IBM Support

PI81722: FEDERATED REPOSITORIES THROWS ACCESSCONTROLEXCEPTION WHEN JAVA SECURITYMANAGER IS ENABLED AND AN SSL CONNECTION IS ATTEMPTED.

Fixes are available

9.0.0.5: WebSphere Application Server traditional V9.0 Fix Pack 5
8.0.0.14: WebSphere Application Server V8.0 Fix Pack 14
9.0.0.6: WebSphere Application Server traditional V9.0 Fix Pack 6
8.5.5.13: WebSphere Application Server V8.5.5 Fix Pack 13
9.0.0.7: WebSphere Application Server traditional V9.0 Fix Pack 7
8.0.0.15: WebSphere Application Server V8.0 Fix Pack 15
9.0.0.8: WebSphere Application Server traditional V9.0 Fix Pack 8
8.5.5.14: WebSphere Application Server V8.5.5 Fix Pack 14
9.0.0.9: WebSphere Application Server traditional V9.0 Fix Pack 9
9.0.0.10: WebSphere Application Server traditional V9.0 Fix Pack 10
8.5.5.15: WebSphere Application Server V8.5.5 Fix Pack 15
9.0.0.11: WebSphere Application Server traditional V9.0 Fix Pack 11
9.0.5.0: WebSphere Application Server traditional Version 9.0.5 Refresh Pack
9.0.5.1: WebSphere Application Server traditional Version 9.0.5 Fix Pack 1
9.0.5.2: WebSphere Application Server traditional Version 9.0.5 Fix Pack 2
8.5.5.17: WebSphere Application Server V8.5.5 Fix Pack 17
9.0.5.3: WebSphere Application Server traditional Version 9.0.5 Fix Pack 3
9.0.5.4: WebSphere Application Server traditional Version 9.0.5 Fix Pack 4
9.0.5.5: WebSphere Application Server traditional Version 9.0.5 Fix Pack 5
WebSphere Application Server traditional 9.0.5.6
9.0.5.7: WebSphere Application Server traditional Version 9.0.5 Fix Pack 7
9.0.5.8: WebSphere Application Server traditional Version 9.0.5.8
8.5.5.20: WebSphere Application Server V8.5.5.20
8.5.5.18: WebSphere Application Server V8.5.5 Fix Pack 18
8.5.5.19: WebSphere Application Server V8.5.5 Fix Pack 19
9.0.5.9: WebSphere Application Server traditional Version 9.0.5.9
9.0.5.10: WebSphere Application Server traditional Version 9.0.5.10
8.5.5.16: WebSphere Application Server V8.5.5 Fix Pack 16
8.5.5.21: WebSphere Application Server V8.5.5.21
9.0.5.11: WebSphere Application Server traditional Version 9.0.5.11

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • Federated Repositories throws AccessControlException when
    Java SecurityManager is enabled and an SSL connection is
    attempted.
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED:  IBM WebSphere Application Server users of   *
    *                  federated repositories                      *
    ****************************************************************
    * PROBLEM DESCRIPTION: VMM will throw an                       *
    *                      AccessControlException when Java        *
    *                      SecurityManager is enabled and an SSL   *
    *                      connection is attempted to an LDAP      *
    *                      server.                                 *
    ****************************************************************
    * RECOMMENDATION:                                              *
    ****************************************************************
    VMM code throws AccessControlException when Java
    SecurityManager is enabled and an SSL connection is attempted:
    java.security.AccessControlException: Access denied
    ("com.ibm.websphere.security.WebSphereRuntimePermission"
    "getSSLConfig")
    at
    java.security.AccessController.throwACE(AccessController.java:12
    5)
    at
    java.security.AccessController.checkPermission(AccessController.
    java:234)
    at
    java.lang.SecurityManager.checkPermission(SecurityManager.java:5
    63)
    at
    com.ibm.ws.security.core.SecurityManager.checkPermission(Securit
    yManager.java:208)
    at
    com.ibm.websphere.ssl.JSSEHelper.getSSLPropertiesOnThread(JSSEHe
    lper.java:418)
    at
    com.ibm.ws.wim.env.was.SSLUtilImpl.getSSLPropertiesOnThread(SSLU
    tilImpl.java:65)
    at
    com.ibm.ws.wim.adapter.ldap.LdapConnection.createDirContext(Ldap
    Connection.java:951)
    at
    com.ibm.ws.wim.adapter.ldap.LdapConnection.createDirContext(Ldap
    Connection.java:941)
    at
    com.ibm.ws.wim.adapter.ldap.LdapConnection.reCreateDirContext(Ld
    apConnection.java:888)
    

Problem conclusion

  • Updated the com.ibm.ws.wim.env.was.SSLUtilImpl class to
    make privileged calls to retrieve SSL connection configuration.
    
    The fix for this APAR is currently targeted for inclusion in
    fix packs 8.0.0.14, 8.5.5.13 and 9.0.0.5.  Please refer to the
    Recommended Updates page for delivery information:
    http://www.ibm.com/support/docview.wss?rs=180&uid=swg27004980
    

Temporary fix

Comments

APAR Information

  • APAR number

    PI81722

  • Reported component name

    WEBSPHERE APP S

  • Reported component ID

    5724J0800

  • Reported release

    850

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2017-05-17

  • Closed date

    2017-06-05

  • Last modified date

    2017-06-05

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    WEBSPHERE APP S

  • Fixed component ID

    5724J0800

Applicable component levels

  • R800 PSY

       UP

  • R850 PSY

       UP

  • R900 PSY

       UP

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSEQTP","label":"WebSphere Application Server"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"8.5","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
04 May 2022