IBM Support

PH71550: REMOVE REDUNDANT CODE TO VALIDATE 2-DIGIT CIPHER LISTS.

A fix is available

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • As of CICS TS 6.3 the use of 2-digit ciphers has been removed.
    There is still code in DFHEIWB that makes a call to validate a
    2-digit cipher list. This call is redundant as CICS will never
    use a 2-digit cipher.
    
    At z/OS 3.2, the validation will always fail with message
    DFHSO0145, this causes the WEB OPEN command to fail with INVREQ
    RESP2=137.
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED: All CICS Users.                              *
    ****************************************************************
    * PROBLEM DESCRIPTION: A WEB OPEN command specifying CIPHERS   *
    *                      fails on a z/OS 3.2 system with abend   *
    *                      AEIP (INVREQ) and EIBRESP2 = 137.       *
    ****************************************************************
    A WEB OPEN command specifying the CIPHERS attribute fails with
    abend AEIP (INVREQ) and RESP2=137 on a z/OS 3.2 system. This is
    because as of z/OS 3.2, the system SSL default 2-digit ciphers
    list is now empty as 2-digit ciphers are no longer supported.
    
    CICS still contains code to validate ciphers specified on the
    CIPHERS attribute of a WEB OPEN command against the system SSL
    default list. This validation will always fail given the system
    SSL default list is now empty.
    
    
    Note that as of CICS TS 6.3, the CIPHERS attribute on the WEB
    OPEN command has been deprecated. CICS TS 6.3 programs will
    not compile with this attribute. However older compilations of
    programs can still contain the CIPHERS parameter.
    

Problem conclusion

  • The redundant validation code has been removed.
    

Temporary fix

Comments

APAR Information

  • APAR number

    PH71550

  • Reported component name

    CICS TS Z/OS V6

  • Reported component ID

    5655YA100

  • Reported release

    600

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2026-06-01

  • Closed date

    2026-06-16

  • Last modified date

    2026-07-02

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

    UO08243

Modules/Macros

  • DFHEIWB
    

Fix information

  • Fixed component name

    CICS TS Z/OS V6

  • Fixed component ID

    5655YA100

Applicable component levels

  • R600 PSY UO08243

       UP26/06/17 P F606

Fix is available

  • Select the PTF appropriate for your component level. You will be required to sign in. Distribution on physical media is not available in all countries.

[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSGMGV","label":"CICS Transaction Server"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"6.3","Line of Business":{"code":"LOB70","label":"Z TPS"}}]

Document Information

Modified date:
02 July 2026