APAR status
Closed as program error.
Error description
When use the MQTT Nodes with TLS enabled the nodes will fail to establish a connection. Taking an SSL trace will reveal that the nodes are attempting to use SSLv3 but this protocol is disabled by the JVM.
Local fix
Problem summary
**************************************************************** USERS AFFECTED: All users of App Connect Enterprise version 11 using the MQTT Nodes with TLS enabled Platforms affected: MultiPlatform **************************************************************** PROBLEM DESCRIPTION: <span style="background-color:rgb(255, 255, 255)">When use the MQTT Nodes with TLS enabled the nodes will fail to </span><span style="background-color:rgb(255, 255, 255)">establish a connection. Taking a JSSE2 trace will reveal that </span><span style="background-color:rgb(255, 255, 255)">the nodes are attempting to use a protocol version that has been disabled by the JVM. for example:</span> 2019-07-04 18:16:31.460 67 MQTT Con: a:hi4f6s:sappipsb-27, READ: TLSv1 Alert, length = 2 2019-07-04 18:16:31.462 67 MQTT Con: a:hi4f6s:sappipsb-27, RECV TLSv1.2 ALERT: fatal, protocol_version 2019-07-04 18:16:31.504 67 MQTT Con: a:hi4f6s:sappipsb-27, called closeSocket()
Problem conclusion
The MQTT Nodes now correctly enable TLS1.2 when TLS is enabled. --------------------------------------------------------------- The fix is targeted for delivery in the following PTFs: Version Maintenance Level v11.0 11.0.0.8 The latest available maintenance can be obtained from: http://www-01.ibm.com/support/docview.wss?rs=849&uid=swg27006041 If the maintenance level is not yet available,information on its planned availability can be found on: http://www-1.ibm.com/support/docview.wss?rs=849&uid=swg27006308 ---------------------------------------------------------------
Temporary fix
Comments
APAR Information
APAR number
IT31821
Reported component name
APP CONNECT ENT
Reported component ID
5724J0550
Reported release
B00
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt / Xsystem
Submitted date
2020-02-11
Closed date
2020-03-23
Last modified date
2020-03-23
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
APP CONNECT ENT
Fixed component ID
5724J0550
Applicable component levels
[{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSDR5J","label":"IBM App Connect Enterprise"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"B00","Edition":"","Line of Business":{"code":"LOB45","label":"Automation"}}]
Document Information
Modified date:
23 March 2020