IBM Support

PH01222: TIMEOUT SETTING FOR OCSP ON IBM HTTP SERVER

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • Enable timeout settings for OSCP responder on IHS
    

Local fix

  • Please add below setting in httpd.conf
    
    SSLAttributeSet 336 5 NUMERIC
    
    This configure a 5-second TCP connection timeout for outbound
    HTTP as used by OCSP.
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED:  Users of IBM HTTP Server connecting to an   *
    *                  OCSP server                                 *
    ****************************************************************
    * PROBLEM DESCRIPTION: There is no explicit default timeout    *
    *                      for connecting to an OCSP server.       *
    ****************************************************************
    * RECOMMENDATION:  Apply this fix if expecting to access OCSP  *
    *                  servers from your IBM HTTP Server.          *
    ****************************************************************
    There was no explicit default timeout for connecting to an
    OCSP server and, especially on the Windows platform, the
    connection attempt could hang for an extended time if it was
    not completed or actively refused.
    

Problem conclusion

  • Use a 10 second timeout by default, which can be overridden by
    the new directive:
    SSLOCSPConnectionTimeout.
    
    This fix is targeted for IBM HTTP Server fix packs:
    - 8.5.5.15
    - 9.0.0.10
    

Temporary fix

Comments

APAR Information

  • APAR number

    PH01222

  • Reported component name

    IBM HTTP SERVER

  • Reported component ID

    5724J0801

  • Reported release

    850

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2018-08-01

  • Closed date

    2018-10-25

  • Last modified date

    2018-10-25

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    IBM HTTP SERVER

  • Fixed component ID

    5724J0801

Applicable component levels

  • R850 PSY

       UP

  • R900 PSY

       UP

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSEQTJ","label":"IBM HTTP Server"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"8.5","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
07 September 2022