VOOZH about

URL: https://www.ibm.com/support/pages/apar/IJ51955

⇱ IJ51955: 8326643 - JDK SERVER DOES NOT SEND A DUMMY CHANGE_CIPHER_SPEC RECORD AFTER HELLORETRYREQUEST MESSAGE


IJ51955: 8326643 - JDK SERVER DOES NOT SEND A DUMMY CHANGE_CIPHER_SPEC RECORD AFTER HELLORETRYREQUEST MESSAGE

APAR status

  • Closed as program error.

Error description

  • Error Message: N/A
    .
    Stack Trace: N/A
    .
    

Local fix

Problem summary

  • JDK server does not send a dummy change_cipher_spec record after
    HelloRetryRequest message.
    According to RFC 8446 (Transport Layer Security (TLS) Protocol
    Version 1.3) Appendix D.4 (Middlebox Compatibility Mode), if the
    client sends a non-empty session ID in the ClientHello message,
    the server sends a dummy change_cipher_spec (CCS) record
    immediately after its first handshake message. This may either
    be after a ServerHello or a HelloRetryRequest.
    

Problem conclusion

Temporary fix

Comments

APAR Information

  • APAR number

    IJ51955

  • Reported component name

    SECURITY

  • Reported component ID

    620700125

  • Reported release

    270

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2024-08-03

  • Closed date

    2024-08-03

  • Last modified date

    2024-08-03

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    SECURITY

  • Fixed component ID

    620700125

Applicable component levels

[{"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Product":{"code":"SSNVBF","label":"Runtimes for Java Technology"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"270","Line of Business":{"code":"LOB08","label":"Cognitive Systems"}}]

Document Information

Modified date:
03 August 2024