IBM Support

PH67623: REMOVE SSLREVOCATIONLIBCURLENABLE

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • Remove SSLRevocationLibCurlEnable
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED:  All users of IBM HTTP Server                *
    ****************************************************************
    * PROBLEM DESCRIPTION: APAR PH64942 8.5.5.28, 9.0.5.23 and     *
    *                      9.0.5.24 overrode an anticipated GSKit  *
    *                      default change that has been reverted.  *
    ****************************************************************
    * RECOMMENDATION:                                              *
    ****************************************************************
    PH64942 updated IHS such that if GSKit 8.0.60.x were to be
    later installed by IHS-GSKIT interim fixes, IHS would use an
    IHS- internal CRL/OCSP client rather than the newly introduced
    libCURL-based client in GSKit.
    The libCURL based client in GSKit has however been reverted,
    and when IHS includes 8.0.60.5 (or later) it will remain
    preferable to use the built-in (non-libCURL) client.
    n/a on IHS for zOS.
    

Problem conclusion

  • The code was updated to do the following:
    
    1. Use the GSKit client by default (since it will not
    have a new libCURL dependency) which matches the historical
    behavior
    2. IHS ignores the recently  added
    directive "SSLRevocationLibCurlEnable"
    3. Provide SSLRevocationIHSInternalClientEnable (default false)
       to allow opt-in to use an alternate IHS-based OCSP/CRL
       implementation. This should only be used at the direction
       of IBM support.
    
    The fix for this APAR is targeted for inclusion in IBM HTTP
    Server fix packs 8.5.5.29 and 9.0.5.26. For more information,
    see 'Recommended Updates for WebSphere Application Server':
    https://www.ibm.com/support/pages/node/715553
    

Temporary fix

Comments

APAR Information

  • APAR number

    PH67623

  • Reported component name

    IBM HTTP SERVER

  • Reported component ID

    5724J0801

  • Reported release

    850

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2025-08-04

  • Closed date

    2025-09-08

  • Last modified date

    2025-09-08

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    IBM HTTP SERVER

  • Fixed component ID

    5724J0801

Applicable component levels

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSEQTJ","label":"IBM HTTP Server"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"8.5","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
08 September 2025