IBM Support

IT31431: MQ appliance createcert and createcertrequest commands truncate last character of DN if escape character present

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • On MQ Appliance, when creating a certificate or certificate
    request where an O(Organization) or OU(Organization Unit) in the
    distinguished name (DN) has an embedded comma escaped with the
    escape sequence '\,', the resulting DN is truncated with missing
    last character.
    
    Example:
    createcert -m QM1 -dn "CN=test,O=Org A\, Inc.,OU=Support,C=US"
    -label testcert
    also
    createcertrequest -m QM1 -dn "CN=test2,O=Org A\,
    Inc.,OU=Support, C=US" -label testcert2
    
    When showing details with detailcert command, the resulting DN
    is truncated.
    Subject : "CN=test,O=Org A\, Inc.,OU=Support,C=U"
    

Local fix

  • <p>Avoid using escape character('\') in O or OU parameters of
    DN.</p><p> </p>
    

Problem summary

  • ****************************************************************
    USERS AFFECTED:
    Appliance users using SSL feature.
    
    
    Platforms affected:
    MultiPlatform
    
    ****************************************************************
    PROBLEM DESCRIPTION:
    A logical error in MQ appliance code caused the createcert and
    createcertrequest commands to incorrectly copy the characters in
    DN(Distinguished Name) when an escape character('\') is present
    in DN, which in turn resulted in truncation of last character in
    DN.
    

Problem conclusion

  • MQ appliance code has been modified to avoid truncation of last
    character in DN <span style="background-color:rgb(255, 255,
    255)">when an escape character('\'</span><span
    style="background-color:rgb(255, 255, 255)">) is present in
    DN.</span>
    
    ---------------------------------------------------------------
    The fix is targeted for delivery in the following PTFs:
    
    Version    Maintenance Level
    v9.1 LTS   9.1.0.5
    
    The latest available maintenance can be obtained from
    'WebSphere MQ Recommended Fixes'
    http://www-1.ibm.com/support/docview.wss?rs=171&uid=swg27006037
    
    If the maintenance level is not yet available information on
    its planned availability can be found in 'WebSphere MQ
    Planned Maintenance Release Dates'
    http://www-1.ibm.com/support/docview.wss?rs=171&uid=swg27006309
    ---------------------------------------------------------------
    

Temporary fix

Comments

APAR Information

  • APAR number

    IT31431

  • Reported component name

    MQ APPLIANCE M2

  • Reported component ID

    5737H4700

  • Reported release

    913

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2020-01-07

  • Closed date

    2020-03-30

  • Last modified date

    2020-03-30

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    MQ APPLIANCE M2

  • Fixed component ID

    5737H4700

Applicable component levels

[{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SS5K6E","label":"IBM MQ Appliance"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"913","Edition":"","Line of Business":{"code":"LOB36","label":"IBM Automation"}}]

Document Information

Modified date:
30 March 2020