IBM Support

PH48807: SSL_SERVER_* ENVIRONMENT VARIABLES MAY BE WRONG WITH SNI OR MULTIPLE CERTIFICATES IN ONE VIRTUALHOST

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • Environment variables that start with SSL_SERVER_* represent the
    servers certificate details for a given requests underlying
    connection. This information is cached per virtual-host but migh
    change with SNI or two-argument SSLServerCert.
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED:  Users of IBM HTTP Server with SNI or two-   *
    *                  argument SSLServerCert                      *
    ****************************************************************
    * PROBLEM DESCRIPTION: SSL_SERVER_* environment variables may  *
    *                      have incorrect values of IHS is         *
    *                      configured to pick from multiple        *
    *                      certificates.                           *
    ****************************************************************
    * RECOMMENDATION:                                              *
    ****************************************************************
    By default, SSL_SERVER_* environment variables are calculated
    once per virtual host and then cached.  With SNI or two-argument
    SSLServerCert, the servers certificate details in these
    variables
    can differ from connection to connection.
    

Problem conclusion

  • A directive SSLServerCertEnvDynamic was added with a default
    value of OFF.
    
    When set to ON, the SSL_SERVER_* environment variables are
    calculated on each new connection so they see the result of SNI
    or two-argument SSLServerCert
    
    The fix for this APAR is targeted for inclusion in IBM HTTP
    Server fix packs 9.0.5.14. For more information, see
    'Recommended Updates for WebSphere Application Server':
    https://www.ibm.com/support/pages/node/715553
    

Temporary fix

Comments

APAR Information

  • APAR number

    PH48807

  • Reported component name

    IBM HTTP SERVER

  • Reported component ID

    5724J0801

  • Reported release

    900

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2022-08-19

  • Closed date

    2022-08-25

  • Last modified date

    2022-08-25

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    IBM HTTP SERVER

  • Fixed component ID

    5724J0801

Applicable component levels

[{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSEQTJ","label":"IBM HTTP Server"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"9.0","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
26 August 2022