IBM Support

PH19164: IF CUSTOM ENCRYPTION MODULE THROWS PASSWORDENCRYPTEXCEPTION OR PASSWORDDECRYPTEXCEPTIO ,IT CAN CORRUPT PASSWORDS IN SECURITY.XML

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • When custom encryption module throws PasswordEncryptException
    or PasswordDecryptException, passwords in configuration files
    have inconsistent encryption tag.
    

Local fix

  • N/A
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED:  All users of IBM WebSphere Application      *
    *                  Server                                      *
    ****************************************************************
    * PROBLEM DESCRIPTION: If custom password encoding module      *
    *                      fails to encrypt default                *
    *                      xor-encoded password, security.xml      *
    *                      becomes unusable.                       *
    ****************************************************************
    * RECOMMENDATION:                                              *
    ****************************************************************
    When custom password encryption module fails to encrypt
    xor password, WebSphere puts original xor-encoded passwords
    back.  However, it incorrectly keeps the custom encryption tag
    for the xor-encoded password. As a result, security.xml becomes
    unusable because WebSphere has mismatched algorithm (custom)
    for the xor-encoded password.
    

Problem conclusion

Temporary fix

Comments

APAR Information

  • APAR number

    PH19164

  • Reported component name

    WEBS APP SERV N

  • Reported component ID

    5724H8800

  • Reported release

    850

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2019-11-13

  • Closed date

    2020-03-16

  • Last modified date

    2020-03-16

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    WEBS APP SERV N

  • Fixed component ID

    5724H8800

Applicable component levels

  • R850 PSY

       UP

  • R900 PSY

       UP

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSEQTP","label":"WebSphere Application Server"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"8.5","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
02 November 2021