IBM Support

PH53800: PROVIDE 4 CHARACTER CIPHER SUPPORT FOR THE WEBSPHERE APPLICATION SERVER DAEMON USING SYSTEM SSL

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • Four character Cipher suites are not recognized for the
    WebSphere Application Server Daemon which is using System SSL.
    It is working for TLSv1.3 but none of the other protocols that
    support 4-character ciphers.
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED:  All users of IBM WebSphere Application      *
    *                  Server                                      *
    *                  V8.5                                        *
    ****************************************************************
    * PROBLEM DESCRIPTION: Unable to set up 4 Character Ciphers    *
    *                      for                                     *
    *                      TLSv1.0,TLSv1.1,TLSv1.2 for daemon      *
    *                      SSSL                                    *
    *                      on zOS.                                 *
    ****************************************************************
    * RECOMMENDATION:                                              *
    ****************************************************************
    Unable to set up 4 Character Ciphers for
    TLSv1.0,TLSv1.1,TLSv1.2
    for daemon SSSL on zOS.
    

Problem conclusion

  • Code has been revised to address this problem and allow the use
    4 Cipher Characters for TLSv1.0,TLSv1.1,TLSv1.2.
    
    On some occasions after applying this fix, it may be necessary
    to refresh the ciphers. To do this go into the Admin console
    under Security>  SSL certificate and key management > SSL
    configurations > <cellname>/DefaultIIOPSSL > Quality of
    protection
    (QoP) settings
    
    Click the button "Update selected ciphersâ??, which will update
    the ciphers to match those of the fresh install, including the 4
    character ciphers as well.
    
    The fix for this APAR is targeted for inclusion in fix pack
    9.0.5.17 and 8.5.5.25. For more information, see 'Recommended
    Updates for WebSphere Application Server':
    https://www.ibm.com/support/pages/node/715553
    

Temporary fix

Comments

APAR Information

  • APAR number

    PH53800

  • Reported component name

    WEBSPHERE FOR Z

  • Reported component ID

    5655I3500

  • Reported release

    850

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2023-04-10

  • Closed date

    2023-06-14

  • Last modified date

    2024-05-03

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    WEBSPHERE FOR Z

  • Fixed component ID

    5655I3500

Applicable component levels

[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SS7K4U","label":"WebSphere Application Server for z\/OS"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"8.5","Line of Business":{"code":"LOB67","label":"IT Automation \u0026 App Modernization"}}]

Document Information

Modified date:
06 May 2024