APAR status
Closed as program error.
Error description
Error Message: aes128-cts is a short for aes128-cts-hmac-sha1-96. IBM's JGSS implementation does not recognize aes128-cts..\java -Dcom.ibm.security.jgss.debug=all -Dcom.ibm.security.krb5.Krb5Debug=all com.ibm.security.krb5.internal.tools.Ktab -k ..\..\..\test.keytab -a TestJazzUser2 TestJazzUser2 > ..\..\..\keytab.logI got this in the keytab.log:<OSB>KRB_DBG_KTAB<CSB> KeyTab:mainLoading the keytab file ... >>> KeyTab: load() entry length: 60<OSB>KRB_DBG_KTAB<CSB> KeyTableInputStream:main: >>> KeyTabInputStream, readName(): KERBEROS.HELSEN.TEST<OSB>KRB_DBG_KTAB<CSB> KeyTableInputStream:main: >>> KeyTabInputStream, readName(): TestJazzUser2<OSB>KRB_DBG_CFG<CSB> Config:main: ConfigFile: c:\WINDOWS\krb5.ini<OSB>KRB_DBG_KDC<CSB> EncryptionKey:main: >>> EncryptionKey: config default key type is des-cbc-crc>>>JGSS Build-Level: 20140714<OSB>JGSS_DBG_PROV<CSB> IBMJGSSProvider (version 1.6) loaded<OSB>KRB_DBG_KTAB<CSB> KeyTabEntry:main: >>> KeyTabEntry: key tab entry size is 60Done!Service key for principal TestJazzUser2 savedKlist command shows that the keytab only has key of DES_CBC_CRC.krb5.ini contents relative to this issue:<OSB>libdefaults<CSB>default_realm = KERBEROS.HELSEN.TESTdefault_tkt_enctypes = aes128-cts rc4-hmacdefault_tgs_enctypes = aes128-cts rc4-hmacpermitted_enctypes = aes128-cts rc4-hmac . Stack Trace: N.A. .
Local fix
Problem summary
The implementation does not support the alias of AES encryption type.
Problem conclusion
Added support to AES aliases.The corresponding Austin defect is 116493.The corresponding Hursley defect is 202697.The corresponding RTC Problem Report is 88031.Platform affected: All platforms.JVMs affected: 5.0, 6.0, 6.26, 7.0, 7.27.Jars affected: ibmjgssprovider.jar.The fix will be available in 150_SR16_FP10, 160_SR16_FP4, 626_SR8_FP4, 170_SR9, 727_SR3.Build level is 20150325. . This APAR will be fixed in the following Java Releases: 7 SR9 (7.0.9.0) 6 SR16 FP4 (6.0.16.4) 6 R1 SR8 FP4 (6.1.8.4) 5.0 SR16 FP10 (5.0.16.10) 7 R1 SR3 (7.1.3.0) . Contact your IBM Product's Service Team for these Service Refreshes and Fix Packs. For those running stand-alone, information about the available Service Refreshes and Fix Packs can be found at: https://www.ibm.com/developerworks/java/jdk/
Temporary fix
Comments
APAR Information
APAR number
IV72097
Reported component name
SECURITY
Reported component ID
620700125
Reported release
260
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt
Submitted date
2015-04-13
Closed date
2015-04-13
Last modified date
2015-04-13
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
IV72098 IV72111
Fix information
Fixed component name
SECURITY
Fixed component ID
620700125
Applicable component levels
R260 PSY
UP
R600 PSY
UP
[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSNVBF","label":"Runtimes for Java Technology"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"260","Edition":"","Line of Business":{"code":"LOB36","label":"IBM Automation"}}]
Document Information
Modified date:
13 April 2015