IBM Support

PH41020: CSR FAILS VALIDATION DUE TO EXTRA LINES RFC822 NAME = USER@DOMAIN

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • When creating a CSR and sending it to CA the CSR is failing
    validation.  Thie is due to extra line added below
    
    
    RFC822 Name = user@domain
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED:  All users of IBM WebSphere Application      *
    *                  Server                                      *
    ****************************************************************
    * PROBLEM DESCRIPTION: Extra information is added to CSR due   *
    *                      that causes issues from Certificate     *
    *                      Authorities.                            *
    ****************************************************************
    * RECOMMENDATION:                                              *
    ****************************************************************
    Due to the design of the underlying APIs used to create a
    certificate and CSR, some extra information is added to the SAN
    email field when the DNS SAN field is populated.
    

Problem conclusion

  • This APAR along with java 1.8.0_301 or higher certificate and CS
    can get created with to the extra information in the SAN email
    extension.  The updated java also allow for multiple values on
    the SAN DNS, email, and IP address fields.
    
    The fix for this APAR is targeted for inclusion in fix pack
    8.5.5.22 and 9.0.5.11. For more information, see 'Recommended
    Updates for WebSphere Application Server':
    https://www.ibm.com/support/pages/node/715553
    

Temporary fix

Comments

APAR Information

  • APAR number

    PH41020

  • Reported component name

    WAS EXPRESS

  • Reported component ID

    5724I6300

  • Reported release

    850

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2021-09-30

  • Closed date

    2022-01-18

  • Last modified date

    2022-01-18

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    WAS EXPRESS

  • Fixed component ID

    5724I6300

Applicable component levels

[{"Line of Business":{"code":"LOB45","label":"Automation"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SS7JFU","label":"WebSphere Application Server - Express"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"850"}]

Document Information

Modified date:
19 January 2022