IBM Support

IT25261: The inbound client listening port for the SP client executables allows legacy SSL/TLS protocols and ciphers to be used.

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • IBM Spectrum Protect allows legacy SSL/TLS protocols and
    ciphers to be used which can result in the use of weaker
    than expected cyrpotographic algoithms.
    
    Products affected:
    IBM Spectrum Protect for Virtual Environments: Data Protection
    for Microsoft Hyper-V version 8.1.2 and 8.1.4 on Microsoft
    Windows x64 platform.
    
    This problem also affects IBM Spectrum Protect Backup-Archive
    Client which is the data mover for Data Protection for
    Microsoft Hyper-V 7.1.8 and higher. If you are using
    Data Protection for VMware 7.1.8 and higher refer to APAR
    IT24684.
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED:                                              *
    * IBM Spectrum Protect for Virtual Environments: Data          *
    * Protection for Microsoft Hyper-V version 8.1.2 and 8.1.4 on  *
    * Microsoft Windows x64 platform.                              *
    ****************************************************************
    * PROBLEM DESCRIPTION:                                         *
    * see ERROR description.                                       *
    * For additional information, refer to the security bulletin   *
    * published here:                                              *
    * http://www.ibm.com/support/docview.wss?uid=ibm10718013       *
    ****************************************************************
    * RECOMMENDATION:                                              *
    * This issue is projected to be fixed in the Data Protection   *
    * for Microsoft Hyper-V version 8.1.4.2 and 8.1.6 on on        *
    * Microsoft Windows x64 platform.                              *
    * Note 1: This is subject to change at the discretion of IBM.  *
    ****************************************************************
    

Problem conclusion

  • Now IBM spectrum protect backup-archive client does not
    initialize SSL/TLS protocols less than TLS1.2 if
    "ssldisablelegacytls" option is enabled.
    

Temporary fix

Comments

APAR Information

  • APAR number

    IT25261

  • Reported component name

    TSM VE DP MS HY

  • Reported component ID

    5725TVEHV

  • Reported release

    81W

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2018-06-04

  • Closed date

    2018-06-04

  • Last modified date

    2018-09-24

  • APAR is sysrouted FROM one or more of the following:

    IT24684

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    TSM VE DP MS HY

  • Fixed component ID

    5725TVEHV

Applicable component levels

  • R81W PSY

       UP

[{"Line of Business":{"code":"LOB26","label":"Storage"},"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SS8TDQ","label":"Tivoli Storage Manager for Virtual Environments"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"81W"}]

Document Information

Modified date:
28 September 2021