IBM Support

IV35713: BADPADDINGEXCEPTION IN JAVAX.CRYPTO

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

APAR status

  • Closed as program error.

Error description

  • Error Message: javax.crypto.BadPaddingException
    .
    Stack Trace: javax.net.ssl.SSLHandshakeException: Invalid
    padding
     at com.ibm.jsse2.j.a(j.java:13)
     at com.ibm.jsse2.nc.a(nc.java:487)
     at com.ibm.jsse2.nc.b(nc.java:20)
     at com.ibm.jsse2.nc.a(nc.java:331)
     at com.ibm.jsse2.nc.unwrap(nc.java:105)
     at javax.net.ssl.SSLEngine.unwrap(SSLEngine.java:26)
     at ServerEngine.main(ServerEngine.java:243)
    Caused by: javax.crypto.BadPaddingException: Padding length
    invalid: 213
     at com.ibm.jsse2.k.a(k.java:196)
     at com.ibm.jsse2.k.b(k.java:201)
     at com.ibm.jsse2.a.a(a.java:82)
     at com.ibm.jsse2.b.a(b.java:52)
     at com.ibm.jsse2.nc.b(nc.java:306)
     ... 4 more
    .
    

Local fix

  • Set the property -Dcom.ibm.crypto.provider.doAESInHardware=false
    to disable hardware assisted acceleration of AES
    Encryption/Decryption.
    

Problem summary

  • Problem is caused when data needed to do encryption/decryption
    was not always aligned to the hardware's requirements.
    

Problem conclusion

  • This defect will be fixed in:
    7.0.0 SR4
    6.0.1 SR5
    .
    The JVM has been updated to ensure the data is always aligned to
    the hardware's requirements.
    

Temporary fix

Comments

APAR Information

  • APAR number

    IV35713

  • Reported component name

    JIT

  • Reported component ID

    620700124

  • Reported release

    260

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt

  • Submitted date

    2013-01-22

  • Closed date

    2013-01-22

  • Last modified date

    2013-02-06

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    JIT

  • Fixed component ID

    620700124

Applicable component levels

  • R260 PSY

       UP



Document information

More support for: Runtimes for Java Technology
Just In Time (JIT) Compiler

Software version: 260

Reference #: IV35713

Modified date: 06 February 2013