IBM Support

IT24119: MQ XMS .NET client uses the wrong certificate and so fails to connect to a queue manager using SSL/TLS

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • An MQ XMS .NET client fails to connect to a queue manager using
    SSL/TLS.  Error message AMQ9637 and reason code 2393 are seen.
    rc=2393 means MQRC_SSL_INITIALIZATION_ERROR.
    
    This problem is seen only if supplying the certificate label
    programatically from the MQ XMS .NET application.  If you use
    the mqclient.ini file to supply your certificate label, the
    problem is not seen.
    
    The following can be seen in the queue manager error log:
    
    The channel is lacking a certificate to use for the SSL
    handshake. The channel name is 'TEST' (if '????' it is unknown
    at this stage in the SSL processing).  The remote host is
    'ABC(xxx.xx.xx.xx)'.  The channel did not start.
    
    A queue manager trace would show error text similar to this:
    
    rrxError (rc=rrcE_SSL_NO_CERT)
    cciSslRemoteCert (rc=rrcE_SSL_NO_CERT)
    cciSslSecureAcceptSess (rc=rrcE_SSL_NO_CERT)
    ccxSecureAcceptSess (rc=rrcE_SSL_NO_CERT)
    

Local fix

  • Set the following properties in mqclient.ini file:
    
    SSL:
      CertificateLabel=[client certificate labelname]
    

Problem summary

  • ****************************************************************
    USERS AFFECTED:
    Programmers of MQ XMS .NET applications which supply the
    certificate label through the programming interfaces of the MQ
    XMS .NET classes.
    
    
    Platforms affected:
    Windows
    
    ****************************************************************
    PROBLEM DESCRIPTION:
    The MQSCO block that passed from the MQ .NET library code to the
    MQ C library code was at version 2.  The certificate label only
    passes in version 5 of the block.  The responsibility for
    setting this correctly belongs to the MQ .NET library code
    running in the application.
    

Problem conclusion

  • The MQ .NET library code has been corrected so that, if the
    programmer passes the certificate label using programming
    interfaces (ie. not using mqclient.ini), the version of the
    MQSCO block is correctly set to 5.
    
    To obtain a complete fix to this on installations where the XMS
    classes are obtained separately (that is MQ client versions
    before v9), then an additional APAR fix will have to be obtained
    separately, and installed on the same installation.  This
    corresponding co-requisite APAR is IJ04255.
    
    ---------------------------------------------------------------
    The fix is targeted for delivery in the following PTFs:
    
    Version    Maintenance Level
    v8.0       8.0.0.10
    v9.0 LTS   9.0.0.4
    
    The latest available maintenance can be obtained from
    'WebSphere MQ Recommended Fixes'
    http://www-1.ibm.com/support/docview.wss?rs=171&uid=swg27006037
    
    If the maintenance level is not yet available information on
    its planned availability can be found in 'WebSphere MQ
    Planned Maintenance Release Dates'
    http://www-1.ibm.com/support/docview.wss?rs=171&uid=swg27006309
    ---------------------------------------------------------------
    

Temporary fix

Comments

APAR Information

  • APAR number

    IT24119

  • Reported component name

    IBM MQ BASE MP

  • Reported component ID

    5724H7251

  • Reported release

    800

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2018-02-19

  • Closed date

    2018-03-19

  • Last modified date

    2018-03-19

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    IBM MQ BASE MP

  • Fixed component ID

    5724H7251

Applicable component levels

[{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSYHRD","label":"IBM MQ"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"8.0.0.0","Edition":"","Line of Business":{"code":"LOB36","label":"IBM Automation"}}]

Document Information

Modified date:
19 March 2018