IBM Support

IT26496: IBM MQ Explorer does not show all of the TLS/SSL cipher specs for MQ Appliance channels

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • When the IBM MQ Explorer was used to change the channel cipher
    spec option on a channel of a queue manager running on a
    MQ Appliance, the drop down list on the "channel properties"
    panel did not show all the available Cipher Spec options.
    

Local fix

  • Use MQ runmqsc to setup the TLS/SSL option.
    

Problem summary

  • ****************************************************************
    USERS AFFECTED:
    This issue affects users of the IBM MQ Explorer who want to
    change the channel cipher spec option on a channel of a queue
    manager running on an IBM MQ Appliance.
    
    
    Platforms affected:
    Linux on x86-64, Windows
    
    ****************************************************************
    PROBLEM DESCRIPTION:
    IBM MQ Explorer did not show all the available cipher spec
    options on the channel properties, while trying to change the
    channel cipher spec, when connected to a queue manager running
    on an IBM MQ Appliance. The list of TLS/SSL cipher specs that
    was displayed by IBM MQ Explorer is shown below:
    
      "DES_SHA_EXPORT"
      "ECDHE_ECDSA_AES_128_CBC_SHA256"
      "ECDHE_ECDSA_AES_256_CBC_SHA384"
      "ECDHE_RSA_AES_128_CBC_SHA256"
      "ECDHE_RSA_AES_256_CBC_SHA384"
      "NULL_MD5"
      "NULL_SHA"
      "RC2_MD5_EXPORT"
      "RC4_MD5_EXPORT"
      "RC4_MD5_US"
      "RC4_SHA_US"
      "TLS_RSA_WITH_AES_128_CBC_SHA"
      "TLS_RSA_WITH_AES_256_CBC_SHA"
      "TRIPLE_DES_SHA_US"
    

Problem conclusion

  • IBM MQ Explorer was updated to show all the supported cipher
    spec options when connected to a queue manager running on an IBM
    MQ Appliance. The list of TLS/SSL cipher specs displayed by IBM
    MQ Explorer when administering channels on an IBM MQ Appliance,
    after the fix for this APAR has been applied, is shown below:
    
      "DES_SHA_EXPORT"
      "ECDHE_ECDSA_AES_128_CBC_SHA256"
      "ECDHE_ECDSA_AES_256_CBC_SHA384"
      "ECDHE_RSA_AES_128_CBC_SHA256"
      "ECDHE_RSA_AES_256_CBC_SHA384"
      "ECDHE_ECDSA_RC4_128_SHA256"
      "ECDHE_ECDSA_3DES_EDE_CBC_SHA256"
      "ECDHE_RSA_RC4_128_SHA256"
      "ECDHE_ECDSA_AES_128_GCM_SHA256"
      "ECDHE_ECDSA_AES_256_GCM_SHA384"
      "ECDHE_RSA_AES_128_GCM_SHA256"
      "ECDHE_RSA_AES_256_GCM_SHA384"
      "ECDHE_RSA_NULL_SHA256"
      "ECDHE_ECDSA_NULL_SHA256"
      "NULL_MD5"
      "NULL_SHA"
      "RC2_MD5_EXPORT"
      "RC4_MD5_EXPORT"
      "RC4_MD5_US"
      "RC4_SHA_US"
      "RC4_56_SHA_EXPORT1024"
      "DES_SHA_EXPORT1024"
      "FIPS_WITH_DES_CBC_SHA"
      "FIPS_WITH_3DES_EDE_CBC_SHA"
      "TLS_RSA_WITH_DES_CBC_SHA"
      "TLS_RSA_WITH_3DES_EDE_CBC_SHA"
      "TLS_RSA_WITH_AES_128_CBC_SHA"
      "TLS_RSA_WITH_AES_256_CBC_SHA"
      "TLS_RSA_WITH_AES_256_CBC_SHA256"
      "TLS_RSA_WITH_AES_128_CBC_SHA256"
      "TLS_RSA_WITH_AES_128_GCM_SHA256"
      "TLS_RSA_WITH_AES_256_GCM_SHA384"
      "TLS_RSA_WITH_NULL_NULL"
      "TLS_RSA_WITH_NULL_SHA256"
      "TLS_RSA_WITH_RC4_128_SHA256"
      "TRIPLE_DES_SHA_US"
    
    ---------------------------------------------------------------
    The fix is targeted for delivery in the following PTFs:
    
    Version    Maintenance Level
    v9.1 CD    9.1.2
    v9.1 LTS   9.1.0.2
    
    The latest available maintenance can be obtained from
    'WebSphere MQ Recommended Fixes'
    http://www-1.ibm.com/support/docview.wss?rs=171&uid=swg27006037
    
    If the maintenance level is not yet available information on
    its planned availability can be found in 'WebSphere MQ
    Planned Maintenance Release Dates'
    http://www-1.ibm.com/support/docview.wss?rs=171&uid=swg27006309
    ---------------------------------------------------------------
    

Temporary fix

Comments

APAR Information

  • APAR number

    IT26496

  • Reported component name

    IBM MQ BASE MP

  • Reported component ID

    5724H7271

  • Reported release

    910

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2018-10-03

  • Closed date

    2018-10-23

  • Last modified date

    2018-10-23

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    IBM MQ BASE MP

  • Fixed component ID

    5724H7271

Applicable component levels

[{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSYHRD","label":"IBM MQ"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"9.1","Edition":"","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
23 October 2018