APAR status
Closed as program error.
Error description
Customized login commands or authentication filter classes are not called when re-authentication is required for REST resources. The default authentication extension mechanism in portal are designed for non REST services and cannot be fully supported for other entry points as REST services. This APAR provides an extension to the authentication framework. To enable the new authentication framework extension, the following property has to be set through WAS admin console: Resource Environment Providers -> "WP AuthenticationService" property: authentication.default.filter.use.new values: true | false (default = false) value false: default authentication flow (no filter chain extension through REST service) value true: filter chains extensions are enabled also for REST services A server restart is necessary after configration changes. - Note - Please note that existing authentication customization classes may not be fully supported with the new authentication flow for REST services. Do not activate the extension (authentication.default.filter.use .new=true) without careful testing of the existing filter customization. In general, it is recommended to leave the extension disabled for compatibility purposes. - Note - This configuration setting and authentication framework is only available in portal 61x release stream with this APAR.
Local fix
N/A
Problem summary
Customized login commands or authentication filter classes are not called when re-authentication is required for REST resources. The default authentication extension mechanism in portal are designed for non REST services and cannot be fully supported for other entry points as REST services.
Problem conclusion
This APAR provides an extension to the authentication framework. To enable the new authentication framework extension, the following property has to be set through WAS admin console: Resource Environment Providers -> "WP AuthenticationService" property: authentication.default.filter.use.new values: true | false (default = false) value false: default authentication flow (no filter chain extension through REST service) value true: filter chains extensions are enabled also for REST services A server restart is necessary after configration changes. - Note - Please note that existing authentication customization classes may not be fully supported with the new authentication flow for REST services. Do not activate the extension (authentication.default.filter.use.new=true) without careful testing of the existing filter customization. In general it is recommended to leave the extension disabled for compatibility purposes. - Note - This configuration setting and authentication framework is only available in portal 61x release stream with this APAR. Manual Steps: None Failing Module(s): Authorization/Authentication (login/logout) Affected Users: All users Version Information: Portal Version(s): 6.1.0.2 Pre-Requisite(s): PK93809 PK87296 PK92357 PK95170 Co-Requisite(s): --- PK90963 is also part of Cumulative Fix 03 for Portal 6.1.0.3. The Cumulative Fix is available on Fix Central: http://www.ibm.com/eserver/support/fixes/fixcentral/swgquickorde r?apar=PM09968&productid=WebSphere%20Portal&brandid=5 Platform Specific: This fix applies to all platforms. A fix is available from Fix Central: http://www.ibm.com/eserver/support/fixes/fixcentral/swgquickorde r?apar=PK90963&productid=WebSphere%20Portal&brandid=5 You may need to type or paste the complete address into your Web browser.
Temporary fix
Comments
APAR Information
APAR number
PK90963
Reported component name
WEBSPHERE PORTA
Reported component ID
5724E7600
Reported release
600
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt
Submitted date
2009-07-09
Closed date
2010-04-07
Last modified date
2010-10-27
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
WEBSPHERE PORTA
Fixed component ID
5724E7600
Applicable component levels
R61B PSY
UP
R61C PSY
UP
[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSHRKX","label":"WebSphere Portal"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"6.0","Line of Business":{"code":"LOB31","label":"WCE Watson Marketing and Commerce"}}]
Document Information
Modified date:
21 December 2021