IBM Support

IJ25003: IMPACT CONSOLE INTEGRATION CERTIFICATE POP-UP IN JAZZSM DASH

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • PEN Test related security changes in Impact FP17 requires fixes
    in Impact/Blaze and Dash to avoid Certificate popup from being
    displayed every time user logs in.
    
    This issue is specific to
    DASH to Impact Console Integration scenarios.
    

Local fix

  • N/A
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED:                                              *
    * Impact users that use Dash console integration               *
    ****************************************************************
    * PROBLEM DESCRIPTION:                                         *
    * Dash/Impact integrated console configurations.  When the     *
    * user logs into a dash GUI the dash GUI always presents the   *
    * user with a dialog claiming                                  *
    * that the certificate to the impact server needs to be        *
    * validated.                                                   *
    ****************************************************************
    * RECOMMENDATION:                                              *
    * install this fix                                             *
    ****************************************************************
    This issue was caused by new security settings in impact http
    responses
    

Problem conclusion

  • The fix will allow Dash to perform CORS type requests when there
    is an integrated console configuration.
    The fix for this APAR is contained in the following:
    
    | Fix Pack | 7.1.0-TIV-NCI-FP0020 |
    
    | MDVREGR 7.1.0-TIV-NCI-FP0017 |
    | MDVREGR 7.1.0-TIV-NCI-FP0018 |
    | MDVREGR 7.1.0-TIV-NCI-FP0019 |
    

Temporary fix

  • turn off the nosniff option by adding an alternate value for
    X-Content-Type-Options  in the blaze.war web.xml file:
    
    <context-param>
    
    <param-name>HTTP_HEADER_X_CONTENT_TYPE_OPTIONS</param-name>
           <param-value>123</param-value>
       </context-param>
    

Comments

APAR Information

  • APAR number

    IJ25003

  • Reported component name

    NETCOOL/IMPACT

  • Reported component ID

    5724O59IS

  • Reported release

    710

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2020-05-18

  • Closed date

    2020-07-06

  • Last modified date

    2020-07-06

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Modules/Macros

  • UNKNOWN
    

Fix information

  • Fixed component name

    NETCOOL/IMPACT

  • Fixed component ID

    5724O59IS

Applicable component levels

  • R710 PSY

       UP

[{"Line of Business":{"code":"LOB45","label":"Automation"},"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSSHYH","label":"Tivoli Netcool\/Impact"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"710"}]

Document Information

Modified date:
27 August 2021