IBM Support

IV00022: WEBSEAL FAILS TO HANDLE SESSION COOKIE FROM EARLIER RELEASES

Direct links to fixes

6.1.1-ISS-TAM-IF0035-AIX
6.1.1-ISS-TAM-IF0035-WIN
6.1.1-ISS-TAM-IF0035-SOL-X86
6.1.1-ISS-TAM-IF0035-SOL
6.1.1-ISS-TAM-IF0035-S390
6.1.1-ISS-TAM-IF0035-LIN-PPC
6.1.1-ISS-TAM-IF0035-LIN
6.1.1-ISS-TAM-IF0035-HP-IA64
6.1.1-ISS-TAM-IF0035-HP
6.1.1-ISS-TAM-IF0034-WIN
6.1.1-ISS-TAM-IF0034-SOL-X86
6.1.1-ISS-TAM-IF0034-SOL
6.1.1-ISS-TAM-IF0034-S390
6.1.1-ISS-TAM-IF0034-LIN-PPC
6.1.1-ISS-TAM-IF0034-LIN
6.1.1-ISS-TAM-IF0034-HP-IA64
6.1.1-ISS-TAM-IF0034-HP
6.1.1-ISS-TAM-IF0034-AIX
6.1.1-ISS-TAM-IF0031-WIN
6.1.1-ISS-TAM-IF0031-SOL-X86
6.1.1-ISS-TAM-IF0031-SOL
6.1.1-ISS-TAM-IF0031-S390
6.1.1-ISS-TAM-IF0031-LIN-PPC
6.1.1-ISS-TAM-IF0031-LIN
6.1.1-ISS-TAM-IF0031-HP-IA64
6.1.1-ISS-TAM-IF0031-HP
6.1.1-ISS-TAM-IF0031-AIX
6.1.1-ISS-TAM-IF0030-WIN
6.1.1-ISS-TAM-IF0030-SOL-X86
6.1.1-ISS-TAM-IF0030-SOL
6.1.1-ISS-TAM-IF0030-S390
6.1.1-ISS-TAM-IF0030-LIN-PPC
6.1.1-ISS-TAM-IF0030-LIN
6.1.1-ISS-TAM-IF0030-HP-IA64
6.1.1-ISS-TAM-IF0030-HP
6.1.1-ISS-TAM-IF0030-AIX
6.1.1-ISS-TAM-FP0026-WIN
6.1.1-ISS-TAM-FP0026-SOL
6.1.1-ISS-TAM-FP0026-SOL-X86
6.1.1-ISS-TAM-FP0026-S390
6.1.1-ISS-TAM-FP0026-LIN
6.1.1-ISS-TAM-FP0026-LIN-PPC
6.1.1-ISS-TAM-FP0026-HP
6.1.1-ISS-TAM-FP0026-HP-IA64
6.1.1-ISS-TAM-FP0026-AIX
6.1.1-ISS-TAM-FP0024-SOL
6.1.1-ISS-TAM-FP0024-WIN
6.1.1-ISS-TAM-FP0024-SOL-X86
6.1.1-ISS-TAM-FP0024-S390
6.1.1-ISS-TAM-FP0024-LIN-PPC
6.1.1-ISS-TAM-FP0024-LIN
6.1.1-ISS-TAM-FP0024-HP-IA64
6.1.1-ISS-TAM-FP0024-HP
6.1.1-ISS-TAM-FP0024-AIX
6.1.1-ISS-TAM-IF0020-WIN
6.1.1-ISS-TAM-IF0020-SOL-X86
6.1.1-ISS-TAM-IF0020-SOL
6.1.1-ISS-TAM-IF0020-S390
6.1.1-ISS-TAM-IF0020-LIN-PPC
6.1.1-ISS-TAM-IF0020-LIN
6.1.1-ISS-TAM-IF0020-HP
6.1.1-ISS-TAM-IF0020-HP-IA64
6.1.1-ISS-TAM-IF0020-AIX
6.1.1-ISS-TAM-FP0019-WIN
6.1.1-ISS-TAM-FP0019-SOL
6.1.1-ISS-TAM-FP0019-SOL-X86
6.1.1-ISS-TAM-FP0019-S390
6.1.1-ISS-TAM-FP0019-LIN
6.1.1-ISS-TAM-FP0019-LIN-PPC
6.1.1-ISS-TAM-FP0019-HP
6.1.1-ISS-TAM-FP0019-HP-IA64
6.1.1-ISS-TAM-FP0019-AIX
6.1.1-ISS-TAM-IF0018-WIN
6.1.1-ISS-TAM-IF0018-SOL-X86
6.1.1-ISS-TAM-IF0018-SOL
6.1.1-ISS-TAM-IF0018-S390
6.1.1-ISS-TAM-IF0018-LIN-PPC
6.1.1-ISS-TAM-IF0018-LIN
6.1.1-ISS-TAM-IF0018-HP-IA64
6.1.1-ISS-TAM-IF0018-HP
6.1.1-ISS-TAM-IF0018-AIX
6.1.1-ISS-TAM-IF0015-S390
6.1.1-ISS-TAM-IF0015-WIN
6.1.1-ISS-TAM-IF0015-SOL-X86
6.1.1-ISS-TAM-IF0015-SOL
6.1.1-ISS-TAM-IF0015-LIN
6.1.1-ISS-TAM-IF0015-HP-IA64
6.1.1-ISS-TAM-IF0015-HP
6.1.1-ISS-TAM-IF0015-AIX
6.1.1-ISS-TAM-IF0015-LIN-PPC
Tivoli Access Manager for e-Business WebSEAL, Patch 6.1.1-TIV-AWS-FP0005
Tivoli Access Manager for e-Business WebSEAL, Patch 6.1.1-ISS-AWS-FP0006
Tivoli Access Manager for e-Business WebSEAL, Patch 6.1.1-ISS-AWS-FP0007

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • <PDFI> *** APAR ************************************************
    Description:
    When Access Manager 6.1.1 WebSEAL receives a session cookie from
    a load balanced 6.0 WebSEAL instance, WebSEAL may fail to handle
    the session cookie, with an HTTP 503 response.
    
     2011-04-26-00:54:12.109-04:00I----- thread(497)
    trace.pdweb.debug:2
    /gsa/ausgsa/projects/a/ameb/build/amweb611/gold_6.1.1-TIV-AWS-FP
    0001/src/pdweb/webseald/ras/trace/debug_log.cpp:134:
    ----------------- Browser ===> PD -----------------
     Thread_ID:255
     GET /example/common/scripts/foresee/foresee-trigger.js HTTP/1.1
     host: www3.example.com
     user-agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10.6;
    en-US; rv:1.9.2.16) Gecko/20110319 Firefox/3.6.16
     Cookie:
    PD-S-SESSION-ID=2_4nC31Lub-vAXAknVcHSGuFzxJSS1WxW4B4rhYtu3I3vXMb
    oY;
    PD-ID=BINHxy/XH3Up1/6MYv31hxcVdgboPQ92Kqcbpfcu4eDAhn0G6TkHQglhM6
    Bo/BLNZMmPa2NRfawBr9BJuJ12VqsLLeTySlKSaYZpy+OQFIYZNukkcnkhdPj7Lp
    /RE9Cr2ars1JmM8nzAzvhw0fjC2kZt6SlbVgWY+lINvmOSAiBSq09RNIERyfZ6Aj
    WrXize25Eqeqo/+Qmfj0jsKAisXYKLiqQQTyGvaSUPYqn4BE+skXIy1Wp4CpA1mA
    jNkUEEZFb2ndibldWexRnv0yagvXSQleiL6oe//3eTSPkpxMA=
    
     ---------------------------------------------------
    
     2011-04-26-00:54:12.111-04:00I----- thread(497)
    trace.pdweb.debug:2
    /gsa/ausgsa/projects/a/ameb/build/amweb611/gold_6.1.1-TIV-AWS-FP
    0001/src/pdweb/webseald/ras/trace/debug_log.cpp:178:
    ----------------- Browser <=== PD -----------------
     Thread_ID:255
     HTTP/1.1 503 Service Unavailable
     content-length: 1365
     content-type: text/html
     date: Tue, 26 Apr 2011 04:54:11 GMT
     p3p: CP="NON CUR OTPi OUR NOR UNI"
     cache-control: no-cache
     pragma: no-cache
    
     2011-04-26-00:54:12.110-04:00I----- 0x38B9A41E webseald ERROR
    wns session WSPartitionedCache.cpp 634 0x000000ff
     DPWNS1054E   Invalid session ID.
    
    Steps to Duplicate:
    Use fiddler to submit an Access Manager 6.0 WebSEAL session
    cookie to an Access Manager 6.1.1 WebSEAL server
    
    Desired Behavior:
    WebSEAL uses the failover cookie, or prompts for authentication.
    
    Environment: Solaris, Access Manager 6.0 WebSEAL IF26, Access
    Manager 6.1.1 WebSEAL FP1+APAR IZ93838+IZ88109 test fix
    
    ****************************************************************
    </PDFI>
    

Local fix

  • Use an alternate cookie name.
    

Problem summary

  • When Access Manager 6.1.1 WebSEAL receives a session cookie from
    a load balanced 6.0 WebSEAL instance, WebSEAL may fail to handle
    the session cookie, with an HTTP 503 response.
    

Problem conclusion

  • | Fixpack 6.1.1-AWS-FP05  |
    
    Changed the 6.1.1 WebSEAL to accept older cookie format
    

Temporary fix

Comments

APAR Information

  • APAR number

    IV00022

  • Reported component name

    ACCESS MGR WEBS

  • Reported component ID

    5724C0811

  • Reported release

    611

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2011-05-04

  • Closed date

    2011-09-22

  • Last modified date

    2011-09-22

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    ACCESS MGR WEBS

  • Fixed component ID

    5724C0811

Applicable component levels

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSPREK","label":"Tivoli Access Manager for e-business"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"611","Edition":"","Line of Business":{"code":"LOB24","label":"Security Software"}}]

Document Information

Modified date:
22 September 2011