APAR status
Closed as program error.
Error description
Error Message: There are four different error conditions described in error message section. 1. AESGCM Update operation results in a ProviderException being thrown. 2. Computing a secret in DHKeyAgreement with DESede or TripleDES as specified algorithm results in an ArrayIndexOutOfBoundsException being thrown. 3. Serialization operations of DHPrivateKey and ECPrivateKey objects fail with IBMJCEPlus provider. 4. The RSAPSS Signature objects could not be reused. . Stack Trace: 1. AES GCM update operation exception: ProviderException: "engineUpdate not supported for AES GCM; only engineDoFinal is supported"; 2. DESede exception ================ java.lang.ArrayIndexOutOfBoundsException: Array index out of range: 24 j> 07:35:26 at java.lang.System.arraycopy(Native Method) j> 07:35:26 at com.ibm.crypto.plus.provider.DESedeKey.<init>(DESedeKey.java:23) j> 07:35:26 at com.ibm.crypto.plus.provider.DHKeyAgreement.engineGenerateSecret (DHKeyAgreement.java:27) j> 07:35:26 at javax.crypto.KeyAgreement.generateSecret(Unknown Source) j> 07:35:26 . N/A
Local fix
Problem summary
Added support for AES GCM Update, changes to Serialization, and a fix to DESede Key.
Problem conclusion
The JVM has been updated to support AES GCM update operation. The JVM was also updated to fix the encountered exceptions. The associated Hursley RTC Problem Report: 146316 The associated Austin Git issues are: IBMJCEPlus - 325, 380, 389, 392 The fix was delivered for Java 8 SR7 The files affected for Java 8 SR7 are: ibmjceplus.jar (Build-Date: 20210921) jgskit.dll (win32, win64) llibjgskit.so on AIX (ppc, ppc64) libjgskit.so - Linux platforms libbjgsikt.so - zOS . This APAR will be fixed in the following Java Releases: 8 SR7 (8.0.7.0) . Contact your IBM Product's Service Team for these Service Refreshes and Fix Packs. For those running stand-alone, information about the available Service Refreshes and Fix Packs can be found at: https://www.ibm.com/developerworks/java/jdk/
Temporary fix
Comments
APAR Information
APAR number
IJ35292
Reported component name
SECURITY
Reported component ID
620700125
Reported release
270
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt / Xsystem
Submitted date
2021-10-01
Closed date
2021-10-18
Last modified date
2021-10-18
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
SECURITY
Fixed component ID
620700125
Applicable component levels
[{"Line of Business":{"code":"LOB36","label":"IBM Automation"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSNVBF","label":"Runtimes for Java Technology"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"270"}]
Document Information
Modified date:
19 October 2021