APAR status
Closed as program error.
Error description
For Active Directory LDAPs which have groups with more than 1500 members, the wimconfig.xml file needs to have the attributeRangeStep property added to the ldapServerConfiguration section of the repository definition, to be able to return the group members. The recommended value is attributeRangeStep="1000". If a value is used that is larger than the maximum LDAP will return, WebSphere hangs and returns no results.
Local fix
Use the recommended value of attributeRangeStep="1000"
Problem summary
**************************************************************** * USERS AFFECTED: All users of IBM WebSphere Application * * Server * **************************************************************** * PROBLEM DESCRIPTION: If attributeRangeStep is set to a * * value * * larger than the maximum LDAP can * * return, a hang occurs. * **************************************************************** * RECOMMENDATION: If attributeRangeStep is set to something * * large, like 2000, try 1000. * **************************************************************** For Active Directory LDAPs which have groups with more than 1500 members, the wimconfig.xml file needs to have the attributeRangeStep property added to the ldapServerConfiguration section of the repository definition, to be able to return the group members. The recommended value is attributeRangeStep="1000". If the value for attributeRangeStep that is used is larger than the maximum number of attributes LDAP can return, WebSphere will hang.
Problem conclusion
If attributeRangeStep is set to a value higher than LDAP can return, WebSphere will request the maximum LDAP can return instead. The fix for this APAR is targeted for inclusion in fix pack 8.5.5.22 and 9.0.5.12. For more information, see 'Recommended Updates for WebSphere Application Server': https://www.ibm.com/support/pages/node/715553
Temporary fix
Comments
APAR Information
APAR number
PH42735
Reported component name
WEBS APP SERV N
Reported component ID
5724H8800
Reported release
850
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt / Xsystem
Submitted date
2021-12-13
Closed date
2022-06-03
Last modified date
2022-06-15
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
WEBS APP SERV N
Fixed component ID
5724H8800
Applicable component levels
[{"Line of Business":{"code":"LOB45","label":"Automation"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSEQTP","label":"WebSphere Application Server"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"8.5"}]
Document Information
Modified date:
16 June 2022