IBM Support

PI81722: FEDERATED REPOSITORIES THROWS ACCESSCONTROLEXCEPTION WHEN JAVA SECURITYMANAGER IS ENABLED AND AN SSL CONNECTION IS ATTEMPTED.

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • Federated Repositories throws AccessControlException when
    Java SecurityManager is enabled and an SSL connection is
    attempted.
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED:  IBM WebSphere Application Server users of   *
    *                  federated repositories                      *
    ****************************************************************
    * PROBLEM DESCRIPTION: VMM will throw an                       *
    *                      AccessControlException when Java        *
    *                      SecurityManager is enabled and an SSL   *
    *                      connection is attempted to an LDAP      *
    *                      server.                                 *
    ****************************************************************
    * RECOMMENDATION:                                              *
    ****************************************************************
    VMM code throws AccessControlException when Java
    SecurityManager is enabled and an SSL connection is attempted:
    java.security.AccessControlException: Access denied
    ("com.ibm.websphere.security.WebSphereRuntimePermission"
    "getSSLConfig")
    at
    java.security.AccessController.throwACE(AccessController.java:12
    5)
    at
    java.security.AccessController.checkPermission(AccessController.
    java:234)
    at
    java.lang.SecurityManager.checkPermission(SecurityManager.java:5
    63)
    at
    com.ibm.ws.security.core.SecurityManager.checkPermission(Securit
    yManager.java:208)
    at
    com.ibm.websphere.ssl.JSSEHelper.getSSLPropertiesOnThread(JSSEHe
    lper.java:418)
    at
    com.ibm.ws.wim.env.was.SSLUtilImpl.getSSLPropertiesOnThread(SSLU
    tilImpl.java:65)
    at
    com.ibm.ws.wim.adapter.ldap.LdapConnection.createDirContext(Ldap
    Connection.java:951)
    at
    com.ibm.ws.wim.adapter.ldap.LdapConnection.createDirContext(Ldap
    Connection.java:941)
    at
    com.ibm.ws.wim.adapter.ldap.LdapConnection.reCreateDirContext(Ld
    apConnection.java:888)
    

Problem conclusion

  • Updated the com.ibm.ws.wim.env.was.SSLUtilImpl class to
    make privileged calls to retrieve SSL connection configuration.
    
    The fix for this APAR is currently targeted for inclusion in
    fix packs 8.0.0.14, 8.5.5.13 and 9.0.0.5.  Please refer to the
    Recommended Updates page for delivery information:
    http://www.ibm.com/support/docview.wss?rs=180&uid=swg27004980
    

Temporary fix

Comments

APAR Information

  • APAR number

    PI81722

  • Reported component name

    WEBSPHERE APP S

  • Reported component ID

    5724J0800

  • Reported release

    850

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2017-05-17

  • Closed date

    2017-06-05

  • Last modified date

    2017-06-05

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    WEBSPHERE APP S

  • Fixed component ID

    5724J0800

Applicable component levels

  • R800 PSY

       UP

  • R850 PSY

       UP

  • R900 PSY

       UP

[{"Business Unit":{"code":"BU053","label":"Cloud \u0026 Data Platform"},"Product":{"code":"SSEQTP","label":"WebSphere Application Server"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"850","Line of Business":{"code":"LOB36","label":"IBM Automation"}}]

Document Information

Modified date:
19 October 2021