IBM Support

PH71721: CMCI JVM SERVERS ADD HTTP STRICT TRANSPORT SECURITY (HSTS) BY DEFAULT

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • Currently, HTTP Strict Transport Security (HSTS) is being
    enabled on CICS JVM servers (EYUCMCIJ & EYUSMSSJ) by default.
    Whilst the com.ibm.cics.jvmserver.cmci.hsts property can be used
    to override the default value, there is no way to remove the
    value without manually editing the server.xml.
    
    This com.ibm.cics.jvmserver.cmci.hsts property can be set via
    the JVMPROFILE directly, or through the following feature
    toggles:
    - com.ibm.cics.web.hsts.max-age
    - com.ibm.cics.web.hsts.includesubdomains
    
    If the feature toggle and JVMPROFILE option are both set,
    the feature toggle values take priority.
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED: All CICS users.                              *
    ****************************************************************
    * PROBLEM DESCRIPTION: HTTP Strict Transport Security (HSTS)   *
    *                      cannot be removed from CMCI JVM servers *
    *                      without manually editing the server.xml *
    ****************************************************************
    When a CMCI JVM server, such as EYUCMCIJ or EYUSMSSJ, is
    installed, it automatically adds HTTP Strict Transport Security
    (HSTS) to the server.xml.
    
    The com.ibm.cics.jvmserver.cmci.hsts property can be used to
    modify this HSTS value, but omitting this property leads to the
    default value of "max-age=31536000;includeSubDomains" being
    used.
    
    As a result, HSTS cannot be removed from the server.xml without
    manual modification, but this is not recommended as CMCI JVM
    servers have their server.xmls maintained by CICS itself.
    

Problem conclusion

  • CICS has been updated to ensure HSTS is only added to CMCI JVM
    servers when specified by the com.ibm.cics.jvmserver.cmci.hsts
    property. A default value of "max-age=31536000" has been added
    to the EYUCMCIJ and EYUSMSSJ sample JVMPROFILEs.
    

Temporary fix

Comments

APAR Information

  • APAR number

    PH71721

  • Reported component name

    CICS TS Z/OS V6

  • Reported component ID

    5655YA100

  • Reported release

    500

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2026-06-12

  • Closed date

    2026-08-07

  • Last modified date

    2026-08-07

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

    UO08903 UO08904

Modules/Macros

  • DFJ@H571 EYUCMCIJ EYUSMSSJ
    

Fix information

  • Fixed component name

    CICS TS Z/OS V6

  • Fixed component ID

    5655YA100

Applicable component levels

[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSGMGV","label":"CICS Transaction Server"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"6.2","Line of Business":{"code":"LOB70","label":"Z TPS"}}]

Document Information

Modified date:
07 August 2026