SAPCRYPTOLIB 555pl26: bugfixes and WS-Security update

[] [] [] [] [] [] [] [] [] [] [] []

  1. SAPCRYPTOLIB versions, bugs and fixesSymptom Problems with SAPCRYPTOLIB in one of the various usage scenarios, e.g.: SSL in SAP WebAS and Netweaver (icman, sapwebdisp) and for saphttp SSF with encryption (HR-ELSTER, Credit card encryption,…) SSF with...
  2. Central note for WS Security on 7.00Symptom This notes describes issues related to security processing for Web service messages. Reason and Prerequisites With 700: You receive error message: CX_SY_MESSAGE_IN_PLUGIN_MODE:Message E 1S 110You receive canonicalization errors.You are using ESR...

Symptom

SAPCRYPTOLIB bugfixes and WS-Security Update
The following covers changes for pl25 (SAP-internal only) plus pl26:
1. New: Additional functionality required by SAP WebServicesSecurity2. Fix for crash in SSL-Server (icman/sapwebdisp) when trying to use an SSL-Server certificate that has a keyUsage without digitalSignature.3. Fix for crash when processing certificates with empty structures in CertificatePolicy attributes.4. Fix for crash in ABAP transaction STRUST when trying to import to or to visualize from the certificate list an X.509 certificate with an unsupported signature algorithm (such as sha256WithRSASignature).5. New: Support for certificate validity dates beyond year 2038.6. Fix for SSL-Server to announce also X.509v1 CA certificates from the certificate list (PKList) of the SSL Server PSE in the SSL handshake (the original change in pl18 was incomplete).7. Change: the CA Certificate of the SAP Workplace CA was updated with a longer validity, the original CA cert is going to expire 31-Jan-2010.Other terms

SAPCRYPTOLIB, SSL, SSF, STRUST, PSE, Certificate, sapgenpse, X.509

Solution

Download and install the latest SAPCRYPTOLIB (Version >=5.5.5pl26) through SAP Service Marketplace.
See related note 455033 about the most recent Version of SAPCRYPTOLIB and some more details how to obtain it.

[Slashdot] [Digg] [Reddit] [del.icio.us] [Facebook] [Technorati] [Google] [StumbleUpon]

Leave a Comment