IBM Support

SE70886: MQM400-Validation of signed AMS message fails with AMQ9070

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • AMS signature validation in an application MQGET or async
    consume call fails with MQRC_SECURITY_ERROR (2063) and an
    AMQ9070 message is written to the error log.
    
    The signers certificate chain is trusted by the application, but
    the certificate contains an extended key usage and this does not
    specify "email protection" as a permitted usage. The OpenSSL
    cryptographic provider for AMS on IBM i implements a strict
    RFC5280 validation policy and rejects an otherwise valid message
    signature.
    

Local fix

  • Regenerate certificates which have "e-mail protection" as a
    permitted extended key usage, or omit extended key usage from
    the certificate.
    

Problem summary

  • ****************************************************************
    USERS AFFECTED:
    Any customer using an ILE or Java bindings application to
    retrieve a message on the IBM i platform with an AMS integrity
    or privacy policy, where the certificate that signed the
    protected message contains extended key usage, may be affected.
    
    
    Platforms affected:
    IBM iSeries
    
    ****************************************************************
    PROBLEM DESCRIPTION:
    When validating a digital signature on IBM i using AMS and the
    OpenSSL cryptographic provider, the extended key usage
    attributes of the signer certificate are validated in strict
    accordance with RFC 5280 section 4.2.1.12. if extended key usage
    is specified but does not include "e-mail protection"
    (id-kp-emailProtection OID 1.3.6.1.5.5.7.3.4), the validation
    fails.
    
    This behaviour is inconsistent with other cryptographic
    providers used by AMS, where the validation succeeds. For other
    platforms, the presence of the signers certificate in the trust
    store indicates that extended key usage is not checked.
    

Problem conclusion

  • The default behaviour when using the OpenSSL cryptographic
    provider is altered to match other implementations.  The
    presence of a signer certificate chain in the trust store
    referenced by the AMS keystore configuration file ignores
    extended key usage checks. The previous behaviour can be
    restored by setting;
    
    pem.checkpurpose = TRUE
    
    in the keystore configuration file.
    
    ---------------------------------------------------------------
    The fix is targeted for delivery in the following PTFs:
    
    Version    Maintenance Level
    v8.0       8.0.0.15
    v9.0 LTS   9.0.0.9
    v9.1 CD    9.1.5
    v9.1 LTS   9.1.0.5
    
    The latest available maintenance can be obtained from
    'WebSphere MQ Recommended Fixes'
    http://www-1.ibm.com/support/docview.wss?rs=171&uid=swg27006037
    
    If the maintenance level is not yet available information on
    its planned availability can be found in 'WebSphere MQ
    Planned Maintenance Release Dates'
    http://www-1.ibm.com/support/docview.wss?rs=171&uid=swg27006309
    ---------------------------------------------------------------
    

Temporary fix

Comments

APAR Information

  • APAR number

    SE70886

  • Reported component name

    IBM MQ ISERIES

  • Reported component ID

    5724H7254

  • Reported release

    800

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2019-03-28

  • Closed date

    2020-02-12

  • Last modified date

    2020-03-16

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    IBM MQ ISERIES

  • Fixed component ID

    5724H7254

Applicable component levels

[{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSYHRD","label":"IBM MQ"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"8.0","Edition":"","Line of Business":{"code":"LOB36","label":"IBM Automation"}}]

Document Information

Modified date:
27 March 2020