IBM Support

IBM Tivoli Composite Application Manager for Transactions Response Time 7.3.0.1 Interim Fix 22 README Tivoli Composite Application Manager for Transactions 7.3.0.1 7.3.0.1-TIV-CAMRT-IF0022 Readme

Fix Readme


Abstract

xxx

Content

Readme file for: 7.3.0.1-TIV-CAMRT-IF0022
Product/Component Release: 7.3.0.1
Update Name: 7.3.0.1-TIV-CAMRT-IF0022
Fix ID: 7.3.0.1-TIV-CAMRT-AIX-IF0022, 7.3.0.1-TIV-CAMRT-LINUX-IF0022, 7.3.0.1-TIV-CAMRT-WINDOWS-IF0022
Publication Date: 16 Sep 2013
Last modified date: 16 Sep 2013

Download location

The information included in this document is published at product release time. For the latest updates on this release please refer to the on-line document: To download this update you must first login to IBM FixCentral. Once logged in, you may select from the individual download packages.
http://www.ibm.com/eserver/support/fixes/

Below is a list of components, platforms, and file names that apply to this Readme file.

Fix Download for AIX

Product/Component Name: Platform: Fix:
Tivoli Composite Application Manager for Transactions AIX
7.3.0.1-TIV-CAMRT-AIX-IF0022

Fix Download for Linux

Product/Component Name: Platform: Fix:
Tivoli Composite Application Manager for Transactions Linux
7.3.0.1-TIV-CAMRT-LINUX-IF0022

Fix Download for Windows

Product/Component Name: Platform: Fix:
Tivoli Composite Application Manager for Transactions Windows
7.3.0.1-TIV-CAMRT-WINDOWS-IF0022

Prerequisites and co-requisites

This update for ITCAM for Transactions Response Time may be applied to the following base versions.

  • 7.1.X.X
  • 7.2.X.X
  • 7.3.X.X
Note: Supported base versions include interim fixes applied to any of the above release levels.

This MDV replaces the two JREs shipped with the Robotics Response Time (T6) agent, bringing them to the latest level. This remediates multiple security issues.

This patch is applicable for T6 agents:
* versions 7.3.0.x, 7.2.0.x and 7.1.0.x
* Windows, AIX and Linux platforms.
The T6's JREs are only used when playing back Rational Performance Tester (RPT) scripts, thus not available on Solaris and HPUX (RPT playback are not supported on those platforms).

7.3 agents need to update both java60 and java 70 JREs. 7.2 and 7.1 agents only needs to update java60. These variations are noted in the installation steps below.

Any customisations done to the existing JREs needs to be preseved. Since these JREs are product specific (ie only used by the T6 agent), there should only be at most one customisation as instructed by IBM support; which is to enable strong encryption by updating the JRE's encryption policy (see technote in Related Material).

After the patch, the Java versions will be:
* Java 6.0 SR14
* Java 7.0 SR5

Related material:
* Oracle's Java June 2013 CPU Advisory - details vulnerabilities addressed
http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

* Details on Strong Encryption keys
http://www-01.ibm.com/support/docview.wss?uid=swg21245273

Superseded By:
N/A

Supersedes:
7.3.0.1-TIV-CAMRT-IF0021

Installation information

Installing

1 Before Installing the fix pack
----------------------------------
A. Validate pre-existing java is older than ones delivered in this IFix.
The RRT Agent's javas are located in
Windows:
java60: $ITMHOME\tmaitm6\java60
java70: $ITMHOME\tmaitm6\java70 - only in 7.3.0.1-LA2 and later
Unix:
java60: $ITMHOME/tmaitm6/java60
java70: $ITMHOME/tmaitm6/java70 - only in 7.3.0.1-LA2 and later

Check their versions, eg
C:\ibm\itm\TMAITM6> .\java70\jre\bin\java.exe -version

java version "1.7.0"
Java(TM) SE Runtime Environment (build pwi3270sr2-20120901_01(SR2))
IBM J9 VM (build 2.6, JRE 1.7.0 Windows Server 2008 R2 x86-32 20120809_118929 (JIT enabled, AOT enabled)
J9VM - R26_Java726_SR2_20120809_0948_B118929
JIT - r11.b01_20120808_24925
GC - R26_Java726_SR2_20120809_0948_B118929
J9CL - 20120809_118929)
JCL - 20120831_02 based on Oracle 7u3-b05

Notice that J9VM indicates it is SR2 (no Fixpack) and hence it is
older than SR5 and needs update.

2 Applying the fix pack
-------------------------
Notes:
1. If you are using 7.2 and 7.1 T6 agents, you do not need to
unarchive the \java70 directory. For 7.3 onwards, please unarchive
both JREs.
2. If you have updated the T6 jre to use strong encryption, you must
migrate the policy files to the new JREs. The two files are:
<JRE_HOME>\lib\security\local_policy.jar
<JRE_HOME>\lib\security\US_export_policy.jar
See: http://www-01.ibm.com/support/docview.wss?uid=swg21245273

A. Back up existing java
1. Stop the T6 agent
2. Backup existing java jres, e.g.
> c:
> cd c:\ibm\itm\tmaitm6\
> move java60 java60.old
> move java70 java70.old - only in 7.3.0.1-LA and later.

B. Replace the JREs
1. Unzip/Untar the archive to the same directory, e.g.
After unarchiving your directory structure should be like

c:\IBM\ITM\TMAITM6>dir java*
Volume in drive C has no label.
Volume Serial Number is 44AB-01FC

Directory of c:\IBM\ITM\TMAITM6

29/05/2013 02:02 PM <DIR> java60
12/03/2012 04:08 PM <DIR> java60.old
29/05/2013 02:04 PM <DIR> java70
13/02/2013 02:14 PM <DIR> java70.old
0 File(s) 0 bytes
4 Dir(s) 30,808,731,648 bytes free
2. (Optional) Preserve security policy files, e.g.
> cd c:\ibm\itm\tmaitm6\
> copy java60.old\jre\lib\security\local_policy.jar java60\jre\lib\security
> copy java60.old\jre\lib\security\US_export_policy.jar java60\jre\lib\security
> copy java70.old\jre\lib\security\local_policy.jar java70\jre\lib\security
> copy java70.old\jre\lib\security\US_export_policy.jar java70\jre\lib\security

C. Validate the update JRE version/function
1. check version number of JRE 6.0, e.g.
> c:
> cd c:\ibm\itm\tmaitm6
> java60\jre\bin\java.exe -version
java version "1.6.0"
Java(TM) SE Runtime Environment (build pwi3260sr14-20130705_01(SR14))
IBM J9 VM (build 2.4, JRE 1.6.0 IBM J9 2.4 Windows 7 x86-32 jvmwi3260sr14-20130704_155156 (JIT enabled, AOT enabled)
J9VM - 20130704_155156
JIT - r9_20130517_38390
GC - GA24_Java6_SR14_20130704_1138_B155156)
JCL - 20130618_01

> java70\jre\bin\java.exe -version
java version "1.7.0"
Java(TM) SE Runtime Environment (build pwi3270sr5-20130619_01(SR5))
IBM J9 VM (build 2.6, JRE 1.7.0 Windows 7 x86-32 20130617_152572 (JIT enabled, AOT enabled)
J9VM - R26_Java726_SR5_20130617_1436_B152572
JIT - r11.b04_20130528_38954ifx1
GC - R26_Java726_SR5_20130617_1436_B152572
J9CL - 20130617_152572)
JCL - 20130616_01 based on Oracle 7u25-b12

D. Restart Agent and ensure RPT Script playback works.

E. (Optional) Delete the backup java runtimes.

Additional information

This fix pack image contains the following files:

- 7.3.0.1-TIV-CAMRT-AIX-IF0022.tar - md5sum cedf784df1e30dc9cef87941316f2b34
- 7.3.0.1-TIV-CAMRT-LINUX-IF0022.tar - md5sum 6bdc82f7c43f031f96a7f8473f48e3ca
- 7.3.0.1-TIV-CAMRT-WIN-IF0022.zip - md5sum 59c0e3a58b3b4544eaf4bee4f1df0a62

The tar/zip files contains the following:
- 7.3.0.1-TIV-CAMRT-AIX-IF0022.tar
\java60\* - JRE 1.6.0 SR14
\java70\* - JRE 1.7.0 SR5 - Not required for 7.2 and 7.1 T6s
- 7.3.0.1-TIV-CAMRT-Linux-IF0022.tar
\java60\* - JRE 1.6.0 SR14
\java70\* - JRE 1.7.0 SR5 - Not required for 7.2 and 7.1 T6s
- 7.3.0.1-TIV-CAMRT-Windows-IF0022.zip
\java60\* - JRE 1.6.0 SR14
\java70\* - JRE 1.7.0 SR5 - Not required for 7.2 and 7.1 T6s

List of fixes

A) APAR Content:

IV48461 RRT: SECURITY UPDATES FOR JRE(S) - SEP 2013
B) Additional Non APAR Defects:

N/A C) Enhancements

N/A

Document change history


Version Date Description of change
1.0 16 Sept 2013 Initial Version


















[{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SS5MD2","label":"Tivoli Composite Application Manager for Transactions"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"","Edition":"","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
16 September 2013

UID

isg400001621