IBM Support

PH69354: IPCONN REMAINS ACQUIRED WHEN CICS DOESN'T RECOGNIZE TLS 1.3 ALERT

A fix is available

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • There is a timing window between CICS receiving a capability
    request and establishing the IPCONN where another request can be
    received from the same remote end. If TLS is in use, CICS will
    check whether the request is a TLS alert and, if it is an alert,
    assume that the connection is being closed. However, CICS was
    not updated to recognize a TLS 1.3 alert.
    
    If TLS 1.3 is in use, CICS will attempt to pass the request to
    the IPCONN, but the IPCONN has not yet had its web session token
    set. CICS cannot find the IPCONN associated with the close
    request and the close request becomes lost. The IPCONN becomes
    ACQUIRED on the CICS side, but it is RELEASED on the client
    side. Further attempts to establish the IPCONN from the client
    receive a DFHIS1015 with code X'0515'.
    
    
    DFHIS1015 IS1015 X'0515' TLS13 TLS1.3
    
    KIXREVNAL
    

Local fix

  • Manually release the IPCONN from the CICS side.
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED: All CICS Users.                              *
    ****************************************************************
    * PROBLEM DESCRIPTION: IPCONN remains ACQUIRED when a TLS 1.3  *
    *                      socket close is sent during connection  *
    *                      initialization.                         *
    ****************************************************************
    An IPIC client, for example CTG, is establishing a connection
    between itself and CICS using IPIC and TLS 1.3.  During the
    initial capability exchange between the systems, CTG closes its
    connection and sends a connection closed to CICS.  CICS fails to
    process this close request and leaves the IPCONN in an ACQUIRED
    state.
    

Problem conclusion

  • DFHWBSO update to notify IS domain when TLS 1.3 close is
    received and ensures the IPCONN is released.
    

Temporary fix

Comments

APAR Information

  • APAR number

    PH69354

  • Reported component name

    CICS TS Z/OS V6

  • Reported component ID

    5655YA100

  • Reported release

    400

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2025-12-11

  • Closed date

    2026-06-18

  • Last modified date

    2026-07-02

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

    UO08305 UO08306 UO08307

Modules/Macros

  • DFHWBSO
    

Fix information

  • Fixed component name

    CICS TS Z/OS V6

  • Fixed component ID

    5655YA100

Applicable component levels

  • R400 PSY UO08307

       UP26/06/19 P F606

  • R500 PSY UO08306

       UP26/06/19 P F606

  • R600 PSY UO08305

       UP26/06/19 P F606

Fix is available

  • Select the PTF appropriate for your component level. You will be required to sign in. Distribution on physical media is not available in all countries.

[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSGMGV","label":"CICS Transaction Server"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"6.1","Line of Business":{"code":"LOB70","label":"Z TPS"}}]

Document Information

Modified date:
02 July 2026