IBM Support

After upgrading ITM to 6.3.0.7 SP0014, components that use TLSv1.3 in FIPS mode can no longer connect.

Troubleshooting


Problem

SP14 enables TLS v1.3 by default.
After being upgraded to SP14, ITM components that are configured to utilise FIPS mode SP800-131a :
KDEBE_FIPS_MODE_ENABLED=SP800-131a
will be unable to establish a connection to other components using TLS v1.3.

Symptom

Connections fail with the following error in the agent and TEMS RAS1 logs:
(64B27404.0001-7E:kdebeal.c,81,"ssl_provider_open") GSKit error 412: GSK_ERROR_UNSUPPORTED

Document Location

Worldwide

[{"Type":"MASTER","Line of Business":{"code":"LOB67","label":"IT Automation \u0026 App Modernization"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSTFXA","label":"Tivoli Monitoring"},"ARM Category":[{"code":"a8m3p000000hBW3AAM","label":"ITM Communications"}],"ARM Case Number":"","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"6.3.0"}]

Log InLog in to view more of this document

This document has the abstract of a technical article that is available to authorized users once you have logged on. Please use Log in button above to access the full document. After log in, if you do not have the right authorization for this document, there will be instructions on what to do next.

Document Information

Modified date:
10 July 2024

UID

ibm17013029