IBM Support

PH09240: Using the z/OS Connect EE API toolkit with invalid credentials causes the user ID to be revoked unexpectedly.

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as unreproducible in next release.

Error description

  • An attempt to connect the API toolkit to a z/OS Connect EE fails
    because an invalid password is used from a saved credential. A
    pop-up box prompts for new credentials, but the subsequent
    validation attempt uses the original user ID and password.
    
    There are multiple attempts to validate the credentials and this
    causes the user ID specified to be revoked.
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED: All users of the z/OS Connect EE API         *
    *                 toolkit.                                     *
    ****************************************************************
    * PROBLEM DESCRIPTION: Using the z/OS Connect EE API toolkit   *
    *                      with invalid credentials causes the     *
    *                      user ID to be revoked unexpectedly.     *
    ****************************************************************
    When the API toolkit attempts to establish a connection to the
    z/OS Connect EE server, multiple parallel attempts to check
    authorization for multiple resources are started. If the
    credentials are not valid all of these attempts will fail, each
    being counted as a failed access attempt.
    
    If saved credentials are used, an Eclipse pop-up window can be
    displayed which requests that new credentials are provided.
    Any details entered into this pop-up box are ignored and the
    original credentials are reused.
    
    This behavior can cause the user ID to be revoked by the SAF
    before the user realized they have made too many failed access
    attempts.
    

Problem conclusion

Temporary fix

Comments

  • The z/OS Connect EE API toolkit has been changed to use serial
    rather than parallel execution of tasks within a z/OS Connect
    EE Host Connection, so if a task encounters an authentication
    failure, the credential referenced by the connection is
    marked invalid, remaining tasks are cancelled, and the
    connection is disconnected so that there are no more attempts
    to use the credential.  Upon attempting to reconnect, the
    toolkit will prompt for and use updated credentials
    
    This problem will be resolved in release 3.0.6.4 of the z/OS
    Connect EE API toolkit.
    

APAR Information

  • APAR number

    PH09240

  • Reported component name

    Z/OS CONNECT EE

  • Reported component ID

    5655CE300

  • Reported release

    000

  • Status

    CLOSED UR1

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2019-03-05

  • Closed date

    2019-03-26

  • Last modified date

    2019-03-26

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    Z/OS CONNECT EE

  • Fixed component ID

    5655CE300

Applicable component levels

[{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SSNPJM","label":"IBM z\/OS Connect"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"3.0","Edition":"","Line of Business":{"code":"LOB35","label":"Mainframe SW"}}]

Document Information

Modified date:
14 February 2023