IBM Support

IT25509: SESSIONSECURITY OF THE NODE IS NOT UPDATED WITH STRICT WHEN THE CLIENT ESTABLISHED THE SESSION USING SHAREDMEM OR NAMEDPIPE.

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • After the 7.1.8/8.1.2 or higher level of client once established
    session with the server 7.1.8/8.1.2 or higher level using
    COMMMETHOD SHAREDMEM or NAMEDPIPE, the old level client of the
    same node name will be rejected with ANR0428W/ANS1357S.
    
    ANR0428W Session * for node nodename(platform) refused - client
    is down-level with this server version.
    
    ANS1357S Session rejected: Downlevel client code version
    
    With this situation, Query Node may display incorrect "Session
    Security: Transitional."  It should be updated with "Session
    Security: Strict" even when COMMMETHOD SHAREDMEM or NAMEDPIPE is
    used.
    
    
    IBM Spectrum Protect Versions affected:
    IBM Spectrum Protect Server 7.1.8/8.1.2 or higher level on all
    supported platforms.
    
    
    Initial Impact:
    Low
    
    Additional keywords:
    TS000997334, TSM
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED:                                              *
    * All IBM Spectrum Protect server users.                       *
    ****************************************************************
    * PROBLEM DESCRIPTION:                                         *
    * See error description.                                       *
    ****************************************************************
    * RECOMMENDATION:                                              *
    * Apply fixing level when available. This problem is currently *
    * projected to be fixed in levels 7.1.10 and 8.1.6. Note that  *
    * this is subject to change at the discretion of IBM.          *
    ****************************************************************
    

Problem conclusion

  • This problem was fixed.
    Affected platforms for reported release:  AIX, HP-UX, Solaris,
    Linux, and Windows.
    Platforms fixed:  AIX, Linux, HP-UX, Solaris, and Windows.
    If a client or administrative id transitions to
    SESSIONSECURITY=STRICT mode using SHARED MEMORY or NAMED PIPES,
    it may require the following procedure to later use TLS for
    communications:
     If the id does not have TLS certificates for the server, they
    must be obtained either through
       1. manual configuration OR
       2. resetting the id's SESSIONSECURITY to TRANSITIONAL mode,
    and connecting to the server to automatically obtain the
    necessary certificates.
    

Temporary fix

Comments

APAR Information

  • APAR number

    IT25509

  • Reported component name

    TSM SERVER

  • Reported component ID

    5698ISMSV

  • Reported release

    81W

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2018-07-02

  • Closed date

    2018-08-06

  • Last modified date

    2018-08-06

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    TSM SERVER

  • Fixed component ID

    5698ISMSV

Applicable component levels

[{"Business Unit":{"code":"BU029","label":"Software"},"Product":{"code":"SSGSG7","label":"Tivoli Storage Manager"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"81W"}]

Document Information

Modified date:
11 September 2024