IBM Support

IC76541: WMQ EXPLORER WITH WMQFTE PLUGIN ENABLED CONNECTING TO REMOTE SERVER VIA SSL WITH FIPS REQUIRED GETS MQRC = 2393

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • A WebSphere MQ Explorer is not able to connect to a remote
    queue manager via a channel using SSL with Federal Information
    Processing Standards (FIPS) required set to YES, if the
    WebSphere MQ File Transfer Edition (WMQFTE) v7 plugin is
    enabled in WMQ Explorer. The connection is rejected with
    MQRC 2393 = MQRC_SSL_INITIALIZATION_ERROR.
    
    The same set up works fine with SSL if FIPS required is set to
    NO.
    The same set up works fine with SSL if FIPS required is set to
    YES and the WMQ FTE plugin is not enabled in WMQ Explorer.
    

Local fix

Problem summary

  • This problem occurs because the IBM WebSphere MQ File Transfer
    Edition MQ Explorer plugin is hardcoded to connect without using
    FIPS. Because of this a JVM property is set within the MQ client
    which prevents all future connections from using FIPS. This
    later prevents Explorer from making its own FIPS connections.
    
    USERS AFFECTED:
    All users using the MQ Explorer to connect to queue managers
    using a FIPS connection
    
    PLATFORMS AFFECTED:
    All
    

Problem conclusion

  • The code has been altered to attempt to connect in FIPS mode if
    the Explorer which the plugin resides in has been set to use
    FIPS. This prevents the FTE plugin from preventing the Explorer
    connecting to other queue managers via FIPS within the same JVM.
    
    This APAR does NOT introduce support for FIPS to WebSphere MQ
    File Transfer Edition.
    

Temporary fix

Comments

APAR Information

  • APAR number

    IC76541

  • Reported component name

    WMQ FILE TRANSF

  • Reported component ID

    5724R1000

  • Reported release

    700

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt

  • Submitted date

    2011-05-23

  • Closed date

    2011-08-25

  • Last modified date

    2011-08-25

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    WMQ FILE TRANSF

  • Fixed component ID

    5724R1000

Applicable component levels

  • R702 PSY

       UP

  • R703 PSY

       UP

  • R704 PSY

       UP

[{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSEP7X","label":"WebSphere MQ File Transfer Edition"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"7.0","Edition":"","Line of Business":{"code":"LOB36","label":"IBM Automation"}}]

Document Information

Modified date:
25 August 2011