APAR status
Closed as program error.
Error description
When the Salesforce Request (no discovery) node is configured with a URL using a self-signed certificate, the App Connect Enterprise client does not honor the certificates set in the "NODE_EXTRA_CA_CERTS" environment. This results in the request failing with the error: "BIP1000: User generated exception. Salesforce create failed. sf0017. request. test connection, login, Error: self-signed certificate in certificate chain."
Local fix
Problem summary
**************************************************************** USERS AFFECTED: All Users of IBM App Connect Enterprise V12 and v13 using Salesforce request node(no discovery) node. Platforms affected: AIX, LinuxX64, LinuxZ64, LinuxPPCLE64 **************************************************************** PROBLEM DESCRIPTION: If a SSL/TLS request to the Salesforce server returns a self-signed certificate for authentication, the default truststore will not recognize this certificate, resulting in "Error: self-signed certificate in certificate chain". Consequently, the handshake between the App Connect Enterprise client and the server will fail.
Problem conclusion
The product has been updated to include an environment variable called CA_PATH. This variable can be set to a path containing a PEM file with additional certificates for validating the certificate sent from the server, effectively extending the default truststore. --------------------------------------------------------------- The fix is targeted for delivery in the following PTFs: Version Maintenance Level v12.0 12.0.12.12 v13.0 13.0.3.0 The latest available maintenance can be obtained from: http://www-01.ibm.com/support/docview.wss?rs=849&uid=swg27006041 If the maintenance level is not yet available,information on its planned availability can be found on: http://www-1.ibm.com/support/docview.wss?rs=849&uid=swg27006308 ---------------------------------------------------------------
Temporary fix
Comments
APAR Information
APAR number
IT47418
Reported component name
APP CONNECT ENT
Reported component ID
5724J0560
Reported release
C00
Status
CLOSED PER
PE
NoPE
HIPER
YesHIPER
Special Attention
NoSpecatt / Xsystem
Submitted date
2024-12-16
Closed date
2025-02-27
Last modified date
2025-02-27
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
APP CONNECT ENT
Fixed component ID
5724J0560
Applicable component levels
[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSDR5J","label":"IBM App Connect Enterprise"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"C00","Line of Business":{"code":"LOB77","label":"Automation Platform"}}]
Document Information
Modified date:
27 February 2025