APAR status
Closed as program error.
Error description
A queue manager is configured to use an LDAP server for user authentication (and/or authorization ). This LDAP server does not support TLS v1.2. The queue manager error logs report that the queue manager is unable to contact the LDAP server. This presents the same way as a genuine failure to contact the LDAP server, in that the following error is seen in the queue manager error log: AMQ5530: Error from LDAP authentication and authorization service EXPLANATION: The LDAP authentication and authorization service has failed. The 'ldap_simple_bind' call returned error 81 : 'Can't contact LDAP server'. Diagnostics show that the connection is being rejected by the LDAP server as the queue manager is only proposing TLS v1.2, which is not supported by the LDAP server.
Local fix
Set the below in the qm.ini file and restart the queue manager. AllowTLSV1=Y in the SSL stanza of the qm.ini file.
Problem summary
**************************************************************** USERS AFFECTED: This issue affects users of MQ who wish to connect to an LDAP server that does not support TLS v1.2 Platforms affected: MultiPlatform **************************************************************** PROBLEM DESCRIPTION: APAR IT23235 added new function to allow TLS v1.0 to be optionally disabled. A logic error within the APAR IT23235 change meant that LDAP connections defaulted to TLS v1.2 only. This can be mitigated by explicitly enabling TLS v1.0 as described in the local fix section above. TLS channels to MQ clients or queue managers are not impacted by this issue.
Problem conclusion
The default behavior has been restored to propose TLS v1.0 and TLS v1.2 by default when connecting to an LDAP server. --------------------------------------------------------------- The fix is targeted for delivery in the following PTFs: Version Maintenance Level v8.0 8.0.0.11 v9.0 LTS 9.0.0.5 v9.1 CD 9.1.1 v9.1 LTS 9.1.0.1 The latest available maintenance can be obtained from 'WebSphere MQ Recommended Fixes' http://www-1.ibm.com/support/docview.wss?rs=171&uid=swg27006037 If the maintenance level is not yet available information on its planned availability can be found in 'WebSphere MQ Planned Maintenance Release Dates' http://www-1.ibm.com/support/docview.wss?rs=171&uid=swg27006309 ---------------------------------------------------------------
Temporary fix
Comments
APAR Information
APAR number
IT25430
Reported component name
IBM MQ BASE M/P
Reported component ID
5724H7261
Reported release
900
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt / Xsystem
Submitted date
2018-06-20
Closed date
2018-07-09
Last modified date
2018-07-09
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
IBM MQ BASE M/P
Fixed component ID
5724H7261
Applicable component levels
[{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSYHRD","label":"IBM MQ"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"9.0","Edition":"","Line of Business":{"code":"LOB45","label":"Automation"}}]
Document Information
Modified date:
09 July 2018