IBM Support

PI87414: AFTER DELETING THE EXISTING DEFAULT CERTIFICATES, THE NEWLY CREATED DEFAULT CERTIFICATES ARE USING SHA1

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • When you delete the *.p12 files in the
    <PROFILE_ROOT>\config\cells\<CELLNAME>\nodes\<NODENAME>
    directory, start WebSphere Application Server, the newly
    created certificates use "SHA1withRSA" as signature
    algorithm whereas "SHA256withRSA" would be expected.
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED:  All users of IBM WebSphere Application      *
    *                  Server                                      *
    ****************************************************************
    * PROBLEM DESCRIPTION: Recovered keystore and truststore       *
    *                      contain certificate with SHA1 algorithm *
    *                      instead of SHA256                       *
    ****************************************************************
    * RECOMMENDATION:  It is recommended to always keep backup     *
    *                  copy                                        *
    *                  of the keystore and truststore.             *
    ****************************************************************
    WebSphere recovers keystore and truststore files if they are
    not found at server startup.  This function is for
    serviceability purpose and not officially supported but many
    customers familiar with it and found handy.
    The reported issue is, recovered keystore and truststore still
    include certificates with SHA1 algorithm although default
    certificates have been updated to SHA256.
    

Problem conclusion

  • The bug was fixed so that recovered keystore and truststore
    contain certificates with SHA256 algorithm.
    
    The fix for this APAR is currently targeted for inclusion in
    fix pack 8.5.5.14 and 9.0.0.7 Please refer to the Recommended
    Updates
    page for delivery information:
    http://www.ibm.com/support/docview.wss?rs=180&uid=swg27004980
    

Temporary fix

  • Replace the certificates with newly created SHA256 certificates.
    

Comments

APAR Information

  • APAR number

    PI87414

  • Reported component name

    WEBSPHERE APP S

  • Reported component ID

    5724J0800

  • Reported release

    850

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2017-09-15

  • Closed date

    2017-12-14

  • Last modified date

    2017-12-14

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    WEBSPHERE APP S

  • Fixed component ID

    5724J0800

Applicable component levels

  • R850 PSY

       UP

  • R900 PSY

       UP

[{"Business Unit":{"code":"BU053","label":"Cloud \u0026 Data Platform"},"Product":{"code":"SSEQTP","label":"WebSphere Application Server"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"850","Line of Business":{"code":"LOB36","label":"IBM Automation"}}]

Document Information

Modified date:
19 October 2021