IBM Support

OA63970: ZSECURE SMF REPORTING SHOWS A TLS KEY EXCHANGE METHOD OF DHE-EC

A fix is available

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • zSecure SMF reporting shows a TLS key exchange method of
    DHE-EC.
    
    The value reported for TLS_KEY_EXCHANGE_METHOD should be
    ECDHE.
    
    
    Neither DHE-EC nor DHE are documented values for
    TLS_KEY_EXCHANGE_METHOD so the documentation should also show
    ECDHE and DHE as valid values.
    

Local fix

  • N/A
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED: Users of zSecure Audit exploiting SMF        *
    *                 reports.                                     *
    ****************************************************************
    * PROBLEM DESCRIPTION: zSecure Audit reports the TLS key       *
    *                      exchange method (field                  *
    *                      TLS_KEY_EXCHANGE_METHOD) as 'DHE-EC'    *
    *                      while it should be 'ECDHE'. The value   *
    *                      'DHE' reported by the same field is not *
    *                      mentioned by zSecure documentation.     *
    ****************************************************************
    * RECOMMENDATION: Apply the PTF provided and review the        *
    *                 documentation update.                        *
    ****************************************************************
    The SMF119SC_TLS_CS_Kex_Alg (The key exchange algorithm used by
    the cipher suite) field value X'001C' of zERT connection detail
    SMF records (type 119, sub-type 11) is reported by zSecure Audit
    (newlist type SMF, field TLS_KEY_EXCHANGE_METHOD) as 'DHE-EC'
    while it should be 'ECDHE'. Also, the value DHE  reported by the
    same field is not mentioned in zSecure documentation.
    

Problem conclusion

  • zSecure Audit and its documentation have been updated, so that:
    
     - a proper value 'DHE-EC' is reported by the field
       TLS_KEY_EXCHANGE_METHOD (newlist type SMF).
     - the 'EDCHE' value reported by the same field is mentioned in
       zSecure documentation.
    
    Please note the documentation update as provided by the APAR
    tracking comment data.
    

Temporary fix

Comments

APAR Information

  • APAR number

    OA63970

  • Reported component name

    ZSEC BASE,ADMIN

  • Reported component ID

    5655T0100

  • Reported release

    250

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2022-11-15

  • Closed date

    2022-12-06

  • Last modified date

    2023-01-03

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Modules/Macros

  • C2R3SME1 CKAOUSMF GKROUSMF
    

Fix information

  • Fixed component name

    ZSEC BASE,ADMIN

  • Fixed component ID

    5655T0100

Applicable component levels

  • R250 PSY UJ09702

       UP22/12/08 P F212

Fix is available

  • Select the PTF appropriate for your component level. You will be required to sign in. Distribution on physical media is not available in all countries.

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSPQTM","label":"IBM Security zSecure Admin"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"250","Line of Business":{"code":"LOB24","label":"Security Software"}}]

Document Information

Modified date:
05 January 2023