PEPM81589 PTF-SUPPLIED MODULES BUILT INCORRECTLY


 
 APAR Identifier ...... PM86100      Last Changed ........ 14/06/17
 PEPM81589 PTF-SUPPLIED MODULES BUILT INCORRECTLY
 
 Symptom ...... PF INCORROUT         Status ........... CLOSED  PER
 Severity ................... 2      Date Closed ......... 13/04/10
 Component .......... 5735FAL00      Duplicate of ........
 Reported Release ......... 620      Fixed Release ............ 999
 Component Name TCP/IP V2 FOR V      Special Notice    PE     HIPER
 Current Target Date ..              Flags
 SCP ...................               FUNCTIONLOSS
 Platform ............                 PERVASIVE
 
 Status Detail: SHIPMENT - Packaged solution is available for
                           shipment.
 
 PE PTF List:    UK91316
 
 PTF List:
 Release 620   : UK93324 available 13/12/30 (1302 )
 
 Parent APAR:
 Child APAR list:
 
 ERROR DESCRIPTION:
 After application of PTF UK91316, customer reports that an
 existing, FIPS-compliant key database cannot be opened using
 the 'gskkyman' command.  An attempt to do so results in the
 error messages that follow:
 
  Unable to open /etc/gskadm/Database.kdb.
  Status 0x03353067 - Known Answer Test has failed.
 
 In addition, the SSL server in use, fails to initialize with
 this error reported:
 
   DTCSSL206E FIPS compliant mode cannot be established
 
 Initial diagnosis of this problem indicates that at least
 one of the MODULE files supplied by PTF UK91316 were not
 correctly built when the PTF was created.
 
 LOCAL FIX:
 None.
 
 PROBLEM SUMMARY:
 ****************************************************************
 * USERS AFFECTED: All users of SSL in FIPS mode.               *
 ****************************************************************
 * PROBLEM DESCRIPTION:                                         *
 ****************************************************************
 * RECOMMENDATION: APPLY PTF                                    *
 ****************************************************************
 Some PTF UK91316 modules were incorrectly built resulting in the
 inability to do FIPS mode operations. These include opening a
 FIPS mode database or initializing an SSL server in FIPS mode.
 
 PROBLEM CONCLUSION:
 A flaw in the PTF build process for the FIPS related SSL modules
 allowed them to sometimes be built incorrectly. This has been
 corrected.
 
 TEMPORARY FIX:
 *********
 * HIPER *
 *********
 
 COMMENTS:
 
 MODULES/MACROS:   GSKCMS31 GSKC31F
 
 SRLS:      NONE
 
 RTN CODES:
 
 CIRCUMVENTION:
 
 MESSAGE TO SUBMITTER: