IBM Support

IT38057: FTPSERVER POLICIES CANNOT SPECIFY AN SFTP MAC OF HMAC-SHA2-256

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • The FileNodes when used in SFTP mode support connecting to SFTP
    server using a MAC algorithm of hmac-sha2-256, but it is not
    possible to set the "Message authentication code" (i.e. mac)
    property on an FTPServer policy to this value. Attempting to use
    a policy with this value set will cause a BIP3379 error to be
    generated when the policy is used.
    
    BIP3379W: File node 'File Read' in message flow 'Flow'. FTP
    server definition '{SFTPPolicy}:TestServer contains an invalid
    mac property.
    
    This MAC algorithm can be used implicitly in a direct connect to
    an SFTP server without using a policy.
    

Local fix

  • N/A
    

Problem summary

  • ****************************************************************
    USERS AFFECTED:
    All users of FTPServer policies connecting to SFTP servers in
    IBM App Connect Enterprise.
    
    
    Platforms affected:
    MultiPlatform
    
    ****************************************************************
    PROBLEM DESCRIPTION:
    The FileNodes when used in SFTP mode support connecting to SFTP
    server using a MAC algorithm of hmac-sha2-256, but it is not
    possible to set the "Message authentication code" (i.e. mac)
    property on an FTPServer policy to this value. Attempting to use
    a policy with this value set will cause a BIP3379 error to be
    generated when the policy is used.
    
    BIP3379W: File node 'File Read' in message flow 'Flow'. FTP
    server definition '{SFTPPolicy}:TestServer contains an invalid
    mac property.
    
    This MAC algorithm can be used implicitly in a direct connect to
    an SFTP server without using a policy.
    

Problem conclusion

Temporary fix

Comments

APAR Information

  • APAR number

    IT38057

  • Reported component name

    APP CONNECT ENT

  • Reported component ID

    5724J0550

  • Reported release

    B00

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2021-08-19

  • Closed date

    2021-11-22

  • Last modified date

    2021-11-22

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    APP CONNECT ENT

  • Fixed component ID

    5724J0550

Applicable component levels

[{"Line of Business":{"code":"LOB45","label":"Automation"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSDR5J","label":"IBM App Connect Enterprise"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"B00"}]

Document Information

Modified date:
23 November 2021