IBM Support

PI30323: ADD SUPPORT FOR DUAL-MODE ECDSA/RSA SSL VIRTUAL HOSTS

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • Add support for dual-mode ECDSA/RSA SSL virtual hosts
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED:  IBM HTTP Server users who wish to use both  *
    *                  ECDSA and RSA ciphers in the same           *
    *                  virtualhost                                 *
    ****************************************************************
    * PROBLEM DESCRIPTION: Enable both ECDSA and RSA ciphers in    *
    *                      the same virtualhost.                   *
    ****************************************************************
    * RECOMMENDATION:  Apply this fix if you wish to use both      *
    *                  ECDSA and RSA ciphers in the same           *
    *                  virtualhost.                                *
    ****************************************************************
    Many modern browsers support ECDSA ciphers. However, a special
    ECDSA certificate must be presented by the server to be able to
    negotiate an ECDSA cipher. In older versions of IHS, it is
    not possible to choose to use an ECDSA certificate when
    negotiating an ECDSA cipher.
    

Problem conclusion

  • New functionality has been added to SSLServerCert to allow IHS
    to send an ECDSA certificate when an ECDSA cipher is being
    negotiated. The server administrator may specify two
    certificate labels separated by a space. One label must
    correspond to the RSA certificate, the other, the ECDSA
    certificate.
    
    This fix is targeted for IBM HTTP Server fix packs:
    - 8.0.0.11
    - 8.5.5.5
    

Temporary fix

Comments

APAR Information

  • APAR number

    PI30323

  • Reported component name

    IBM HTTP SERVER

  • Reported component ID

    5724J0801

  • Reported release

    850

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2014-11-25

  • Closed date

    2015-01-29

  • Last modified date

    2015-01-29

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    IBM HTTP SERVER

  • Fixed component ID

    5724J0801

Applicable component levels

  • R800 PSY

       UP

  • R850 PSY

       UP

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSEQTJ","label":"IBM HTTP Server"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"8.5","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
07 September 2022