IBM Support

After upgrading to 9.2.23, users cannot log in to LMT if FIPS 140-2 compliance is enabled

Troubleshooting


Problem

After upgrading License Metric Tool to application update 9.2.23, users might observe problems with logging in to the application if FIPS 140-2 compliance was enabled before or after the upgrade.

Symptom

When you log in to License Metric Tool, the following message might appear:
'This site can’t provide a secure connection'
Additionally, the following error message might also appear in the tema.log file:
com.ibm.ws.logging.internal.impl.IncidentImpl I FFDC1015I: An FFDC Incident has been created: "java.lang.NullPointerException ..."

Resolving The Problem

To work around this issue, perform the following steps:
  1. Stop the License Metric Tool server.
  2. Open the ..\LMT\jre\jre\lib\security\java.security file and add the RSAPSS value as the last entry to the jdk.tls.disabledAlgorithms comma-separated list property. The updated property list should look as follows:
    jdk.tls.disabledAlgorithms=SSLv3, RC4, DES, MD5withRSA, DH keySize < 1024, DESede, \ EC keySize < 224, 3DES_EDE_CBC, anon, NULL, DES_CBC, RSAPSS
  3. Start the License Metric Tool server.

Document Location

Worldwide

[{"Type":"SW","Line of Business":{"code":"LOB45","label":"Automation"},"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SS8JFY","label":"IBM License Metric Tool"},"ARM Category":[{"code":"a8m0z000000CbkMAAS","label":"Upgrade->Upgrade LMT server"}],"ARM Case Number":"","Platform":[{"code":"PF016","label":"Linux"},{"code":"PF033","label":"Windows"}],"Version":"9.2.0"}]

Document Information

Modified date:
07 April 2021

UID

ibm16440621