IBM Support

PM40787: TRUST ASSOCIATION INTERCEPTOR (TAI) IS INVOKED WHEN IT SHOULD NOT BE

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • Trust Association Interceptor (TAI) is invoked for all
    incoming Web requests if TAI is configured.
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED:  All users of IBM WebSphere Application      *
    *                  Server who configured Trust Association     *
    *                  Interceptor (TAI)                           *
    ****************************************************************
    * PROBLEM DESCRIPTION: TAI is invoked on unprotected URI       *
    *                      by default when "Use available          *
    *                      authentication data when an             *
    *                      unprotected URI is accessed"            *
    ****************************************************************
    * RECOMMENDATION:                                              *
    ****************************************************************
    TAI is invoked on an unprotected URI
    by default when "Use available
    authentication data when an
    unprotected URI is accessed"
    

Problem conclusion

  • Code has been updated so that WebSphere Application
    Server invokes TAI appropriately.
    
    Following is the expected behavior for TAI invocation after
    applying this APAR:
    
    1. When protected URI is accessed, TAI is invoked.
    2  When unprotected URI is accessed,
    if  "Use available authentication data when an unprotected URI
    is accessed" is enabled, TAI is not invoked unless
    following custom proeprty is set to "true"
    "com.ibm.websphere.security.performTAIForUnprotectedURI"
    (More info about this custom property below)
    3 When unprotected URI is accessed,
    if "Use available authentication data when an unprotected URI
    is accessed" is unchecked, TAI is not invoked.
    
    The option "Use available authentication data when an
    unprotected URI is accessed" can be found at the
    Administration Console by going "Global security"
    > "Web security -
    General settings"
    
    Custom Property:
    "com.ibm.websphere.security.performTAIForUnprotectedURI"
    This property is used to specify TAI invocation behavior
    when "Use available authentication data when an unprotected
    URI is accessed".
    Value:
    "true" : TAI is invoked.
    "false": TAI is not invoked. This is default value
    
    To specify this custom property, from adminconsole
    "Global security" > "Custom properties" and select "New".
    
    WebSphere Application Server v6.1 and v7,  this custom
    property's default value is "true".  For v8, default value is
    "false".
    This is a behavior change to Application Server v8
    after applying this APAR.
    
    The fix for this APAR is currently targeted for inclusion in
    fix pack 8.0.0.1.  Please refer to the Recommended
    Updates page for delivery information:
    http://www.ibm.com/support/docview.wss?rs=180&uid=swg27004980
    

Temporary fix

  • Note to reviewer: Included Keys' comment.  Resubmitting.
    

Comments

APAR Information

  • APAR number

    PM40787

  • Reported component name

    WEBSPHERE APP S

  • Reported component ID

    5724J0800

  • Reported release

    800

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt

  • Submitted date

    2011-06-06

  • Closed date

    2011-06-23

  • Last modified date

    2011-08-18

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    WEBSPHERE APP S

  • Fixed component ID

    5724J0800

Applicable component levels

  • R800 PSY

       UP

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSEQTP","label":"WebSphere Application Server"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"8.0","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
27 October 2021