APAR status
Closed as duplicate of another APAR.
Error description
The sample scripts for AT-TLS contain outdated guidance for cipher suites and key usage
Local fix
Problem summary
The AT-TLS sample scripts contain outdated guidance for AT-TLS configuration. Two of the cipher suites (TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 and TLS_DHE_RSA_WITH_AES_128_GCM_SHA256) are now considered to be weak. Two cipher suites that are needed for TLS 1.2 with the NISTECC key algorithm (TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 and TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256) are missing. The key usage includes a usage (DATAENCRYPT) that is no longer needed with the recommended cipher suites. There was no guidance for the key algorithm or key size.
Problem conclusion
The CECRDTL1 sample JCL script was updated to change the key usage to HANDSHAKE and to add a key algorithm (NISTECC) and key size (256). The CECRDTLP sample AT-TLS profile script was updated to add the TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 and TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 cipher suites and to remove the TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 and TLS_DHE_RSA_WITH_AES_128_GCM_SHA256 cipher suites
Temporary fix
Comments
This Apar has been shipped at part of PTF UO07993 (APAR PH71187).
APAR Information
APAR number
PH71273
Reported component name
CLASSIC FED & E
Reported component ID
5697I8200
Reported release
B30
Status
CLOSED DUB
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt / Xsystem
Submitted date
2026-05-11
Closed date
2026-05-28
Last modified date
2026-05-28
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Applicable component levels
[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSDP9S","label":"InfoSphere Classic Federation Server for z\/OS"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"B30","Line of Business":{"code":"LOB76","label":"Data Platform"}}]
Document Information
Modified date:
12 June 2026