IBM Support

PH32528: PLUGIN DOES NOT ALLOW PERSONAL CERTIFICATES SIGNED BY CAS USING WEAK SIGNATURE ALGORITHMS SUCH AS SHA1WITHRSA.

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • Plugin requests fail if SSL client authentication is enabled in
    WAS and if any certificate in the full chain for the plugin
    certificate has a weak signature algorithm such as SHA1WithRSA.
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED:  All users of IBM WebSphere Application      *
    *                  Server                                      *
    *                  Plugin                                      *
    ****************************************************************
    * PROBLEM DESCRIPTION: Plugin does not allow certificates with *
    *                      weak signature algorithm such as        *
    *                      SHA1WithRSA anywhere in certificate     *
    *                      chain.                                  *
    ****************************************************************
    * RECOMMENDATION:                                              *
    ****************************************************************
    Plugin requests will fail with the following error if SSL client
    authentication is enabled in WAS and if any certificate in the
    full chain for the client certificate has a weak signature
    algorithm such as SHa1WithRSA:
    ERROR: lib_stream: openStream: Failed in r_gsk_secure_soc_init
    to
    localhost:9443 : GSK_ERROR_CERTIFICATE_INVALIDSIGALG(gsk rc =
    447)
    

Problem conclusion

  • Certificates with SHA1 signature algorithms anywhere in the
    certificate chain are now allowed by the plugin.
    
    
    The fix for this APAR is targeted for inclusion in fix packs
    9.0.5.7 and 8.5.5.20. For more information, see 'Recommended
    Updates for WebSphere Application Server':
    https://www.ibm.com/support/pages/node/715553
    

Temporary fix

Comments

APAR Information

  • APAR number

    PH32528

  • Reported component name

    WEBS APP SERV N

  • Reported component ID

    5724H8800

  • Reported release

    900

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2020-12-10

  • Closed date

    2021-03-10

  • Last modified date

    2021-03-10

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    WEBS APP SERV N

  • Fixed component ID

    5724H8800

Applicable component levels

  • R850 PSY

       UP

  • R900 PSY

       UP

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSEQTP","label":"WebSphere Application Server"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"9.0","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
02 November 2021