IBM Support

IT37569: ACE REST ADMIN ENABLED WITH LDAP AUTHORIZATION MAY FAIL TO GET THE EG DETAILS WHEN THE USER IS MEMBER OF HUGE LIST OF GROUPS

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • As part of LDAP authorization, when the roles(group DNs)
    retrieved from LDAP server  is huge and significant in number,
    the Webui/REST API fails to show Integration Server properties
    .. ACE UI shows waiting circle when User clicks on Integration
    Server link.
    

Local fix

  • Customer can try to use less broader scope and any other
    attribute for authorization which is smaller is size may be CN
    

Problem summary

  • ****************************************************************
    USERS AFFECTED:
    All Users of IBM Integration Bus v10.0 and App Connect
    Enterprise V11, V12  using LDAP Authorization for
    Administration.
    
    
    Platforms affected:
    MultiPlatform
    
    ****************************************************************
    PROBLEM DESCRIPTION:
    As part of LDAP authorization, when the roles(group DNs)
    retrieved from LDAP server are huge and significant in number,
     the WebUI/REST API fails to show Integration Server
    properties.. The WebUI shows waiting circle when User clicks on
    Integration Server link.  This happens due to header size
    exceeding the default value allowed by boost http request.
    

Problem conclusion

  • The product now  provides  below environment variables to
    configure the IPC properties:
    1. MQSI_IPC_SOCKET_HEADER_SIZE_LIMIT :Allows user to set
    request header size upto UINT32_MAX.
    2. MQSI_IPC_SOCKET_TIMEOUT : This env variable can be set in
    millisecs to allow more time to receive data.
    
    ---------------------------------------------------------------
    The fix is targeted for delivery in the following PTFs:
    
    Version    Maintenance Level
    v11.0      11.0.0.20
    v12.0      12.0.8.0
    
    The latest available maintenance can be obtained from:
    http://www-01.ibm.com/support/docview.wss?rs=849&uid=swg27006041
    
    If the maintenance level is not yet available,information on
    its planned availability can be found on:
    http://www-1.ibm.com/support/docview.wss?rs=849&uid=swg27006308
    ---------------------------------------------------------------
    

Temporary fix

Comments

APAR Information

  • APAR number

    IT37569

  • Reported component name

    APP CONNECT ENT

  • Reported component ID

    5724J0550

  • Reported release

    B00

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2021-07-12

  • Closed date

    2023-01-24

  • Last modified date

    2023-01-24

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    APP CONNECT ENT

  • Fixed component ID

    5724J0550

Applicable component levels

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSDR5J","label":"IBM App Connect Enterprise"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"B00","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
25 January 2023