IBM Support

IJ53567: UPDATE IKEYMAN TO RESOLVE ISSUES WITH EXPIRED CERTIFICATES AND PBES2 KEYSTORES.

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • Error Message: N/A
    .
    Stack Trace: N/A
    .
    

Local fix

Problem summary

  • 1. Update LetsEncrypt and Digicert certificates
    Replace the expired 'Let's Encrypt Authority X3' certificate and
    add the necessary DigiCert root certificates.
    2. Remove DummyCert in PKCS12 Keystore When Not Empty
    iKeyman version 8.0.425 included a security measure where a
    "dummyCert" was added to prevent the creation of empty PKCS12
    keystores. However, this dummy certificate persisted even when
    other entries were present.
    3. Fix Certreq Compatibility with Java CMS & GSKCApicmd
    To address an interoperability issue between Java CMS and
    GskCapicmd for certificate request file (RDB).
    

Problem conclusion

  • 1. Update LetsEncrypt and Digicert certificates
    Replace the expired 'Let's Encrypt Authority X3' certificate
    with 'Let's Encrypt Authority R3'. Also, add these new DigiCert
    root certificates: DigiCert Global Root G2, DigiCert TLS RSA4096
    Root G5, and DigiCert TLS ECC P384 Root G5.
    2. Remove DummyCert in PKCS12 Keystore When Not Empty
    This fix removes the dummy certificate when other entries are
    added to the keystore.
    3. Fix Certreq Compatibility with Java CMS & GSKCApicmd
    We've updated iKeyman to support certificate request database
    (RDB) files in version 6, including the PBES2 algorithm.
    .
    This APAR will be fixed in the following Releases:
    .
    IBM Semeru Runtimes
    IBM SDK, Java Technology Edition
       8    SR8 FP40  (8.0.8.40)
    .
    Downloads and supplementary documentation can be found at the
    following locations:
    - For non z/OS operating systems:
      - IBM Semeru Runtimes, Version 11 and later
        https://www.ibm.com/semeru-runtimes/downloads/
      - IBM SDK, Java Technology Edition, Version 8
        https://www.ibm.com/support/pages/java-sdk-downloads/
    - For the z/OS operating system:
      - Java SDK Products on z/OS
        https://www.ibm.com/support/pages/java-sdk-products-zos
    

Temporary fix

Comments

APAR Information

  • APAR number

    IJ53567

  • Reported component name

    SECURITY

  • Reported component ID

    620700125

  • Reported release

    270

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2025-02-10

  • Closed date

    2025-02-10

  • Last modified date

    2025-02-10

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    SECURITY

  • Fixed component ID

    620700125

Applicable component levels

[{"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Product":{"code":"SSNVBF","label":"Runtimes for Java Technology"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"270","Line of Business":{"code":"LOB08","label":"Cognitive Systems"}}]

Document Information

Modified date:
10 February 2025