be set for each admin user inGlobal Mailbox. If an admin user without a Global Mailboxvirtual root accesses an FTP or SFTP server adapter that is enabled for Global Mailbox, the user is directed to traditional mailboxes and not to Global Mailbox.
Admins can directly access theGlobal Mailboxmanagement tool from Sterling B2B Integratorif single sign-on is configured. Admins must have the necessary permissions in Sterling B2B Integratorto access the Global Mailboxmanagement tool by single sign-on.
InGlobal Mailbox, admins are not listed on pages where permissions are assigned. Permissions for admins cannot be restricted.
Global Mailboxadministrators can create event rules to automatically initiate specific actions when a message is added to a Global Mailbox.
- The date and time (V5.2.6.3_2or later) that the message was sent
- The processing status of the message
- The data center that processed the message
With event information,Global Mailboxadministrators can monitor each individual message transfer in the Global Mailboxsystem. If one or more events are unsuccessfully processed, a Global Mailboxadministrator can resend the events for processing from the Global Mailboxmanagement tool.
An event rule is a specific action, or set of actions, that is performed by an application when a message is added to aGlobal Mailboxthat the event rule applies to. Global Mailboxadministrators can create event rules to automate event processing when messages are added to specified mailboxes. When a message is added to a Global Mailbox, all event rules that apply to the mailbox are automatically evaluated.
When an event is evaluated, this means that the event is sent to be processed by the application that it is configured to be processed by. An event rule ensures that the event is automatically evaluated at least once.
- The event rule name
- The mailboxes that the event rule applies to
- The processing application
- The Message Name Filter
- Any additional properties that are supported by the processing application
Event rules can be temporarily enabled or disabled from theMailbox Exploreror Event Explorerpages.
- Event processing
When a file is uploaded, events are posted to the B2Bi application queue immediately. The file is uploaded to the local data center without waiting for being replicated to other data centers.
For event processing to be successful, Cassandra is required in the local data center.
In event processing, protocol traffic is automatically routed to a remote data center if a WebSphere MQ outage occurs on the local data center. Files are not processed more than once. In case of failures, all files are automatically processed.
If event processing fails because the queue manager failed or the WebSphere MQ service failed, the files are processed when the events are resent through the UI or through theeventUtilityscript. The files are resent to the data center from which the files originated, and the files are then processed.
Availability, performance, consistency, and durability ofGlobal Mailboxare achieved by the replication feature.
Global Mailboxis, in essence, a distributed file system (DFS). Mailboxes correspond to directories in a DFS, and messages correspond to files within DFS directories. Files, much like messages, store two kinds of information:
- Metadata about the file. For example, file size and file name.
- The actual content of the file, the payload.
InGlobal Mailbox, replication consists of two subsystems:
Unlike traditionalSterling B2B Integratormailboxing, Global Mailboxcan automatically replicate both the metadata and payloads associated with messages to remote data centers, thereby providing an increased degree of fault tolerance.
It is expected of a distributed system likeGlobal Mailboxto be available most of the times, to perform at the best, to maintain data consistency, and to be durable. However, there are various trade-offs that must be considered by you, based on your business requirements, before configuring each functionality.
Availability
Availability refers to the proportion of time during which a particular service or a system inGlobal Mailboxis operating at functional capacity. For instance, we consider the payload replication service available only when users can successfully upload new payloads to Global Mailbox. The metadata replication service, on the other hand, is available only when sufficient number of Cassandra instances are online to service read and write requests.
Performance
Two primary concepts are involved in performance:
- The response time of individual operations executed
- The aggregate throughput of operations executed at some level of granularity. For example, within a user session, all concurrent sessions within a data center, or all concurrent global sessions.
Minimizing response time and maximizing throughput are both desirable performance goals. In general, it is possible that some operations might have high response times but scale well across concurrent sessions, that is, be high-throughput. Similarly, low-throughput operations might complete quickly in the context of an individual session.
Consistency
Consistency defines the congruency of visible states within a computer system. A distributed system, comprised of different nodes can provide strong consistency only if every component can observe the same state in the same order. Weak consistency, on the other hand, does not provide this guarantee. Apache Cassandra supports a consistency model known as eventual consistency. There are chances, that an eventually consistent system might provide an outdated answer to a query. However, after a sufficient period of time passes, during which no component failures occur, all components in an eventually consistency system respond to a query with the same answer.
Though an eventually consistent system has potential benefits to performance and availability, it is suggested not to configure eventual consistency in Cassandra due to data integrity related issues inGlobal Mailbox.
Durability
Durability is the guarantee that any operation that completed successfully is not lost, rolled back, or changed due to a component failure. Durability is often compromised in distributed systems to improve performance and availability.
Configuration options
Payload replication and metadata replication provide different levels of availability, performance, consistency, and durability functionality. Availability, performance, consistency, and durability can be configured for payload replication. However for metadata replication, only availability, performance, and durability can be configured. You must retain the default consistency level for metadata replication.
- Payload replication
Replication is the process of creating a copies of a message that is added to Global Mailboxin a data center. The copies are created in other data centers. - Message replication configuration trade-offs
Immediate replication and delayed replication provide different levels of availability, durability, and performance functions. Based on your business requirements, you must carefully evaluate the required functions and accordingly configure payload replication. - Default consistency settings in Global Mailbox
To maximize availability and consistency where required, different default consistency levels are specified for different components in the Global Mailboxsystem.
In theGlobal Mailboxsystem, storage (file system) implementation is based on the concept of storage buckets. The buckets are containers (logical groups) in the file system, which are configured according to business requirements based on security and retention.
The storage system includes buckets, which store blobs. Buckets include variants, which are versions of the buckets. Blobs are stored in the variants. You must configure at least one bucket and variant for storage to operate.
A variant can have a different configuration (for example, encryption settings). Each variant within a bucket is identified by a unique variant identifier (0 - 63). Variants can be marked as retired after which a variant becomes read only. The data in blobs is distributed among the active variants of the bucket. During a READ or GET operation, the blob is retrieved from the variant it exists in.
File transfer process flow
- AGlobal Mailboxenabled protocol server adapter calls the storage client to read or write a file.
- The storage client looks up for the specified file or variant.
- The storage client transfers the file to or from the file system.
Storage configuration
- Bucket variants
- File system base path
- Security (hash value, encryption)
- Maximum lifespan of blobs
- Buffer size for storage
- Input and output threads
- Storage of blob metadata
When you install the initialGlobal Mailboxnode, storage buckets ( 1st_provisionedand global_mbx) and the first variant ( 0) are created. By default, Global Mailboxuses the global_mbxbucket to store message payload. When installing the initial Global Mailboxnode, you must also specify the shared storage path for all other data centers. The configuration information ( 1st_provisionedand global_mbxbuckets, global.propertiesand installinfo.propertiesfiles), is copied to the shared storage path specified for other data centers after installing the initial Global Mailboxnode.
When you configure your storage system, you must decide how you want to use buckets and variants to store the different kinds of information that flow through theGlobal Mailbox.
Pause and resume
If resumption is configured for a file that is uploaded, the file is broken into segments.
If a file is broken into four segments, a total of five files, one for each segment, and a stub file, are created and stored on the disk. The stub file contains metadata with information to reassemble the segments.
If the upload is interrupted (either by pause or loss of network connection) in the middle of uploading a segment, the whole segment is removed, and upload is resumed when the error is corrected.
A scheduled job is a regularly performed task on theGlobal Mailboxsystem to automate routine operations and to maintain optimal system performance. You can modify the configuration of scheduled jobs with the schedulerConfigUtilityscript to meet your system requirements.
Scheduled jobs perform regular operations to maintain optimalGlobal Mailboxsystem performance. For example, the PayloadPurgeJob routinely identifies and removes orphaned payloads from the Global Mailboxsystem by deleting the orphan payload data from Cassandra. An orphaned payload is a message payload that is no longer referenced by a message.
You can set the frequency and schedule for jobs to meet your business requirements, with different schedules and frequencies for different jobs depending on your data patterns. A job can be scheduled for a specific time of day, such as 2 AM, with a frequency between daily and every several months.
- Purge
Purging of data follows a regular, automated schedule to maintainGlobal Mailboxsystem performance. You can modify the configuration of purge jobs and purge job triggers with the schedulerConfigUtilityscript.
Purge jobs delete the following types of data on a regular schedule:- Messages that are not referenced or have no parent
- Messages with partial or incomplete payloads
- System artifacts that have no user or application
- Payloads with no message
- Mailboxes that have no parent
- Events by processing status
Removing unneeded items prevents allocation of resources and prevents performance deterioration.
Items that are purged cannot be recovered.
You can convertSterling File Gatewaypartners and mailboxes to use Global Mailbox. You can create new accounts in Global Mailboxfor Sterling B2B Integratorusers and mailboxes and use adapters that are enabled for Global Mailbox. You cannot migrate users and mailboxes from one Global Mailboxsystem to another.
AfterGlobal Mailboxis installed and configured, Sterling File Gatewaypartners can be converted to enable Global Mailboxfunctionality. After a partner is converted in one data center, export the related resources and import them to the other data centers to take advantage of the features and architecture of Global Mailbox.
To use the features and advantages ofGlobal Mailbox, you can convert the existing Sterling File Gatewaypartners (producer and consumer) to use Global Mailbox. You can only convert a single partner at a time. A Sterling File Gatewayroute provisioner, administrator, architect, or operator can convert a partner to use Global Mailbox. The conversion is irreversible. If for any reason you no longer want to use Global Mailbox, you must re-create the partner and routes in Sterling File Gateway.
When you convert the partners to useGlobal Mailbox, mailboxes that are equivalent to the existing traditional mailboxes are created in the Global Mailboxrealm for the partner. User permissions and virtual roots are also created in the Global Mailboxrealm. The user accounts associated with a Sterling File Gatewaypartner remain in Sterling B2B Integratorwhen the partner is converted to use Global Mailbox. Permissions for the user on certain mailboxes are granted within the Global Mailboxsystem, but the user account remains within Sterling B2B Integrator.
Traditional mailboxes continue to exist, but are no longer used. You can move the messages in traditional mailboxes toGlobal Mailboxat the time you convert the partner. After a partner is converted to use Global Mailbox, new messages for that partner are written to the mailboxes in Global Mailbox.
By creating your mailboxes and virtual roots inGlobal Mailbox, you can gain Global Mailboxadvantages while continuing to use your existing Sterling B2B Integratorbusiness processes. If you want to limit partner-facing impact, you may want to re-direct your load balancers to new Global Mailboxenabled adapters. Some downtime would be required while you adjust your adapters, but by re-using the externally facing ports, you may not need to have partners make additional adjustments.
With file transfer resumptions, active file transfers that are interrupted, disrupted, or stopped can be resumed because theGlobal Mailboxsaves data prior to the occurrence of errors.
If an active file transfer is interrupted due to a network error, the protocol adapter getting disrupted or stopped, or theSterling B2B Integratornode going down, the Global Mailboxsaves the data that was uploaded before the error occurred.
To support transfer resumption, the server adapters inSterling B2B Integratorstore the incomplete files in a temporary document staging area. This allows FTP and SFTP clients to resume a transfer. File transfer is resumed on another server in the same data center.
With Load balancer, if an FTP server adapter from a specific data center goes down, an error occurs. When you resume the file transfer, a connection is established to the existing data center if the data center is not down and the file upload is successfully resumed.
However, if the data center is down, and a connection to the other data center is attempted, then resume fails. In this case, file resumption is possible only in the data center in which the file was initially uploaded.
TheGlobal Mailboximplementation supports REST services to view and consume some resources in the Sterling B2B Integratorand Sterling File Gateway.
To establish a connection to theGlobal Mailboxsystem, Sterling B2B Integratoris registered with Global Mailboxby using the appConfigUtilityduring the installation. When registering Sterling B2B Integrator, the REST services are also registered with Global Mailbox. The registration is automated and does not require any manual intervention. However, if you need to change any parameters for user lookup or event data lookup, then you can run the following commands after installing Global Mailboxand Sterling B2B Integrator:
To connect toSterling B2B Integrator, and access the required resources through Global MailboxREST Service adapter (of type HTTP Server adapter), Global Mailboxmust have the following information. The installer configures the REST parameters during the installation.
| Element | Description | Example |
|---|---|---|
| Request method | The REST request method. Only GET is supported. | GET |
| Host name | The host where theGlobal MailboxREST Services adapter instance (HTTP Server adapter type) is running. It is a Sterling B2B Integratorhost. | si.myco.com |
| Port | The listening port of theGlobal MailboxREST Services adapter. An appropriate port is configured by the Sterling B2B Integratoradministrator. | 9876 |
| Resource path | The REST resource path. It must start with/api/V1 | /api/V1/users
|
| User name | User name for basic authentication. A newSterling B2B Integratoruser is supported. Any other user with permission corresponding to the specific REST API can also be used. Thegmbx_useruser is granted the following permissions to execute the rest services:
| gmbx_user |
| Password | Password for basic authentication. The password is configured by theSterling B2B Integratoradministrator. | password |
| Server certificate | SSL certificate that represents the hostSterling B2B Integratoridentity. Might be self-signed or signed by a certifying authority. The client ( Global Mailbox) must be configured to trust this certificate as representing the server ( Sterling B2B Integrator). | Certificate file that is downloaded fromSterling B2B Integratorand associated with HTTPS Server adapter. |
- Optionally change the port to a different value.
- Change the certificate that is used for server authentication (default certificate is a self-signed certificate that is created duringSterling B2B Integratorinstallation. The default certificate is different for each Sterling B2B Integratornode.)
- Enable theGlobal MailboxREST Service adapter instance, as it is disabled by default.
- User Lookup REST Service
- Event Property REST Service
Note:If the auth password is modified using the command line in the setUserLookuputility, ensure you update the same in the setEventDataLookuputility.
For example:
./appConfigUtility.sh setUserLookup --authPassword="newpc4us" --appName="B2Bi" --adminUser="admin" --adminPassword="password" ./appConfigUtility.sh setEventDataLookup --authPassword="newpc4us" --appName="B2Bi" --adminUser="admin" --adminPassword="password"
User Lookup REST Service
The User Lookup REST Service is hosted in theGlobal MailboxREST Services adapter, and can be accessed from the URI /api/V1/users/. After successfully authenticating the user, the request returns a list of users who are in the Activestate in Sterling B2B Integrator. If required, a Global Mailboxadministrator can optionally choose to view Sterling B2B Integratoradministrator users also.
Event Properties REST Service
The Event Properties REST Service is hosted in theGlobal MailboxREST Services adapter, and can be accessed from the URI /api/V1/event_properties/. After successfully authenticating the user, the request returns a list of Sterling B2B Integratorsupported event properties, such as, business process name, contract name, and user. By default, the service returns information on mandatory and invalid event property combinations. If required, the Global Mailboxadministrator can initiate a second call to view the allowed values, for example, /api/V1/event_properties/BPNAME/allowed_values.
The performance of yourIBM® Global High Availability Mailboxsystem depends upon the interaction of the components, the communication paths between components, and the configuration settings. By monitoring your performance and tuning your system, you can balance file transfer speed with availability and protection from data loss. Your business requirements must be a consideration in designing and tuning performance.
- Number of data centers
- Geographical distribution of data centers
- Number of Cassandra nodes in the cluster and consistency settings for replication
- Number of ZooKeeper nodes in the ensemble
- Number of files transferred
- Size of payloads
- GPFS tuning (or other file system tuning)
- Storage tuning (for example, adjusting concurrent access lease parameters)
- Security settings, such as encryption for data during transfer and data at rest in storage
Security for yourGlobal Mailboxsystem must be planned and implemented as an integrated aspect of your deployment, and carefully monitored and administered to continue evolving to meet new risks as they form. By taking appropriate steps, your organization can minimize and mitigate threats.
- Trusted connections
- Authentication of components
- Authorization of users
- Access control to data
- Permissions
- Audit-ability of events, including authentication events and access control changes
- Configured firewalls
Global Mailboxrelies on the connecting applications, such as Sterling B2B Integratorand Sterling File Gatewayto authorize end users. Multiple applications can access the same mailboxes, depending on permissions. Careful management of users in all applications is necessary to ensure security.
Administrators are authenticated with a user ID and password. Certain parts of theGlobal Mailboxmanagement tool can only be accessed by administrators. Because of the extensive privileges granted to administrators, the user ID and password must be carefully controlled, changed frequently, and adhere to strict rules for complexity. Delete the default administrator after you have created a unique one for your system.
Previous Topic
IBM Global Mailbox - components at a glance
Parent Topic
IBM Global Mailbox - overview
