IBM Support

PH44197: MAKE IBMJCEPLUS PROVIDER AVAILABLE IN THE JAVA PROVIDER LIST

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as new function.

Error description

  • The administrative Console does not have TLSv1.3 pull
    down for WAS855 for zOS after 8.5.5.20
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED:  All users of IBM WebSphere Application      *
    *                  Server                                      *
    *                  V8.5.5 on zOS.                              *
    ****************************************************************
    * PROBLEM DESCRIPTION: The administrative console does not     *
    *                      show                                    *
    *                      TLSv1.3 in the pull down for WebSphere  *
    *                      8.5.5.20 and above.                     *
    ****************************************************************
    * RECOMMENDATION:                                              *
    ****************************************************************
    The administrative console does not show TLSv1.3 in the pull
    down
    for WebSphere 8.5.5.20 and above.
    The default java.security file did not include IBMJCEPlus
    provider
    for WebSphere 8.5.5 on zOS.  For TLSv1.3 to be enabled,
    IBMJCEPlus
    provider needs to be available.
    

Problem conclusion

Temporary fix

  • Add IBMJCEPlus provider in the active java.security file
    com.ibm.crypto.plus.provider.IBMJCEPlus
    
    In the following example, security.provider.2.
    --- Example ---
    #
    # List of providers and their preference orders (see above):
    #
    #security.provider.1=com.ibm.crypto.hdwrCCA.provider.IBMJCECCA
    security.provider.1=com.ibm.crypto.provider.IBMJCE
    security.provider.2=com.ibm.crypto.plus.provider.IBMJCEPlus
    security.provider.3=com.ibm.jsse2.IBMJSSEProvider2
    security.provider.4=com.ibm.security.jgss.IBMJGSSProvider
    security.provider.5=com.ibm.security.cert.IBMCertPath
    security.provider.6=com.ibm.security.sasl.IBMSASL
    security.provider.7=com.ibm.security.cmskeystore.CMSProvider
    security.provider.8=com.ibm.security.jgss.mech.spnego.IBMSPNEGO
    security.provider.9=com.ibm.xml.crypto.IBMXMLCryptoProvider
    security.provider.10=com.ibm.xml.enc.IBMXMLEncProvider
    security.provider.11=org.apache.harmony.security.provider.Policy
    Provider
    ---------------------------------
    

Comments

APAR Information

  • APAR number

    PH44197

  • Reported component name

    WEBSPHERE FOR Z

  • Reported component ID

    5655I3500

  • Reported release

    850

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2022-02-16

  • Closed date

    2022-02-22

  • Last modified date

    2022-02-22

  • APAR is sysrouted FROM one or more of the following:

    PH43098

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    WEBSPHERE FOR Z

  • Fixed component ID

    5655I3500

Applicable component levels

[{"Line of Business":{"code":"LOB45","label":"Automation"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SS7K4U","label":"WebSphere Application Server for z\/OS"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"850"}]

Document Information

Modified date:
23 February 2022