IBM Support

SE72642: Channel specified certificate not used at runtime-AMQ9673

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • MQ v8 and above allows a channel to use a different server
    certificate than the one specified by the Manager (or assigned
    in DCM)  using channel parameter CERTLABEL.  This is not
    current honored at 8 (8.0.0.10 and newer at least)
    
    Attempts to connect a secured channel will fail on the inbound
    channel side with
    AMQ9673  "The channel %1 did not send the correct certificate
    to the remote peer"
    
    The corresponding sender channel may log AMQ9503: Channel
    negotiation failed.
    

Local fix

  • On IBM i,  the keystore *SYSTEM can be used to assign multiple
    certificates to the Manager (listed as an "Application")   Set
    the Manager to use the *SYSTEM keystore, import all the
    appropriate server certificates and signer certificates.  Make
    sure that the partner Manager or client specify the
    certificates to use for that channel.
    

Problem summary

  • ****************************************************************
    USERS AFFECTED:
    IBM i MQ users attempting to use CERTLABEL on either the queue
    manager or a specific channel using a non-default label.
    
    
    Platforms affected:
    IBM iSeries
    
    ****************************************************************
    PROBLEM DESCRIPTION:
    When assigning a specific certificate to a channel or the queue
    manager that is different from the default label, there is a
    problem in the code logic that results in a channel failure.
    

Problem conclusion

  • IBM MQ code has been modified to allow for usage of the
    CERTLABEL parameter on the queue manager or channel to specify a
    non-default certificate label
    
    ---------------------------------------------------------------
    The fix is targeted for delivery in the following PTFs:
    
    Version    Maintenance Level
    v8.0       8.0.0.14
    v9.0 LTS   9.0.0.9
    v9.1 CD    9.1.5
    v9.1 LTS   9.1.0.5
    
    The latest available maintenance can be obtained from
    'WebSphere MQ Recommended Fixes'
    http://www-1.ibm.com/support/docview.wss?rs=171&uid=swg27006037
    
    If the maintenance level is not yet available information on
    its planned availability can be found in 'WebSphere MQ
    Planned Maintenance Release Dates'
    http://www-1.ibm.com/support/docview.wss?rs=171&uid=swg27006309
    ---------------------------------------------------------------
    

Temporary fix

Comments

APAR Information

  • APAR number

    SE72642

  • Reported component name

    IBM MQ ISERIES

  • Reported component ID

    5724H7254

  • Reported release

    800

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2019-12-09

  • Closed date

    2019-12-13

  • Last modified date

    2020-03-10

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    IBM MQ ISERIES

  • Fixed component ID

    5724H7254

Applicable component levels

[{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSYHRD","label":"IBM MQ"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"8.0","Edition":"","Line of Business":{"code":"LOB36","label":"IBM Automation"}}]

Document Information

Modified date:
10 March 2020