IBM Support

PH47400: ATTLS CURRENCY SUPPORT FOR X25519 AND X448 KEX UNDER TLSV1.2

A fix is available

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as new function.

Error description

  • NEW FUNCTION IN V2R5 NETWORK CONFIGURATION ASSISTANT UPDATE:
    AT-TLS Currency - Support for x25519 and x448 KEX under TLSv1.2.
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED:                                              *
    * All users of the IBM Network Configuration Assistant for     *
    * z/OS                                                         *
    * Communications Server Version 2 Release 5:  AT-TLS           *
    * policy-based                                                 *
    * networking.                                                  *
    ****************************************************************
    * PROBLEM DESCRIPTION:                                         *
    * NEW FUNCTION IN V2R5 NETWORK CONFIGURATION ASSISTANT UPDATE: *
    *                                                              *
    * AT-TLS Currency - Support for x25519 and x448 KEX under      *
    * TLSv1.2.                                                     *
    ****************************************************************
    * RECOMMENDATION:                                              *
    * Apply PTF                                                    *
    ****************************************************************
    N/A
    

Problem conclusion

  • ATTLS has been ammended with the following:
    
    1. Adding support for the x25519 and x448 key exchange
    algorithms to TLS v1.2
    
    2. Adding support for controlling which elliptic curves (
    Named Groups) the server can accept when using TLS v1.0
    through TLS v1.2
    

Temporary fix

Comments

APAR Information

  • APAR number

    PH47400

  • Reported component name

    Z/MF CONFIG ASS

  • Reported component ID

    5655S28CA

  • Reported release

    25A

  • Status

    CLOSED UR1

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2022-06-21

  • Closed date

    2022-07-29

  • Last modified date

    2022-09-01

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

    UI81718

Modules/Macros

  • IZUCAHLP IZUCAPAX IZUCAWFT
    

Fix information

  • Fixed component name

    Z/MF CONFIG ASS

  • Fixed component ID

    5655S28CA

Applicable component levels

  • R25A PSY UI81718

       UP22/08/02 P F208

Fix is available

  • Select the PTF appropriate for your component level. You will be required to sign in. Distribution on physical media is not available in all countries.

[{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SSSN3L","label":"z\/OS Communications Server"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"25A","Line of Business":{"code":"LOB35","label":"Mainframe SW"}}]

Document Information

Modified date:
01 September 2022