IBM Support

IT26102: SSLPEERUNVERIFIEDEXCEPTION FROM SOAPREQUEST/HTTPREQUEST NODE IF HOSTNAME CHECKING IS ENABLED.

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • If a proxy server is configured for the SOAPRequest/HTTPRequest
    node and SSL certificate hostname checking is enabled, then the
    proxy server name is taken for hostname comparison instead of
    webservice endpoint server name. This causes SSL connectivity
    failure with 'javax.net.ssl.SSLPeerUnverifiedException: SSL Peer
    certificate did not match host name' error.
    
    
    
    
    
    
    
    Additional Symptom(s) Search Keyword(s) :SOAPRequest,
    HTTPRequest, javax.net.ssl.SSLPeerUnverifiedException: SSL,
    certificate Peer certificate did not match host name' error.
    

Local fix

Problem summary

  • ****************************************************************
    USERS AFFECTED:
    All users of IBM AppConnect Enterprise V11.0 and IBM Integration
    Bus V10.0 using the SOAPRequest or HTTPRequest node with proxy
    server and SSL certificate host name checking.
    
    
    Platforms affected:
    z/OS, MultiPlatform
    
    ****************************************************************
    PROBLEM DESCRIPTION:
    If a http proxy server is configured for the
    SOAPRequest/HTTPRequest node and SSL certificate hostname
    checking is enabled, then the http proxy server name is taken
    for the certificate hostname comparison instead of webservice
    endpoint server name. This causes SSL connectivity failure with
    'javax.net.ssl.SSLPeerUnverifiedException: SSL Peer certificate
    did not match host name' error.
    

Problem conclusion

  • The product now correctly carry out the certificate hostname
    check against the webservice endpoint server.
    
    ---------------------------------------------------------------
    The fix is targeted for delivery in the following PTFs:
    
    Version    Maintenance Level
    v10.0      10.0.0.15
    v11.0      11.0.0.3
    
    The latest available maintenance can be obtained from:
    http://www-01.ibm.com/support/docview.wss?rs=849&uid=swg27006041
    
    If the maintenance level is not yet available,information on
    its planned availability can be found on:
    http://www-1.ibm.com/support/docview.wss?rs=849&uid=swg27006308
    ---------------------------------------------------------------
    

Temporary fix

Comments

APAR Information

  • APAR number

    IT26102

  • Reported component name

    INTEGRATION BUS

  • Reported component ID

    5724J0540

  • Reported release

    A00

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2018-08-29

  • Closed date

    2019-02-11

  • Last modified date

    2019-02-11

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    INTEGRATION BUS

  • Fixed component ID

    5724J0540

Applicable component levels

[{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSNQK6","label":"IBM Integration Bus"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"10.0","Edition":"","Line of Business":{"code":"LOB36","label":"IBM Automation"}}]

Document Information

Modified date:
11 February 2019