IBM Support

PH71675: THERE IS AN ISSUE WITH THE SAFKEYRING PROTOCOL IN JAVA 21+ WHEN SPECIFYING A RACF USER ID WITH CERTAIN SPECIAL CHARACTERS.

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • Error Message: .ERROR . CWPKI0033E: The keystore located at
    safkeyring://USERID#/RINGID did not load because of the
    following error: Illegal character found in host: '#'
    .
    Stack Trace: N/A
    .
    There was an attempt to use %23 instead of the # character,
    however this made the user ID length too long. There is also no
    support to convert %23 back to #.
    

Local fix

  • There is no workaround for Java 21+. However, this issue is not
    present in Java 17.
    

Problem summary

  • Special characters such as # when used in the RACF user ID for a
    
    safkeyring URL will throw an error.
    

Problem conclusion

  • The safkeyring protocol providers will now accept URL encoded
    versions of special characters such as %23 for #.
    .
    This APAR will be fixed in the following Releases:
    .
    IBM Semeru Runtimes
      25              25.0.4.0
      21              21.0.12.0
      17              17.0.20.0
    .
    Downloads and supplementary documentation can be found at the
    following locations:
    - For the z/OS operating system:
     - Java SDK Products on z/OS
       https://www.ibm.com/support/pages/java-sdk-products-zos
    

Temporary fix

Comments

APAR Information

  • APAR number

    PH71675

  • Reported component name

    JAVA Z/OS 64

  • Reported component ID

    620700104

  • Reported release

    L00

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2026-06-10

  • Closed date

    2026-06-10

  • Last modified date

    2026-07-28

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    JAVA Z/OS 64

  • Fixed component ID

    620700104

Applicable component levels

[{"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Product":{"code":"SSNVBF","label":"Runtimes for Java Technology"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"L00","Line of Business":{"code":"LOB08","label":"Cognitive Systems"}}]

Document Information

Modified date:
28 July 2026