IBM Support

IZ66903: HMAC-SHA256 ASSOC TYPE FAILS WITH NO-ENCRYPTION SESSION TYPE

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • When an OpenID relying-party requests an association from a TFIM
    OP with the no-encryption session type and the HMAC-SHA256
    association type, TFIM incorrectly generates a 20 byte random
    key for the shared secret, when for HMAC-SHA256 this should be a
    32 byte key.
    

Local fix

  • Use the DH-SHA256 session type.
    

Problem summary

  • The plaintext key type was hard-coded to return a 20-byte
    key rather than check the association type. For HMAC-SHA256
    the key length needs to be 32 bytes.
    
    CMVC Defects:
    
    IZ66903
    IZ66903.1
    

Problem conclusion

  • The fix for this APAR will be contained in the following
    maintenance packages:
    | fix pack | 6.2.0-TIV-TFIM-FP0003 |
    

Temporary fix

Comments

APAR Information

  • APAR number

    IZ66903

  • Reported component name

    TIV FED ID MGR

  • Reported component ID

    5724L7300

  • Reported release

    620

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt

  • Submitted date

    2009-12-16

  • Closed date

    2009-12-16

  • Last modified date

    2009-12-16

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    TIV FED ID MGR

  • Fixed component ID

    5724L7300

Applicable component levels

  • R620 PSY

       UP

[{"Business Unit":{"code":"BU029","label":"Software"},"Product":{"code":"SSZSXU","label":"Tivoli Federated Identity Manager"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"620"}]

Document Information

Modified date:
29 December 2021