A fix is available
APAR status
Closed as program error.
Error description
RACDCERT ADD a certificate package containing CA certificates already installed in RACF results in different LISTCHAIN output. When there are two existing CA certificates which have the same public key, one is expired and one is not, the adding of the package which contains the non expired CA certificate, the non expired one is re-added and it is placed after the expired one. As a result, the expired one will be picked up by the SSL/TLS process. An SSL trace may show the error. Unable to validate certificate: Error 0x0335302f and result in an Alert 42 being sent VERIFICATION STEPS: Examine the output of a RACDCERT LISTCHAIN command before and after a certificate package is added. ADDITIONAL SYMPTOMS: Unable to validate certificate: Error 0x0335302f Sent SSL V3 alert 42
Local fix
BYPASS/CIRCUMVENTION: Mark the expired CA certificates as NOTRUST or delete then from RACF. NOTE: Marking them as NOTRUST won't change the RACDCERT LISTCHAIN output but it will resolve the connection issue. The certificate must be removed to correct the RACDCERT LISTCHAIN output
Problem summary
**************************************************************** * USERS AFFECTED: * * Users who try to ADD a certificate which already exists in * * RACF * * * **************************************************************** * PROBLEM DESCRIPTION: * * When a certificate is added to RACF, it always rebuilds the * * certificate data in the owner's user profile, no matter * * whether the certificate already exists or not. * * The rebuild process changes the order of the certificates in * * the user profile. This may affect the output of RACDCERT * * LISTCHAIN command and the R_DATALIB DataGet functions. Since * * the DataGet functions are used by the SSL/TLS process, the * * unintended order change due to re-adding an existing * * certificate may cause a TLS problem. * * * **************************************************************** * RECOMMENDATION: * ****************************************************************
Problem conclusion
With the fix, when a certificate is added to RACF which already exists, the certificate order information in the user profile is no longer updated. The order of certificate in the chain built by RACDCERT LISTCHAIN or R_DATALIB remains unchanged. If the certificate is deleted and re-added, the order will change as expected.
Temporary fix
Comments
APAR Information
APAR number
OA59912
Reported component name
RACF
Reported component ID
5752XXH00
Reported release
7B0
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt / Xsystem
Submitted date
2020-07-16
Closed date
2020-10-29
Last modified date
2020-12-01
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
UJ04307 UJ04308
Modules/Macros
IRRCDC02
Fix information
Fixed component name
RACF
Fixed component ID
5752XXH00
Applicable component levels
Fix is available
Select the PTF appropriate for your component level. You will be required to sign in. Distribution on physical media is not available in all countries.
[{"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Product":{"code":"SG19M","label":"APARs - z\/OS environment"},"Platform":[{"code":"PF054","label":"z\/OS"}],"Version":"7B0"}]
Document Information
Modified date:
02 December 2020