IBM Support

IV69290: AES-GCM IN IBMPKCS11IMPL IS CHOSEN EVEN THOUGH IT'S NOT ENABLED IN IBMPKCS11IMPL

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • Error Message: When specifying AES/GCM/NoPadding in
    Cipher.getInstance() when IBMPKCS11Impl provider is before
    IBMJCE provider in the provider list,  an
    java.lang.UnsatisfiedLinkError exception was thrown.
    .
    Stack Trace: Exception in thread "main"
    java.lang.UnsatisfiedLinkError:
    com/ibm/pkcs11/nat/NativePKCS11Session.encryptDoFinalGCM(ILjava/
    lang/Object;Lcom/ibm/pkcs11/PKCS11Object;<OSB>BII<OSB>BI)Iat
    com.ibm.crypto.pkcs11impl.provider.Session.encryptDoFinalGCM(Ses
    sion.java:774)at
    com.ibm.crypto.pkcs11impl.provider.PKCS11Cipher.engineDoFinalGCM
    (PKCS11Cipher.java:839)at
    com.ibm.crypto.pkcs11impl.provider.GeneralPKCS11Cipher.engineDoF
    inal(GeneralPKCS11Cipher.java:1046)at
    com.ibm.crypto.pkcs11impl.provider.GeneralPKCS11Cipher.engineDoF
    inal(GeneralPKCS11Cipher.java:890)at
    javax.crypto.Cipher.doFinal(Unknown Source)at
    com.ibm.jsse2.m.a(m.java:321)at
    com.ibm.jsse2.n$a.a(n$a.java:6)at
    com.ibm.jsse2.n$a.a(n$a.java:45)at
    com.ibm.jsse2.n.a(n.java:165)at com.ibm.jsse2.o.a(o.java:31)at
    com.ibm.jsse2.o.h(o.java:85)at com.ibm.jsse2.as.a(as.java:407)at
    com.ibm.jsse2.as.<init>(as.java:731)at
    com.ibm.jsse2.SSLSocketFactoryImpl.createSocket(SSLSocketFactory
    Impl.java:7)
    .
    N/A
    

Local fix

  • N/A
    

Problem summary

  • AES-GCM in IBMPKCS11Impl is chosen even though it's not enabled
    in IBMPKCS11Impl
    

Problem conclusion

  • The Cipher service for algorithm AES has been updated in
    IBMPKCS11impl.The associated RTC PR is 84714The associated
    Austin CMVC defect is 116020The associated Austin APAR is
    IV69232JVMs affected : Java 7.0, Java 7.1 and Java 8.0The fix
    was delivered for Java 7.0 SR9, Java 7.1 SR3 and Java 8.0 SR1The
    affected jar is "ibmpkcs11impl.jar".The build level of this jar
    for the affected releases is "20150202"
    .
    This APAR will be fixed in the following Java Releases:
       7    SR9       (7.0.9.0)
       7 R1 SR3       (7.1.3.0)
       8    SR1       (8.0.1.0)
    .
    Contact your IBM Product's Service Team for these Service
    Refreshes and Fix Packs.
    For those running stand-alone, information about the Service
    Refreshes and Fix Packs can be found at:
               https://www.ibm.com/developerworks/java/jdk/
    

Temporary fix

Comments

APAR Information

  • APAR number

    IV69290

  • Reported component name

    SECURITY

  • Reported component ID

    620700125

  • Reported release

    260

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2015-02-09

  • Closed date

    2015-02-09

  • Last modified date

    2015-03-09

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    SECURITY

  • Fixed component ID

    620700125

Applicable component levels

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSNVBF","label":"Runtimes for Java Technology"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Line of Business":{"code":"LOB36","label":"IBM Automation"}}]

Document Information

Modified date:
14 December 2020