Fixes are available
8.0.0.4: WebSphere Application Server V8.0 Fix Pack 4
8.5.0.1: WebSphere Application Server V8.5 Fix Pack 1
8.0.0.5: WebSphere Application Server V8.0 Fix Pack 5
8.5.0.2: WebSphere Application Server V8.5 Fix Pack 2
8.0.0.6: WebSphere Application Server V8.0 Fix Pack 6
8.0.0.7: WebSphere Application Server V8.0 Fix Pack 7
8.0.0.8: WebSphere Application Server V8.0 Fix Pack 8
8.0.0.9: WebSphere Application Server V8.0 Fix Pack 9
8.0.0.10: WebSphere Application Server V8.0 Fix Pack 10
8.0.0.11: WebSphere Application Server V8.0 Fix Pack 11
8.0.0.12: WebSphere Application Server V8.0 Fix Pack 12
8.0.0.13: WebSphere Application Server V8.0 Fix Pack 13
8.0.0.14: WebSphere Application Server V8.0 Fix Pack 14
8.0.0.15: WebSphere Application Server V8.0 Fix Pack 15
APAR status
Closed as program error.
Error description
After migrating one the V6.1 DMGR and one (of several) V6.1 nodes to V8, the adminconsole shows unexpected values for migrated SSL Repertoire Cipher suites. In adminconsole: SSL certificate and key management > SSL configurations > {some migrated SSL repertoire} > Quality of protection (QoP) settings displays the following error instead of a cipher list; [ServletException in:/com.ibm.ws.console.security/cipherAddDeleteLayout. jsp] Define tag cannot set a null value' . Also, after the SSL Repertoire's JSSE Provider is set to "Customer JSSE Provider". JSSE SSL repertoires created after migration to V8 don't have the cipher list problem.
Local fix
Problem summary
**************************************************************** * USERS AFFECTED: All users of IBM WebSphere Application * * Server V8.0 and V8.5 * **************************************************************** * PROBLEM DESCRIPTION: Cipher Suites list panel might display * * a blank page * **************************************************************** * RECOMMENDATION: * **************************************************************** To have a list of supported cipher suites, WAS security code invokes ListSSLCiphers mbean call. While processing this request, the security code instanciates SSLSocketFactory call by using specified SSL alias name. In here, if either server certificate alias or client certificate alias is set as an attribute, and if spedified alias name doesn't exist in a keystore. SSLSocketFactory cannot be instanciated. As a result, ListSSLCiphers call returns null. Then, webui code fails to initialize the form data for the jsp.
Problem conclusion
With this fix, the code is modified to ignore certificate alias names which do not affect cipher suite setting to avoid the error. APAR PM60579 is currently targeted for inclusion in Fix Packs 8.0.0.4 and 8.5.0.1 of WebSphere Application Server. Please refer to the Recommended Updates page for delivery information: http://www.ibm.com/support/docview.wss?rs=180&uid=swg27004980 In addition, please refer to URL: http://www.ibm.com/support/docview.wss?rs=404&uid=swg27006970 for Fix Pack PTF information.
Temporary fix
Comments
APAR Information
APAR number
PM60579
Reported component name
WEBSPHERE FOR Z
Reported component ID
5655I3500
Reported release
800
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt
Submitted date
2012-03-16
Closed date
2012-05-08
Last modified date
2012-10-16
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
WEBSPHERE FOR Z
Fixed component ID
5655I3500
Applicable component levels
R800 PSY
UP
Document Information
Modified date:
28 October 2021