IBM Support

IJ24986: CISCO APIC REST JAVA COLLECTOR LOGFILE IS NOT UPDATING

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • Cisco APIC Rest java collector logfile is not updating after
    they have upgraded to FP8. Seems it was working for a while and
    now it shows this error in the collector
    log:
    
    [2020-05-01T08:36:13]:SEVERE:HNMTrace:[XML-RPC-0]:POST :
    https://10.41.249.13/api/aaaLogin.json Error occured processing
    Response:java.util.concurrent.ExecutionException:
    javax.net.ssl.SSLHandshakeException: No negotiable cipher
    suite
    [2020-05-01T08:36:13]:SEVERE:HNMTrace:[XML-RPC-0]:Failed
    to connect to target::java.util.concurrent.ExecutionException:
    javax.net.ssl.SSLHandshakeException: No negotiable cipher
    suite
    [2020-05-01T08:36:13]:SEVERE:HNMZH0201E:[XML-RPC-0]:Failed
    to create connection to Cisco APIC Failed to connect to Cisco
    APIC
    
    Customer reported similar incident during a previous
    upgrade
    

Local fix

Problem summary

  • User affected: Users using the Cisco APIC REST collector
    
    Problem description: The collector fails to connect to Cisco
    APIC with following error:
    
    Error occured processing
    Response:java.util.concurrent.ExecutionException:
    javax.net.ssl.SSLHandshakeException: No negotiable cipher
    suite
    
    
    SEVERE:HNMTrace:[XML-RPC-0]:Failed
    to connect to target::java.util.concurrent.ExecutionException:
    javax.net.ssl.SSLHandshakeException: No negotiable cipher
    suite
    SEVERE:HNMZH0201E:[XML-RPC-0]:Failed
    to create connection to Cisco APIC Failed to connect to Cisco
    APIC
    

Problem conclusion

  • There was a mismatch in cipher options between the Jetty libs
    and the IBM JRE. Jetty libraries by default exclude ciphers that
    start with SSL, however the IBM JRE uses ciphers starting with
    SSL. Code updated to remove the "SSL" ciphers from the Jetty
    exclude list.
    
    Fix delivered with ITNM 4.2.0.11 (ITNM 4.2 Fixpack 11)
    

Temporary fix

Comments

APAR Information

  • APAR number

    IJ24986

  • Reported component name

    TIV NETWK MGR I

  • Reported component ID

    5724S4500

  • Reported release

    420

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2020-05-18

  • Closed date

    2020-07-24

  • Last modified date

    2020-07-24

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    TIV NETWK MGR I

  • Fixed component ID

    5724S4500

Applicable component levels

[{"Line of Business":{"code":"LOB45","label":"Automation"},"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSSHRK","label":"Tivoli Network Manager IP Edition"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"420"}]

Document Information

Modified date:
30 October 2020