APAR status
Closed as program error.
Error description
Error Message: If a Cipher instance is created with algorithm OID(e.g "1.2.840.113549.1.12.1.3") and if unrestricted jurisdiction policy file is not installed, an InvalidKeyException is thrown. . Stack Trace: java.security.InvalidKeyException: Illegal key size at javax.crypto.Cipher.a(Unknown Source) at javax.crypto.Cipher.a(Unknown Source) at javax.crypto.Cipher.a(Unknown Source) at javax.crypto.Cipher.a(Unknown Source) at javax.crypto.Cipher.init(Unknown Source) at javax.crypto.Cipher.init(Unknown Source) .
Local fix
Problem summary
Algorithm OID is not converted to algorithm name when doing permission check
Problem conclusion
The fix is to convert the algorithm OID to the algorithm name before doing the permission check. The associated RTC PR is 108946 The associated Austin CMVC defect is 117195 The associated Austin APAR is IV82024 JVMs affected : Java 6.0, Java 6.1, Java 7.0, Java 7.1 and Java 8.0 The fix was delivered for Java 6.0 SR16 FP25, Java 6.1 SR8 FP25, Java 7.0 SR9 FP40, Java 7.1 SR3 FP 40 and Java 8.0 SR3 The affected jar is "ibmjcefw.jar". The build level of this jar for the affected releases is "20160307" . This APAR will be fixed in the following Java Releases: 8 SR3 (8.0.3.0) 7 R1 SR3 FP40 (7.1.3.40) 7 SR9 FP40 (7.0.9.40) 6 R1 SR8 FP25 (6.1.8.25) 6 SR16 FP25 (6.0.16.25) . Contact your IBM Product's Service Team for these Service Refreshes and Fix Packs. For those running stand-alone, information about the available Service Refreshes and Fix Packs can be found at: https://www.ibm.com/developerworks/java/jdk/
Temporary fix
Comments
APAR Information
APAR number
IV82443
Reported component name
SECURITY
Reported component ID
620700125
Reported release
270
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt / Xsystem
Submitted date
2016-03-09
Closed date
2016-03-18
Last modified date
2016-03-18
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
SECURITY
Fixed component ID
620700125
Applicable component levels
R270 PSY
UP
R260 PSY
UP
R600 PSY
UP
[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSNVBF","label":"Runtimes for Java Technology"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"270","Edition":"","Line of Business":{"code":"LOB36","label":"IBM Automation"}}]
Document Information
Modified date:
07 December 2020