Known Issues

The following items are known issues with this release of Secure Proxy.

  • If the IBM Sterling Control Center's OSA monitoring interval value is changed in Configuration Manager GUI (via CM GUI > System > System Settings > ICC OSA Monitoring > ICC OSA monitoring interval), you must restart SSP CM for the new value to take effect.
  • TLS1.3 connections from the SSP Engine to SEAS timeout intermittently. As a workaround, continue to use TLSv1.2 as the security protocol between SSP and SEAS.
  • TLSv1.3 Outbound connections from SSP to a CD i5 Server timeout during the handshake. As a workaround, continue to use TLSv1.2 as the security protocol to CD i5 outbound nodes.
  • TLSv1.3 Outbound connections from SSP to a Connect Express (C:X) Server timeout during the handshake. As a workaround, continue to use TLSv1.2 as the security protocol to C:X outbound nodes.
  • TLS handshakes fail between an incoming CD PNode to SSP when the PNode has all the TLS protocols selected (TLSv1, TLSv1.1, TLSv1.2, TSv1.3) in its Secure Plus configuration and SSP has only TLSv1 or TLSv1.1 selected for that node in its netmap. Workaround is to select TLSv1.2 or TLSv1.3 in the SSP netmap configuration for the node.
  • When architecting connections from the More Secure Perimeter Servers to the Secure Proxy engines, you must keep the Secure Proxy Engine listening port numbers unique across all ports and engines. Instead of defining More Secure listening ports 2001 and 2002 on both Engine 1 and 2 for connections from More Secure Perimeter Servers on Nodes 1 and 2, for example, define ports 2001, 2002, 2003, and 2004 to keep the port numbers unique.
Note: These issues are being actively worked on and fixes will be delivered as soon as they are ready after v6.1.0.