APAR status
Closed as program error.
Error description
Unlike IIB, ACE does not provide DisableHttpMethods option under HTTP(S)Connector to block HTTP methods like OPTIONS,DELETE, etc.
Local fix
Problem summary
**************************************************************** USERS AFFECTED: All Users of App Connect Enterprise V12.0 and V11.0 who wants to block certain http methods from accessing the webservice flows. Platforms affected: MultiPlatform **************************************************************** PROBLEM DESCRIPTION: ACE does not provide DisableHttpMethods option under HTTP(S)Connector to block HTTP methods like OPTIONS,DELETE, etc.
Problem conclusion
<div>A new property named DisableHttpMethods can now be configured under HTTPConnector and HTTPSConnector to block http methods.</div><div> </div><div>for eg: To block http methods DELETE and OPTIONS for an integration server listener, configure the property in server.conf.yaml as below</div><div> </div><div> HTTPConnector:</div><div> DisableHttpMethods: 'DELETE,OPTIONS'</div><div> </div><div> HTTPSConnector:</div><div> DisableHttpMethods: 'DELETE,OPTIONS'</div><div> </div><div>It can also be set using mqsichangeproperties command as</div><div> </div><div>mqsichangeproperties ACENODE -e ACESERVER -o HTTPConnector -n DisableHttpMethods -v \"DELETE,OPTIONS\"</div><div>mqsichangeproperties ACENODE -e ACESERVER -o HTTPSConnector -n DisableHttpMethods -v \"DELETE,OPTIONS\" The listener replies back with a '403 Forbidden' status line if a request is made with blocked http method.</div> --------------------------------------------------------------- The fix is targeted for delivery in the following PTFs: Version Maintenance Level v11.0 11.0.0.21 v12.0 12.0.8.0 The latest available maintenance can be obtained from: http://www-01.ibm.com/support/docview.wss?rs=849&uid=swg27006041 If the maintenance level is not yet available,information on its planned availability can be found on: http://www-1.ibm.com/support/docview.wss?rs=849&uid=swg27006308 ---------------------------------------------------------------
Temporary fix
Comments
APAR Information
APAR number
IT41726
Reported component name
APP CONNECT ENT
Reported component ID
5724J0550
Reported release
B00
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt / Xsystem
Submitted date
2022-08-09
Closed date
2023-03-08
Last modified date
2023-03-08
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
APP CONNECT ENT
Fixed component ID
5724J0550
Applicable component levels
[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSDR5J","label":"IBM App Connect Enterprise"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"B00","Line of Business":{"code":"LOB45","label":"Automation"}}]
Document Information
Modified date:
09 March 2023