IBM Support

LI81745: OIDC HTTP 500 ERROR WHEN VERIFYING C_HASH IN ID_TOKEN

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • After configuring an oidc user registry for logging into
    developer portals. The login fails with an error of the api
    management consumer endpoint:
    "{"status":500,"message":["An internal error occurred."]}"
    In the apim logs we see:
    ===
    020-07-16T10:44:18.984Z audit
    [267a312bfb25beb2b58a9aebed96db4e] START: >>>>>>>> [GET]:
    /consumer-api/oauth2/redirect
    2020-07-16T10:44:19.080Z bhendi:error
    [267a312bfb25beb2b58a9aebed96db4e] Error in GET
    get:/api/oauth2/redirect (oauth2.js:redirect)
    - status : 500
    - message: An internal error occurred.
    - stack : ReferenceError: An internal error occurred.
      at oidcStandard.handleRedirect (/app/lib/oidcBase.js:794:54)
      at runMicrotasks (<anonymous>)
      at processTicksAndRejections
    (internal/process/task_queues.js:97:5)
      at async OAuth2.redirect (/app/routes/oauth2.js:1459:43)
      at async dispatch
    (/app/node_modules/bhendi/mw/dispatcher.js:416:20)
      at async Array.<anonymous>
    (/app/node_modules/bhendi/mw/dispatcher.js:322:9)
    - errors : undefined: {"stack":"ReferenceError: An internal
    error occurred.\n  at oidcStandard.handleRedirect
    (/app/lib/oidcBase.js:794:54)\n  at runMicrotasks
    (<anonymous>)\n  at processTicksAndRejections
    (internal/process/task_queues.js:97:5)\n  at async
    OAuth2.redirect (/app/routes/oauth2.js:1459:43)\n  at async
    dispatch (/app/node_modules/bhendi/mw/dispatcher.js:416:20)\n
    at async Array.<anonymous>
    (/app/node_modules/bhendi/mw/dispatcher.js:322:9)","message":"An
    internal error occurred.","status":500}
    2020-07-16T10:44:19.080Z bhendi:error
    [267a312bfb25beb2b58a9aebed96db4e] invoker::invoke, error for
    call to get
    /oauth2/redirect?code=<redacted-code>&id_token=<redacted-token>&
    state=<redacted-sate>&session_state=<redacted-session_state>
    fxbG (operation id:
    oauth2_redirect_get):{"status":500,"message":["An internal
    error occurred."]}
    2020-07-16T10:44:19.081Z audit
    [267a312bfb25beb2b58a9aebed96db4e] END:  <<<<<<<< FAILURE:
    [500] response (GET /consumer-api/oauth2/redirect) (took 97ms)
    [267a312bfb25beb2b58a9aebed96db4e] {
      "status": 500,
      "message": [
        "An internal error occurred."
      ]
    }
    ===
    

Local fix

  • A potential workaround is turn on "disable_hash_verification"
    feature, to not to verify the c_hash in the id_token, to skip
    that code block for now. The "disable_hash_verification"
    feature is not available in the v10 GA UI, but it can be
    enabled by REST API call.
    

Problem summary

  • When integrating with an OIDC provider which support c_hash, API
    Connect does not handle c_hash correctly
    

Problem conclusion

  • The product is updated in 10.0.1.1 to address the issue.
    

Temporary fix

Comments

APAR Information

  • APAR number

    LI81745

  • Reported component name

    API CONNECT ENT

  • Reported component ID

    5725Z2201

  • Reported release

    A0X

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2020-09-29

  • Closed date

    2021-01-31

  • Last modified date

    2021-01-31

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    API CONNECT ENT

  • Fixed component ID

    5725Z2201

Applicable component levels

  • RA0X PSY

       UP

[{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSMNED","label":"IBM API Connect"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"A0X","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
29 September 2021