IBM Support

PH02461: MODIFYING OIDC RP CUSTOM PROPERITES IN A SECURITY DOMAIN VIA THE ADMIN CONSOLE RESULTED IN DUPLICATES

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • When trying to modify the OpenID Connect Relying Party custom
    properties (com.ibm.ws.security.oidc.client.RelyingParty) in a
    security domain via the Admin Console, the custom property gets
    duplicated:
    1. Add a property ex: 'identifier' with valid value 'ping2'
    2. Edit the property as 'provider_2.identifier' using the edit
    or delete option to re-enter the same property
    3. The property isn't updated and two entries are seen in the
    console and domain-security.xml, e.g.
     <trustProperties xmi:id="Property_1234869004738"
    name="identifier" value="ping2"/>
    ---
     <trustProperties xmi:id="Property_1534969441343"
    name="provider_2.identifier" value="ping2"/>
    
    The same issue has been observed when trying to edit/delete all
    custom properties.
    

Local fix

  • Delete each property and re-create all properties
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED:  All users of IBM WebSphere Application      *
    *                  Server who configured custom properties     *
    *                  for TrustAssociationInterceptor (TAI) in    *
    *                  Security Domain                             *
    ****************************************************************
    * PROBLEM DESCRIPTION: On adminconsole, changes made to TAI    *
    *                      custom properties in Security Domain    *
    *                      are not saved.                          *
    ****************************************************************
    * RECOMMENDATION:                                              *
    ****************************************************************
    On adminconsole, changes made to TAI custom properties in
    SecurityDomain is not saved as expected.  After
    pressing "save", previous configuration is displayed.
    

Problem conclusion

  • Existing configuration was not properly unconfigured before
    saving the new configuration. The bug was fixed.
    
    The fix for this APAR is currently targeted for inclusion in
    fix pack 8.5.5.15 and 9.0.0.10.  Please refer to the
    Recommended Updates
    page for delivery information:
    http://www.ibm.com/support/docview.wss?rs=180&uid=swg27004980
    

Temporary fix

Comments

APAR Information

  • APAR number

    PH02461

  • Reported component name

    WEBS APP SERV N

  • Reported component ID

    5724H8800

  • Reported release

    900

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2018-09-05

  • Closed date

    2018-10-18

  • Last modified date

    2018-10-18

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    WEBS APP SERV N

  • Fixed component ID

    5724H8800

Applicable component levels

  • R850 PSY

       UP

  • R900 PSY

       UP

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSEQTP","label":"WebSphere Application Server"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"9.0","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
28 April 2022