IBM Support

PH71081: ALLOW FIPS-140-2 WITH TLS 1.3

A fix is available

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as new function.

Error description

  • System SSL has been enhanced to allow the TLS V1.3 protocol to
    be enabled when running in FIPS 140-2 mode. This allows TLS V1.3
    handshakes to occur in a FIPS mode environment.
    
    This will be available with OA68974 on z/OS 3.1 and 3.2.
    
    Currently CICS prevents MAXTLSLEVEL=TLS13 and
    NISTSP800131A=CHECK being set together. This combination causes
    message DFHSO0255 to be issued.
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED: All CICS Users.                              *
    ****************************************************************
    * PROBLEM DESCRIPTION: System SSL has been enhanced to allow   *
    *                      the TLS V1.3 protocol to be enabled     *
    *                      when running in FIPS 140-2 mode. CICS   *
    *                      currently prevents this configuration   *
    *                      from working.                           *
    ****************************************************************
    System SSL has been enhanced to allow the TLS V1.3 protocol to
    be enabled when running in FIPS 140-2 mode. This allows TLS V1.3
    handshakes to occur in a FIPS mode environment.
    
    This will be available with OA68974 on z/OS 3.1 and 3.2.
    

Problem conclusion

Temporary fix

Comments

  • This APAR allows CICS to support the combination of FIPS 140-2
    mode and TLS V1.3 once the System SSL APAR is applied.
    
    The CICS Transaction Server for z/OS V6 documentation will be
    updated to describe the new function.
    

APAR Information

  • APAR number

    PH71081

  • Reported component name

    CICS TS Z/OS V6

  • Reported component ID

    5655YA100

  • Reported release

    400

  • Status

    CLOSED UR1

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    YesSpecatt / New Function / Xsystem

  • Submitted date

    2026-04-28

  • Closed date

    2026-08-27

  • Last modified date

    2026-09-02

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

    UO09172 UO09173 UO09174

Modules/Macros

  • DFHSOIS  DFHSOSK
    

Fix information

  • Fixed component name

    CICS TS Z/OS V6

  • Fixed component ID

    5655YA100

Applicable component levels

  • R400 PSY UO09174

       UP26/08/29 P F608  

  • R500 PSY UO09173

       UP26/08/29 P F608  

  • R600 PSY UO09172

       UP26/08/29 P F608  

Fix is available

  • Select the PTF appropriate for your component level. You will be required to sign in. Distribution on physical media is not available in all countries.

[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSGMGV","label":"CICS Transaction Server"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"6.1","Line of Business":{"code":"LOB70","label":"Z TPS"}}]

Document Information

Modified date:
02 September 2026