IBM Support

PH08485: JWT SSO USABILITY ENHANCEMENTS FOR LIBERTY 18.0.0.3

A fix is available

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • Several enhancements to Liberty are required to improve the
    usability of the jwtSso-1.0 feature.
    .
    If a JWT SSO cookie is expired or invalid, Liberty emits error
    messages which can fill up the log.  These messages include
    CWWKS5523E, CWWKS5524E, CWWKS6031E, and CWWKS6025E.  Where
    possible these messages should be suppressed to mirror the
    behavior of LTPA cookies.
    .
    The property "useAuthenticationDataForUnprotectedResource" does
    not currently apply to the JWT SSO cookie.  It should have the
    same behavior as the LTAP cookie.
    .
    There is no API available to get the JWT SSO cookie name.  An
    equivalent function is provided to get the LTPA cookie name.
    .
    The JsonWebToken class is not available when the jwtSso-1.0
    feature is enabled.  This class is used to represent the JWT
    used by the jwtSso-1.0 feature and is required in order for
    applications to be able to parse the JWT.
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED: All users of IBM WebSphere Application       *
    *                 Server Liberty                               *
    ****************************************************************
    * PROBLEM DESCRIPTION: JWT usability improvements for Liberty  *
    *                      Embedded z/OS                           *
    *                                                              *
    *                      This PTF delivers service for the IBM   *
    *                      z/OS Liberty Embedded product (HWLPEM0) *
    *                      18.0.0.3 fix pack stream.               *
    ****************************************************************
    Several usability issues in the JWT support for Liberty are
    described in GitHub issues 6034, 6241, 6246, 6248, 6663 and
    6833. More information can be found at the following link:
      http://github.com/openliberty/Open-Liberty
    
    This PTF delivers service for the IBM z/OS Liberty Embedded
    product (HWLPEM0) 18.0.0.3 fix pack stream.
    

Problem conclusion

  • Code was added to address the JWT usability issues described in
    GitHub issues 6034, 6241, 6246, 6248, 6663 and 6833.
    

Temporary fix

Comments

APAR Information

  • APAR number

    PH08485

  • Reported component name

    LIBERTY PROF -

  • Reported component ID

    5655W6514

  • Reported release

    EM0

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2019-02-12

  • Closed date

    2019-04-05

  • Last modified date

    2019-05-02

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Modules/Macros

  • BBL18003 BBLS1803
    

Fix information

  • Fixed component name

    LIBERTY PROF -

  • Fixed component ID

    5655W6514

Applicable component levels

  • REM0 PSY UI62369

       UP19/04/12 P F904

Fix is available

  • Select the PTF appropriate for your component level. You will be required to sign in. Distribution on physical media is not available in all countries.

[{"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Product":{"code":"SG19M","label":"APARs - z\/OS environment"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"EM0","Edition":"","Line of Business":{"code":"","label":""}}]

Document Information

Modified date:
02 May 2019