IBM Support

PI80549: OPENID CONNECT (OIDC) RELYING PARTY (RP) DOES NOT SUPPORT POST INTROSPECTION ENDPOINTS

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • The OIDC RP does not support POST requests to introspection
    endpoints on provider servers.
    

Local fix

  • NA
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED:  IBM WebSphere Application Server users of   *
    *                  OpenID Connect                              *
    ****************************************************************
    * PROBLEM DESCRIPTION: The OIDC TAI does not support POST      *
    *                      introspection endpoints                 *
    ****************************************************************
    * RECOMMENDATION:  Install a fix pack that includes this       *
    *                  APAR.                                       *
    ****************************************************************
    The OpenID Connect specification requires that POST requests
    be made to introspection endpoints.  The OpenID Connect
    Relying Party TAI in WebSphere Application Server should limit
    HTTP request method to POST only.
    

Problem conclusion

  • The OpenID Connect RP TAI is updated to send POST requests to
    introspecting endpoints.
    
    The following OpenID Connect TAI custom property is added:
    
    introspectEndpointMethod
    
    The default value for this property is 'post'.  Setting this
    property to anything other than 'post' will result in the OIDC
    TAI reverting back to using the GET method for introspection
    endpoints.
    
    The fix for this APAR is currently targeted for inclusion in
    fix pack 8.0.0.14, 8.5.5.13, and 9.0.0.5.  Please refer to the
    Recommended Updates page for delivery information:
    http://www.ibm.com/support/docview.wss?rs=180&uid=swg27004980
    

Temporary fix

Comments

APAR Information

  • APAR number

    PI80549

  • Reported component name

    WEBSPHERE APP S

  • Reported component ID

    5724J0800

  • Reported release

    850

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2017-04-25

  • Closed date

    2017-05-23

  • Last modified date

    2017-05-23

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    WEBSPHERE APP S

  • Fixed component ID

    5724J0800

Applicable component levels

[{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSEQTP","label":"WebSphere Application Server"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"850","Line of Business":{"code":"LOB36","label":"IBM Automation"}}]

Document Information

Modified date:
29 June 2020