IBM Support

IO27863: CONFIGURING SSL FOR LDAP ON RHEL REQUIRES AN UNCRYPTED PASSWORD IN THE CMBCMENV.PROPERTIES FILE.

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • When enabling SSL for LDAP server communication, the logon
    fails with the following error in the LDAP debug enabled log
    file: SSL client init failed : 408
    
    The error shows that the
    password for the key is incorrect, even though it is
    correct.
    
    To summarize:
    
    1. LDAP Import utility runs without
    any issues connecting to AD on SSL port.
    2. Our 5,000 user
    logging in PROD without any issues via ICN using accounts
    loaded from AD by LDAP Import utility.
    3. After enabling user
    exit for LDAP authentication AND with
    LDAP_SECURITY_PROTOCOL=none, I am able to log in to CM via ICI
    with LDAP account.
    4. After enabling user exit for LDAP
    authentication AND with LDAP_SECURITY_PROTOCOL=ssl, the log in
    to CM fails via ICI with LDAP account.
    
    
    --
    Temporary
    workaround is to update the cmbcmenv.properties file with an
    unencrypted password.
    
    Note that version is CMEE 8.6.2 The apar
    tool will not let me enter that version.
    
    But this is obviously
    a security issue, and needs to be resolved.
    

Local fix

  • Temporary workaround is to update the cmbcmenv.properties file
    with an unencrypted password.
    

Problem summary

  • the problem has been fixed/shipped in a previous out of support
    release.
    

Problem conclusion

  • na
    

Temporary fix

Comments

APAR Information

  • APAR number

    IO27863

  • Reported component name

    LIBRARY SERVER

  • Reported component ID

    5724B1907

  • Reported release

    860

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2020-06-05

  • Closed date

    2021-07-30

  • Last modified date

    2021-07-30

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    LIBRARY SERVER

  • Fixed component ID

    5724B1907

Applicable component levels

[{"Line of Business":{"code":"LOB45","label":"Automation"},"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSRS7Z","label":"IBM Content Manager Enterprise Edition"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"860"}]

Document Information

Modified date:
31 July 2021