IBM Support

IT46611: TLS IN ACE NEEDS TO BE ABLE TO HANDLE CERTIFICATE CHAINS WITH CERTIFICATES APPEARING IN ANY ORDER

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • Prior to rotating the certs on IBM Secret Manager, App Connect
    is able to resolve the full certificate chain but after
    certificate rotation, App Connect produces only partial chain.
    ACE should be able to handle  certificate chains with
    certificates appearing in any order.
    

Local fix

Problem summary

  • ****************************************************************
    USERS AFFECTED:
    All user of App Connect Enterprise v12 who use rotating
    certificates for TLS
    
    
    Platforms affected:
    MultiPlatform
    
    ****************************************************************
    PROBLEM DESCRIPTION:
    Prior to TLS 1.3, "certificate_list" ordering required each
    certificate to certify the one immediately preceding it;
    however, some implementations allowed some flexibility. Servers
    sometimes send both a current and deprecated intermediate for
    transitional purposes, and others are simply configured
    incorrectly, but these cases can nonetheless be validated
    properly. For maximum compatibility, all implementations SHOULD
    be prepared to handle potentially extraneous certificates and
    arbitrary orderings from any TLS version, with the exception of
    the end-entity certificate which MUST be first.
    
    The App Connect Enterprise v12 currently does not implement this
    and this will need to be implemented in HTTP listener.
    

Problem conclusion

Temporary fix

Comments

APAR Information

  • APAR number

    IT46611

  • Reported component name

    APP CONNECT ENT

  • Reported component ID

    5724J0560

  • Reported release

    C00

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2024-07-30

  • Closed date

    2024-07-31

  • Last modified date

    2024-07-31

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    APP CONNECT ENT

  • Fixed component ID

    5724J0560

Applicable component levels

[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSDR5J","label":"IBM App Connect Enterprise"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"C00","Line of Business":{"code":"LOB67","label":"IT Automation \u0026 App Modernization"}}]

Document Information

Modified date:
31 July 2024