IBM Support

PH71273: THE SAMPLE SCRIPTS FOR AT-TLS CONTAIN OUTDATED GUIDANCE FOR CIPHER SUITES AND KEY USAGE

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as duplicate of another APAR.

Error description

  • The sample scripts for AT-TLS contain outdated guidance for
    cipher suites and key usage
    

Local fix

Problem summary

  • The AT-TLS sample scripts contain outdated guidance for AT-TLS
    configuration. Two of the cipher suites
    (TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 and
    TLS_DHE_RSA_WITH_AES_128_GCM_SHA256) are now considered to be
    weak. Two cipher suites that are needed for TLS 1.2 with the
    NISTECC key algorithm (TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384
    and TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256) are missing. The
    key usage includes a usage (DATAENCRYPT) that is no longer
    needed with the recommended cipher suites. There was no guidance
    for the key algorithm or key size.
    

Problem conclusion

  • The CECRDTL1 sample JCL script was updated to change the key
    usage to HANDSHAKE and to add a key algorithm (NISTECC) and key
    size (256).
    
    The CECRDTLP sample AT-TLS profile script was updated to add the
    TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 and
    TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 cipher suites and to
    remove the TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 and
    TLS_DHE_RSA_WITH_AES_128_GCM_SHA256 cipher suites
    

Temporary fix

Comments

  • This Apar has been shipped at part of PTF UO07993 (APAR
    PH71187).
    

APAR Information

  • APAR number

    PH71273

  • Reported component name

    CLASSIC FED & E

  • Reported component ID

    5697I8200

  • Reported release

    B30

  • Status

    CLOSED DUB

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2026-05-11

  • Closed date

    2026-05-28

  • Last modified date

    2026-05-28

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

Applicable component levels

[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSDP9S","label":"InfoSphere Classic Federation Server for z\/OS"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"B30","Line of Business":{"code":"LOB76","label":"Data Platform"}}]

Document Information

Modified date:
12 June 2026