IBM Support

JR63208: PASSWORD IS IN CLEAR IN EVENTS EMITTER

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • The current Content Event Emitter log shows that the password
    is in clear:
    
    [12/10/20 7:24:51:129 UTC] 00000097
    com.ibm.dba.bai.events.kafka.Transport I Building transport
    with Kafka producer configuration: {security.protocol=SASL_SSL,
    ssl.truststore.type=PKCS12, ssl.enabled.protocols=TLSv1.2, ssl.t
    ruststore.location=/opt/ib
    m/wlp/usr/servers/defaultServer/resou
    rces/security/ibm_customFNCMTrustStore.p12, bootstrap.servers=de
    velopment-kafka-bootstrap-event-streams.apps.ocp45.tec.uk.ibm.co
    m:443, ssl.truststore.password=passw0rd,
    ssl.endpoint.identification.algorithm=, value.serializer=org.apa
    ch
    e.kafka.common.serialization.StringSerializer, sasl.jaas.conf
    ig=org.apache.kafka.common.security.scram.ScramLoginModule
    required username="eventstreams-for-icp4a-kafka-user"
    password="qjYhITWzQz2k";, retries=10, key.serializer=org.apache.
    kafka.common.serialization.StringS
    erializer,
    sasl.mechanism=SCRAM-SHA-512, acks=all}
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED:                                              *
    * Users working with events emitter.                           *
    ****************************************************************
    * PROBLEM DESCRIPTION:                                         *
    * The current Content Event Emitter log shows that the         *
    * password                                                     *
    * is in clear:                                                 *
    *                                                              *
    * [12/10/20 7:24:51:129 UTC] 00000097                          *
    * com.ibm.dba.bai.events.kafka.Transport I Building transport  *
    * with Kafka producer configuration:                           *
    * {security.protocol=SASL_SSL,                                 *
    * ssl.truststore.type=PKCS12, ssl.enabled.protocols=TLSv1.2,   *
    * ssl.t                                                        *
    * ruststore.location=/opt/ib                                   *
    * m/wlp/usr/servers/defaultServer/resou                        *
    * rces/security/ibm_customFNCMTrustStore.p12,                  *
    * bootstrap.servers=de                                         *
    * velopment-kafka-bootstrap-event-streams.apps.ocp45.tec.uk.ib *
    * m.co                                                         *
    * m:443, ssl.truststore.password=passw0rd,                     *
    * ssl.endpoint.identification.algorithm=,                      *
    * value.serializer=org.apa                                     *
    * ch                                                           *
    * e.kafka.common.serialization.StringSerializer,               *
    * sasl.jaas.conf                                               *
    * ig=org.apache.kafka.common.security.scram.ScramLoginModule   *
    * required username="eventstreams-for-icp4a-kafka-user"        *
    * password="qjYhITWzQz2k";, retries=10,                        *
    * key.serializer=org.apache.                                   *
    * kafka.common.serialization.StringS                           *
    * erializer,                                                   *
    * sasl.mechanism=SCRAM-SHA-512, acks=all}                      *
    ****************************************************************
    * RECOMMENDATION:                                              *
    ****************************************************************
    

Problem conclusion

  • No clear password in the log.
    

Temporary fix

Comments

APAR Information

  • APAR number

    JR63208

  • Reported component name

    CLOUD PAK FOR A

  • Reported component ID

    5737I2300

  • Reported release

    K00

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2021-01-11

  • Closed date

    2021-01-11

  • Last modified date

    2021-01-11

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    CLOUD PAK FOR A

  • Fixed component ID

    5737I2300

Applicable component levels

  • RK00 PSY

       UP

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSBYVB","label":"IBM Cloud Pak for Business Automation"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"K00","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
28 April 2022