Fixes are available
APAR status
Closed as program error.
Error description
RSA Workflow validator exposes encrypted password. Steps to repro: 1. create topology with core.unit and windows user 2. create requirement on unit for windows user 3. configure automation signature for core.unit 4. create in attribute, match with windows user password
Local fix
Problem summary
**************************************************************** * USERS AFFECTED: * **************************************************************** * PROBLEM DESCRIPTION: * **************************************************************** * RECOMMENDATION: * **************************************************************** Automation signature parameters that are based on encrypted attributes do not carry that encryption forward, and therefore result in the possibilty of the attribute value being exposed. One example of this was the workflow validation when a password value did not match the expected value from the signature.
Problem conclusion
Solution was to add the necessary encyrption to the extended attributes
Temporary fix
Comments
APAR Information
APAR number
PM62380
Reported component name
SW ARCHITECT WI
Reported component ID
5724I7001
Reported release
804
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt
Submitted date
2012-04-12
Closed date
2012-05-15
Last modified date
2012-05-15
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
SW ARCHITECT WI
Fixed component ID
5724I7001
Applicable component levels
R804 PSN
UP
[{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSYKBQ","label":"Rational Software Architect Designer for WebSphere Software"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"804","Edition":"","Line of Business":{"code":"LOB45","label":"Automation"}},{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SS4JCV","label":"Rational Software Architect for WebSphere Software"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"804","Edition":"","Line of Business":{"code":"LOB15","label":"Integration"}}]
Document Information
Modified date:
15 May 2012