IBM Support

IT37899: DEPLOYING A FLOW WITH A SECURITY PROFILE IS CAUSING TLS CONNECTIONS TO REQUEST CLIENT CERTIFICATES.

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • Deploying a flow with a security profile may cause the listener
    to request for client certificate while establishing a
    connection over https. A user may expect that the client
    certificate request is off when ReqClientAuth property of
    HTTPSConnector is not set.
    

Local fix

Problem summary

  • ****************************************************************
    USERS AFFECTED:
    All Users of IBM App Connect Enterprise V12 and V11 hosting
    https web services.
    
    
    Platforms affected:
    MultiPlatform
    
    ****************************************************************
    PROBLEM DESCRIPTION:
    Deploying a flow with a security profile may cause the listener
    to request for client certificate while establishing a
    connection over https. A user may expect that the client
    certificate request is off when ReqClientAuth property of
    HTTPSConnector is not set.
    

Problem conclusion

  • The product is now fixed to avoid security profiles having any
    impact on the TLS handshake. A new property named
    'RejectUnauthorizedClient' is also introduced under the
    HTTPSConnector to allow connections from clients without client
    certificates which was earlier achieved through Security
    profiles.
    
    The property can be set under HTTPSConnector of integration node
    or integration server listener.
    
    -n RejectUnauthorizedClient
    
    This property is only applicable when ReqClientAuth property is
    set to true. Set this value to false if you want to allow
    connections from clients who do not furnish client certificates.
    - Value type - Boolean
    - Initial value - true
    
    ---------------------------------------------------------------
    The fix is targeted for delivery in the following PTFs:
    
    Version    Maintenance Level
    v11.0      11.0.0.14
    v12.0      12.0.2.0
    
    The latest available maintenance can be obtained from:
    http://www-01.ibm.com/support/docview.wss?rs=849&uid=swg27006041
    
    If the maintenance level is not yet available,information on
    its planned availability can be found on:
    http://www-1.ibm.com/support/docview.wss?rs=849&uid=swg27006308
    ---------------------------------------------------------------
    

Temporary fix

Comments

APAR Information

  • APAR number

    IT37899

  • Reported component name

    APP CONNECT ENT

  • Reported component ID

    5724J0550

  • Reported release

    B00

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2021-08-06

  • Closed date

    2021-08-31

  • Last modified date

    2021-10-06

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    APP CONNECT ENT

  • Fixed component ID

    5724J0550

Applicable component levels

[{"Line of Business":{"code":"LOB45","label":"Automation"},"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSDR5J","label":"IBM App Connect Enterprise"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"B00"}]

Document Information

Modified date:
13 October 2021