Fixes are available
8.0.0.1: WebSphere Application Server V8.0 Fix Pack 1
8.0.0.2: WebSphere Application Server V8.0 Fix Pack 2
8.0.0.3: WebSphere Application Server V8.0 Fix Pack 3
8.0.0.4: WebSphere Application Server V8.0 Fix Pack 4
8.0.0.5: WebSphere Application Server V8.0 Fix Pack 5
8.0.0.6: WebSphere Application Server V8.0 Fix Pack 6
8.0.0.7: WebSphere Application Server V8.0 Fix Pack 7
8.0.0.8: WebSphere Application Server V8.0 Fix Pack 8
8.0.0.9: WebSphere Application Server V8.0 Fix Pack 9
8.0.0.10: WebSphere Application Server V8.0 Fix Pack 10
8.0.0.11: WebSphere Application Server V8.0 Fix Pack 11
8.0.0.12: WebSphere Application Server V8.0 Fix Pack 12
8.0.0.13: WebSphere Application Server V8.0 Fix Pack 13
8.0.0.14: WebSphere Application Server V8.0 Fix Pack 14
8.0.0.15: WebSphere Application Server V8.0 Fix Pack 15
APAR status
Closed as program error.
Error description
Trust Association Interceptor (TAI) is invoked for all incoming Web requests if TAI is configured.
Local fix
Problem summary
**************************************************************** * USERS AFFECTED: All users of IBM WebSphere Application * * Server who configured Trust Association * * Interceptor (TAI) * **************************************************************** * PROBLEM DESCRIPTION: TAI is invoked on unprotected URI * * by default when "Use available * * authentication data when an * * unprotected URI is accessed" * **************************************************************** * RECOMMENDATION: * **************************************************************** TAI is invoked on an unprotected URI by default when "Use available authentication data when an unprotected URI is accessed"
Problem conclusion
Code has been updated so that WebSphere Application Server invokes TAI appropriately. Following is the expected behavior for TAI invocation after applying this APAR: 1. When protected URI is accessed, TAI is invoked. 2 When unprotected URI is accessed, if "Use available authentication data when an unprotected URI is accessed" is enabled, TAI is not invoked unless following custom proeprty is set to "true" "com.ibm.websphere.security.performTAIForUnprotectedURI" (More info about this custom property below) 3 When unprotected URI is accessed, if "Use available authentication data when an unprotected URI is accessed" is unchecked, TAI is not invoked. The option "Use available authentication data when an unprotected URI is accessed" can be found at the Administration Console by going "Global security" > "Web security - General settings" Custom Property: "com.ibm.websphere.security.performTAIForUnprotectedURI" This property is used to specify TAI invocation behavior when "Use available authentication data when an unprotected URI is accessed". Value: "true" : TAI is invoked. "false": TAI is not invoked. This is default value To specify this custom property, from adminconsole "Global security" > "Custom properties" and select "New". WebSphere Application Server v6.1 and v7, this custom property's default value is "true". For v8, default value is "false". This is a behavior change to Application Server v8 after applying this APAR. The fix for this APAR is currently targeted for inclusion in fix pack 8.0.0.1. Please refer to the Recommended Updates page for delivery information: http://www.ibm.com/support/docview.wss?rs=180&uid=swg27004980
Temporary fix
Note to reviewer: Included Keys' comment. Resubmitting.
Comments
APAR Information
APAR number
PM40787
Reported component name
WEBSPHERE APP S
Reported component ID
5724J0800
Reported release
800
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt
Submitted date
2011-06-06
Closed date
2011-06-23
Last modified date
2011-08-18
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
WEBSPHERE APP S
Fixed component ID
5724J0800
Applicable component levels
R800 PSY
UP
Document Information
Modified date:
27 October 2021