IBM Support

IV90867: Deprecation of triple DES CipherSpecs

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • This APAR covers changes to the IBM MQ Queue Manager to
    disallow the use of CipherSpecs which specify cryptographic
    algorithms that are now
    considered to be broken or weak.
    

Local fix

Problem summary

  • ****************************************************************
    USERS AFFECTED:
    This affects users of IBM MQ who are
    using SSL/TLS security on queue manager channels.
    
    
    Platforms affected:
    MultiPlatform
    
    ****************************************************************
    PROBLEM DESCRIPTION:
    In line with industry security guidelines and research,
    IBM MQ now considers the following CipherSpecs to be weak:
    
    
    TLS_RSA_WITH_3DES_EDE_CBC_SHA
    ECDHE_ECDSA_3DES_EDE_CBC_SHA256
    ECDHE_RSA_3DES_EDE_CBC_SHA256
    

Problem conclusion

Temporary fix

Comments

APAR Information

  • APAR number

    IV90867

  • Reported component name

    WMQ LIN X86-64

  • Reported component ID

    5724H7230

  • Reported release

    710

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2016-11-18

  • Closed date

    2017-01-31

  • Last modified date

    2017-06-01

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    WMQ LIN X86-64

  • Fixed component ID

    5724H7230

Applicable component levels

  • R710 PSY

       UP

[{"Line of Business":{"code":"LOB45","label":"Automation"},"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSFKSJ","label":"WebSphere MQ"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"7.1"}]

Document Information

Modified date:
09 March 2021