DB2 - Problem description
Problem IT19627 | Status: Closed |
LDAP PLUGIN NOW ALLOWS SIGNATURE ALGORITHMS TO BE SPECIFIED WHENUSING TLS 1.2 | |
product: | |
DB2 FOR LUW / DB2FORLUW / A50 - DB2 | |
Problem description: | |
When using TLS 1.2, the client should provide a list of the signature algorithms that it supports, otherwise the Server assumes that only RSA+SHA1 are supported. This is a problem with some LDAP Servers (eg. Active Directory) because they require that all certificates be signed with SHA2 or better. This APAR adds the SSL_EXTN_SIGALG keyword to the IBMLDAPSecurity.ini. It can take the following values: GSK_TLS_SIGALG_RSA_WITH_SHA224 GSK_TLS_SIGALG_RSA_WITH_SHA256 GSK_TLS_SIGALG_RSA_WITH_SHA384 GSK_TLS_SIGALG_RSA_WITH_SHA512 GSK_TLS_SIGALG_ECDSA_WITH_SHA224 GSK_TLS_SIGALG_ECDSA_WITH_SHA256 GSK_TLS_SIGALG_ECDSA_WITH_SHA384 GSK_TLS_SIGALG_ECDSA_WITH_SHA512 Multiple algorithms can be specified, separated by commas. | |
Problem Summary: | |
**************************************************************** * USERS AFFECTED: * * ALL * **************************************************************** * PROBLEM DESCRIPTION: * * See Error Description * **************************************************************** * RECOMMENDATION: * * Upgrade to Db2 10.5 Fix Pack 9 or higher * **************************************************************** | |
Local Fix: | |
Solution | |
First fixed in Db2 10.5 Fix Pack 9 | |
Workaround | |
not known / see Local fix | |
Timestamps | |
Date - problem reported : Date - problem closed : Date - last modified : | 09.03.2017 29.09.2017 29.09.2017 |
Problem solved at the following versions (IBM BugInfos) | |
9.0. | |
Problem solved according to the fixlist(s) of the following version(s) |