IBM Support

IT25430: Queue manager unable to connect to LDAP server which only supports TLS v1.0

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • A queue manager is configured to use an LDAP server for user
    authentication (and/or authorization
                                ). This LDAP server does not support
    TLS v1.2. The queue manager error logs report that the queue
    manager is unable to contact the LDAP server.
    
    This presents the same way as a genuine failure to contact the
    LDAP server, in that the following error is seen in the queue
    manager error log:
    
    AMQ5530: Error from LDAP authentication and authorization
    service
    
    EXPLANATION:
    The LDAP authentication and authorization service has failed.
    The
    'ldap_simple_bind' call returned error 81 : 'Can't contact LDAP
    server'.
    
    
    Diagnostics show that the connection is being rejected by the
    LDAP server as the queue manager is only proposing TLS v1.2,
    which is not supported by the LDAP server.
    

Local fix

  • Set the below in the qm.ini file and restart the queue manager.
    
       AllowTLSV1=Y
    
    in the SSL stanza of the qm.ini file.
    

Problem summary

  • ****************************************************************
    USERS AFFECTED:
    This issue affects users of MQ who wish to connect to an LDAP
    server that does not support TLS v1.2
    
    
    Platforms affected:
    MultiPlatform
    
    ****************************************************************
    PROBLEM DESCRIPTION:
    APAR IT23235 added new function to allow TLS v1.0 to be
    optionally disabled.
    
    A logic error within the APAR IT23235 change meant that LDAP
    connections defaulted to TLS v1.2 only. This can be mitigated by
    explicitly enabling TLS v1.0 as described in the local fix
    section above.
    
    TLS channels to MQ clients or queue managers are not impacted by
    this issue.
    

Problem conclusion

  • The default behavior has been restored to propose TLS v1.0 and
    TLS v1.2 by default when connecting to an LDAP server.
    
    ---------------------------------------------------------------
    The fix is targeted for delivery in the following PTFs:
    
    Version    Maintenance Level
    v8.0       8.0.0.11
    v9.0 LTS   9.0.0.5
    v9.1 CD    9.1.1
    v9.1 LTS   9.1.0.1
    
    The latest available maintenance can be obtained from
    'WebSphere MQ Recommended Fixes'
    http://www-1.ibm.com/support/docview.wss?rs=171&uid=swg27006037
    
    If the maintenance level is not yet available information on
    its planned availability can be found in 'WebSphere MQ
    Planned Maintenance Release Dates'
    http://www-1.ibm.com/support/docview.wss?rs=171&uid=swg27006309
    ---------------------------------------------------------------
    

Temporary fix

Comments

APAR Information

  • APAR number

    IT25430

  • Reported component name

    IBM MQ BASE M/P

  • Reported component ID

    5724H7261

  • Reported release

    900

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2018-06-20

  • Closed date

    2018-07-09

  • Last modified date

    2018-07-09

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    IBM MQ BASE M/P

  • Fixed component ID

    5724H7261

Applicable component levels

[{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSYHRD","label":"IBM MQ"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"9.0","Edition":"","Line of Business":{"code":"LOB36","label":"IBM Automation"}}]

Document Information

Modified date:
09 July 2018