IBM Support

IJ39703: KEY CERTIFICATE MANAGER AUTHORITY KEY IDENTIFIER VALUE INCORRECT

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • Error Message: The extended error message from the SSL handshake
    exception is: PKIX path validation failed:
    java.security.cert.CertPathValidatorException: Path does not
    chain with any of the trust anchors.
    .
    Stack Trace: N/A
    .
    Certificate chains containing certificates generated by iKeyman,
    Keytool and Key Certificate Management fail to validate due to
    AKI/SKI mismatch
    

Local fix

  • Use the same tool to generate all certificates in the
    certificate chain. Use Key Certificate Manager version prior to
    8.0.6.36
    

Problem summary

  • The key identifier value generated by Key Certificate Management
    is different than that generated by Keytool or iKeyman. The
    certificate chain will not validate when the Subject Key
    Identifier (SKI) of the signer certificate does not match the
    Authority Key Identifier (AKI) of the signed certificate.
    

Problem conclusion

  • Key Certificate Management was modified to copy the SKI value of
    the signing certificate to the AKI value of the signed
    certificate. The associated Hursley RTC Problem Report is 147372
    The associated Austin GIT defect is IBMKCM#18 The associated
    Austin APAR is IJ38324 JVMs affected: Java 8.0 The fix was
    delivered for Java 8 sr7 fp15 The affected jar is
    "ibmkeycert.jar". The build level of this jar for the affected
    releases is Java 8 build_20220408--77
    .
    This APAR will be fixed in the following Releases:
    .
    IBM SDK, Java Technology Edition
       8    SR7 FP10  (8.0.7.10)
    .
    Contact your IBM Product's Service Team for these Service
    Refreshes and Fix Packs.
    For those running stand-alone, information about the available
    maintenance can be found at:
               https://www.ibm.com/support/pages/java-sdk
    

Temporary fix

Comments

APAR Information

  • APAR number

    IJ39703

  • Reported component name

    SECURITY

  • Reported component ID

    620700125

  • Reported release

    270

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2022-04-29

  • Closed date

    2022-04-29

  • Last modified date

    2022-04-29

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    SECURITY

  • Fixed component ID

    620700125

Applicable component levels

[{"Line of Business":{"code":"LOB36","label":"IBM Automation"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSNVBF","label":"Runtimes for Java Technology"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"270"}]

Document Information

Modified date:
30 April 2022