IBM Support

IT10681: FALSE POSITIVE VERIFYING SIGNED DOC WITH MULTIPLE SIGNATURES

Subscribe

You can track all active APARs for this component.

APAR status

  • Closed as program error.

Error description

  • JWS allows multiple signatures in a signed document.  During
    verification, all signatures must be validated prior to finally
    accepting the document.
    
    In the case of GatewayScript, if the first signatures tests
    positive, the document is accepted regardless of the validity of
    the remaining signatures in the payload.
    

Local fix

Problem summary

  • Affect users who use JWS verify action.
    
    JWS allows multiple signatures in a signed document.  During
    verification, all signatures must be validated prior to finally
    accepting the document.
    
    In the case of GatewayScript, if the first signatures tests
    positive, the document is accepted regardless of the validity of
    the remaining signatures in the payload.
    

Problem conclusion

  • Fix is available in 7.2.0.1.
    

Temporary fix

Comments

APAR Information

  • APAR number

    IT10681

  • Reported component name

    DATAPOWER

  • Reported component ID

    DP1234567

  • Reported release

    720

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt

  • Submitted date

    2015-08-17

  • Closed date

    2015-10-27

  • Last modified date

    2015-10-27

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    DATAPOWER

  • Fixed component ID

    DP1234567

Applicable component levels

  • R720 PSY

       UP



Document information

More support for: IBM DataPower Gateways
General

Software version: 7.2

Reference #: IT10681

Modified date: 27 October 2015