IBM Support

PI16626: BASIC AUTHENTICATION REQUESTS FAIL IN LIBERTY

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • Liberty profile used within CICS is encountering a very high
    failure rate for BASIC AUTHENTICATION when running in a
    stressed environment.
    E.g. 512 separate HTTPS requests are sent to the server, each
    with a different USERID and each request contains the correct
    PASSWORD.
    Out of the 512 requests sent, only 287 successfully call the
    servlet they're trying to reach.
    From the remaining 225 calls:
    - 59 produce an Exception on the client side with HTTP
      response code 401.
    - 43 are never heard from again on the client side but on the
      server side following Exception can be seen:
        Exception = java.util.ConcurrentModificationException
        Source = com.ibm.ws.security.authentication.internal.jaas.
                 modules.UsernameAndPasswordLoginModule
    - 123 are never heard from again,
      they are just swallowed somewhere
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED:  All users of IBM WebSphere Application      *
    *                  Server Liberty Profile                      *
    ****************************************************************
    * PROBLEM DESCRIPTION: Under stressed environment on z/OS      *
    *                      platform, a very high failure rate      *
    *                      for basic authentication might be       *
    *                      observed.                               *
    ****************************************************************
    * RECOMMENDATION:                                              *
    ****************************************************************
    Since some of the z/OS unique code was not thread safe, under
    stressed environment, some of concurrent requets for basic
    authentication failed even there were valid credentials.
    

Problem conclusion

Temporary fix

Comments

APAR Information

  • APAR number

    PI16626

  • Reported component name

    LIBERTY - Z/OS

  • Reported component ID

    5655W6514

  • Reported release

    850

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2014-04-23

  • Closed date

    2014-05-13

  • Last modified date

    2014-05-13

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    LIBERTY - Z/OS

  • Fixed component ID

    5655W6514

Applicable component levels

  • R850 PSY

       UP

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SS7K4U","label":"WebSphere Application Server for z\/OS"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"850","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
28 April 2022