A fix is available
APAR status
Closed as program error.
Error description
After apply of SystemSSL APAR OA66482 higher CPU usage is observed in SystemSSL for TLS1.2 connections. SMF82 crypto usage statistics shows an increase of CSF1GK2 calls. ANALYSIS: SystemSSL APAR OA66482 added function crypto_pkcs11_generate_secret_gk2key() and update logic to call ICSF CSFPGK2 for PBES2 for clear key. KNOWN IMPACT: SSL handshake is using now CSFPGK2 which runs in CLiC and increase CPU usage. VERIFICATION STEPS: collect SMF82 crypto usage statistics and check for high number of CSF1GK2 calls. collect SystemSSL trace and check for crypto_generate_pbkdf2_key() and crypto_pkcs11_generate_secret_gk2key() PE INFORMATION: USERS AFFECTED: ATTLS and System SSL users with PTFs for APAR OA66482 applied: zOS 2.5 UJ96829, UJ96831 zOS 3.1 UJ96825, UJ96827 USER IMPACT: APAR OA66482 fixed the problem it reported but introduced a new problem. SystemSSL APAR OA66482 may cause higher CPU usage in SystemSSL for TLS1.2 connections. We recommend removing the PTF for OA66482 until the fixing PTF can be applied.
Local fix
BYPASS/CIRCUMVENTION: remove SystemSSL APAR OA66482 PTFs for APAR OA66482 are zOS 2.5 UJ96829, UJ96831 zOS 3.1 UJ96825, UJ96827
Problem summary
**************************************************************** * USERS AFFECTED: Users of z/OS System SSL applications that * * use SAF key rings, PKCS#11 tokens, and * * PKCS#12 packages containing private keys. * **************************************************************** * PROBLEM DESCRIPTION: The new support added in APAR OA66482 * * resulted in a performance issue when * * reading into memory certificates with * * accompanying private keys from a SAF * * key ring, PKCS#11 token, or PKCS#12 * * package. This change caused high CPU * * utilization due to the enhanced * * protection that is being done to * * protect private keys in-memory. * **************************************************************** * RECOMMENDATION: APPLY PTF * **************************************************************** When analyzing the System SSL code and performing additional diagnostics, it was determined that the parameters that System SSL was providing to the ICSF callable service were not optimal.
Problem conclusion
The System SSL code has been updated to change the parameters passed to the ICSF callable service when protecting the private keys in-memory.
Temporary fix
Comments
APAR Information
APAR number
OA67949
Reported component name
SYSTEM SSL
Reported component ID
565506805
Reported release
510
Status
CLOSED PER
PE
YesPE
HIPER
YesHIPER
Special Attention
NoSpecatt / Xsystem
Submitted date
2025-05-22
Closed date
2025-07-28
Last modified date
2025-10-01
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
UJ97735 UJ97736 UJ97737 UJ97739
Modules/Macros
GSKC31 GSKC31F GSKC64 GSKC64F GSKCMS31 GSKCMS64
Fix information
Fixed component name
SYSTEM SSL
Fixed component ID
565506805
Applicable component levels
R450 PSY UJ97737
UP25/08/12 P F508 {
R451 PSY UJ97739
UP25/08/12 P F508 {
R510 PSY UJ97735
UP25/08/12 P F508 {
R511 PSY UJ97736
UP25/08/12 P F508 {
Fix is available
Select the PTF appropriate for your component level. You will be required to sign in. Distribution on physical media is not available in all countries.
[{"Business Unit":{"code":"BU011","label":"Systems - zSystems software"},"Product":{"code":"SG19O"},"Platform":[{"code":"PF054","label":"z Systems"}],"Version":"510"}]
Document Information
Modified date:
02 October 2025