IBM Support

IV68073: RANDOM NUMBER GENERATED BY SHA1PRNG MAY NOT BE UNIQUE IN HIGHLY STRESSED ENVIRONMENT

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • Error Message: N/A
    .
    Stack Trace: N/A
    .
    When SHA1PRNG is used to generate random number on large number
    of JVMs, there might be duplicate random numbers in the result.
    

Local fix

  • N/A
    

Problem summary

  • The problem happens because the internal state do not have
    enough entryopy.
    

Problem conclusion

  • A fix is made to IBMJCE providerThe associated Hursley RTC
    Problem Report is 81891The associated Hursley CMVC defect is
    202648The associated Austin CMVC defect is 116197The associated
    Austin APAR is IV67837JVMs affected: Java 5.0, Java 6.0, Java
    626, Java 7.0 and Java 727The fix was delivered for Java 5.0
    SR16FP10, Java 6.0 SR16FP4, Java 626 SR8FP4, Java 7.0 SR9 and
    Java 727 SR3The affected jar is "ibmjceprovider.jar".The build
    level of this jar for the affected releases is "20141216"
    .
    This APAR will be fixed in the following Java Releases:
       6    SR16 FP4  (6.0.16.4)
       5.0  SR16 FP10 (5.0.16.10)
       7    SR9       (7.0.9.0)
       6 R1 SR8 FP4   (6.1.8.4)
       7 R1 SR3       (7.1.3.0)
    .
    Contact your IBM Product's Service Team for these Service
    Refreshes and Fix Packs.
    For those running stand-alone, information about the Service
    Refreshes and Fix Packs can be found at:
               https://www.ibm.com/developerworks/java/jdk/
    

Temporary fix

Comments

APAR Information

  • APAR number

    IV68073

  • Reported component name

    SECURITY

  • Reported component ID

    620700125

  • Reported release

    600

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt

  • Submitted date

    2014-12-18

  • Closed date

    2014-12-23

  • Last modified date

    2014-12-23

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

    IV68074

Fix information

  • Fixed component name

    SECURITY

  • Fixed component ID

    620700125

Applicable component levels

  • R600 PSY

       UP

  • R260 PSY

       UP

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSNVBF","label":"Runtimes for Java Technology"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"6.0","Edition":"","Line of Business":{"code":"LOB36","label":"IBM Automation"}}]

Document Information

Modified date:
07 December 2020