Central note for WS Security on 7.10

[] [] [] []

  1. DB2-z/OS: DDIC problems with Basis Release 7.10Symptom The following symptoms are observed: Table PRTTEST cannot be created or altered in unicode systems. The procedure fails with SQLCODE -670.Runtime error PERFORM_NOT_FOUND. The form SPECIAL_TOLERANCE is missing in report SDB8FDB2.Partitioning...
  2. ICM patch collection (7.10)Symptom Internet Communication Manager (ICM) 7.10 contains errors. Other terms icm, icman, sapwebdisp, HTTP, SMTP, Internet, HTTP request, 0d0a, \r\n, OOB, x-forwarded-for, ClientProtocol, watchdog, GET, POST, HEAD, PUT, SSL, dev_icm, dev_webdisp, soft...

Symptom

This notes describes issues related to security processing for Web service messages.

Reason and Prerequisites

With 710 SP6 or lower:
You receive error message: CX_SY_MESSAGE_IN_PLUGIN_MODE:Message E 1S 110You receive canonicalization errors.
With 710 SP8 or lower:
You are using ESR services generated with 6.40 or 7.00 < SP14 and have issues with authorization checks. Due to changed services names, existing roles using older service names may not be correct. Corrected per note.
With 7.10 SP1-SP8:

You are using ESR services generated with 6.40 or 7.00 < SP14 and have issues with authorization checks. Due to changed services names, existing roles using old service names may not be correct. Corrected per note.
With 7.10 SP1-SP9:
You are using SAML authentication and authentication fails as the SAML assertion is sent in the default namespace (i.e. ). Corrected with Kernel Patchlevel 150.

Solution

The following issues have been corrected:
ABAP Kernel 710_REL
T22 Short Dump: SYSTEM_CORE_DUMPED in CL_SXML_READER
Error in XML canonicalization
Fixed in Patch Level #114
Error in XML canonicalization for non-ASCII characters Fixed in Patch Level #116
SAML Assertion in default namespace
Fixed in Patch Level #150
WS Security implementation (ABAP)
7.10 SP7:
Incorrect parameters to to crypto api causes error message CX_SY_MESSAGE_IN_PLUGIN_MODE:Message E 1S 110. Please use correction attached to this note to solve the issue.
7.10 SP8:
Added a backward compatible authorization check for older ESR services. Either upgrade to SP2, or implement the correction attached to this note.

[Slashdot] [Digg] [Reddit] [del.icio.us] [Facebook] [Technorati] [Google] [StumbleUpon]

Leave a Comment