IBM Support

PH12421: AuthLDAPURL not allowing specification of RACFID unless user has RACF search permission

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • AuthLDAPURL not working when specifying RACFID unless the user
    has access to RACF SEARCH.   Trying to specify racfuserid can
    result in muliple finds and thus fails the check.
    

Local fix

  • N/A
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED:  Users of IBM HTTP Server on z/OS with LDAP  *
    ****************************************************************
    * PROBLEM DESCRIPTION: AuthLDAPURL not working when            *
    *                      specifying RACFID unless the user has   *
    *                      access to RACF SEARCH.                  *
    ****************************************************************
    * RECOMMENDATION:  Apply this fix if using IBM HTTP Server on  *
    *                  z/OS with LDAP                              *
    ****************************************************************
    Trying to specify RACFID with AuthLDAPURL doesn't work unless
    user has RACF search permission.
    

Problem conclusion

  • Added the  ´AuthLDAPDNFromBindAsUser ON´ directive to allow
    skipping the retrieval of the HTTP users DN from a configured
    LDAP server.
    This requires AuthLDAPInitialBindAsUser and
    AuthLDAPInitialBindPattern to determine the users DN.  Used in
    environments where no dedicated AuthLDAPBindDN is specified
    but users cannot lookup their own distinguished names (SDBM
    with RACF SEARCH limitations)
    
    This fix is targeted for IBM HTTP Server fix packs:
    - 9.0.5.1
    

Temporary fix

Comments

APAR Information

  • APAR number

    PH12421

  • Reported component name

    WAS IHS ZOS

  • Reported component ID

    5655I3510

  • Reported release

    90P

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2019-05-24

  • Closed date

    2019-07-15

  • Last modified date

    2019-07-15

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    WAS IHS ZOS

  • Fixed component ID

    5655I3510

Applicable component levels

  • R90P PSY

       UP

[{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SS7K4U","label":"WebSphere Application Server for z\/OS"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"90P","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
16 October 2021