IBM Support

7.1.0-TIV-TDI-LA0017

Download


Abstract

This Limited Availability Interim Fix contains TDI AND JRE fixes for RC4 Bar Mitzvah Vulnerability

Download Description

+-----------------------------------------------------+
Interim Fix 7.1.0-TIV-TDI-LA0017 README
Tivoli Directory Integrator 7.1.0
LA Interim Fix 17
(All platforms)
JRE Level: Java 1.6 SR16 FP3 + FREAK iFix + Bar Mitzvah iFix
Date: April 2015
+-----------------------------------------------------+

COPYRIGHT STATEMENT
====================
April 2015

References in this publication to IBM products, programs, or services do
not imply that IBM intends to make these available in all countries in
which IBM operates. Any reference to an IBM program product in this
publication is not intended to state or imply that only IBM's program
product may be used. Any functionally equivalent program may be used
instead.

IBM is a trademark of the International Business Machines Corporation.

Copyright International Business Machines Corporation 2015. All rights
Reserved.

Fix For
========

APAR - NA
PMR - NA

General Description:
====================
TDI FIXES FOR RC4 BAR MITZVAH ATTACK VULNERABILITY.

Details:
========
This Limited Availability Interim Fix contains TDI AND JRE fixes for RC4 Bar Mitzvah Vulnerability

For details about the vulnerability refer the bulletin link -> http://www-01.ibm.com/support/docview.wss?uid=swg21883309


Prerequisites:
==============
For Tivoli Directory Integrator v7.1.0 : Ensure 7.1.0-TIV-TDI-FP0008 is applied.

Platforms:
==========
All supported Platforms

Downloading the Fix:
====================
- Under the Download options section, Click on the "Change Download options" link.
- Set the "Include prerequisites and co-requisite fixes (you can select the ones you need later)" checkbox to true.


Applying the JRE Fix:
=================
- Shutdown TDI.

- Unzip the fix package to a temporary directory. The LA contains platform specific JRE's, copy the .zip or the .tar.gz to respective platforms.

- Extract the .zip /.tar.gz files.

- Copy the jre dir from the extracted .zip / .tar.gz into a dir called jvm.

- Backup the older JVM dir under <TDI_Install_Dir\jvm>. For this, rename the older dir by changing its name to anything other than JVM.

- Replace the existing JVM dir which was backed up earlier with the fix files ( newly created JVM folder ).

- Apply command 'chmod -R 755 JVM' under JVM dir for non windows platform.


Applying the TDI Fix:
=================
- Shutdown TDI.

- Unzip the fix package to a temporary directory. The LA contains miserver.jar, diserverapi.jar and diserverapirmi.jar

- Backup the older miserver.jar, diserverapi.jar and diserverapirmi.jar dir under <TDI_Install_Dir>/jars/common folder. For this, rename the older jar by changing its name to anything other than .jar.

- Replace the miserver.jar, diserverapi.jar and diserverapirmi.jar from the extracted fix package to <TDI_Install_Dir>/jars/common.


Confirming the Fix has been applied successfully:
=================================================
The RC4 Bar Mitzvah Attack vulnerability will be resolved.


md5sum of SDI Jars Included in this Fix:
=====================================
0be0544b99ed2b68d41cadc15f542726 miserver.jar
ee64a2c1a5249604fb44d8e487f634c4 diserverapi.jar
0b3df3f9e758082d2c45ce101d5c7377 diserverapirmi.jar

Prerequisites

For Tivoli Directory Integrator v7.1.0 : Ensure 7.1.0-TIV-TDI-FP0008 is applied.

Installation Instructions

Refer to 7.1.0-TIV-TDI-LA0017_README.txt for details

On
[{"DNLabel":"7.1.0-TIV-TDI-LA0017","DNDate":"24 Apr 2015","DNLang":"English","DNSize":"1475128","DNPlat":{"label":"Platform Independent","code":"PF025"},"DNURL":"http://www.ibm.com/support/fixcentral/quickorder?product=ibm%2FTivoli%2FTivoli+Directory+Integrator&fixids=7.1.0-TIV-TDI-LA0017-BarMitzvah&source=SAR","DNURL_FTP":" ","DDURL":null}]
[{"Product":{"code":"SSCQGF","label":"Tivoli Directory Integrator"},"Business Unit":{"code":"BU008","label":"Security"},"Component":"General","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"7.1","Edition":"All Editions","Line of Business":{"code":"LOB24","label":"Security Software"}}]

Product Synonym

TDI ITDI IDI SDI

Document Information

Modified date:
15 June 2018

UID

swg24039871