Central note for WS Security on 7.10
[7.10] [nero7.10.1.0] [ubuntu 7.10] [ws security]
- DB2-z/OS: DDIC problems with Basis Release 7.10Symptom The following symptoms are observed: Table PRTTEST cannot be created or altered in unicode systems. The procedure fails with SQLCODE -670.Runtime error PERFORM_NOT_FOUND. The form SPECIAL_TOLERANCE is missing in report SDB8FDB2.Partitioning...
- ICM patch collection (7.10)Symptom Internet Communication Manager (ICM) 7.10 contains errors. Other terms icm, icman, sapwebdisp, HTTP, SMTP, Internet, HTTP request, 0d0a, \r\n, OOB, x-forwarded-for, ClientProtocol, watchdog, GET, POST, HEAD, PUT, SSL, dev_icm, dev_webdisp, soft...
Symptom
This notes describes issues related to security processing for Web service messages.
Reason and Prerequisites
With 710 SP6 or lower:
You receive error message: CX_SY_MESSAGE_IN_PLUGIN_MODE:Message E 1S 110You receive canonicalization errors.
With 710 SP8 or lower:
You are using ESR services generated with 6.40 or 7.00 < SP14 and have issues with authorization checks. Due to changed services names, existing roles using older service names may not be correct. Corrected per note.
With 7.10 SP1-SP8:
You are using ESR services generated with 6.40 or 7.00 < SP14 and have issues with authorization checks. Due to changed services names, existing roles using old service names may not be correct. Corrected per note.
With 7.10 SP1-SP9:
You are using SAML authentication and authentication fails as the SAML assertion is sent in the default namespace (i.e.
Solution
The following issues have been corrected:
ABAP Kernel 710_REL
T22 Short Dump: SYSTEM_CORE_DUMPED in CL_SXML_READER
Error in XML canonicalization
Fixed in Patch Level #114
Error in XML canonicalization for non-ASCII characters Fixed in Patch Level #116
SAML Assertion in default namespace
Fixed in Patch Level #150
WS Security implementation (ABAP)
7.10 SP7:
Incorrect parameters to to crypto api causes error message CX_SY_MESSAGE_IN_PLUGIN_MODE:Message E 1S 110. Please use correction attached to this note to solve the issue.
7.10 SP8:
Added a backward compatible authorization check for older ESR services. Either upgrade to SP2, or implement the correction attached to this note.