APAR status
Closed as program error.
Error description
In the Knowledge Centre under "Enabling CipherSpecs" at- https://www.ibm.com/support/knowledgecenter/en/SSFKSJ_8.0.0/com. ibm.mq.sec.doc/q014260_.htm Note 4 states that "after 2^22 TLS records are sent, using the same session key, the connection is terminated with message AMQ9288." This is incorrect. It should be 2^32 instead of 2^22. The same is true for- https://www-01.ibm.com/support/docview.wss?uid=swg21964105 Also the error message for example (CipherSpec could be different)- AMQ9288E: Secure data transfer limit for channel 'aaaa.bbb' exceeded. EXPLANATION: CipherSpec 'ECDHE_RSA_AES_256_GCM_SHA384' has reached a data transfer limit of 0 (the transfer limit is expressed in terms of TLS records for GCM ciphers, or MB for all other ciphers). Session keys using this CipherSpec must be used only to encrypt a limited quantity of data to reduce the risk of key compromise. is incorrect as it gives a value of zero.
Local fix
To prevent a channel failing with error AMQ9288, you may select one of three choices: 1) Enable Secret Key resets on the channel in order to renegotiate the session keys in use after a certain number of bytes have been sent through the channel. 2) Use a different CipherSpec that does not use GCM and is not affected by the TLS limit. 3) Set the environment variable "GSK_ENFORCE_GCM_RESTRICTION=GSK_FALSE" before starting an MQ QMGR or Client
Problem summary
**************************************************************** USERS AFFECTED: MQ SSL users configured to use GCM ciphers for their connections. Platforms affected: MultiPlatform **************************************************************** PROBLEM DESCRIPTION: The information provided on the IBM MQ Knowledge Centre and associated documentation for SSL GCM ciphers indicates an incorrect value for the limit of number of TLS records sent using the same session key. The correct value should be 2^32 records before the connection is terminated with message AMQ9288. In addition to this, when the number of TLS records is actually exceeded, the AMQ9288 error message incorrectly indicates 0 as the the number of TLS records.
Problem conclusion
In the AMQ9288 error message, MQ will now display the value 4294967295 (which equates to 2^32 - 1), indicating the number of TLS records sent using the same session key. The following documentation (note 4) has been corrected to indicate the correct value of 2^32 TLS records: https://www.ibm.com/support/knowledgecenter/no/SSFKSJ_8.0.0/com. ibm.mq.sec.doc/q014260_.htm#q014260___d48014e3000 https://www.ibm.com/support/knowledgecenter/en/SSFKSJ_9.0.0/com. ibm.mq.sec.doc/q014260_.htm#q014260___d47472e3327 https://www.ibm.com/support/knowledgecenter/en/SSFKSJ_9.1.0/com. ibm.mq.sec.doc/q014260_.htm#q014260___d47852e4123 https://www.ibm.com/support/knowledgecenter/en/SSFKSJ_8.0.0/com. ibm.mq.ref.adm.doc/q085520_.htm#q085520___d99602e3000 https://www.ibm.com/support/knowledgecenter/en/SSFKSJ_9.0.0/com. ibm.mq.ref.adm.doc/q085520_.htm#q085520___d96980e3327 https://www.ibm.com/support/knowledgecenter/en/SSFKSJ_9.1.0/com. ibm.mq.ref.adm.doc/q085520_.htm#q085520___d141598e4123 https://www.ibm.com/support/knowledgecenter/no/SSFKSJ_8.0.0/com. ibm.mq.sec.doc/q014260_.htm#q014260___d48014e3000 In addition the tech note below has been similarly corrected: https://www-01.ibm.com/support/docview.wss?uid=swg21964105 --------------------------------------------------------------- The fix is targeted for delivery in the following PTFs: Version Maintenance Level v8.0 8.0.0.13 v9.0 LTS 9.0.0.8 v9.1 CD 9.1.4 v9.1 LTS 9.1.0.4 The latest available maintenance can be obtained from 'WebSphere MQ Recommended Fixes' http://www-1.ibm.com/support/docview.wss?rs=171&uid=swg27006037 If the maintenance level is not yet available information on its planned availability can be found in 'WebSphere MQ Planned Maintenance Release Dates' http://www-1.ibm.com/support/docview.wss?rs=171&uid=swg27006309 ---------------------------------------------------------------
Temporary fix
Comments
APAR Information
APAR number
IT29602
Reported component name
IBM MQ BASE MP
Reported component ID
5724H7251
Reported release
800
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt / Xsystem
Submitted date
2019-07-02
Closed date
2019-08-19
Last modified date
2019-08-27
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
IBM MQ BASE MP
Fixed component ID
5724H7251
Applicable component levels
[{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSYHRD","label":"IBM MQ"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"8.0.0.0","Edition":"","Line of Business":{"code":"LOB45","label":"Automation"}}]
Document Information
Modified date:
27 August 2019