IV71427: IKEYMAN VALIDATION FAILED DESPITE KEYS BEING PRESENT (PROBLEM 1) AND REVIEW CA CERTS INCLUDED IN IKEYMAN (PROBLEM 2)
Closed as program error.
Error Message: Pb 1. Certificate validation failed with iKeyman with error message "Validation failed: Missing intermediate or root certificate".Pb 2. Review new CA certificates : Some new Entrust CA's are not in IKeyman . Stack Trace: N/A .
For iKeyman validation fail (Pb 1), the workaround for the user is to ignore this iKeyman warning as the gsk8capicmd validation passes.
Pb 1. Certificate validated through native GSK command (gskcapicmd) and open ssl command, but failed to validate through iKeyman.Pb 2. Entrust has been using new CA to issue certificates for customers and that these CA's are not in iKeyman.
Pb 1. iKeyman has a problem with the validation of the certificates when using the validation selector of the subject name. It appears that the subject name in this certificate is complex and the selection requires an exact match. The problem can be resolved in iKeyman by changing the code to use the entire certificate as the selector rather than a string representation of the subject name.Pb 2. The following new Entrust CA's were added "Entrust.net Certification Authority (2048) 29", "Entrust Root Certification Authority - EC1", "Entrust Root Certification Authority - EV", "Entrust Root Certification Authority - G2". . This APAR will be fixed in the following Java Releases: 6 SR16 FP4 (126.96.36.199) 7 SR9 (188.8.131.52) 8 SR1 (184.108.40.206) 7 R1 SR3 (220.127.116.11) 6 R1 SR8 FP4 (18.104.22.168) . Contact your IBM Product's Service Team for these Service Refreshes and Fix Packs. For those running stand-alone, information about the available Service Refreshes and Fix Packs can be found at: https://www.ibm.com/developerworks/java/jdk/
Reported component name
Reported component ID
Last modified date
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fixed component name
Fixed component ID
Applicable component levels