IBM Support

PI85478: Disable symmetric offload by default when IHS is configured to use a crypto card

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • The default configuration for IHS with crypto cards should
    have symmetric offload disabled.
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED:  Users of IHS 8.0 and 8.5 that are           *
    *                  configured to use a crypto card             *
    ****************************************************************
    * PROBLEM DESCRIPTION: Many crypto cards are not compatible    *
    *                      with symmetric offload, so it           *
    *                      shouldn't be enabled by default.        *
    ****************************************************************
    * RECOMMENDATION:  Apply this fix if using IHS 8.0             *
    *                  or 8.5 with a crypto card.                  *
    ****************************************************************
    Offload of symmetric key operations when SSLPKCSDriver is
    specified should not be automatically enabled. Many
    crypto cards are not compatible with symmetric offload, and
    there is little value in the offload. Symmetric offload is
    now disabled by default but can be restored with:
    "SSLAttributeSet 417 549"
    

Problem conclusion

  • The default configuration for IHS with crypto card usage no
    longer has symmetric offload enabled.
    
    This fix is targeted for IBM HTTP Server fix packs:
    - 8.0.0.15
    - 8.5.5.13
    

Temporary fix

Comments

APAR Information

  • APAR number

    PI85478

  • Reported component name

    IBM HTTP SERVER

  • Reported component ID

    5724J0801

  • Reported release

    800

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2017-08-07

  • Closed date

    2018-01-24

  • Last modified date

    2018-01-24

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    IBM HTTP SERVER

  • Fixed component ID

    5724J0801

Applicable component levels

  • R800 PSY

       UP

  • R850 PSY

       UP

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSEQTJ","label":"IBM HTTP Server"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"8.0","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
07 September 2022