IBM Support

PM78434: PROVIDE END-TO-END TIMEOUTS FOR SSL HANDSHAKES

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as new function.

Error description

  • Currently handshake timeout is not end to end; consequently any
    handshakes that take an excessive amount of time also hold open
    the thread for that time. It would be useful and more efficient
    of thread usage to be able to set a timer for SSL handshakes to
    help alleviate the thread usage.
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED:  Users of IBM HTTP Server with slow-running  *
    *                  handshakes and shortage of webserver        *
    *                  threads.                                    *
    ****************************************************************
    * PROBLEM DESCRIPTION: End-to-end SSL Handshake time cannot be *
    *                      effectively limited with the "Timeout"  *
    *                      directive                               *
    ****************************************************************
    * RECOMMENDATION:                                              *
    ****************************************************************
    Most modules that implement timeouts use the core "Timeout" by
    default and provide a directive to override it.  mod_ibm_ssl
    cannnot override the core Timeout during a handshake, and has no
    way to impose an end-to-end timeout on the handshake.
    

Problem conclusion

  • A new directive was added to mod_ibm_ssl:
    
      SSLHandshakeTimeout IOtimeout [end-to-end timeout]
    
    The end-to-end timeout defaults to seconds and accepts "ms" as
    a suffix.
    
    This fix is targeted for IHS fixpacks:
     - 8.0.0.6
     - 8.5.0.2
    

Temporary fix

Comments

APAR Information

  • APAR number

    PM78434

  • Reported component name

    WEBSPHERE FOR Z

  • Reported component ID

    5655I3500

  • Reported release

    800

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2012-12-04

  • Closed date

    2012-12-06

  • Last modified date

    2013-01-10

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    WAS IHS ZOS

  • Fixed component ID

    5655I3510

Applicable component levels

  • R800 PSY

       UP

  • R850 PSY

       UP

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SS7K4U","label":"WebSphere Application Server for z\/OS"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"8.0","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
29 October 2021