|
Info from IBM that a customer got:
-APAR MA48442 (“OSP-OTHER-UNPRED SYSTEM TLS FAILS TLSV1.2 SERVER HELLO
WITHOUT EXTENSION DATA LENGTH”)
-Update a few PTF Groups to current levels
-Apply PTF MF67593, which isn’t in any PTF Group.
So it does seem to be an IBM issue that has already been (hopefully)
fixed. I will know for sure after the weekend.
I tried searching for PTFs but that seems futile these days... unless I'm
just not understanding how their newer searches work...lol.
On Thu, Oct 1, 2020 at 10:07 AM Brad Stone <bvstone@xxxxxxxxx> wrote:
Hi, Jeff.an
I haven't seen any issues with Google, no. I just am wondering if it's
issue with only certain endpoints. It's hard to tell. I am hoping tohear
from one customer to see what IBM tells them.the
On Thu, Oct 1, 2020 at 9:36 AM Jeff Crosby <jlcrosby@xxxxxxxxxxxxxxxx>
wrote:
Is this 7.3? Would this possibly affect my using G4G uploading PDFs?
Asking because I'm set to IPL and apply some PTF groups tomorrow night.
Thanks.
On Thu, Oct 1, 2020 at 10:23 AM Brad Stone <bvstone@xxxxxxxxx> wrote:
I have a few customers that seem to be reporting an issue with the IBMSSL
APIs after applying a recent PTF group when using GETURI (HTTPAPI alsotrace
reports the same issues) communicating with a web service.
Also from tests using cURL and PHP on the IBM i the error cannot be
reproduced, neither can it on the PC using Postman, etc.
Randomly they are receiving the error:
415 - Peer not recognized or badly formatted message received.
If the standard SSL APIs are used RC is normally -16 if I recall.
One customer was able to work with a trading partner and they did a
on their end and tracked it down to the "Hello" communications from
upIBM
i during SSL negotiation.are
What they saw and explained was something like this:
"...When everything is working fine we have noticed the server hellos
super small …376 bytes which is an indication of TLS session reuse.Then
there is an attempt to do TLS reuse with a different proxy or backendTLS
server and it fails which is likely this TLS FATAL illegal parameter
error. The NEXT server hello is much larger, 3586 bytes, because the
session is trashed and has to start over.
It then works for a while with the little server hello's doing session
reuse ... until a proxy or backend server gets switched and it blows
yearsand
starts all over..."what
So, when this error is reported on the IBM i seems to correlate with
they see on their end where the TLS session is "trashed".
My suspicion is that a recent PTF broke this, since it worked for
mailingpreviously and after the PTFs this behavior started.this
I have the customer contacting IBM to see when they can find with all
information, but I am just curious if anyone else is experiencing thisCloud
issue and what they have found.
Thanks.
Bradley V. Stone
www.bvstools.com
Native IBM i e-Mail solutions for Microsoft Office 365, Gmail, or any
Provider!
--
This is the Web Enabling the IBM i (AS/400 and iSeries) (WEB400)
--list
To post a message email: WEB400@xxxxxxxxxxxxxxxxxx
To subscribe, unsubscribe, or change list options,
visit: https://lists.midrange.com/mailman/listinfo/web400
or email: WEB400-request@xxxxxxxxxxxxxxxxxx
Before posting, please take a moment to review the archives
at https://archive.midrange.com/web400.
--
Jeff Crosby
VP Information Systems
UniPro FoodService/Dilgard
P.O. Box 13369
Ft. Wayne, IN 46868-3369
260-422-7531
direct.dilgardfoods.com
The opinions expressed are my own and not necessarily the opinion of my
company. Unless I say so.
--
This is the Web Enabling the IBM i (AS/400 and iSeries) (WEB400) mailing
list
To post a message email: WEB400@xxxxxxxxxxxxxxxxxx
To subscribe, unsubscribe, or change list options,
visit: https://lists.midrange.com/mailman/listinfo/web400
or email: WEB400-request@xxxxxxxxxxxxxxxxxx
Before posting, please take a moment to review the archives
at https://archive.midrange.com/web400.
This is the Web Enabling the IBM i (AS/400 and iSeries) (WEB400) mailing
list
To post a message email: WEB400@xxxxxxxxxxxxxxxxxx
To subscribe, unsubscribe, or change list options,
visit: https://lists.midrange.com/mailman/listinfo/web400
or email: WEB400-request@xxxxxxxxxxxxxxxxxx
Before posting, please take a moment to review the archives
at https://archive.midrange.com/web400.
As an Amazon Associate we earn from qualifying purchases.
This mailing list archive is Copyright 1997-2024 by midrange.com and David Gibbs as a compilation work. Use of the archive is restricted to research of a business or technical nature. Any other uses are prohibited. Full details are available on our policy page. If you have questions about this, please contact [javascript protected email address].
Operating expenses for this site are earned using the Amazon Associate program and Google Adsense.