IBM Support

OA69113: RA.5.2 DISALLOWS GENERATING NIST-ECC CERTIFICATES WITH A PRIVATE KEY SIZE OF 521 BUT ALLOWS 512 BITS TO BE SPECIFIED

A fix is available

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • RA.5.2 disallows generating NIST-ECC certificates with a private
    key size of 521 but allows 512 bits to be specified.
    
    The RACF documentation for the RACDCERT GENERATE command states:
    
    "For NISTECC keys, valid key sizes are 192, 224, 256, 384, and
    521 bits."
    
    Therefore, the zSecure RA.5.2 panel should allow a "Size of new
    private key" value of 521 and disallow 512 for NIST-ECC
    certificates.
    

Local fix

  • Override the RACDCERT command generated by zSecure to specify
    size(521).
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED: Users of zSecure Admin exploiting the        *
    *                 RACDCERT function in interactive mode to     *
    *                 generate new digital certificates.           *
    ****************************************************************
    * PROBLEM DESCRIPTION: zSecure Admin user interface does not   *
    *                      allow generation of certificates having *
    *                      the NIST ECC key type if the size of    *
    *                      the cerificate's private key is set to  *
    *                      521.                                    *
    ****************************************************************
    * RECOMMENDATION: Apply the PTF provided.                      *
    ****************************************************************
    When the certificate's private key is set to 521 (on panel
    CKRP3DS1, interactive option RA.5.2), the subsequent panel
    CKRP3DS2 does not allow creation of the NIST ECC key type (the
    option is incorrectly disabled).
    

Problem conclusion

  • zSecure Admin is modified, so that a certificate with private
    key size of 521 and NIST ECC key type can be created.
    

Temporary fix

Comments

APAR Information

  • APAR number

    OA69113

  • Reported component name

    ZSEC BASE,ADMIN

  • Reported component ID

    5655T0100

  • Reported release

    310

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2026-02-18

  • Closed date

    2026-02-20

  • Last modified date

    2026-03-02

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

    UJ99041 UJ99042

Modules/Macros

  • C2R3DC3  CKRI14   CKRP3DC2 CKRP3DS2
    

Fix information

  • Fixed component name

    ZSEC BASE,ADMIN

  • Fixed component ID

    5655T0100

Applicable component levels

  • R310 PSY UJ99042

       UP26/02/24 P F602

  • R320 PSY UJ99041

       UP26/02/24 P F602

Fix is available

  • Select the PTF appropriate for your component level. You will be required to sign in. Distribution on physical media is not available in all countries.

[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSPQTM","label":"IBM Security zSecure Admin"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"310","Line of Business":{"code":"LOB70","label":"Z TPS"}}]

Document Information

Modified date:
02 March 2026