IBM Support

IT46152: FILE NODES USING SFTP PROTOCOL MAY FAIL WITH BIP3380E

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • When file nodes configured to use SFTP protocol, the connection
    to the SFTP server might fail with error code BIP3380E if the
    server is configured to use below listed KEX algorithms as these
    are not supported currently:
    
    1) diffie-hellman-group14-sha1
    
    2) diffie-hellman-group-exchange-sha1
    3) diffie-hellman-group1-sha1
    

Local fix

  • The issue can be work around by setting the JVM system property
    "jsch.kex" to specify the Algorithms that can be used.  This can
    be achieved either
    
    - by  modifying server.conf.yaml file  (
    ResourceManagers/JVM/jvmSystemProperty)
    
    ResourceManagers:
    
     JVM:
    
       jvmSystemProperty: '-Djsch.kex=<Comma separated list of Kex
    Algorithms>'
    
    
    OR
    
    
    - by setting the environment variable IBM_JAVA_OPTIONS (export
    IBM_JAVA_OPTIONS=-Djsch.kex=).
    

Problem summary

  • ****************************************************************
    USERS AFFECTED:
    All users of IBM App Connect Enterprise V12.0 using the File
    nodes with SFTP transfer protocol.
    
    
    Platforms affected:
    MultiPlatform
    
    ****************************************************************
    PROBLEM DESCRIPTION:
    The file nodes, when configured to use an SFTP connection, do
    not currently support the following key exchange (kex)
    algorithms:
    
    1) diffie-hellman-group14-sha1
    2) diffie-hellman-group-exchange-sha1
    3) diffie-hellman-group1-sha1
    
    Any attempt to use one of these unsupported kex algorithms may
    cause the SFTP connection to fail with the error code BIP3380E -
    'MAC OR CIPHER NOT SUPPORTED BY SERVER'.
    

Problem conclusion

  • The product has been modified so that the file nodes in SFTP
    mode now support the key exchange algorithms
    diffie-hellman-group14-sha1, diffie-hellman-group-exchange-sha1,
    and diffie-hellman-group1-sha1.
    
    ---------------------------------------------------------------
    The fix is targeted for delivery in the following PTFs:
    
    Version    Maintenance Level
    v12.0      12.0.12.3
    
    The latest available maintenance can be obtained from:
    http://www-01.ibm.com/support/docview.wss?rs=849&uid=swg27006041
    
    If the maintenance level is not yet available,information on
    its planned availability can be found on:
    http://www-1.ibm.com/support/docview.wss?rs=849&uid=swg27006308
    ---------------------------------------------------------------
    

Temporary fix

Comments

APAR Information

  • APAR number

    IT46152

  • Reported component name

    APP CONNECT ENT

  • Reported component ID

    5724J0560

  • Reported release

    C00

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2024-05-14

  • Closed date

    2024-05-28

  • Last modified date

    2024-05-28

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    APP CONNECT ENT

  • Fixed component ID

    5724J0560

Applicable component levels

[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSDR5J","label":"IBM App Connect Enterprise"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"C00","Line of Business":{"code":"LOB67","label":"IT Automation \u0026 App Modernization"}}]

Document Information

Modified date:
28 May 2024