IBM Support

IV75701: AES/CTR DOESN'T BEHAVE STREAM CIPHER LIKE

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

APAR status

  • Closed as program error.

Error description

  • Error Message, as reported by customer:
    When using AES/CTR, the length of output of Cipher.update() is
    not the same as the input data length.
    
    Stack Trace, if applicable:
    N/A
    
    Other Error Information, as reported by customer:
    N/A
    

Local fix

  • N/A
    

Problem summary

  • AES/CTR doesn't behave stream cipher like
    
    ERROR DESCRIPTION:
    When using AES/CTR, the length of output of Cipher.update() is
    not the same as the input data length.
    

Problem conclusion

  • The fix is to change the data unit to be processed to be one
    byte each time for AES/CTR.
    The associated RTC PR is 97798
    The associated Austin CMVC defect is 116826
    The associated Hursley CMVC defect is 202847
    The associated APAR is IV75701
    JVMs affected : Java 5.0, Java 6.0, Java 6.1, Java 7.0 , Java
    7.1 and Java 8.0
    The fix was delivered for Java 5.0 SR16 FP14, Java 6.0 SR16
    FP15, Java 6.1 SR8 FP15, Java 7.0 SR9 FP20, Java 7.1 SR3 FP20
    and Java 8.0 SR2
    The affected jar is "ibmjceprovider.jar".
    The build level of this jar for the affected releases is
    "20150812"
    

Temporary fix

Comments

APAR Information

  • APAR number

    IV75701

  • Reported component name

    TIV JAVA CRYPTO

  • Reported component ID

    TIVSECJCE

  • Reported release

    100

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt

  • Submitted date

    2015-08-03

  • Closed date

    2015-09-03

  • Last modified date

    2015-09-03

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    TIV JAVA CRYPTO

  • Fixed component ID

    TIVSECJCE

Applicable component levels

  • R100 PSY

       UP



Document information

More support for: Tivoli Components - Java Security
JCE

Software version: 100

Reference #: IV75701

Modified date: 03 September 2015