IBM Support

PH70996: SUPPORT FOR CLASSIFYING A LIBERTY WORKLOAD, SUCH AS THAT FROM A KAFKA LISTENER, WITH A USER SPECIFIED USER ID

A fix is available

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as new function.

Error description

  • This APAR adds support to allow a Java program running in a
    Liberty JVM server to set the Liberty runAsSubject on a thread.
    This allows the specified user ID to be used as the user ID for
    the CICS tasks that run on any spawned threads.
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED: All CICS users.                              *
    ****************************************************************
    * PROBLEM DESCRIPTION: This APAR adds support for specifying   *
    *                      the user ID for a CICS task started     *
    *                      within a Liberty JVM server.            *
    ****************************************************************
    Prior to this APAR a CICS task spawned from within a Liberty JVM
    server would run under the user ID of the originating task, or
    the CICS default user ID unless overridden using the
    com.ibm.cics.jvmserver.unclassified.userid property.
    
    This APAR expands CICS' security coverage to support a wider
    range of application patterns beyond HTTP requests, such as
    Apache Kafka applications, by providing a mechanism to specify
    the user ID that a non-HTTP task should run under.
    

Problem conclusion

  • With this APAR applied a Java program running in a Liberty JVM
    server can set the Liberty runAsSubject on a parent/spawning
    thread.  The Security Subject will be propagated onto any
    spawned threads and if they run under a CICS task, onto the CICS
    task user ID. No configuration or API changes are required. An
    example of this pattern, might be a CICS Liberty application
    which employs an Apache Kafka listener. The listener thread
    establishes the runAs security identity and then begins message
    processing on asynchronous CICS tasks - who inherit the
    established identity.
    
    For an example of this pattern see the GitHub CICSdev sample:
    https://github.com/cicsdev/cics-java-liberty-kafka, specifically
    https://github.com/cicsdev/cics-java-liberty-kafka/blob/main/cic
    s-java-liberty-kafka-app/src/main/java/com/ibm/cicsdev/kafka/Kaf
    kaConsumerService.java.
    

Temporary fix

Comments

APAR Information

  • APAR number

    PH70996

  • Reported component name

    CICS TS Z/OS V6

  • Reported component ID

    5655YA100

  • Reported release

    400

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    YesSpecatt / New Function / Xsystem

  • Submitted date

    2026-04-21

  • Closed date

    2026-09-18

  • Last modified date

    2026-09-26

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

    UO09515 UO09516 UO09517

Modules/Macros

  • DFJ@H387 DFJ@H417 DFJ@H469 DFJ@H639
    

Fix information

  • Fixed component name

    CICS TS Z/OS V6

  • Fixed component ID

    5655YA100

Applicable component levels

  • R400 PSY UO09517

       UP26/09/22 I 1000  

  • R500 PSY UO09516

       UP26/09/19 I 1000  

  • R600 PSY UO09515

       UP26/09/26 I 1000  

Fix is available

  • Select the PTF appropriate for your component level. You will be required to sign in. Distribution on physical media is not available in all countries.

[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSGMGV","label":"CICS Transaction Server"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"6.1","Line of Business":{"code":"LOB70","label":"Z TPS"}}]

Document Information

Modified date:
26 September 2026