IBM Support

OA59912: A RACDCERT LISTCHAIN OUTPUT IS DIFFERENT AFTER SERVER CERTIFICATE ADDED

A fix is available

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • RACDCERT ADD a certificate package containing CA certificates
    already installed in RACF results in different LISTCHAIN
    output. When there are two existing CA certificates which have
    the same public key, one is expired and one is not, the adding
    of the package which contains the non expired CA certificate,
    the non expired one is re-added and it is placed after the
    expired one. As a result, the expired one will be picked up
    by the SSL/TLS process.
    An SSL trace may show the error.
    Unable to validate certificate: Error 0x0335302f and result in
    an Alert 42 being sent
    
    VERIFICATION STEPS:
    Examine the output of a RACDCERT LISTCHAIN command before and
    after a certificate package is added.
    
    ADDITIONAL SYMPTOMS:
    Unable to validate certificate: Error 0x0335302f
    Sent SSL V3 alert 42
    

Local fix

  • BYPASS/CIRCUMVENTION:
    Mark the expired CA certificates as NOTRUST or delete then from
    RACF.
    NOTE: Marking them as NOTRUST won't change the RACDCERT
    LISTCHAIN output but it will resolve the connection issue. The
    certificate must be removed to correct the RACDCERT LISTCHAIN
    output
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED:                                              *
    * Users who try to ADD a certificate which already exists in   *
    * RACF                                                         *
    *                                                              *
    ****************************************************************
    * PROBLEM DESCRIPTION:                                         *
    * When a certificate is added to RACF, it always rebuilds the  *
    * certificate data in the owner's user profile,  no matter     *
    * whether the certificate already exists or not.               *
    * The rebuild process changes the order of the certificates in *
    * the user profile. This may affect the output of RACDCERT     *
    * LISTCHAIN command and the R_DATALIB DataGet functions. Since *
    * the DataGet functions are used by the SSL/TLS  process, the  *
    * unintended order change due to re-adding an existing         *
    * certificate may cause a TLS problem.                         *
    *                                                              *
    ****************************************************************
    * RECOMMENDATION:                                              *
    ****************************************************************
    

Problem conclusion

  • With the fix, when a certificate is added to RACF which already
    exists, the certificate order information in the user profile is
    no longer updated. The order of certificate in the chain built
    by RACDCERT LISTCHAIN or R_DATALIB remains unchanged. If the
    certificate is deleted and re-added, the order will change as
    expected.
    

Temporary fix

Comments

APAR Information

  • APAR number

    OA59912

  • Reported component name

    RACF

  • Reported component ID

    5752XXH00

  • Reported release

    7B0

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2020-07-16

  • Closed date

    2020-10-29

  • Last modified date

    2020-12-01

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

    UJ04307 UJ04308

Modules/Macros

  • IRRCDC02
    

Fix information

  • Fixed component name

    RACF

  • Fixed component ID

    5752XXH00

Applicable component levels

  • R7B0 PSY UJ04307

       UP20/11/18 P F011

  • R7C0 PSY UJ04308

       UP20/11/18 P F011

Fix is available

  • Select the PTF appropriate for your component level. You will be required to sign in. Distribution on physical media is not available in all countries.

[{"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Product":{"code":"SG19M","label":"APARs - z\/OS environment"},"Platform":[{"code":"PF054","label":"z\/OS"}],"Version":"7B0"}]

Document Information

Modified date:
02 December 2020