IBM Support

IC83231: DISABLED KDC SERVER OBJECT MIGHT BREAK AP-REQ TOKEN GENERATION IN THAT DOMAIN

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • An admin state disabled KDC Server object might prevent other
    KDC Server objects in the same domain from working properly in
    the dp:get-kerberos-apreq() extension function (which is used to
    generate Kerberos and SPNEGO tokens in AAA Post-Processing).
    This error will occur if the disabled KDC Server object has an
    object name that is lexicographically lower than the other KDC
    Server objects that should have been used (the non-disabled ones
    with the proper realm for the request).
    
    When the error occurs the following log message will appear:
    Kerberos KDC 'disabledkdc' for realm 'MYREALM' not up
    
    and an error will be generated as the return value of
    dp:get-kerberos-apreq (instead of the expected AP-REQ token).
    

Local fix

  • Delete any disabled KDC Server objects to avoid this problem.
    

Problem summary

  • A disabled KDC Server object might break Kerberos AP-REQ token
    generation for other KDC Servers in the same domain.
    

Problem conclusion

  • The fix is available in 3.8.2.13, 4.0.1.11, 4.0.2.7, and
    5.0.0.1.
    

Temporary fix

Comments

APAR Information

  • APAR number

    IC83231

  • Reported component name

    DATAPOWER

  • Reported component ID

    DP1234567

  • Reported release

    382

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt

  • Submitted date

    2012-05-09

  • Closed date

    2012-06-01

  • Last modified date

    2012-06-11

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    DATAPOWER

  • Fixed component ID

    DP1234567

Applicable component levels

  • R382 PSY

       UP

  • R401 PSY

       UP

  • R402 PSY

       UP

  • R500 PSY

       UP

  • R380 PSN

       UP

  • R381 PSN

       UP

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SS9H2Y","label":"IBM DataPower Gateway"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"3.8.2","Edition":"","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
11 February 2022