A fix is available
APAR status
Closed as documentation error.
Error description
Connections to storage devices ceased to work after SSL certification renewal at Device Server. After replacing the default SSL certificate for the IBM Spectrum Control Device server, utilizing the below linked procedure, the following type error is realized in the Data Collector trace logs: 2019-10-02 10:59:38.529-0500 [Dispatch] [CollectorStatus.handleConnectionError] [ERROR] Connection failed from Dispatch.run [SOAPException: faultCode=SOAP-ENV:Client; msg=Error opening socket: javax.net.ssl.SSLHandshakeException: com.ibm.jsse2.util.h: PKIX path validation failed: java.security.cert.CertPathValidatorException: The certificate issued by CN=xx.xxx.xxxx.com, OU=deviceServer, O=ibm, C=us is not trusted; internal cause is: java.security.cert.CertPathValidatorException: Certificate chaining error; targetException=java.lang.IllegalArgumentException: Error opening socket: javax.net.ssl.SSLHandshakeException: com.ibm.jsse2.util.h: PKIX path validation failed: java.security.cert.CertPathValidatorException: The certificate issued by CN=xxxxxx.xxxxx.xxxxxx.com, OU=deviceServer, O=ibm, C=us is not trusted; internal cause is: java.security.cert.CertPathValidatorException: Certificate chaining error] at org.apache.soap.transport.http.SOAPHTTPConnection.send(Unknown Source) at org.apache.soap.rpc.Call.invoke(Unknown Source) at co m.tivoli.sanmgmt.middleware.data.SoapClient.handshake(SoapClient .java:478) at com.tivoli.sanmgmt.middleware.data.SoapClient.init (SoapClient.java:231) at com.tivoli.sanmgmt.middleware.data.Soap ServiceProxy.invoke(SoapServiceProxy.java:86) at com.sun.proxy.$Proxy0.getRequestToCollector(Unknown Source) at com.ibm.saas.agent.Dispatch.run(Dispatch.java:121) at java.lang.Thread.run(Thread.java:812) -To offer additional clarification: Under the 'Procedure' section and in reference to: renewing SSL certificate regarding the IBM Spectrum Control Device Server: https://www.ibm.com/support/knowledgecenter/en/SS 5R93_5.3.3/com.ibm.spectrum.sc.doc/fqz0_t_tbs_renewing_security_ certificates.html Needs to point to the link below with the requirement to update the Data Collector SSL Certificate: https ://www.ibm.com/support/knowledgecenter/en/SS5R93_5.3.3/com.ibm.s pectrum.sc.doc/cfg_update_dc_certificate_after.html Which states in the header: Use the keytool command to update the IBM Spectrum Control? data collector trusted certificates after you replace the default SSL certificate for the IBM Spectrum Control Device server.
Local fix
Knowledge Center Doc APAR
Problem summary
****************************************************************
Problem conclusion
The fix for this APAR is targeted for the following release:IBM
Temporary fix
Comments
APAR Information
APAR number
IT30572
Reported component name
TPC ADVANCED
Reported component ID
5608TPCA0
Reported release
532
Status
CLOSED DOC
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt / Xsystem
Submitted date
2019-10-10
Closed date
2019-11-04
Last modified date
2019-11-04
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Applicable component levels
[{"Business Unit":{"code":"BU029","label":"Software"},"Product":{"code":"SSNECY","label":"Tivoli Storage Productivity Center Advanced"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"532"}]
Document Information
Modified date:
24 June 2022