IBM Support

PH05010: IDZ HOST CONNECTION EMULATOR FAILS TO CONNECT WITH TLS AND 256 BIT CYPHER SUITE.

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • In IBM Developer for z Systems - IDz - v14.1.3,
    Host Connection Emulator (HCE) fails to connect when using TLS,
    FIPS mode and 256 bit or higher cypher suite.
    
    When consoleLog and debug are enabled, log shows the following
    cypher from HCE:
    
    HODJSSEImpl.configureSSLSocket : Enabled ciphers : [
    SSL_RSA_WITH_3DES_EDE_CBC_SHA,
    SSL_RSA_FIPS_WITH_3DES_EDE_CBC_SHA,
    SSL_RSA_WITH_AES_128_CBC_SHA,
    SSL_DHE_RSA_WITH_AES_128_CBC_SHA,
    SSL_DHE_RSA_WITH_3DES_EDE_CBC_SHA,
    SSL_DHE_DSS_WITH_AES_128_CBC_SHA,
    SSL_DHE_DSS_WITH_3DES_EDE_CBC_SHA
    ]
    
    javax.net.ssl.SSLHandshakeException:
    Received fatal alert: handshake_failure
    
    The server certificate chain is null
    

Local fix

  • There is no known workaround at this time
    

Problem summary

  • Option needed to add custom ciphers to support 256-bit cipher
    suites.
    

Problem conclusion

  • The option has been added.
    

Temporary fix

Comments

APAR Information

  • APAR number

    PH05010

  • Reported component name

    DEV FOR Z SYS

  • Reported component ID

    5724T0700

  • Reported release

    E12

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2018-11-09

  • Closed date

    2019-03-22

  • Last modified date

    2019-03-22

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    DEV FOR Z SYS

  • Fixed component ID

    5724T0700

Applicable component levels

[{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SSJK49","label":"IBM Developer for z Systems"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"E12","Edition":"","Line of Business":{"code":"LOB35","label":"Mainframe SW"}}]

Document Information

Modified date:
22 March 2019