IBM Support

PM68660: Outbound SSL connection may fail when different SSL configs are used for JAX-WS web services connections.

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • When a new SSL config is created, other services that rely on
    existing SSL config may fail intermittently.  For example, the
    error may look like following:
    
    java.lang.IllegalArgumentException: CWPKI0024E: The certificate
    alias "client-cert" specified by the property
    com.ibm.ssl.keyStoreServerAlias is not found in KeyStore
    "/opt/ibm/WebSphere/AppServer/profiles/myProfile/config/cells/my
    Cell/nodes/myNode/aaa.bbb".
    at
    com.ibm.ws.ssl.channel.impl.SSLChannel.getSSLContextForLink(SSLC
    hannel.java:517)
    at
    com.ibm.ws.ssl.channel.impl.SSLChannel.getSSLContextForOutboundL
    ink(SSLChannel.java:331)
    at
    com.ibm.ws.ssl.channel.impl.SSLConnectionLink.connect(SSLConnect
    ionLink.java:981)
    at
    com.ibm.wsspi.channel.base.OutboundProtocolLink.connect(Outbound
    ProtocolLink.java:87)
    at
    com.ibm.ws.http.channel.outbound.impl.HttpOutboundLink.connect(H
    ttpOutboundLink.java:278)
    at
    com.ibm.ws.channel.framework.impl.OutboundVirtualConnectionImpl.
    connect(OutboundVirtualConnectionImpl.java:79)
    at
    com.ibm.ws.websvcs.transport.http.HTTPConnection.doConnect(HTTPC
    onnection.java:484)
    Caused by: java.lang.IllegalArgumentException: CWPKI0024E: The
    certificate alias "client-cert" specified by the property
    com.ibm.ssl.keyStoreServerAlias is not found in KeyStore
    "/opt/ibm/WebSphere/AppServer/profiles/myProfile/config/cells/my
    Cell/nodes/myNode/aaa.bbb".
    at
    com.ibm.ws.ssl.core.WSX509KeyManager.setServerAlias(WSX509KeyMan
    ager.java:103)
    at
    com.ibm.ws.ssl.provider.AbstractJSSEProvider.getKeyTrustManagers
    (AbstractJSSEProvider.java:546)
    at
    com.ibm.ws.ssl.provider.AbstractJSSEProvider.generateNewSSLConte
    xt(AbstractJSSEProvider.java:209)
    at
    com.ibm.ws.ssl.provider.AbstractJSSEProvider.getSSLContext(Abstr
    actJSSEProvider.java:191)
    at
    com.ibm.ws.ssl.channel.impl.SSLChannel.getSSLContextForLink(SSLC
    hannel.java:504)
    ...
    

Local fix

  • N/A
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED:  All users of IBM WebSphere Application      *
    *                  Server Feature Pack for Web Services using  *
    *                  multiple SSL configurations.                *
    ****************************************************************
    * PROBLEM DESCRIPTION: Outbound SSL connection may fail when   *
    *                      different SSL configurations are        *
    *                      used for Web services connections.      *
    ****************************************************************
    * RECOMMENDATION:  Install this APAR.                          *
    ****************************************************************
    When Web services applications are configured to use different
    SSL configs for outbound connections, the outbound SSL
    connection may fail due to incorrect SSL configuration being
    bound to the SSL channel.
    

Problem conclusion

  • Web services code has been changed to use the correct SSL
    configuration when creating the SSL channel for outbound
    connections.
    
    An interim fix for this APAR is available from IBM support.
    
    PM48098 Corrects this issue on WebSphere Application Server
    versions 7 and higher.
    

Temporary fix

Comments

APAR Information

  • APAR number

    PM68660

  • Reported component name

    WEBSERVIC FEATU

  • Reported component ID

    5724J0850

  • Reported release

    610

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt

  • Submitted date

    2012-07-11

  • Closed date

    2012-09-24

  • Last modified date

    2012-09-24

  • APAR is sysrouted FROM one or more of the following:

    PM48098

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    WEBSERVIC FEATU

  • Fixed component ID

    5724J0850

Applicable component levels

  • R610 PSY

       UP

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSEQTP","label":"WebSphere Application Server"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"6.1","Edition":"","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
10 February 2022