APAR status
Closed as program error.
Error description
Error Message: java.security.ProviderException: Unsupported algorithm 1.2.840.113549.1.1.10 . Stack Trace: java.security.cert.CertificateParsingException: java.io.IOException: subject key, java.security.spec.InvalidKeySpecException: Inappropriate key specification: java.security.ProviderException: Unsupported algorithm 1.2.840.113549.1.1.10 at com.ibm.security.x509.X509CertInfo.<init>(X509CertInfo.java:248) at com.ibm.security.x509.X509CertImpl.parse(X509CertImpl.java:2754) at com.ibm.security.x509.X509CertImpl.<init>(X509CertImpl.java:235) at com.ibm.crypto.provider.X509Factory.engineGenerateCertificate(X5 09Factory.java:341) at java.security.cert.CertificateFactory.generateCertificate(Certif icateFactory.java:350) at com.ibm.crypto.provider.PKCS12KeyStoreOracle.a(PKCS12KeyStoreOra cle.java:490) at com.ibm.crypto.provider.PKCS12KeyStoreOracle.engineLoad(PKCS12Ke yStoreOracle.java:927) at java.security.KeyStore.load(KeyStore.java:1460) .
Local fix
Problem summary
Keystore/truststore loading fails for X.509 certs with RSASSA-PSS algorithm identifier (OID 1.2.840.113549.1.1.10) in SPKI
Problem conclusion
Binary affected - ibmpkcs.jar GIT Issue - #256 RTC - 154015 Build - 8.0 build_20260417-658 JVM to be delivered in - JDK 8 SR8FP70 . This APAR will be fixed in the following Releases: . IBM Semeru Runtimes IBM SDK, Java Technology Edition 8 SR8 FP70 (8.0.8.70) . Downloads and supplementary documentation can be found at the following locations: - For non z/OS operating systems: - IBM Semeru Runtimes, Version 11 and later https://www.ibm.com/semeru-runtimes/downloads/ - IBM SDK, Java Technology Edition, Version 8 https://www.ibm.com/support/pages/java-sdk-downloads/ - For the z/OS operating system: - Java SDK Products on z/OS https://www.ibm.com/support/pages/java-sdk-products-zos
Temporary fix
Comments
APAR Information
APAR number
IJ58391
Reported component name
SECURITY
Reported component ID
620700125
Reported release
270
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt / Xsystem
Submitted date
2026-05-18
Closed date
2026-05-18
Last modified date
2026-05-18
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
SECURITY
Fixed component ID
620700125
Applicable component levels
[{"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Product":{"code":"SSNVBF","label":"Runtimes for Java Technology"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"270","Line of Business":{"code":"LOB08","label":"Cognitive Systems"}}]
Document Information
Modified date:
18 May 2026