APAR status
Closed as program error.
Error description
In the node.conf.yaml file, in the RestAdminListener section, the following comment and entry appear # Note the Admin REST API will be insecure without the following being set #host: 'localhost' # Set the hostname otherwise we bind to the unspecified address The entry should be used to restrict connections to a particular interface, set via the hostname, such as for security reasons. It would then prevent connections via any other interfaces. The comment therefore only refers to when you want to limit access to a single interface. In other circumstances not setting this entry is not less secure.
Local fix
Problem summary
**************************************************************** USERS AFFECTED: User of IBM App Connect Enterprise v12 and v13 who use secured servers Platforms affected: MultiPlatform **************************************************************** PROBLEM DESCRIPTION: There is a comment In the node.conf.yaml and server.conf.yaml files, in the RestAdminListener section, that can be seen to imply that a setting is needed to prevent the server or node being insecure. # Note the Admin REST API will be insecure without the following being set #host: 'localhost'
Problem conclusion
The setting is used to restrict connections to a particular interface and not setting it outside this particular use case does not make the server insecure. The comment has been removed to prevent any confusion. --------------------------------------------------------------- The fix is targeted for delivery in the following PTFs: Version Maintenance Level v12.0 12.0.12.8 The latest available maintenance can be obtained from: http://www-01.ibm.com/support/docview.wss?rs=849&uid=swg27006041 If the maintenance level is not yet available,information on its planned availability can be found on: http://www-1.ibm.com/support/docview.wss?rs=849&uid=swg27006308 ---------------------------------------------------------------
Temporary fix
Comments
APAR Information
APAR number
IT45961
Reported component name
APP CONNECT ENT
Reported component ID
5724J0560
Reported release
C00
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt / Xsystem
Submitted date
2024-04-17
Closed date
2025-01-13
Last modified date
2025-01-13
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
APP CONNECT ENT
Fixed component ID
5724J0560
Applicable component levels
[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSDR5J","label":"IBM App Connect Enterprise"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"C00","Line of Business":{"code":"LOB67","label":"IT Automation \u0026 App Modernization"}}]
Document Information
Modified date:
13 January 2025