IBM Support

PH09987: USE CLIENT CERTIFICATE FOR AUTHENTICATION WHEN AT-TLS IS USED.

A fix is available

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as new function.

Error description

  • Customer is moving one of its client servers to the cloud. The
    cloud based client server will mean they no longer have static
    IP Addresses. Customer intends to use AT-TLS to secure
    connections and therefore would like to be able to query the
    client certificate from IMS Connect, to obtain and dynamically
    set the UserID on requests.
    

Local fix

  • N/A
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED: Users of IMS Connect Extensions V3.1         *
    ****************************************************************
    * PROBLEM DESCRIPTION: Use client certificate for              *
    *                      authentication when AT/TLS is used.     *
    ****************************************************************
    Customer is moving one of its client servers to the cloud. The
    cloud based client server will mean they no longer have static
    IP Addresses. Customer intends to use AT/TLS to secure
    connections and therefore would like to be able to query the
    client certificate from IMS Connect, to obtain and dynamically
    set the UserID on requests.
    

Problem conclusion

  • 1. This new function allows messages on an AT-TLS connection to
       be assigned the userID associated with the client SSL
       certificate.  Once obtained, the userID is implicitly trusted
       and can be used to create an ACEE.
    2. This function is activated via a new sub-option
       CLIENTCERT_UID on the SECURITY control input data set option.
    

Temporary fix

Comments

APAR Information

  • APAR number

    PH09987

  • Reported component name

    IMS CONNECT EXT

  • Reported component ID

    5655K4800

  • Reported release

    310

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    YesSpecatt / New Function / Xsystem

  • Submitted date

    2019-03-20

  • Closed date

    2019-06-04

  • Last modified date

    2019-07-01

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

    UI63408

Modules/Macros

  • CEXCPSR  CEXCR62  CEXCTL01 CEXEXRTR CEXMAIN  CEXMSGCM CEXMSGL
    CEXMSGT
    

Fix information

  • Fixed component name

    IMS CONNECT EXT

  • Fixed component ID

    5655K4800

Applicable component levels

  • R310 PSY UI63408

       UP19/06/08 P F906  

Fix is available

  • Select the PTF appropriate for your component level. You will be required to sign in. Distribution on physical media is not available in all countries.

[{"Line of Business":{"code":null,"label":null},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSCX88S","label":"IMS Connect Extensions"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"3.1.0"}]

Document Information

Modified date:
22 October 2020