IBM Support

AIX server crashes repeatedly after adding inspection engine in Guardium

Troubleshooting


Problem

This article discusses causes and solution to a problem where the AIX database server with InfoSphere Guardium S-TAP installed, crashes very frequently (ie. every few minutes) after adding an inspection engine or a new program running on AIX server.

Symptom

Guardium S-TAP crashes very frequently (ie. every few minutes) after adding an inspection engine or adding a new program on the AIX server. Crashes stop if the inspection engine is removed.

Cause

Guardium S-TAP defect. Any version 9.0 S-TAP with a release older than r57344 is vulnerable, on any version of AIX.
The crash will occur when adding an inspection engine if a running program on AIX is using a UNIX socket path shorter than 1024 bytes. The crash will also occur if such a program is added to the server and an existing inspection engine intercepts traffic from it.

Related IBM defect: bugzilla number 37574.

Environment

Any version 9.0 S-TAP with a release older than r57344 is vulnerable, on any version of AIX

Diagnosing The Problem

AIX server starts crashing after adding an inspection engine or new AIX program and keeps crashing very frequently (minutes). If the inspection engine is removed, the server does not crash anymore.

Resolving The Problem

Download and install the latest S-TAP release. The defect was resolved starting with S-TAP InfoSphere_Guardium_S-TAP_AIX_9.0_r57344. Since FixCentral often substitutes releases for more newer releases, it is possible you do not find InfoSphere_Guardium_S-TAP_AIX_9.0_r57344 . That is fine, as long as you download a release newer than that (recommendation is to download the latest at the moment).

Related Information

[{"Product":{"code":"SSMPHH","label":"IBM Security Guardium"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Component":"--","Platform":[{"code":"PF002","label":"AIX"}],"Version":"9.0","Edition":"","Line of Business":{"code":"LOB24","label":"Security Software"}}]

Document Information

Modified date:
16 June 2018

UID

swg21660315