APAR status
Closed as program error.
Error description
CWPKI0811E: The xxx DNS name either starts with a digit or contains a character that is not valid for the DNS name value of a Subject Alternative Name. The specifications RFC 1123 now permits these characters. This APAR requires Java APAR IJ50880
Local fix
Problem summary
**************************************************************** * USERS AFFECTED: All users of IBM WebSphere Application * * Server * **************************************************************** * PROBLEM DESCRIPTION: WebSphere incorrectly enforced outdated * * DNS validation in the Subject * * Alternative * * Name * **************************************************************** * RECOMMENDATION: * **************************************************************** WebSphere previously validated the first digit or an asterisk in the DNS name within the Subject Alternative Name when creating a certificate. Despite these limitations being relaxed under the RFC2253, the code continued enforcing the check and throwing an error. This fix removes the validation check.
Problem conclusion
The fix for this APAR is targeted for inclusion in fix pack 8.5.5.27 and 9.0.5.23. For more information, see 'Recommended Updates for WebSphere Application Server': https://www.ibm.com/support/pages/node/715553 Note: PH61655 takes effect with IJ51335 that is included in Java 8.0.8.30. IJ51335: https://www.ibm.com/support/pages/apar/IJ51335 IBM Java 8.0.8.30 fixlist: https://www.ibm.com/support/pages/java-sdk-fixes-version- 80#SR8FP30
Temporary fix
Use external certificate tools such as Keytool or OpenSSL to cre the certificate, then import it into WebSphere.
Comments
APAR Information
APAR number
PH61655
Reported component name
WEBS APP SERV N
Reported component ID
5724H8800
Reported release
850
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt / Xsystem
Submitted date
2024-06-03
Closed date
2024-12-02
Last modified date
2025-04-22
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
WEBS APP SERV N
Fixed component ID
5724H8800
Applicable component levels
[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSEQTP","label":"WebSphere Application Server"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"8.5","Line of Business":{"code":"LOB77","label":"Automation Platform"}}]
Document Information
Modified date:
22 April 2025