IBM Support

IJ57394: THE IBMJCEPLUS PROVIDER FAILED TO GENERATE AN ECDHEMLKEM KEYPAIR ON THE IBMI PLATFORM.

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • Error Message (as reported by customer):
    java.lang.RuntimeException: Could not generate ECDHEMLKEM
    keypair
    
    Stack Trace:
    None provided.
    
    Additional Information (as reported by customer):
    The issue was observed on JVM level 8.0.8.55 on the IBMi
    platform. The algorithms registered under the IBMJCEPlus
    provider do not include MLKEM or MLDSA.
    
    Workaround:
    None.
    

Local fix

Problem summary

  • The IBMJCEPlus provider failed to generate an ECDHEMLKEM KeyPair
    on the IBMi platform.
    
    ERROR DESCRIPTION:
    
    Customer encountered the exception: java.lang.RuntimeException:
    Could not generate ECDHEMLKEM keypair
    
    The issue was observed on JVM level 8.0.8.55 on the IBMi
    platform. The algorithms registered under the IBMJCEPlus
    provider do not include MLKEM or MLDSA.
    

Problem conclusion

  • FIPS140-2:  ibmjceplus.jar Build: 8.0 build_20260225-605
    
    FIPS140-3 ibmjceplus.jar  Build:  8.0 build_20260226-606
    
    The associated Hursley RTC Problem Report is 153862
    
    The associated Austin GIT issue(IBMJCEPlus) is 977
    
    The associated Austin APAR is IJ57394
    
    JVMs affected: Java 8
    
    The fix was delivered for Java 8 SR8 FP65
    

Temporary fix

Comments

APAR Information

  • APAR number

    IJ57394

  • Reported component name

    TIV JAVA CRYPTO

  • Reported component ID

    TIVSECJCE

  • Reported release

    600

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2026-02-19

  • Closed date

    2026-02-27

  • Last modified date

    2026-02-27

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    TIV JAVA CRYPTO

  • Fixed component ID

    TIVSECJCE

Applicable component levels

[{"Business Unit":{"code":"BU029","label":"Software"},"Product":{"code":"SSWKFH","label":"Tivoli Components - Java Security"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"600"}]

Document Information

Modified date:
27 February 2026