IBM Support

PH68945: ENHANCE DB2 LOG READER TO OBTAIN THE DB2 FOR Z/OS USER FROM AN AT-TLS CLIENT CERTIFICATE MAPPING.

A fix is available

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • Enhance Db2 log reader to obtain the Db2 for z/OS user from an
    AT-TLS client certificate mapping.
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED: CDC Replication Engine for Db2 for           *
    *                 z/OS Remote Source                           *
    *                                                              *
    *                 IBM Data Replication for Db2®               *
    *                 z/OS® Cartridge                             *
    ****************************************************************
    * PROBLEM DESCRIPTION: Enhance Db2 log reader to obtain the    *
    *                      Db2 for z/OS user from an AT-TLS        *
    *                      client certificate mapping              *
    ****************************************************************
    Customer uses TLS Client Authentication when connecting to Db2
    z/OS. They do not allow user ID / passwords to be entered. We
    need to enhance the Db2 z/OS Remote Source engine to login
    using client certificate.
    
    The idea is to configure AT-TLS to use mutual authentication,
    and associate the client certificate with a user. When the
    CDC connects to the classic log reader through the client
    certificate, retrieve the user from AT-TLS, and then
    perform SAF checks and IFI calls using that user.
    

Problem conclusion

  • When RACF is configured to map the client certificate to a user
    ID and AT-TLS is configured with mutual authentication and
    client authentication type SAFCheck, then the Db2 log reader
    will obtain the Db2 for z/OS user from AT-TLS.
    

Temporary fix

Comments

APAR Information

  • APAR number

    PH68945

  • Reported component name

    CLASSIC FED & E

  • Reported component ID

    5697I8200

  • Reported release

    B30

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2025-11-12

  • Closed date

    2026-02-10

  • Last modified date

    2026-02-12

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

    UO06767

Modules/Macros

  • CECCLRD3 CECCLRDD CECCLRDE CECCLRDH CECCLRDI CECCLRDQ CECCLRDR
    CECCLRDT CECCSKA  CECRDMAP CECRDTL2 CECRDTLP
    

Fix information

  • Fixed component name

    CLASSIC FED & E

  • Fixed component ID

    5697I8200

Applicable component levels

  • RB30 PSY UO06767

       UP26/02/12 I 1000

Fix is available

  • Select the PTF appropriate for your component level. You will be required to sign in. Distribution on physical media is not available in all countries.

[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSDP9S","label":"InfoSphere Classic Federation Server for z\/OS"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"B30","Line of Business":{"code":"LOB76","label":"Data Platform"}}]

Document Information

Modified date:
12 February 2026