IBM Support

IT02781: VERIFY SHOULD USE ENCRYPTED INPUT CONTEXT FOR ENCRYPTBEFORESIGN.

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as fixed if next.

Error description

  • Verify action fails when enforcing a WS-Policy in a WS-Proxy
    containing the assertion EncryptBeforeSigning. The message
    should first encrpyted then signed. But the DataPower policy
    enforcement framework uses the INPUT context for the verify
    action.As the proxy implizitly decryptes the message the INPUT
    context contains the decrypted message. Verify will fail with
    the hash mismatch error.
    

Local fix

Problem summary

  • Certain WS-Policy setting may generate Web Service Proxy
    processing rules that use the decrypted message an input when
    the action requires the encrypted message.  A fix will be
    available in next major releases.
    

Problem conclusion

Temporary fix

Comments

APAR Information

  • APAR number

    IT02781

  • Reported component name

    DPWR SRV GTWAY

  • Reported component ID

    DP905XG45

  • Reported release

    600

  • Status

    CLOSED FIN

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt

  • Submitted date

    2014-06-25

  • Closed date

    2014-08-14

  • Last modified date

    2014-08-14

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

Applicable component levels

  • R402 PSN

       UP

[{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSNR47","label":"WebSphere DataPower Service Gateway XG45"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"6.0.0","Edition":"","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
14 August 2014