IBM Support

PM80646; 8.0.0.5: oauth provider does not support reverse proxy configuration ca

Download


Abstract

With OAuth, a user may not be redirected to a reverse proxy server.

Download Description

PM80646 resolves the following problem:

ERROR DESCRIPTION:
For OAuth, in the case of reverse proxy, the authorization URL doesn't reflect the real URL and a reverse proxy is not able to rewrite the value.

LOCAL FIX:
For the work around, as the content form template is customizable, the developer can update the template to reset the authorization url to target server on page load.

PROBLEM SUMMARY

USERS AFFECTED:
IBM WebSphere Application Server administrators of application servers using OAuth

PROBLEM DESCRIPTION:
With OAuth, a user may not be redirected to a reverse proxy server.

RECOMMENDATION:
Install a fix pack that incluses this APAR and update the installed OAuth app, WebSphereOauth20SP.ear, from the (WAS_HOME)/installableApps directory..

In a WebSphere OAuth authorization process, a user may not be redirected to the requested reverse proxy server after authorization is granted. The user is redirected to an HTTP server directly.

PROBLEM CONCLUSION:
The WebSphere Application Server is updated to redirected the user to the requested URL.

When a fix pack containing this APAR is installed, the fix will not be active until the installed OAuth ear,
WebSphereOauth20SP.ear, is updated from the (WAS_HOME)/installableApps directory.

The fix for this APAR is currently targeted for inclusion in fix packs 7.0.0.29, 8.0.0.7 and the fix pack following 8.5.0.2. Please refer to the Recommended Updates page for delivery information:
http://www.ibm.com/support/docview.wss?uid=swg27004980

Prerequisites

None

Installation Instructions

Please review the readme.txt for detailed installation instructions.

On
[{"DNLabel":"8.0.0.5-WS-WASProd-IFPM80646","DNDate":"11 Jul 2013","DNLang":"US English","DNSize":"426802","DNPlat":{"label":"AIX","code":"PF002"},"DNURL":"http://www.ibm.com/support/fixcentral/quickorder?fixids=8.0.0.5-WS-WASProd-IFPM80646&product=ibm%2FWebSphere%2FWebSphere+Application+Server&source=dbluesearch","DNURL_FTP":" ","DDURL":null}]

Technical Support

Contact IBM Support using SR (http://www.ibm.com/software/support/probsub.html), visit the WebSphere Application Server support web site (http://www.ibm.com/software/webservers/appserv/was/support/), or contact 1-800-IBM-SERV (U.S. only).

[{"Product":{"code":"SSEQTP","label":"WebSphere Application Server"},"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Component":"Security","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF010","label":"HP-UX"},{"code":"PF012","label":"IBM i"},{"code":"PF016","label":"Linux"},{"code":"PF027","label":"Solaris"},{"code":"PF033","label":"Windows"},{"code":"PF035","label":"z\/OS"}],"Version":"8.0.0.5","Edition":"Base;Express;Network Deployment","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
15 June 2018

UID

swg24035401