IBM Support

PK67774: MAP SECURITY ROLES TO USERS(GROUPS) FAILS TO ESCAPE EMBEDDED DOUBLEQUOTES IN LDAP DN.

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • In the console Map security roles to users(groups) fails
    to escape embedded doubleQuotes in LDAP DN causes incomplete
    binding string to be entered after upgrading to V6.0.2.27 from
    V6.0.2.17.
    
    within ear file: Any.ear/META-INF/ibm-application-bnd.xmi
    WebSphere Patch Level 17 assignment escapes double quote within
    Organization:
    =======================================================
        <authorizations xmi:id="RoleAssignment_1212090404532">
          <users xmi:id="User_1212430712302"
    name="ndGuid=xx.yyy.xxxx5ft8,
    ou=people,o="University of xxxx yyyy",st=xxxx,c=US"/>
          <users xmi:id="User_1212430712303"
    name="ndGuid=xx.yyy.xxsg4mv4,
    ou=people,o="University of xxxx yyyy",st=xxxx,c=US"/>
          <role
    href="META-INF/application.xml#SecurityRole_1212430712302"/>
        </authorizations>
    
    
    WebSphere Patch Level 27 assignment stops at the quote within
    Organization:
    ====================================================
        <authorizations xmi:id="RoleAssignment_1212090404532">
          <users xmi:id="User_1212426036269"
    name="ndGuid=nd.edu.ndxx5ft8,
    ou=people,o="/>
          <users xmi:id="User_1212426036268"
    name="ndGuid=nd.edu.ndsg4mv4,
    ou=people,o="/>
          <role
    href="META-INF/application.xml#SecurityRole_1212426036269"/>
        </authorizations>
    

Local fix

  • Use the wsadmin tool to perform this mapping operation.
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED: IBM Websphere Application Server V6.0.2 and  *
    *                 V6.1 adminstrative console users who are     *
    *                 using the "Map Roles to users or groups"     *
    *                 panel.                                       *
    ****************************************************************
    * PROBLEM DESCRIPTION: The double quote is not parsed for      *
    *                      Users or Groups during selection to     *
    *                      map the roles.                          *
    ****************************************************************
    * RECOMMENDATION:                                              *
    ****************************************************************
    The users and groups fail to escape the double quote during
    the process of selection in the Map roles to Users/Groups
    panel .
    
    Within ear file: Any.ear/META-INF/ibm-application-bnd.xmi
    
    =======================================================
    <authorizations xmi:id="RoleAssignment_1212090404532">
    <users xmi:id="User_1212430712302"
    name="ndGuid=xx.yyy.xxxx5ft8,
    ou=people,o="University of xxxx yyyy",st=xxxx,c=US"/>
    <users xmi:id="User_1212430712303"
    name="ndGuid=xx.yyy.xxsg4mv4,
    ou=people,o="University of xxxx yyyy",st=xxxx,c=US"/>
    <role
    href="META-INF/application.xml#SecurityRole_1212430712302"/>
    </authorizations>
    
    The problem arose due to an HTML parsing mechanism for quote
    and double quote.
    

Problem conclusion

Temporary fix

Comments

APAR Information

  • APAR number

    PK67774

  • Reported component name

    WEBS APP SERV N

  • Reported component ID

    5724H8800

  • Reported release

    61A

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt

  • Submitted date

    2008-06-18

  • Closed date

    2008-08-13

  • Last modified date

    2008-08-13

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    WEBS APP SERV N

  • Fixed component ID

    5724H8800

Applicable component levels

  • R60A PSY

       UP

  • R60H PSY

       UP

  • R60I PSY

       UP

  • R60P PSY

       UP

  • R60S PSY

       UP

  • R60W PSY

       UP

  • R61A PSY

       UP

  • R61H PSY

       UP

  • R61I PSY

       UP

  • R61P PSY

       UP

  • R61S PSY

       UP

  • R61W PSY

       UP

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSEQTP","label":"WebSphere Application Server"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"6.1","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
29 December 2021