APAR status
Closed as program error.
Error description
In SSL Client Profile, when both "Validate server host name" and "Validation Credential" are used and enabled, validation of SSL server certificate against only either one of them during SSL handshake. However, the correct validation should be against both options. SSL client should validate the SSL server certificate against both server host name and also the validation credential setting.
Local fix
Problem summary
An SSL Client profile will only enforce either host name validation or a validation credential.
Problem conclusion
Fix is available in 2018.4.1.10 For a list of the latest fix packs available, please see: http://www-01.ibm.com/support/docview.wss?uid=swg21237631
Temporary fix
Comments
APAR Information
APAR number
IT31371
Reported component name
DATAPOWER
Reported component ID
DP1234567
Reported release
770
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt / Xsystem
Submitted date
2019-12-23
Closed date
2020-02-18
Last modified date
2020-02-25
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
DATAPOWER
Fixed component ID
DP1234567
Applicable component levels
[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SS9H2Y","label":"IBM DataPower Gateway"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"770","Edition":"","Line of Business":{"code":"LOB45","label":"Automation"}}]
Document Information
Modified date:
11 February 2022