APAR status
Closed as program error.
Error description
The customer is unable to use FIPS 140-2 with Semeru JDK on 25.0.0.3 and 25.0.0.4 because their Liberty server will think they are trying to run FIPS 140-3. Thus, when the customer tries to run FIPS 140-2 with Semeru JDK on 25.0.0.3 and 25.0.0.4, they will see an error with their ltpa.keys missing the com.ibm.websphere.ltpa.SharedKey, which should only be present in their ltpa.keys when running FIPS 140-3. They will also see logs in their server saying that the server is using FIPS 140-3 instead of FIPS 140-2.
Local fix
Problem summary
**************************************************************** * USERS AFFECTED: All users of IBM WebSphere Application * * Server * * Liberty Core * **************************************************************** * PROBLEM DESCRIPTION: Not able to configure Liberty 25.0.0.3 * * and 25.0.0.4 using Semeru JDK with * * FIPS * * 140-2. * **************************************************************** * RECOMMENDATION: * **************************************************************** The customer is unable to use FIPS 140-2 with Semeru JDK on 25.0.0.3 and 25.0.0.4 because their Liberty server will think they are trying to run FIPS 140-3. Thus, when the customer tries to run FIPS 140-2 with Semeru JDK on 25.0.0.3 and 25.0.0.4, they will see an issue with their ltpa.keys missing the com.ibm.websphere.ltpa.SharedKey, which should only be present in their ltpa.keys when running FIPS 140-3. They will also see logs in their server saying that the server is using FIPS 140-3 instead of FIPS 140-2.
Problem conclusion
The check for FIPS 140-3 enabled has been fixed, which should now return false when the FIPS level is set to 140-2. Open Liberty GitHub issue: https://github.com/OpenLiberty/open-liberty/issues/31347 The fix for this APAR is targeted for inclusion in fix pack 25.0.0.5. For more information, see 'Recommended Updates for WebSphere Application Server': https://www.ibm.com/support/pages/node/715553
Temporary fix
Comments
APAR Information
APAR number
PH66379
Reported component name
WAS LIBERTY COR
Reported component ID
5725L2900
Reported release
CD0
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt / Xsystem
Submitted date
2025-05-02
Closed date
2025-05-05
Last modified date
2025-05-08
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
WAS LIBERTY COR
Fixed component ID
5725L2900
Applicable component levels
[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSD28V","label":"WebSphere Application Server Liberty Core"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"CD0","Line of Business":{"code":"LOB77","label":"Automation Platform"}}]
Document Information
Modified date:
08 May 2025