IBM Support

PI29459: STORAGE LEAK OF ACEE OBJECTS IN NATIVE STORAGE WHEN USING ZOSSECURITY-1.0 WITH CERTIFICATE AUTHENTICATION

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • Native ACEE objects are created when authenticating X509
    certificates to the SAF service provider (e.g. RACF). These
    objects are leaked due to a parameter list error on the
    function call that is supposed to delete them.
    
    This error affects Liberty servers using feature
    zosSecurity-1.0 with authorization to SAFCRED z/OS
    authorized services
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED:  Users of IBM WebSphere Application Server   *
    *                  Liberty Profile on z/OS with feature        *
    *                  zosSecurity-1.0 enabled                     *
    ****************************************************************
    * PROBLEM DESCRIPTION: Storage leak of ACEE objects / ABEND0C4 *
    *                      in native storage when using            *
    *                      zosSecurity-1.0 with certificate        *
    *                      authentication                          *
    ****************************************************************
    * RECOMMENDATION:                                              *
    ****************************************************************
    Native ACEE objects are created when authenticating X509
    certificates to the SAF service provider (e.g. RACF). These
    objects are leaked due to a parameter list error on the function
    that is supposed to delete them.
    
    In addition, if the ACEE object is deleted successfully, an
    ABEND0C4 might occur due to code that incorrectly reads the ACEE
    storage after it has been deleted.
    
    These errors affect Liberty servers that use feature zosSecurity
    1.0 and are configured to use SAFCRED z/OS authorized services
    

Problem conclusion

  • The parameter list erorr on the delete function was corrected.
    The code that caused the ABEND0C4 was also corrected.
    
    The fix for this APAR is currently targeted for inclusion in fix
    pack 8.5.5.5. Please refer to the Recommended Updates page for
    delivery information:
    http://www.ibm.com/support/docview.wss?rs=180&uid=swg27004980
    

Temporary fix

Comments

APAR Information

  • APAR number

    PI29459

  • Reported component name

    LIBERTY - Z/OS

  • Reported component ID

    5655W6514

  • Reported release

    850

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2014-11-12

  • Closed date

    2015-01-07

  • Last modified date

    2015-01-07

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    LIBERTY - Z/OS

  • Fixed component ID

    5655W6514

Applicable component levels

  • R850 PSY

       UP

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SS7K4U","label":"WebSphere Application Server for z\/OS"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"850","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
28 April 2022