Fixes are available
9.0.0.10: WebSphere Application Server traditional V9.0 Fix Pack 10
8.5.5.15: WebSphere Application Server V8.5.5 Fix Pack 15
9.0.0.11: WebSphere Application Server traditional V9.0 Fix Pack 11
9.0.5.0: WebSphere Application Server traditional Version 9.0.5 Refresh Pack
9.0.5.1: WebSphere Application Server traditional Version 9.0.5 Fix Pack 1
9.0.5.2: WebSphere Application Server traditional Version 9.0.5 Fix Pack 2
8.5.5.17: WebSphere Application Server V8.5.5 Fix Pack 17
9.0.5.3: WebSphere Application Server traditional Version 9.0.5 Fix Pack 3
8.5.5.20: WebSphere Application Server V8.5.5.20
8.5.5.18: WebSphere Application Server V8.5.5 Fix Pack 18
8.5.5.19: WebSphere Application Server V8.5.5 Fix Pack 19
8.5.5.16: WebSphere Application Server V8.5.5 Fix Pack 16
8.5.5.21: WebSphere Application Server V8.5.5.21
APAR status
Closed as program error.
Error description
accept SHA2 cert chains in LDAP connections
Local fix
Problem summary
**************************************************************** * USERS AFFECTED: Users of IBM HTTP Server making LDAP * * connections * **************************************************************** * PROBLEM DESCRIPTION: TLS 1.2 LDAP connection failures due * * to certificate signature algorithm * * problems. * **************************************************************** * RECOMMENDATION: Apply this fix * **************************************************************** Accept SHA2 cert chains for ldaps:// connections over TLS 1.2 by sending the signature_algorithms extension.
Problem conclusion
TLS signature algorithms are now set so SHA2 cert chains are accepted for LDAP connections This fix is targeted for IBM HTTP Server fix packs: - 8.5.5.15 - 9.0.0.10
Temporary fix
Comments
APAR Information
APAR number
PH01302
Reported component name
IBM HTTP SERVER
Reported component ID
5724J0801
Reported release
850
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt / Xsystem
Submitted date
2018-08-06
Closed date
2018-10-29
Last modified date
2018-10-29
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
IBM HTTP SERVER
Fixed component ID
5724J0801
Applicable component levels
R850 PSY
UP
R900 PSY
UP
Document Information
Modified date:
07 September 2022