APAR status
Closed as program error.
Error description
Error Message: The extended error message from the SSL handshake exception is: PKIX path validation failed: java.security.cert.CertPathValidatorException: Path does not chain with any of the trust anchors. . Stack Trace: N/A . Certificate chains containing certificates generated by iKeyman, Keytool and Key Certificate Management fail to validate due to AKI/SKI mismatch
Local fix
Use the same tool to generate all certificates in the certificate chain. Use Key Certificate Manager version prior to 8.0.6.36
Problem summary
The key identifier value generated by Key Certificate Management is different than that generated by Keytool or iKeyman. The certificate chain will not validate when the Subject Key Identifier (SKI) of the signer certificate does not match the Authority Key Identifier (AKI) of the signed certificate.
Problem conclusion
Key Certificate Management was modified to copy the SKI value of the signing certificate to the AKI value of the signed certificate. The associated Hursley RTC Problem Report is 147372 The associated Austin GIT defect is IBMKCM#18 The associated Austin APAR is IJ38324 JVMs affected: Java 8.0 The fix was delivered for Java 8 sr7 fp15 The affected jar is "ibmkeycert.jar". The build level of this jar for the affected releases is Java 8 build_20220408--77 . This APAR will be fixed in the following Releases: . IBM SDK, Java Technology Edition 8 SR7 FP10 (8.0.7.10) . Contact your IBM Product's Service Team for these Service Refreshes and Fix Packs. For those running stand-alone, information about the available maintenance can be found at: https://www.ibm.com/support/pages/java-sdk
Temporary fix
Comments
APAR Information
APAR number
IJ39703
Reported component name
SECURITY
Reported component ID
620700125
Reported release
270
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt / Xsystem
Submitted date
2022-04-29
Closed date
2022-04-29
Last modified date
2022-04-29
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
SECURITY
Fixed component ID
620700125
Applicable component levels
[{"Line of Business":{"code":"LOB36","label":"IBM Automation"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSNVBF","label":"Runtimes for Java Technology"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"270"}]
Document Information
Modified date:
30 April 2022