IBM Support

PK73552: PROBLEMS WITH NODE SYNCHRONIZATION AFTER LTPA KEYS ARE GENERATED VIA SCRIPT.

Fixes are available

7.0.0.5: WebSphere Application Server V7.0 Fix Pack 5 for AIX
7.0.0.5: WebSphere Application Server V7.0 Fix Pack 5 for IBM i
7.0.0.5: WebSphere Application Server V7.0 Fix Pack 5 for Windows
7.0.0.5: WebSphere Application Server V7.0 Fix Pack 5 for HP-UX
7.0.0.5: Java SDK 1.6 SR5 Cumulative Fix for WebSphere Application Server
7.0.0.5: WebSphere Application Server V7.0 Fix Pack 5 for Solaris
7.0.0.5: WebSphere Application Server V7.0 Fix Pack 5 for Linux
Java SDK 1.5 SR10 Cumulative Fix for WebSphere Application Server
7.0.0.7: WebSphere Application Server V7.0 Fix Pack 7 for IBM i
7.0.0.7: WebSphere Application Server V7.0 Fix Pack 7 for AIX
7.0.0.7: WebSphere Application Server V7.0 Fix Pack 7 for Windows
7.0.0.7: WebSphere Application Server V7.0 Fix Pack 7 for HP-UX
7.0.0.7: Java SDK 1.6 SR6 Cumulative Fix for WebSphere Application Server
7.0.0.7: WebSphere Application Server V7.0 Fix Pack 7 for Solaris
7.0.0.7: WebSphere Application Server V7.0 Fix Pack 7 for Linux
7.0.0.9: WebSphere Application Server V7.0 Fix Pack 9 for IBM i
7.0.0.9: WebSphere Application Server V7.0 Fix Pack 9 for Windows
7.0.0.9: WebSphere Application Server V7.0 Fix Pack 9 for AIX
7.0.0.9: WebSphere Application Server V7.0 Fix Pack 9 for HP-UX
7.0.0.9: Java SDK 1.6 SR7 Cumulative Fix for WebSphere Application Server
7.0.0.9: WebSphere Application Server V7.0 Fix Pack 9 for Solaris
7.0.0.9: WebSphere Application Server V7.0 Fix Pack 9 for Linux
6.1.0.31: Java SDK 1.5 SR11 FP1 Cumulative Fix for WebSphere Application Server
7.0.0.11: WebSphere Application Server V7.0 Fix Pack 11 for IBM i
7.0.0.11: WebSphere Application Server V7.0 Fix Pack 11 for Windows
7.0.0.11: WebSphere Application Server V7.0 Fix Pack 11 for HP-UX
7.0.0.11: WebSphere Application Server V7.0 Fix Pack 11 for AIX
7.0.0.11: Java SDK 1.6 SR7 Cumulative Fix for WebSphere Application Server
7.0.0.11: WebSphere Application Server V7.0 Fix Pack 11 for Solaris
7.0.0.11: WebSphere Application Server V7.0 Fix Pack 11 for Linux
6.1.0.33: Java SDK 1.5 SR12 FP1 Cumulative Fix for WebSphere
6.1.0.29: Java SDK 1.5 SR11 Cumulative Fix for WebSphere Application Server
7.0.0.13: WebSphere Application Server V7.0 Fix Pack 13 for AIX
7.0.0.13: WebSphere Application Server V7.0 Fix Pack 13 for HP-UX
7.0.0.13: WebSphere Application Server V7.0 Fix Pack 13 for IBM i
7.0.0.13: WebSphere Application Server V7.0 Fix Pack 13 for Linux
7.0.0.13: WebSphere Application Server V7.0 Fix Pack 13 for Solaris
7.0.0.13: WebSphere Application Server V7.0 Fix Pack 13 for Windows
7.0.0.13: Java SDK 1.6 SR8FP1 Cumulative Fix for WebSphere Application Server
6.1.0.35: Java SDK 1.5 SR12 FP2 Cumulative Fix for WebSphere
7.0.0.15: WebSphere Application Server V7.0 Fix Pack 15 for AIX
7.0.0.15: Java SDK 1.6 SR9 Cumulative Fix for WebSphere Application Server
7.0.0.15: WebSphere Application Server V7.0 Fix Pack 15 for HP-UX
7.0.0.15: WebSphere Application Server V7.0 Fix Pack 15 for IBM i
7.0.0.15: WebSphere Application Server V7.0 Fix Pack 15 for Linux
7.0.0.15: WebSphere Application Server V7.0 Fix Pack 15 for Solaris
7.0.0.15: WebSphere Application Server V7.0 Fix Pack 15 for Windows
6.1.0.37: Java SDK 1.5 SR12 FP3 Cumulative Fix for WebSphere
7.0.0.17: WebSphere Application Server V7.0 Fix Pack 17
7.0.0.17: Java SDK 1.6 SR9 FP1 Cumulative Fix for WebSphere Application Server
6.1.0.39: Java SDK 1.5 SR12 FP4 Cumulative Fix for WebSphere Application Server
7.0.0.19: WebSphere Application Server V7.0 Fix Pack 19
6.1.0.41: Java SDK 1.5 SR12 FP5 Cumulative Fix for WebSphere Application Server
7.0.0.21: WebSphere Application Server V7.0 Fix Pack 21
6.1.0.43: Java SDK 1.5 SR13 Cumulative Fix for WebSphere Application Server
7.0.0.23: WebSphere Application Server V7.0 Fix Pack 23
7.0.0.25: WebSphere Application Server V7.0 Fix Pack 25
6.1.0.45: Java SDK 1.5 SR14 Cumulative Fix for WebSphere Application Server
7.0.0.27: WebSphere Application Server V7.0 Fix Pack 27
7.0.0.29: WebSphere Application Server V7.0 Fix Pack 29
6.1.0.47: WebSphere Application Server V6.1 Fix Pack 47
7.0.0.31: WebSphere Application Server V7.0 Fix Pack 31
7.0.0.27: Java SDK 1.6 SR13 FP2 Cumulative Fix for WebSphere Application Server
7.0.0.33: WebSphere Application Server V7.0 Fix Pack 33
7.0.0.35: WebSphere Application Server V7.0 Fix Pack 35
6.1.0.47: Java SDK 1.5 SR16 Cumulative Fix for WebSphere Application Server
7.0.0.19: Java SDK 1.6 SR9 FP2 Cumulative Fix for WebSphere Application Server
7.0.0.21: Java SDK 1.6 SR9 FP2 Cumulative Fix for WebSphere
7.0.0.23: Java SDK 1.6 SR10 FP1 Cumulative Fix for WebSphere
7.0.0.25: Java SDK 1.6 SR11 Cumulative Fix for WebSphere Application Server
7.0.0.27: Java SDK 1.6 SR12 Cumulative Fix for WebSphere Application Server
7.0.0.29: Java SDK 1.6 SR13 FP2 Cumulative Fix for WebSphere Application Server
7.0.0.45: Java SDK 1.6 SR16 FP60 Cumulative Fix for WebSphere Application Server
7.0.0.31: Java SDK 1.6 SR15 Cumulative Fix for WebSphere Application Server
7.0.0.35: Java SDK 1.6 SR16 FP1 Cumulative Fix for WebSphere Application Server
7.0.0.37: Java SDK 1.6 SR16 FP3 Cumulative Fix for WebSphere Application Server
7.0.0.39: Java SDK 1.6 SR16 FP7 Cumulative Fix for WebSphere Application Server
7.0.0.41: Java SDK 1.6 SR16 FP20 Cumulative Fix for WebSphere Application Server
7.0.0.43: Java SDK 1.6 SR16 FP41 Cumulative Fix for WebSphere Application Server

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • Problems with node synchronization after LTPA keys are generated
    via script.
    

Local fix

  • Disabling the dynamic ssl update function.
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED:  All users of WebSphere Application          *
    *                  Server's $AdminTask                         *
    *                  generateKeyForKeySetGroup command           *
    ****************************************************************
    * PROBLEM DESCRIPTION: When generating LTPA keys manually      *
    *                      with the wsadmin command using the      *
    *                      $AdminTask generateKeyForKeySetGroup    *
    *                      command, customers may experience       *
    *                      synchronization errors when             *
    *                      attempting to synchronize a             *
    *                      running cell with Dynamic SSL Update    *
    *                      enabled.                                *
    *                      The failing sequence of commands look   *
    *                      similar to the following:               *
    *                                                              *
    *                      wsadmin>$AdminTask                      *
    *                      generateKeyForKeySetGroup               *
    *                      {-keySetGroupName CellLTPAKeySetGroup}  *
    *                      wsadmin>$AdminConfig save               *
    *                      wsadmin>set sync [$AdminControl         *
    *                      completeObjectName type=NodeSync,*]     *
    *                      wsadmin>$AdminControl invoke $sync sync *
    *                                                              *
    *                      executing these commands may result     *
    *                      in a "false" result being returned      *
    *                      (meaning the cell failed to             *
    *                      synchronize), or this error:            *
    *                                                              *
    *                      WASX7017E: Exception received while     *
    *                      running file "xxxxx"; exception         *
    *                      information:                            *
    *                      javax.management.JMRuntimeException:    *
    *                      A                                       *
    *                      DMN0022E: Access is denied for the      *
    *                      sync operation on NodeSync MBean        *
    *                      because of insufficient or empty        *
    *                      credentials.                            *
    *                                                              *
    *                      FFDC logs may show something similar    *
    *                      to the following:                       *
    *                                                              *
    *                      Stack Dump =                            *
    *                      com.ibm.websphere.security.auth.WSLogin *
    *                      FailedException: Validation of LTPA     *
    *                      token failed due to invalid keys or     *
    *                      token type.                             *
    *                       at                                     *
    *                      com.ibm.ws.security.ltpa.LTPAServerObje *
    *                      ct.validateToken(LTPAServerObject.java: *
    *                      942)                                    *
    *                       at                                     *
    *                      com.ibm.ws.security.token.WSCredentialT *
    *                      okenMapper.validateLTPAToken(WSCredenti *
    *                      alTokenMapper.java:1300)                *
    *                       at                                     *
    *                      com.ibm.ws.security.auth.ContextManager *
    *                      Impl.getOpaqueTokenFromCacheOrOriginati *
    *                      ngServer(ContextManagerImpl.java:1324)  *
    *                       at                                     *
    *                      com.ibm.ws.security.auth.ContextManager *
    *                      Impl.login(ContextManagerImpl.java:2796 *
    *                      )                                       *
    *                       at                                     *
    *                      com.ibm.ws.security.auth.ContextManager *
    *                      Impl.login(ContextManagerImpl.java:2735 *
    *                      )                                       *
    *                       at                                     *
    *                      com.ibm.ws.security.web.WebAuthenticato *
    *                      r.validate(WebAuthenticator.java:1627)  *
    *                       at                                     *
    *                      com.ibm.ws.security.web.WebAuthenticato *
    *                      r.validateCookie(WebAuthenticator.java: *
    *                      598)                                    *
    *                       at                                     *
    *                      com.ibm.ws.security.web.WebAuthenticato *
    *                      r.handleSSO(WebAuthenticator.java:519)  *
    *                       at                                     *
    *                      com.ibm.ws.security.web.WebAuthenticato *
    *                      r.authenticate(WebAuthenticator.java:14 *
    *                      22)                                     *
    *                       at                                     *
    *                      com.ibm.ws.security.web.WebCollaborator *
    *                      .authorize(WebCollaborator.java:657)    *
    *                       at                                     *
    *                      com.ibm.ws.security.web.EJSWebCollabora *
    *                      tor.preInvoke(EJSWebCollaborator.java:3 *
    *                      18)                                     *
    *                                                              *
    *                                                              *
    *                                                              *
    *                                                              *
    *                                                              *
    *                                                              *
    *                                                              *
    *                                                              *
    *                                                              *
    *                                                              *
    ****************************************************************
    * RECOMMENDATION:                                              *
    ****************************************************************
    WebSphere Application Server was failing to properly refresh
    the runtime LTPA keys.
    

Problem conclusion

  • WebSphere Application Server has been modified to properly
    refresh the runtime LTPA keys during a dynamic SSL update.
    In addition, refreshing the runtime LTPA keys using this
    sequence of commands requires the -keySetGroupUpdateRuntime
    flag, with a setting of true, to be passed as an option to the
    $AdminTask generateKeyForKeySetGroup command task. This option
    is not currently documented. An example wsadmin command
    task looks like this:
    
    $AdminTask generateKeyForKeySetGroup {-keySetGroupName
    CellLTPAKeySetGroup -keySetGroupUpdateRuntime true}
    
    The fix for this APAR is currently targeted for inclusion in
    fixpack 6.1.0.25 and 7.0.0.5.  Please refer to the Recommended
    Updates page for delivery information:
    http://www.ibm.com/support/docview.wss?rs=180&uid=swg27004980
    

Temporary fix

Comments

APAR Information

  • APAR number

    PK73552

  • Reported component name

    WEBS APP SERV N

  • Reported component ID

    5724H8800

  • Reported release

    61A

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt

  • Submitted date

    2008-10-09

  • Closed date

    2009-03-02

  • Last modified date

    2009-03-02

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    WEBS APP SERV N

  • Fixed component ID

    5724H8800

Applicable component levels

  • R61A PSY

       UP

  • R61H PSY

       UP

  • R61I PSY

       UP

  • R61S PSY

       UP

  • R61W PSY

       UP

  • R61Z PSY

       UP

  • R700 PSY

       UP

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSEQTP","label":"WebSphere Application Server"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"6.1","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
29 December 2021