APAR status
Closed as program error.
Error description
When an X509 token is used as Authentication token, its seen that it is only propagated for the first message. For subsequent messages the value is empty. Ideally, for every authenticated request, the IdentitySourceToken field of properties folder should have the token irrespective of the token type(provided that the security profile has propagation property set as TRUE).
Local fix
Problem summary
**************************************************************** USERS AFFECTED: All users of Integration Bus V10.0/V9.0 using X.509 authentication token. Platforms affected: z/OS, MultiPlatform **************************************************************** PROBLEM DESCRIPTION: When an X.509 token is used for Authentication, it is only propagated for the first message. For subsequent messages the value is empty. If the security profile is set to propagate identity then all authenticated requests should have a token in the IdentitySourceToken field of properties folder, this is true for all token types. There are a number of resource name changes between WebSphere Message Broker and IBM Integration Bus Version 9.0. For details visit http://pic.dhe.ibm.com/infocenter/wmbhelp/v9r0m0/topic/com.ibm.e tools.mft.doc/bb23814_.htm
Problem conclusion
The product now always propagates an authenticated x.509 token when the Security profile has propagation property set as TRUE. --------------------------------------------------------------- The fix is targeted for delivery in the following PTFs: Version Maintenance Level v8.0 8.0.0.8 v9.0 9.0.0.6 v10.0 10.0.0.5 The latest available maintenance can be obtained from: http://www-01.ibm.com/support/docview.wss?rs=849&uid=swg27006041 If the maintenance level is not yet available,information on its planned availability can be found on: http://www-1.ibm.com/support/docview.wss?rs=849&uid=swg27006308 ---------------------------------------------------------------
Temporary fix
Comments
APAR Information
APAR number
IT08119
Reported component name
INTEGRATION BUS
Reported component ID
5724J0530
Reported release
900
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt / Xsystem
Submitted date
2015-04-07
Closed date
2016-05-24
Last modified date
2016-05-24
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
INTEGRATION BUS
Fixed component ID
5724J0530
Applicable component levels
R900 PSY
UP
[{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSNQK6","label":"IBM Integration Bus"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"9.0","Edition":"","Line of Business":{"code":"LOB45","label":"Automation"}}]
Document Information
Modified date:
23 March 2020