IBM Support

IT24684: The inbound client listening port for the SP client executables allows legacy SSL/TLS protocols and cipher to be used.

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • IBM Spectrum Protect allows legacy SSL/TLS protocols and
    ciphers to be used which can result in the use of weaker
    than expected cyrptographic algorithms.
    
    Products affected:
    IBM Spectrum Protect Backup-Archive Client version
    7.1.8, 8.1.2 and 8.1.4 on all platforms.
    Note: In IBM Spectrum Protect for Virtual Environments,
    the Backup-Archive Client is also known as the
    data mover.
    
    This problem also affects IBM Spectrum Protect for Virtual
    Environments: Data Protection for VMware 8.1.2 and 8.1.4.
    If you are using Data Protection for VMware 8.1.2 or 8.1.4,
    refer to APAR IT25260
    This problem also affects IBM Spectrum Protect for Virtual
    Environments: Data Protection for Microsoft Hyper-V 8.1.2 and
    8.1.4. If you are using Data Protection for Microsoft Hyper-V
    8.1.2 or
    8.1.4, refer to APAR IT25261
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED:                                              *
    * IBM Spectrum Protect backup-archive client version 7.1.8,    *
    * 8.1.2 and 8.1.4 running on all  platforms.                   *
    ****************************************************************
    * PROBLEM DESCRIPTION:                                         *
    * See ERROR DESCRIPTION                                        *
    * For additional information, refer to the security bulletin   *
    * published here:                                              *
    * http://www.ibm.com/support/docview.wss?uid=ibm10718013       *
    ****************************************************************
    * RECOMMENDATION:                                              *
    * This issue is projected to be fixed in the IBM Spectrum      *
    * Protect backup-archive client version  7.1.8.3 and 8.1.6 on  *
    * all platforms.                                               *
    * Note 1: This is subject to change at the discretion of IBM.  *
    ****************************************************************
    

Problem conclusion

  • Now IBM spectrum protect backup-archive client does not
    initialize SSL/TLS protocols less than TLS1.2 if
    "ssldisablelegacytls" option is enabled.
    

Temporary fix

Comments

APAR Information

  • APAR number

    IT24684

  • Reported component name

    TSM CLIENT

  • Reported component ID

    5698ISMCL

  • Reported release

    71W

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2018-04-10

  • Closed date

    2018-05-30

  • Last modified date

    2018-09-24

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

    IT25260 IT25261

Fix information

  • Fixed component name

    TSM CLIENT

  • Fixed component ID

    5698ISMCL

Applicable component levels

  • R81A PSY

       UP

  • R81H PSY

       UP

  • R81L PSY

       UP

  • R81M PSY

       UP

  • R81S PSY

       UP

  • R81W PSY

       UP

  • R71A PSY

       UP

  • R71H PSY

       UP

  • R71L PSY

       UP

  • R71M PSY

       UP

  • R71S PSY

       UP

  • R71W PSY

       UP

[{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SSGSG7","label":"Tivoli Storage Manager"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"71W","Edition":"","Line of Business":{"code":"LOB26","label":"Storage"}}]

Document Information

Modified date:
24 September 2018