IBM Support

DY47731: LDAP SIGN ON VIA SSL/TLS FAILS, IF CRYPTO CARDS ARE USED

A fix is available

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as unreproducible in next release.

Error description

  • When using the z/VSE LDAP client with OpenSSL via the LE/C
    multiplexer (EDCTCPMC), an error occurs if Crypto Express cards
    are used. The error is caused by an incorrect switching to key
    zero for accessing a card, but not switching back to the correct
    CICS key. This APAR corrects key zero handling in phase IJBCRLIB
    for accessing crypto cards.
    

Local fix

  • Apply PTF.
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED: All OpenSSL users using crypto cards.        *
    ****************************************************************
    * PROBLEM DESCRIPTION: SSL/TLS handshaking fails with z/VSE    *
    *                      LDAP client when crypto cards are       *
    *                      used.                                   *
    ****************************************************************
    * RECOMMENDATION:                                              *
    ****************************************************************
    z/VSE LDAP client fails.
    

Problem conclusion

Temporary fix

Comments

  • Apply PTF.
    

APAR Information

  • APAR number

    DY47731

  • Reported component name

    VSE/AF MACROS

  • Reported component ID

    5686CF906

  • Reported release

    52C

  • Status

    CLOSED UR1

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2017-09-27

  • Closed date

    2017-09-28

  • Last modified date

    2017-10-17

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

    UD54261

Modules/Macros

  • IJBCRLIB IJBHC
    

Fix information

  • Fixed component name

    VSE/AF MACROS

  • Fixed component ID

    5686CF906

Applicable component levels

  • R52C PSY UD54261

       UP17/10/16 I 1000

Fix is available

  • Select the PTF appropriate for your component level. You will be required to sign in. Distribution on physical media is not available in all countries.

[{"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Product":{"code":"SG32M","label":"APARs - VSE\/ESA environment"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"52C","Edition":"","Line of Business":{"code":"","label":""}}]

Document Information

Modified date:
11 December 2020