IBM Support

IV42981: IBMPKCS11IMPL PROVIDER THROWS NOSUCHALGORITHMEXCEPTION

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • Error Message: The IBMPKCS11Impl provider supports an RSA cipher
    only if the underlying crypto hardware supports the mechanism
    CKM_RSA_X_509.  In other words, if the underlying crypto
    hardware supports the crypto mechanism CKM_RSA_PKCS, but not
    CKM_RSA_X_509, then the IBMPKCS11Impl provider will not be able
    to support an RSA cipher and will throw a
    NoSuchAlgorithmException for any attempt to use one.
    .
    Stack Trace: N/A
    .
    

Local fix

Problem summary

  • The IBMPKCS11Impl provider supports an RSA cipher only if the
    underlying crypto hardware supports the mechanism CKM_RSA_X_509.
     In other words, if the underlying crypto hardware supports the
    crypto mechanism CKM_RSA_PKCS, but not CKM_RSA_X_509, then the
    IBMPKCS11Impl provider will not be able to support an RSA cipher
    and will throw a NoSuchAlgorithmException for any attempt to use
    one.
    

Problem conclusion

  • This defect will be fixed in:
    5.0.0 SR16FP3
    6.0.0 SR14
    6.0.1 SR6
    7.0.0 SR5
    .
    The IBMPKCS11Impl provider has been modified to enable it to
    support an RSA cipher if "either" the CKM_RSA_X_509 or
    CKM_RSA_PKCS crypto mechanism is supported by the underlying
    crypto hardware.
    

Temporary fix

Comments

APAR Information

  • APAR number

    IV42981

  • Reported component name

    SECURITY

  • Reported component ID

    620700125

  • Reported release

    600

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt

  • Submitted date

    2013-05-21

  • Closed date

    2013-05-22

  • Last modified date

    2013-05-22

  • APAR is sysrouted FROM one or more of the following:

    IV42980

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    SECURITY

  • Fixed component ID

    620700125

Applicable component levels

  • R600 PSY

       UP

  • R260 PSY

       UP

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSNVBF","label":"Runtimes for Java Technology"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"6.0","Edition":"","Line of Business":{"code":"LOB36","label":"IBM Automation"}}]

Document Information

Modified date:
07 December 2020