A fix is available
APAR status
Closed as program error.
Error description
When using system property -Dcom.ibm.cics.jvmserver.wlp.ltpa.regenerate=true in a JVM profile to automatically recreate the LTPA key file with a new password, the JVMSERVER fails with javax.crypto.BadPaddingException if WLP_OUTPUT_DIR and WLP_USER_DIR point to different directory structures (i.e. they didn't use the defaults).
Local fix
Delete the existing ltpa.keys file first.
Problem summary
**************************************************************** * USERS AFFECTED: All CICS users with UO08217, UO08273, or * * UO08240 applied. * **************************************************************** * PROBLEM DESCRIPTION: Regeneration of Liberty JVMERVER * * LTPA keys file fails with * * javax.crypto.BadPaddingException * * when WLP_OUTPUT_DIR and WLP_USER_DIR * * are set to custom locations. * **************************************************************** A Liberty JVMSERVER is started with the following system property to regenerate the LTPA key file: -Dcom.ibm.cics.jvmserver.wlp.ltpa.regenerate=true CICS attempts to delete the LTPA keys file from Liberty's configuration directory. When WLP_OUTPUT_DIR and WLP_USER_DIR are set, this file is located in the output directory, and so CICS does not delete the LTPA keys file. CICS then creates a new keysPassword and populates the server.xml. Liberty reads the old LTPA keys file from the output directory which was never deleted and recreated. Since the password was regenerated, but the LTPA keys file was not, the password does not match which results in a javax.crypto.BadPaddingException which can be observed in messages.log. An FFDC is also written.
Problem conclusion
UO08217 UO08273 UO08240 CICS has been updated to ensure old LTPA key files are deleted from Liberty JVMSERVER output and configuration directories when using system property com.ibm.cics.jvmserver.wlp.ltpa.regenerate
Temporary fix
Comments
APAR Information
APAR number
PH72873
Reported component name
CICS TS Z/OS V6
Reported component ID
5655YA100
Reported release
400
Status
CLOSED PER
PE
YesPE
HIPER
NoHIPER
Special Attention
NoSpecatt / Xsystem
Submitted date
2026-08-25
Closed date
2026-10-01
Last modified date
2026-10-03
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
PH73070 UO09767 UO09768 UO09769
Modules/Macros
DFJ@H387 DFJ@H427 DFJ@H498 DFJ@H571 DFJ@H639
Fix information
Fixed component name
CICS TS Z/OS V6
Fixed component ID
5655YA100
Applicable component levels
R400 PSY UO09769
UP26/10/03 I 1000 {
R500 PSY UO09768
UP26/10/03 I 1000 {
R600 PSY UO09767
UP26/10/03 I 1000 {
Fix is available
Select the PTF appropriate for your component level. You will be required to sign in. Distribution on physical media is not available in all countries.
[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSGMGV","label":"CICS Transaction Server"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"6.1","Line of Business":{"code":"LOB70","label":"Z TPS"}}]
Document Information
Modified date:
03 October 2026