IBM Support

PH70272: CERTLABL IN CLUSSDR CHANNEL

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • Cluster sender channels use the queue manager's default
    certificate label, even when one has been set manually with
    'DEFINE' or 'ALTER CHANNEL'. Auto-defined channels do not adopt
    the certlabl from the manually defined channel, so its channel
    definition has an empty certlabel, which defaults to the queue
    manager's certlabl.
    
    Currently it is possible to set the CERTLABL parameter in
    CLUSSDR channel by DEFINE or ALTER CHANNEL commands, but
    customers should be notified that this field cannot be set.
    

Local fix

  • Do not set CERTLABL in a CLUSSDR channel.
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED: All users of IBM MQ for z/OS Version 9       *
    *                 Release 3 Modification 0 and                 *
    *                 Release 4 Modification 0                     *
    ****************************************************************
    * PROBLEM DESCRIPTION: MQ users can specify CERTLABL on a      *
    *                      CLUSSDR channel definition or           *
    *                      alteration command. This allowed        *
    *                      customers to believe that a certificate *
    *                      label had been set for the CLUSSDR      *
    *                      channel, even though that attribute     *
    *                      will not be used by the channel.        *
    ****************************************************************
    The CERTLABL attribute was being accepted during CLUSSDR channel
    command processing instead of being rejected for that channel
    type. As a result, the command processor allowed CERTLABL to be
    specified for CLUSSDR channels when it should not have been
    permitted.
    

Problem conclusion

  • This APAR introduces code to reject the CERTLABL attribute for
    CLUSSDR channels. An exception is made for ALTER CHANNEL
    commands when CERTLABL is specified as blank, allowing an
    existing certificate label to be removed.
    

Temporary fix

Comments

APAR Information

  • APAR number

    PH70272

  • Reported component name

    IBM MQ Z/OS V9

  • Reported component ID

    5655MQ900

  • Reported release

    300

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2026-02-24

  • Closed date

    2026-08-24

  • Last modified date

    2026-08-24

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

    PH72386 UO09120 UO09121

Modules/Macros

  • CSQMCNAC
    

Fix information

  • Fixed component name

    IBM MQ Z/OS V9

  • Fixed component ID

    5655MQ900

Applicable component levels

[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSYHRD","label":"IBM MQ"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"300","Line of Business":{"code":"LOB77","label":"Automation Platform"}}]

Document Information

Modified date:
24 August 2026