|
Well, my client had a call with IBM.
IBM had them change the system value QSSLPCL from *OPSYS to a list:
*TLSV1.2
*TLSV1.1
*TLSV1
And that seemed to fix their specific issue. Doesn't make sense (well, it
does). I have a feeling their trading partner was using older version of
TLS. That should have been easy to tell. Seems like a bandaid fix.
On Tue, Oct 6, 2020 at 10:09 AM Gerald Magnuson <
gmagqcy.midrange@xxxxxxxxx>
wrote:
Sorry, I should clarify , we use HTTPAPI here.if
On Tue, Oct 6, 2020 at 9:40 AM Brad Stone <bvstone@xxxxxxxxx> wrote:
I'd sure love to be able to test it, though. Then I could figure out
Ihave a
needed to just retry the handshake, or if I need to totally restart theeither
connection. But the trace from the customer did show that the SSL
handshake wasn't working properly...
On Tue, Oct 6, 2020 at 9:20 AM Charles Wilt <charles.wilt@xxxxxxxxx>
wrote:
I'd agree that there should be a number of retries.
Charles
On Tue, Oct 6, 2020 at 7:05 AM Brad Stone <bvstone@xxxxxxxxx> wrote:
Thanks for following up. I haven't heard from my customers yet
(which I normally take as a good thing).
I wonder if in our applications if a handshake fails we should
solveswrote:issuedefault number of retries. The only issue is I can't recreate the
on
my end to test with.gmagqcy.midrange@xxxxxxxxx
On Tue, Oct 6, 2020 at 7:59 AM Gerald Magnuson <
wrote:
The PTF (MF67570) didn't fix it.
On Mon, Oct 5, 2020 at 1:48 PM Brad Stone <bvstone@xxxxxxxxx>
Keep up updated on your issues and if the PTF IBM suggest
havethe
recognized...issue.
gmagqcy.midrange@xxxxxxxxx
On Mon, Oct 5, 2020 at 1:43 PM Gerald Magnuson <
wrote:
Also, not only are we getting the TLSv1.2 Peer not
errors
when connecting to our internal servers (HAProxy), were
notVANsbeen
getting that -16 error when we try to connect to one of our
weAfter(COVISINT).gmagqcy.midrange@xxxxxxxxx
On Mon, Oct 5, 2020 at 1:22 PM Gerald Magnuson <
wrote:
We have had these errors since we went to 7.4 on Labor Day.
changing ciphers and putting on all the latest PTF groups,
now
have
this very strange symptom: these errors "(GSKit) Peer
bvstone@xxxxxxxxxbetweenrecognized
or
badly formatted message received." are only happening
thelet's
frame).hours
of 6am through 10am (we may get 1 or 2 outside of this time
I have just installed that ptf (MF67593 - 7.4 MF67570), so
see
what
tomorrow brings.
On Thu, Oct 1, 2020 at 4:07 PM Brad Stone <
work...lol.days...
SERVERwrote:
Info from IBM that a customer got:
-APAR MA48442 (“OSP-OTHER-UNPRED SYSTEM TLS FAILS TLSV1.2
HELLO(hopefully)
WITHOUT EXTENSION DATA LENGTH”)
-Update a few PTF Groups to current levels
-Apply PTF MF67593, which isn’t in any PTF Group.
So it does seem to be an IBM issue that has already been
fixed. I will know for sure after the weekend.
I tried searching for PTFs but that seems futile these
unless
I'm
just not understanding how their newer searches
Ibvstone@xxxxxxxxx
On Thu, Oct 1, 2020 at 10:07 AM Brad Stone <
wonderingwrote:
Hi, Jeff.
I haven't seen any issues with Google, no. I just am
if
it's
an
issue with only certain endpoints. It's hard to tell.
amthe
issueuploadinghoping
to
jlcrosby@xxxxxxxxxxxxxxxxhear
from one customer to see what IBM tells them.
On Thu, Oct 1, 2020 at 9:36 AM Jeff Crosby <
wrote:
Is this 7.3? Would this possibly affect my using G4G
bvstone@xxxxxxxxx>tomorrowPDFs?
Asking because I'm set to IPL and apply some PTF groups
night.
Thanks.
On Thu, Oct 1, 2020 at 10:23 AM Brad Stone <
wrote:
I have a few customers that seem to be reporting an
GETURIwith
the
IBM
SSL
APIs after applying a recent PTF group when using
errorservice.(HTTPAPI
also
reports the same issues) communicating with a web
Also from tests using cURL and PHP on the IBM i the
etc.cannot
be
reproduced, neither can it on the PC using Postman,
if Ireceived.
Randomly they are receiving the error:
415 - Peer not recognized or badly formatted message
If the standard SSL APIs are used RC is normally -16
andrecall.
One customer was able to work with a trading partner
they
communicationsdid a
trace
on their end and tracked it down to the "Hello"
from
the
IBM
i during SSL negotiation.
What they saw and explained was something like this:
"...When everything is working fine we have noticed
switchedbytes,proxyserversession
hellos
are
super small …376 bytes which is an indication of TLS
reuse.
Then
there is an attempt to do TLS reuse with a different
orillegal
backend
server and it fails which is likely this TLS FATAL
parameter
error. The NEXT server hello is much larger, 3586
hello'sbecause
the
TLS
session is trashed and has to start over.
It then works for a while with the little server
doing
session
reuse ... until a proxy or backend server gets
itand"trashed".
it
correlateblows
up
and
starts all over..."
So, when this error is reported on the IBM i seems to
with
what
they see on their end where the TLS session is
My suspicion is that a recent PTF broke this, since
canworked
for
years
previously and after the PTFs this behavior started.
I have the customer contacting IBM to see when they
365,find
with
experiencingall
this
information, but I am just curious if anyone else is
this
issue and what they have found.
Thanks.
Bradley V. Stone
www.bvstools.com
Native IBM i e-Mail solutions for Microsoft Office
iSeries)Gmail,
or
any
Cloud
Provider!
--
This is the Web Enabling the IBM i (AS/400 and
thehttps://lists.midrange.com/mailman/listinfo/web400(WEB400)
mailing
list
To post a message email: WEB400@xxxxxxxxxxxxxxxxxx
To subscribe, unsubscribe, or change list options,
visit:
archivesor email: WEB400-request@xxxxxxxxxxxxxxxxxx
Before posting, please take a moment to review the
at https://archive.midrange.com/web400.
--
Jeff Crosby
VP Information Systems
UniPro FoodService/Dilgard
P.O. Box 13369
Ft. Wayne, IN 46868-3369
260-422-7531
direct.dilgardfoods.com
The opinions expressed are my own and not necessarily
archiveshttps://lists.midrange.com/mailman/listinfo/web400opinion
(WEB400)of
my
company. Unless I say so.
--
This is the Web Enabling the IBM i (AS/400 and iSeries)
mailing
list
To post a message email: WEB400@xxxxxxxxxxxxxxxxxx
To subscribe, unsubscribe, or change list options,
visit:
archivesor email: WEB400-request@xxxxxxxxxxxxxxxxxx
Before posting, please take a moment to review the
(WEB400)--at https://archive.midrange.com/web400.
This is the Web Enabling the IBM i (AS/400 and iSeries)
mailing
list
To post a message email: WEB400@xxxxxxxxxxxxxxxxxx
To subscribe, unsubscribe, or change list options,
visit: https://lists.midrange.com/mailman/listinfo/web400
or email: WEB400-request@xxxxxxxxxxxxxxxxxx
Before posting, please take a moment to review the
(WEB400)(WEB400)--at https://archive.midrange.com/web400.
This is the Web Enabling the IBM i (AS/400 and iSeries)
mailing
list--
To post a message email: WEB400@xxxxxxxxxxxxxxxxxx
To subscribe, unsubscribe, or change list options,
visit: https://lists.midrange.com/mailman/listinfo/web400
or email: WEB400-request@xxxxxxxxxxxxxxxxxx
Before posting, please take a moment to review the archives
at https://archive.midrange.com/web400.
This is the Web Enabling the IBM i (AS/400 and iSeries)
mailingmailingmailingmailingmailing
list--
To post a message email: WEB400@xxxxxxxxxxxxxxxxxx
To subscribe, unsubscribe, or change list options,
visit: https://lists.midrange.com/mailman/listinfo/web400
or email: WEB400-request@xxxxxxxxxxxxxxxxxx
Before posting, please take a moment to review the archives
at https://archive.midrange.com/web400.
This is the Web Enabling the IBM i (AS/400 and iSeries) (WEB400)
list--
To post a message email: WEB400@xxxxxxxxxxxxxxxxxx
To subscribe, unsubscribe, or change list options,
visit: https://lists.midrange.com/mailman/listinfo/web400
or email: WEB400-request@xxxxxxxxxxxxxxxxxx
Before posting, please take a moment to review the archives
at https://archive.midrange.com/web400.
This is the Web Enabling the IBM i (AS/400 and iSeries) (WEB400)
list--
To post a message email: WEB400@xxxxxxxxxxxxxxxxxx
To subscribe, unsubscribe, or change list options,
visit: https://lists.midrange.com/mailman/listinfo/web400
or email: WEB400-request@xxxxxxxxxxxxxxxxxx
Before posting, please take a moment to review the archives
at https://archive.midrange.com/web400.
This is the Web Enabling the IBM i (AS/400 and iSeries) (WEB400)
list--
To post a message email: WEB400@xxxxxxxxxxxxxxxxxx
To subscribe, unsubscribe, or change list options,
visit: https://lists.midrange.com/mailman/listinfo/web400
or email: WEB400-request@xxxxxxxxxxxxxxxxxx
Before posting, please take a moment to review the archives
at https://archive.midrange.com/web400.
This is the Web Enabling the IBM i (AS/400 and iSeries) (WEB400)
--list--
To post a message email: WEB400@xxxxxxxxxxxxxxxxxx
To subscribe, unsubscribe, or change list options,
visit: https://lists.midrange.com/mailman/listinfo/web400
or email: WEB400-request@xxxxxxxxxxxxxxxxxx
Before posting, please take a moment to review the archives
at https://archive.midrange.com/web400.
This is the Web Enabling the IBM i (AS/400 and iSeries) (WEB400) mailing
list
To post a message email: WEB400@xxxxxxxxxxxxxxxxxx
To subscribe, unsubscribe, or change list options,
visit: https://lists.midrange.com/mailman/listinfo/web400
or email: WEB400-request@xxxxxxxxxxxxxxxxxx
Before posting, please take a moment to review the archives
at https://archive.midrange.com/web400.
This is the Web Enabling the IBM i (AS/400 and iSeries) (WEB400) mailing
list
To post a message email: WEB400@xxxxxxxxxxxxxxxxxx
To subscribe, unsubscribe, or change list options,
visit: https://lists.midrange.com/mailman/listinfo/web400
or email: WEB400-request@xxxxxxxxxxxxxxxxxx
Before posting, please take a moment to review the archives
at https://archive.midrange.com/web400.
As an Amazon Associate we earn from qualifying purchases.
This mailing list archive is Copyright 1997-2024 by midrange.com and David Gibbs as a compilation work. Use of the archive is restricted to research of a business or technical nature. Any other uses are prohibited. Full details are available on our policy page. If you have questions about this, please contact [javascript protected email address].
Operating expenses for this site are earned using the Amazon Associate program and Google Adsense.