<?xml version="1.0" encoding="iso-8859-1"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
      "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en-US" xml:lang="en-us">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" />
<meta name="dc.language" scheme="rfc1766" content="en-us" />
<!-- All rights reserved. Licensed Materials Property of IBM -->
<!-- US Government Users Restricted Rights                   -->
<!-- Use, duplication or disclosure restricted by            -->
<!-- GSA ADP Schedule Contract with IBM Corp.                -->
<meta name="dc.date" scheme="iso8601" content="2007-08-01" />
<meta name="copyright" content="(C) Copyright IBM Corporation 2003, 2007" />
<meta name="security" content="public" />
<meta name="Robots" content="index,follow"/>
<meta http-equiv="PICS-Label" content='(PICS-1.1 "http://www.icra.org/ratingsv02.html" l gen true r (cz 1 lz 1 nz 1 oz 1 vz 1) "http://www.rsac.org/ratingsv01.html" l gen true r (n 0 s 0 v 0 l 0) "http://www.classify.org/safesurf/" l gen true r (SS~~000 1))' />
<meta name="type" content="task" />
<title>Security User Guide</title>
<link rel="stylesheet" type="text/css" href="../ibmidwb.css" />
<link rel="stylesheet" type="text/css" href="../swg_info_common.css" />
</head>
<body class="revised">
<a id="Top_Of_Page" name="Top_Of_Page"></a><h1>IBM 32-bit SDK for Windows platforms, Java Standard Edition,&nbsp;Version 5.0</h1>
<h1>Security User Guide</h1>
<br />
<span class="ibmdocnum"></span><br />
<a name="notices_link"></a>
<div id="notices_link">
<div class="pblklblbox">
<span class="pblktitle">Note</span>
<p>Before using this information and the product it supports, read the information
in <a href="#notices">Notices</a>.</p></div></div>
<a name="copyright"></a>
<div id="copyright">
<span class="ednoticestitle">Copyright information</span>
<p><strong>Note</strong>: Before using this information and the product it supports,
read the general information under <a href="#notices">Notices</a>.</p>
<p>This edition of the User Guide applies to: 
</p>
<ul>
<li> iKeyman</li>
<li>Java Authentication and Authorization
Service (JAAS) v2.0</li>
<li>IBM Java Certification
Path (CertPath) v1.0 Provider</li>
<li>IBM Java Cryptography
Extension (JCE) Provider</li>
<li>IBM Java Generic
Security Service (JGSS) v1.5 Provider</li>
<li>IBM Java Secure Socket Extension (JSSE) IBM JSSE2 Provider</li>
<li>IBM PKCS11 Implementation
Provider</li>
<li>IBM Java JCE FIPS Provider</li>
<li>IBM SASL Provider v1.5</li>
<li>Key Certificate Management utilities</li></ul><p class="indatacontent">and to all subsequent releases and modifications until otherwise indicated
in new editions.</p>
<p>(c) Copyright Sun Microsystems, Inc. 1997, 2007, 901 San Antonio Rd., Palo
Alto, CA 94303 USA. All rights reserved.</p>
<p>(c) Copyright International Business Machines Corporation, 1999, 2007.
All rights reserved.</p>
<p>U.S. Government Users Restricted Rights - Use, duplication or disclosure
restricted by GSA ADP Schedule Contract with IBM Corp.</p></div><div><strong>Copyright International Business Machines Corporation 2003, 2007. All rights reserved.</strong><br />US Government Users Restricted Rights -- Use, duplication or disclosure restricted by GSA ADP Schedule Contract with IBM Corp.</div>

<a name="wq2"></a>
<div id="wq2">
<h1>Contents</h1>
<div class="head1"><a id="ToC_1" name="ToC_1" href="#preface" class="toclink">Preface</a></div>
<div class="head1"><a id="ToC_2" name="ToC_2" href="#gen_info_sec_prov" class="toclink">General information about IBM security providers</a></div>
<div class="head1"><a id="ToC_3" name="ToC_3" href="#ikeyman" class="toclink">iKeyman tool</a></div>
<div class="head2"><a id="ToC_4" name="ToC_4" href="#ikeyman_new" class="toclink">What's new?</a></div>
<div class="head2"><a id="ToC_5" name="ToC_5" href="#ikeyman_doc" class="toclink">Documentation</a></div>
<div class="head1"><a id="ToC_6" name="ToC_6" href="#jaas" class="toclink">Java Authentication and Authorization Service (JAAS) V2.0</a></div>
<div class="head2"><a id="ToC_7" name="ToC_7" href="#jaas_differences_sun" class="toclink">Differences between IBM and Sun versions of JAAS</a></div>
<div class="head2"><a id="ToC_8" name="ToC_8" href="#jaas_new_win32" class="toclink">What's new?</a></div>
<div class="head2"><a id="ToC_9" name="ToC_9" href="#jaas_win32_doc" class="toclink">Documentation</a></div>
<div class="head2"><a id="ToC_10" name="ToC_10" href="#jaas_active_login" class="toclink">JAAS Active Login</a></div>
<div class="head3"><a id="ToC_11" name="ToC_11" href="#jaas_active_login_using" class="toclink">Using JAAS Active Login</a></div>
<div class="head1"><a id="ToC_12" name="ToC_12" href="#certpath" class="toclink">Java Certification Path (CertPath)</a></div>
<div class="head2"><a id="ToC_13" name="ToC_13" href="#certpath_differences_sun" class="toclink">Differences between IBM and Sun versions of CertPath</a></div>
<div class="head2"><a id="ToC_14" name="ToC_14" href="#certpath_new" class="toclink">What's new?</a></div>
<div class="head2"><a id="ToC_15" name="ToC_15" href="#certpath_doc" class="toclink">Documentation</a></div>
<div class="head1"><a id="ToC_16" name="ToC_16" href="#jce" class="toclink"> Java Cryptography Extension (JCE)</a></div>
<div class="head2"><a id="ToC_17" name="ToC_17" href="#jce_differences_sun" class="toclink">Differences between IBM and Sun versions of JCE</a></div>
<div class="head2"><a id="ToC_18" name="ToC_18" href="#jce_new" class="toclink">What's new?</a></div>
<div class="head2"><a id="ToC_19" name="ToC_19" href="#jce_doc" class="toclink">Documentation</a></div>
<div class="head1"><a id="ToC_20" name="ToC_20" href="#jgss" class="toclink">Java Generic Security Service (JGSS)</a></div>
<div class="head2"><a id="ToC_21" name="ToC_21" href="#jgss_differences_sun" class="toclink">Differences between IBM and Sun versions of JGSS</a></div>
<div class="head2"><a id="ToC_22" name="ToC_22" href="#jgss_new" class="toclink">What's new?</a></div>
<div class="head2"><a id="ToC_23" name="ToC_23" href="#jgss_doc" class="toclink">Documentation</a></div>
<div class="head1"><a id="ToC_24" name="ToC_24" href="#ibmjsse2" class="toclink">IBMJSSE2 Provider</a></div>
<div class="head2"><a id="ToC_25" name="ToC_25" href="#ibmjsse2_differences_ibmjsse" class="toclink">Differences between the IBMJSSE Provider and the IBMJSSE2 Provider</a></div>
<div class="head2"><a id="ToC_26" name="ToC_26" href="#ibmjsse2_differences_sun" class="toclink">Differences between the IBMJSSE2 Provider and Sun's version of JSSE</a></div>
<div class="head2"><a id="ToC_27" name="ToC_27" href="#ibmjsse2_new" class="toclink">What's new?</a></div>
<div class="head2"><a id="ToC_28" name="ToC_28" href="#ibmjsse2_doc" class="toclink">Documentation</a></div>
<div class="head1"><a id="ToC_29" name="ToC_29" href="#ibmpkcs11" class="toclink"> IBMPKCS11Impl Provider</a></div>
<div class="head2"><a id="ToC_30" name="ToC_30" href="#ibmpkcs11_differences_sun" class="toclink">Differences between IBM and Sun versions of IBMPKCS11Impl</a></div>
<div class="head2"><a id="ToC_31" name="ToC_31" href="#ibmpkcs11_new" class="toclink">What's new?</a></div>
<div class="head2"><a id="ToC_32" name="ToC_32" href="#ibmpkcs11_doc" class="toclink">Documentation</a></div>
<div class="head1"><a id="ToC_33" name="ToC_33" href="#ibmjcefips" class="toclink"> IBMJCEFIPS Provider</a></div>
<div class="head2"><a id="ToC_34" name="ToC_34" href="#ibmjcefips_differences_sun" class="toclink">Differences between IBM and Sun versions of IBMJCEFIPS</a></div>
<div class="head2"><a id="ToC_35" name="ToC_35" href="#ibmjcefips_new" class="toclink">What's new?</a></div>
<div class="head2"><a id="ToC_36" name="ToC_36" href="#ibmjcefips_doc" class="toclink">Documentation</a></div>
<div class="head1"><a id="ToC_37" name="ToC_37" href="#sasl" class="toclink"> IBM SASL Provider</a></div>
<div class="head2"><a id="ToC_38" name="ToC_38" href="#sasl_differences_sun" class="toclink">Differences between Sun and IBM SASL Provider</a></div>
<div class="head2"><a id="ToC_39" name="ToC_39" href="#sasl_new" class="toclink">What's new</a></div>
<div class="head2"><a id="ToC_40" name="ToC_40" href="#sasl_doc" class="toclink">Documentation</a></div>
<div class="head1"><a id="ToC_41" name="ToC_41" href="#keycert" class="toclink"> Key Certificate Management utilities</a></div>
<div class="head2"><a id="ToC_42" name="ToC_42" href="#keycert_new" class="toclink">What's new</a></div>
<div class="head2"><a id="ToC_43" name="ToC_43" href="#keycert_doc" class="toclink">Documentation</a></div>
<div class="head1"><a id="ToC_44" name="ToC_44" href="#notices" class="toclink">Notices</a></div>
<div class="head2"><a id="ToC_45" name="ToC_45" href="#trademarks" class="toclink">Trademarks</a></div>
</div>
<a name="preface"></a>
<h1 id="preface"><a href="#ToC_1">Preface</a></h1>
<p>
<p>The security components described in this User Guide
are shipped with the SDK and are not extensions. They provide a wide range
of security services through standard Java<sup>(TM)</sup> APIs (except
iKeyman). The security components contain the IBM<sup>(R)</sup> implementation of various security algorithms
and mechanisms. IBM does
not provide support for any of the IBM Java security components when used with
a non-IBM JVM or with non-IBM security providers when used with the IBM JVM.</p>
<p>The IBM SDK
also provides a FIPS 140-2 certified cryptographic module, IBMJCEFIPS, implemented
as a JCE provider. Applications can comply with the FIPS 140-2 requirements
by using the IBMJCEFIPS module.</p>
<p>The CertPath component provides PKIX-compliant
certification path building and validation.</p>
<p>The JGSS component provides
a generic API that can be plugged in by different security mechanisms. IBM JGSS
uses Kerberos V5 as the default mechanism for authentication and secure communication.</p>
<p>The JAAS component provides a means for principal-based
authentication and authorization.</p>
<p>The JCE framework has two providers:
IBMJCE is the pre-registered default provider; IBMJCEFIPS is optional.</p>
<p>JSSE is the Java implementation of the SSL and TLS protocols.
The JSSE pre-registered default provider is IBMJSSE2.</p></p>
<p>IBM Java Simple
Authentication and Security Layer, or SASL, is an Internet standard (RFC 2222)
that specifies a protocol for authentication and optional establishment of
a security layer between client and server applications.</p>
<p>The Java security configuration file does not
refer to the Sun provider. The IBM JCE provider has replaced the Sun provider.
The JCE supplies all the signature handling message digest algorithms that
were previously supplied by the Sun provider. It also supplies the IBM secure random
number generator, IBMSecureRandom, which is a real Random
Number Generator. SHA1PRNG is a Pseudo Random Number Generator and is supplied
for code compatibility. SHA1PRNG is not guaranteed to produce the same output
as the SUN SHA1PRNG.</p>
<p>In the IBM SDK
v1.4.1, the following options were added to the <strong>java.security.debug</strong> property
to help you debug Java Cryptography Architecture (JCA)-related problems:</p>
<dl>
<dt class="bold">provider</dt>
<dd>Displays each provider request and load, provider add and provider remove.
It also displays the related exception when a provider load fails.
</dd>
<dt class="bold">algorithm</dt>
<dd>Displays each algorithm request, which provider has supplied the algorithm
and the implementing class name.
</dd>
<dt class="bold">:stack</dt>
<dd>You can append this option to either of <strong>algorithm</strong> - or <strong>provider</strong>.
When you request an algorithm, a stack trace is displayed. Use this stack
trace to determine the code that has requested the algorithm. This option
also prints the stack trace for exceptions that are swallowed or converted.
</dd>
<dt class="bold">:thread</dt>
<dd>Adds the thread id to all debug message lines. You can use this option
together with all the other debug options.
</dd>
</dl>
<p>An example of a valid option string is "provider, algorithm:stack".</p>
<p>In this guide, you will see a 'What's new' section for each component.
This information is provided to help you with migration.</p>
<a name="gen_info_sec_prov"></a>
<h1 id="gen_info_sec_prov"><a href="#ToC_2">General information about IBM security providers</a></h1>
<div>
<p>Overview of the security providers tested with the IBM SDK.</p></div>
<p>The IBM SDK V5.0 has
been tested with the following default security providers:   
</p>
<ul>
<li>security.provider.1=com.ibm.jsse2.IBMJSSEProvider2</li>
<li>security.provider.2=com.ibm.crypto.provider.IBMJCE</li>
<li>security.provider.3=com.ibm.security.jgss.IBMJGSSProvider</li>
<li>security.provider.4=com.ibm.security.cert.IBMCertPath</li>
<li>security.provider.5=com.ibm.security.sasl.IBMSASL</li></ul>
<p>You can add other IBM security providers either statically or from within
your Java application's code. To add a new provider statically, edit a Java
security properties file (for example, java.security).
To add a new provider from your application's code, use the methods of the java.security.Security class
(for example, <tt class="xph">java.security.Security.addProvider()</tt>).</p>
<p>You can also add this IBM security provider, com.ibm.crypto.fips.provider.IBMJCEFIPS.</p>
<p>Note that code written for the IBMJSSE Provider might not compile or execute
in exactly the same way for IBMJSSE2. For details, see <a href="#ibmjsse2">IBMJSSE2 Provider</a>.</p>
<a name="ikeyman"></a>
<h1 id="ikeyman"><a href="#ToC_3">iKeyman tool</a></h1>
<div>
<p>Overview of the iKeyman tool.</p></div>
<p>The iKeyman utility is a tool for managing your digital certificates. With
iKeyman, you can: 
</p>
<ul>
<li>Create a new key database or a test digital certificate</li>
<li>Add CA roots to your database</li>
<li>Copy certificates from one database to another</li>
<li>Request and receive a digital certificate from a CA</li>
<li>Set default keys, and change passwords</li></ul>
<a name="ikeyman_new"></a>
<h2 id="ikeyman_new"><a href="#ToC_4">What's new?</a></h2>
<div>
<p>History of changes to the iKeyman tool.</p></div>
<p>There are no changes for v5.0 over v1.4.2.</p>
<p>There are no changes in v1.4.2 over v1.4.1.</p>
<p>The following change was added in v1.4.1:  
</p>
<ul>
<li>An iKeyman wrapper that invokes the correct tool class was added.</li></ul>
<a name="ikeyman_doc"></a>
<h2 id="ikeyman_doc"><a href="#ToC_5">Documentation</a></h2>
<div>
<p>Available documentation for the iKeyman tool.</p></div>
<p>The <em>iKeyman User Guide</em> is on the developerWorks Web site, at <a href="http://www.ibm.com/developerworks/java/jdk/security/index.html" target="_blank">http://www.ibm.com/developerworks/java/jdk/security/index.html</a>.</p>
<a name="jaas"></a>
<h1 id="jaas"><a href="#ToC_6">Java Authentication and Authorization Service (JAAS) V2.0</a></h1>
<div>
<p>The Sun Microsystems Java 2 platform provides a means to enforce
access controls based on <em>where</em> code came from and <em>who signed</em> it.
These access controls are needed because of the distributed nature of the
Java platform where, for example, a remote applet can be downloaded over a
public network and then run locally.</p></div>
<p>However, before SDK v1.4.0, the Java 2 platform did not provide a way to
enforce similar access controls based on <em>who runs</em> the code. To provide
this type of access control, the Java 2 security architecture requires the
following:</p>
<ul>
<li>Additional support for authentication (determining who is actually running
the code)</li>
<li>Extensions to the existing authorization components to enforce new access
controls based on who was authenticated</li></ul>
<p>The Java Authentication and Authorization Service (JAAS) framework provides
these enhancements.</p>
<p>JAAS is supported on the following products: 
</p>
<ul>
<li>Microsoft Windows NT 4.0</li>
<li>Windows 2000</li>
<li>Windows XP</li>
<li>Windows Server 2003</li>
<li>Windows Vista</li></ul>
<p>For a general overview of JAAS, see the Sun Web site: <a href="http://java.sun.com/products/jaas" target="_blank">http://java.sun.com/products/jaas</a>.</p>
<a name="jaas_differences_sun"></a>
<h2 id="jaas_differences_sun"><a href="#ToC_7">Differences between IBM and Sun versions of JAAS</a></h2>
<p>The IBM version of JAAS differs from the Sun version in the following ways:</p>
<ul>
<li>The com.sun.* packages are reimplemented by IBM and renamed com.ibm.*
packages.</li>
<li>IBM has added Active Login to JAAS. See <a href="#jaas_active_login">JAAS
Active Login</a> for more information.</li></ul>
<a name="jaas_new_win32"></a>
<h2 id="jaas_new_win32"><a href="#ToC_8">What's new?</a></h2>
<p>There are no changes to JAAS in v5.0.</p>
<p>There are no changes in v1.4.2 over v1.4.1.</p>
<p>The original release of JAAS for Windows and the Java 2 Platform included
the following login modules and principal classes:</p>
<ul>
<li>com.ibm.security.auth.module.NTLoginModule</li>
<li>com.ibm.security.auth.module.NTActiveLoginModule</li>
<li>com.ibm.security.auth.NTDomainPrincipal</li>
<li>com.ibm.security.auth.NTSidDomainPrincipal</li>
<li>com.ibm.security.auth.NTSidGroupPrincipal</li>
<li>com.ibm.security.auth.NTSidPrimaryGroupPrincipal</li>
<li>com.ibm.security.auth.NTSidUserPrincipal</li>
<li>com.ibm.security.auth.NTUserPrincipal</li></ul>
<p>The login modules called com.ibm.security.auth.module.NTLoginModule2000 and com.ibm.security.auth.module.NTActiveLoginModule2000 were added. These login modules have the same function as NTLoginModule and NTActiveLoginModule,
but reference a different set of principals. Additional principal classes
had been included to facilitate the writing of new login modules.</p>
<p>If you want to migrate applications to the different set of principals,
most of the changes were in the JAAS policy and configuration files rather
than in the applications. Refer to the following table for guidance. 
</p>
<a name="wq4"></a>
<table id="wq4" width="100%" summary="" border="1" frame="border" rules="all">
<caption>Table 1. Principal class names.</caption>
<thead valign="bottom">
<tr>
<th id="wq5" align="left" valign="top">Original Class</th>
<th id="wq6" align="left" valign="top">Replaced by...</th>
</tr>
</thead>
<tbody valign="top">
<tr>
<td headers="wq5">NTUserPrincipal</td>
<td headers="wq6">UsernamePrincipal</td>
</tr>
<tr>
<td headers="wq5">NTSidGroupPrincipal</td>
<td headers="wq6">GroupIDPrincipal</td>
</tr>
<tr>
<td headers="wq5">NTSidUserPrincipal</td>
<td headers="wq6">UserIDPrincipal</td>
</tr>
<tr>
<td headers="wq5">NTDomainPrincipal</td>
<td headers="wq6">DomainPrincipal</td>
</tr>
<tr>
<td headers="wq5">NTSidDomainPrincipal</td>
<td headers="wq6">DomainIDPrincipal</td>
</tr>
<tr>
<td headers="wq5">NTSidPrimaryGroupIDPrincipal</td>
<td headers="wq6">PrimaryGroupIDPrincipal</td>
</tr>
<tr>
<td headers="wq5">n/a</td>
<td headers="wq6">ServerPrincipal</td>
</tr>
<tr>
<td headers="wq5">n/a</td>
<td headers="wq6">WkstationPrincipal</td>
</tr>
<tr>
<td headers="wq5">NTLoginModule</td>
<td headers="wq6">NTLoginModule2000</td>
</tr>
<tr>
<td headers="wq5">NTActiveLoginModule</td>
<td headers="wq6">NTActiveLoginModule2000</td>
</tr>
</tbody>
</table>
<p>Principal classes are in the com.ibm.security.auth package.
The login module is in the com.ibm.security.auth.module package.
Check the JAAS API (javadoc) information for details of how to use the principal
classes.</p>
<p>For example, this JAAS policy grant block:</p>
<p> </p>
<pre class="xmp">grant Principal com.ibm.security.auth.NTUserPrincipal "bob",
      Principal com.ibm.security.auth.NTSidUserPrincipal 
          "S-1-5-21-1202660629-764733703-839523458-1000",
      Principal com.ibm.security.auth.NTSidGroupPrincipal 
          "S-1-1-0" {
   permission java.util.PropertyPermission "java.home", "read";
};</pre><p class="indatacontent"> would be replaced by:   </p>
<pre class="xmp">grant Principal com.ibm.security.auth.UsernamePrincipal "bob",
      Principal com.ibm.security.auth.UserIDPrincipal  
           "S-1-5-21-1202660629-764733703-839523458-1000",
      Principal com.ibm.security.auth.GroupIDPrincipal 
           "S-1-1-0" {
   permission java.util.PropertyPermission "java.home", "read";
};</pre>
<a name="jaas_win32_doc"></a>
<h2 id="jaas_win32_doc"><a href="#ToC_9">Documentation</a></h2>
<p>For detailed information, including API documentation and samples, see
the developerWorks Web site at  <a href="http://www.ibm.com/developerworks/java/jdk/security/index.html" target="_blank">http://www.ibm.com/developerworks/java/jdk/security/index.html</a>.
This site contains the <cite>LoginModule Developer's Guide</cite> and sample
code in &quot;HelloWorld.tar&quot;.</p>
<a name="jaas_active_login"></a>
<h2 id="jaas_active_login"><a href="#ToC_10">JAAS Active Login</a></h2>
<p>The IBM version of JAAS for Windows contains an additional function called
Active Login. Because Windows has an extensive security infrastructure, it
is important on servers to allow a Java program to log in as a particular
Windows user and run with the underlying operating system knowing the security
identity on a particular thread. Without this extended support, JAAS would
allow Java programs to know who the user is, strictly on a Java level. With
this extended support, Java programs can log in as different users and have
even non-Java programs (such as the Windows kernel) enforce security appropriately.</p>
<p>The following classes contain the additional support for Active Login:</p>
<dl>
<dt class="bold">com.ibm.security.auth.NTThreadSubject</dt>
<dd>This is the gateway to changing identities on an operating system thread
level.
</dd>
<dt class="bold">com.ibm.security.auth.module.NTActiveLoginModule</dt>
<dd>This is specified in the login configuration file. If you construct a
LoginContext using a string name that calls this LoginModule, and you supply
a CallbackHandler that can supply a user ID and password suitable for this
Windows computer, you can log in.
</dd>
<dt class="bold">com.ibm.security.auth.module.NTActiveSystem</dt>
<dd>This is an implementation class, largely hidden from users.
</dd>
</dl>
<p>These classes are described in the JAAS APIs that are included with the
Java SDK.</p>
<a name="jaas_active_login_using"></a>
<h3 id="jaas_active_login_using"><a href="#ToC_11">Using JAAS Active Login</a></h3>
<div>
<p>To log in on Windows, an authorized program is required. The Runtime
Environment contains a Windows service that can perform the login operation.
This task will show you how to use the service.</p></div>
<p>Log in to as an administrator.</p>
<ol type="1">
<li>Open a command prompt window.

<ol type="a">
<li> Select <strong>Start</strong> -&gt; <strong>Run...</strong></li>
<li>Type <tt>cmd</tt></li></ol></li>
<li>Change to the bin directory of the Runtime Environment.

<ol type="a">
<li>Type <tt>cd C:\Program Files\IBM\Java50\jre\bin</tt>.</li></ol> Your Runtime Environment may be installed in a different directory.</li>
<li>Install or remove the service using the provided program.

<ul>
<li>Type <tt>jaaslogon -install</tt> to install the service.</li>
<li>Type <tt>jaaslogon -remove</tt> to remove the service.</li></ul></li></ol>
<p>
<p>The
following error messages are associated with starting and removing JAASLogon:</p>
<pre class="xmp"> jaaslogon Difficulty in starting JaasLogon, error code = 1063  Cause:  Incorrect syntax.  The correct syntax is jaaslogon -install</pre>
<pre class="xmp">jaaslogon -install Difficulty in CreateService, error code = 1073  Cause:  The service has already been started.  </pre>
<pre class="xmp">jaaslogon -remove In OpenService, error Code = 1060  Cause:  The service cannot be removed since it was not started.</pre></p>
<a name="certpath"></a>
<h1 id="certpath"><a href="#ToC_12">Java Certification Path (CertPath)</a></h1>
<div>
<p>The Java Certification Path API provides interfaces and abstract
classes for creating, building, and validating certification paths (also known
as "certificate chains").</p></div>
<a name="certpath_differences_sun"></a>
<h2 id="certpath_differences_sun"><a href="#ToC_13">Differences between IBM and Sun versions of CertPath</a></h2>
<p>The IBM CertPath classes differ from the Sun version in the following ways:</p>
<ul>
<li>The IBM CertPath provider is in the package com.ibm.security.cert.</li>
<li>The IBM CertPath provider is called "IBMCertPath". Sun
does not have a separate provider for CertPath; CertPath is already supported
by the "SUN" provider.</li>
<li>To enable CRL Distribution Points extension checking,
use the system property <strong>com.ibm.security.enableCRLDP</strong>.
The system property used by the Sun version is <strong>com.sun.security.enableCRLDP</strong>.</li>
<li>When checking the certificate's CRL Distribution Points
extension, Sun's version retrieves the CRL only if the CRL location is specified
as an HTTP URL value inside the extension. The IBM provider recognizes both
HTTP and LDAP URLs.</li></ul>
<a name="certpath_new"></a>
<h2 id="certpath_new"><a href="#ToC_14">What's new?</a></h2>
<p>The following changes have been added in v5.0: 
</p>
<ul>
<li>Support of checking a certificate's revocation status based on On-Line
Certificate Status Protocol (OCSP) has been added.</li>
<li>A new constructor and a public API in TrustAnchor class
have been added: 

<ul>
<li><tt class="xph">public TrustAnchor(X500Principal caPrincipal, PublicKey pubKey,
byte[] nameConstraints);</tt></li>
<li><tt class="xph">public final X500Principal getCA();</tt></li></ul></li>
<li>Four new public APIs in X509CertSelector have been
added: 

<ul>
<li><tt class="xph">public X500Principal getIssuer();</tt></li>
<li><tt class="xph">public void setIssuer(X500Principal issuer);</tt></li>
<li><tt class="xph">public X500Principal getSubject();</tt></li>
<li><tt class="xph">public void setSubject(X500Principal subject);</tt></li></ul></li>
<li>Three new public APIs in X509CRLSelector have been
added: 

<ul>
<li><tt class="xph">public void setIssuers(Collection issuers);</tt></li>
<li><tt class="xph">public void addIssuer(X500Principal issuer);</tt></li>
<li><tt class="xph">public Collection getIssuers();</tt></li></ul></li>
<li>The PolicyQualifier class has been changed to be non-final
and its public APIs have changed to be final.</li></ul>
<p>The following changes were added in v1.4.2: 
</p>
<ul>
<li>The performance of the IBM CertPath provider has been improved.</li>
<li>Limited support for the CRL Distribution Points extension has been added.</li>
<li>IBM LDAP CertStore provides caching to cache lookups.</li></ul>
<p>The following changes were added in v1.4.1 SR1: 
</p>
<ul>
<li>The trusted certificate that acts as TrustAnchor can
be an X.509 v1 certificate.</li>
<li>When you specify the certificate's subject or issuer name as a String
in X509CertSelector, the search for a matched certificate
mechanism checks only the name value and ignores the tag type.</li></ul>
<p>There were no changes in v1.4.1 over v1.4.0.</p>
<p>The following changes were added in v1.4.0: 
</p>
<ul>
<li>Certificates from CertificatePair entry can be retrieved
from LDAP type certstore.</li>
<li>The framework package name was changed from javax.security.cert to java.security.cert.
However, the old framework package is still supported.</li></ul>
<a name="certpath_doc"></a>
<h2 id="certpath_doc"><a href="#ToC_15">Documentation</a></h2>
<p>For detailed information, including API documentation and samples, see
the developerWorks Web site, at <a href="http://www.ibm.com/developerworks/java/jdk/security/index.html" target="_blank">http://www.ibm.com/developerworks/java/jdk/security/index.html</a>.</p>
<a name="jce"></a>
<h1 id="jce"><a href="#ToC_16"> Java Cryptography Extension (JCE)</a></h1>
<div>
<p>The Java Cryptography Extension (JCE) provides a framework and
implementations for  encryption, key generation and key agreement, and Message
Authentication Code (MAC) algorithms.  Support for encryption includes symmetric,
asymmetric, block, and stream ciphers.  The software also supports secure
streams and sealed objects.   JCE supplements the Java 2 platform, which already
includes interfaces and  implementations of message digests and digital signatures.</p></div>
<p>You can obtain unrestricted jurisdiction policy files from <a href="http://www.ibm.com/developerworks/java/jdk/security/index.html" target="_blank">http://www.ibm.com/developerworks/java/jdk/security/index.html</a>.</p>
<p>The v1.4.2 unrestricted (and restricted) jurisdiction policy
files are suitable for use with v5.0. The v1.4.1 files are not suitable.</p>
<a name="jce_differences_sun"></a>
<h2 id="jce_differences_sun"><a href="#ToC_17">Differences between IBM and Sun versions of JCE</a></h2>
<p>The com.sun.* packages are reimplemented by IBM and
renamed com.ibm.* packages.</p>
<p>The IBM version of JCE differs from the Sun version in the following ways:
 
</p>
<ul>
<li>The com.sun.crypto.* packages are reimplemented by
IBM and renamed com.ibm.crypto.* packages.</li>
<li>The IBM JCE provider replaces the Sun providers sun.security.provider.Sun, com.sun.rsajca.Provider,
and com.sun.crypto.provider.SunJCE.</li>
<li>IBM provides more algorithms than Sun does:  

<ul>
<li><strong>Cipher algorithms</strong>  

<ul>
<li>AES</li>
<li>Blowfish</li>
<li>DES</li>
<li>Mars</li>
<li>ARCFOUR</li>
<li>PBE with MD2 and DES</li>
<li>PBE with MD2 and Triple DES</li>
<li>PBE with MD2 and RC2</li>
<li>PBE with MD5 and DES</li>
<li>PBE with MD5 and Triple DES</li>
<li>PBE with MD5 and RC2</li>
<li>PBE with SHA1 and DES</li>
<li>PBE with SHA1 and TripleDES</li>
<li>PBE with SHA1 and RC2</li>
<li>PBE with SHA1 and 40-bit RC2</li>
<li>PBE with SHA1 and 128-bit RC2</li>
<li>PBE with SHA1 and 40-bit RC4</li>
<li>PBE with SHA1 and 128-bit RC4</li>
<li>PBE with SHA1 and 2-key Triple DES</li>
<li>PBE with SHA1 and 3-key Triple DES</li>
<li>RC2</li>
<li>RC4</li>
<li>RSA encryption/decryption</li>
<li>RSA encryption/decryption with OAEP Padding</li>
<li>Seal</li>
<li>Triple DES</li></ul></li>
<li><strong> Signature algorithms  </strong> 

<ul>
<li>SHA1 with RSA, SHA2 with RSA, SHA3 with RSA, SHA5 with RSA,
MD5 with RSA, MD2 with RSA signatures</li>
<li> SHA1 with DSA signature</li></ul></li>
<li> <strong>Message digest algorithms</strong> 

<ul>
<li> SHA1</li>
<li> SHA2</li>
<li> SHA3</li>
<li> SHA5</li>
<li> MD5</li>
<li> MD2</li></ul></li>
<li> <strong>Message authentication code (MAC)  </strong> 

<ul>
<li> Hmac/SHA1</li>
<li> Hmac/MD5</li>
<li>Hmac/SHA2</li>
<li>Hmac/SHA3</li>
<li>Hmac/SHA5</li></ul></li>
<li> <strong>Key agreement algorithm</strong>  

<ul>
<li> DiffieHellman</li></ul></li>
<li><strong>Random number generation algorithms</strong> 

<ul>
<li> IBMSecureRandom</li>
<li> IBM SHA1PRNG</li></ul></li>
<li><strong>Key Store  </strong> 

<ul>
<li> JCEKS</li>
<li> JKS</li>
<li> PKCS12KS</li></ul></li></ul></li></ul>
<a name="jce_new"></a>
<h2 id="jce_new"><a href="#ToC_18">What's new?</a></h2>
<p>The following changes are made in v5.0:  
</p>
<ul>
<li>RSA with OAEP Padding is added</li>
<li>SHA2withRSA, SHA3withRSA and SHA5withRSA signature algorithms are added</li>
<li>HmacSHA2, HmacSHA3, HmacSH5 MAC algorithms are added.</li>
<li>ARCFOUR encryption algorithm is added</li></ul>
<p>The following changes were made in v1.4.2:  
</p>
<ul>
<li> SHA2, SHA3 and SHA5  algorithms were added for hashing</li>
<li> SHA1PRNG  algorithm was added for generating pseudo random numbers</li></ul>
<p>There were no changes in v1.4.1 from v1.4.0.</p>
<p>The following changes were made in v1.4.0: 
</p>
<ul>
<li>AES cipher algorithm has been added.</li>
<li>Strong cryptography is the default, unlimited cryptography is available.</li>
<li>Provider authentication of the JCE framework no longer required.</li>
<li>JCE is now shipped with the Java SDK v1.4 on all platforms.</li></ul>
<a name="jce_doc"></a>
<h2 id="jce_doc"><a href="#ToC_19">Documentation</a></h2>
<p>For detailed information, including API documentation and samples, see
the developerWorks Web site at  <a href="http://www.ibm.com/developerworks/java/jdk/security/index.html" target="_blank">http://www.ibm.com/developerworks/java/jdk/security/index.html</a>.</p>
<a name="jgss"></a>
<h1 id="jgss"><a href="#ToC_20">Java Generic Security Service (JGSS)</a></h1>
<div>
<p>The Java Generic Security Service (JGSS) API provides secure exchange
of messages between communicating applications.</p></div>
<p>The JGSS is an API framework that has Kerberos V5 as the underlying default
security mechanism. The API is a standardized abstract interface under which
you can plug different security mechanisms that are based on private-key,
public-key, and other security technologies. JGSS shields secure applications
from the complexities and peculiarities of the different underlying security
mechanisms. JGSS provides identity and message origin authentication, message
integrity, and message confidentiality. JGSS also features an optional Java
Authentication and Authorization Service (JAAS) Kerberos login interface,
and authorization checks. JAAS augments the access control features of Java
2, which is based on CodeSource with access controls based on authenticated
principal identities.</p>
<a name="jgss_differences_sun"></a>
<h2 id="jgss_differences_sun"><a href="#ToC_21">Differences between IBM and Sun versions of JGSS</a></h2>
<p>The IBM version of JGSS differs from the Sun version in the following ways:</p>
<ul>
<li>The com.sun.* packages  are reimplemented by IBM and
renamed com.ibm.* packages.</li>
<li>The format of the parameters passed to the Java tools kinit, ktab,
and klist is different from Sun's equivalent tools.</li></ul>
<a name="jgss_new"></a>
<h2 id="jgss_new"><a href="#ToC_22">What's new?</a></h2>
<p>The following change is added in v5.0 Service Refresh 1: 
</p>
<dl>
<dt class="bold">AES is now a supported algorithm type</dt>
<dd>These additional algorthims can be set in the krb5.conf file
under [libdefault] as follows:    
<div class="lines">default_tkt_enctypes	= aes128-cts-hmac-sha1-96<br />
default_tkt_enctypes	= aes256-cts-hmac-sha1-96<br />
default_tgs_enctypes	= aes128-cts-hmac-sha1-96<br />
default_tgs_enctypes	= aes256-cts-hmac-sha1-96<br />
<br />
default_checksum 	= hmac-sha1-96-aes128<br />
default_checksum 	= hmac-sha1-96-aes256<br />
</div>
</dd>
</dl>
<p>The following changes are added in v5.0: 
</p>
<dl>
<dt class="bold">TCP or UDP Preference Configuration </dt>
<dd>JSE now supports the use of the <strong>udp_preference_limit</strong> property
in the Kerberos configuration file (krb5.ini).  When sending a message to
the KDC, the JSE Kerberos library will use TCP if the size of the message
is above <strong>udp_preference_list</strong>. If the message is smaller
than <strong>udp_preference_list</strong>, UDP will be tried up to three
times. If the KDC indicates that the request is too big, the JSE Kerberos
library will use TCP.
</dd>
<dt class="bold">IPv6 support in Kerberos </dt>
<dd>JSE now supports IPv6 addresses in Kerberos tickets. Before J2SE 5, only
IPv4 addresses were supported in tickets.
</dd>
<dt class="bold">TGT Renewals</dt>
<dd>The Java Authentication and Authorization Server (JAAS) Kerberos login
module in v5.0, Krb5LoginModule, now supports Ticket Granting
Ticket (TGT) renewal. This support allows long-running services to renew their
TGTs automatically without user interaction or requiring the services to restart.
 With this feature, if Krb5LoginModule obtains an expired
ticket from the ticket cache, the TGT will be automatically renewed and be
added to the Subject of the caller who requested the ticket. If the ticket
cannot be renewed for any reason, Krb5LoginModule will
use its configured callback handler to retrieve a username and password to
acquire a new TGT.  

<p>To use this feature, configure Krb5LoginModule to
use the ticket cache and set the newly introduced <strong>renewTGT</strong> option
to true. Here is an example of a JAAS login configuration file that requests
TGT renewal:</p> 
<pre class="xmp">server {
  com.ibm.security.auth.module.Krb5LoginModule required
        principal=principal@your_realm
		useDefaultCcache=TRUE
		 renewTGT=true;
};</pre>Note that if <strong>renewTGT</strong> is set to true, <strong>useDefaultCcache</strong> must
also be set to true; otherwise, it results in a configuration error.
</dd>
</dl>
<p>The following changes were added in v1.4.2: 
</p>
<dl>
<dt class="bold">Configurable Kerberos Settings </dt>
<dd>You can provide the name and realm settings for the Kerberos Key Distribution
Center (KDC) either from the Kerberos configuration file or by using the system
properties files java.security.krb5.kdc and java.security.krb5.realm. You
can also specify the boolean option <strong>refreshKrb5Config</strong> in
the entry for Krb5LoginModule in the JAAS configuration
file. If you set this option to <tt class="xph">true</tt>, the configuration values
will be refreshed before the login method of the Krb5LoginModule is
called.
</dd>
<dt class="bold">Support for Slave Kerberos Key Distribution Center </dt>
<dd>Kerberos uses slave KDCs so that, if the master KDC is unavailable, the
slave KDCs will respond to your requests. In previous releases, Kerberos tried
the master KDC only and would give up if there was no response within the
default KDC timeout.
</dd>
<dt class="bold">Support TCP for Kerberos Key Distribution Center Transport </dt>
<dd>Kerberos uses UDP transport for ticket requests. In cases where Kerberos
tickets exceed the UDP packet size limit, Kerberos supports automatic fallback
to TCP. If a Kerberos ticket request using UDP fails and the KDC returns the
error code <tt class="xph">KRB_ERR_RESPONSE_TOO_BIG</tt>, TCP becomes the transport
protocol.
</dd>
<dt class="bold">Kerberos Service Ticket in the Subject's Private Credentials</dt>
<dd>The Kerberos service ticket is stored in the Subject's private credentials.
This gives you access to the service ticket so that you can use it outside
the JGSS (for example, in native applications or for proprietary uses). In
addition, you can reuse the service ticket if the application tries to establish
a security context to the same service again. The service ticket should be
valid for it to be reusable.
</dd>
</dl>
<p>The following change was added in v1.4.1:  
</p>
<ul>
<li>Wrappers have been added for the klist, kinit,
and ktab Java tools. These wrappers invoke the relevant
tool classes so that you do not have to remember the full package name.</li></ul>
<a name="jgss_doc"></a>
<h2 id="jgss_doc"><a href="#ToC_23">Documentation</a></h2>
<p>For detailed information about JGSS, including API documentation and samples,
see the developerWorks Web site, at <a href="http://www.ibm.com/developerworks/java/jdk/security/index.html" target="_blank">http://www.ibm.com/developerworks/java/jdk/security/index.html</a>.</p>
<a name="ibmjsse2"></a>
<h1 id="ibmjsse2"><a href="#ToC_24">IBMJSSE2 Provider</a></h1>
<div>
<p>The Java Secure Socket Extension (JSSE) is a Java package that
enables secure internet communications. It implements a Java version of SSL
(Secure Sockets Layer) and TLS (Transport Layer Security) protocols and includes
functions for data encryption, server authentication, message integrity, and
optional client authentication.</p></div>
<p>By abstracting the complex underlying security algorithms and
"handshaking" mechanisms, JSSE minimizes the risk of creating subtle but dangerous
security vulnerabilities. Also, it simplifies application development by serving
as a building block that you can integrate directly into your applications.
Using JSSE, you can provide for the secure passage of data between a client
and a server running any application protocol (such as HTTP, Telnet, NNTP,
and FTP) over TCP/IP.</p>
<p>In v5.0, the IBMJSSE2 Provider, which was introduced in the
v1.4.2 JVM, has replaced the IBMJSSE Provider.  Although they are nearly equivalent,
there are differences between the two providers.  See the next section for
details.</p>
<a name="ibmjsse2_differences_ibmjsse"></a>
<h2 id="ibmjsse2_differences_ibmjsse"><a href="#ToC_25">Differences between the IBMJSSE Provider and the IBMJSSE2 Provider</a></h2>
<p>The now-discontinued IBMJSSE Provider and the IBMJSSE2 Provider differ
in the following ways:</p>
<ul>
<li>The IBMJSSE2 Provider is called com.ibm.jsse2.IBMJSSEProvider2.</li>
<li>The HTTPS protocol handler for the IBMJSSE2 Provider is called com.ibm.net.ssl.www2.protocol.Handler.
 The com.ibm.net.ssl.internal.www.protocol.Handler and
the com.ibm.net.ssl.www.protocol.Handler protocol handlers
have been removed.</li>
<li>The IBMJSSE2 Provider does not support the com.ibm.net.ssl framework.
Use the javax.net.ssl framework instead.</li>
<li>The IBMJSSE2 Provider does not support the SSL version 2 protocol. However,
the server side of a JSSE2 connection does accept the SSLv2Hello protocol.</li>
<li>The AES_256 ciphers require the installation of the JCE Unlimited Strength
Jurisdiction Policy. The old IBMJSSE Provider did not use JCE for its cryptographic
support and therefore did not require these files.</li>
<li>The IBMJSSE2 Provider requires a JCE Provider for its cryptography.</li>
<li>  The IBMJSSE2 Provider does not build the server's private
key certificate chain from the trusted keystore. The trusted certificates
must be added to the server's private key to complete the chain. This is an
incompatible change.</li>
<li>The IBMJSSE2 Provider considers a certificate trusted if you have the
private key.</li>
<li>The HTTPS protocol handler for the IBMJSSE2 Provider performs hostname
verification and rejects requests where the host to connect to and the server
name from the certificate do not match. A HostnameVerification implementation
called com.ibm.jsse2.HostnameVerifierIgnore is provided. com.ibm.jsse2.HostnameVerifierIgnore always
accepts the connection even when a mismatch occurs.</li>
<li>Tracing no longer requires a separate debug jar.</li>
<li>The class com.ibm.jsse.SSLContext which in IBMJSSE
is used to access secure tokens has been removed.  Use the hardware crypto
support in IBMJSSE2 instead.  See the documentation on the developerWorks
Web site <a href="http://www.ibm.com/developerworks/java/jdk/security/index.html" target="_blank">http://www.ibm.com/developerworks/java/jdk/security/index.html</a> for
details.</li>
<li>The IBMJSSEFIPS Provider has been removed.  JSSE FIPS support is supported
within the IBMJSSE2 Provider and no separate jar is required.  See the documentation
on the developerWorks Web site <a href="http://www.ibm.com/developerworks/java/jdk/security/index.html" target="_blank">http://www.ibm.com/developerworks/java/jdk/security/index.html</a> for
instructions how to set up JSSE to run in FIPS mode.</li></ul>
<a name="ibmjsse2_differences_sun"></a>
<h2 id="ibmjsse2_differences_sun"><a href="#ToC_26">Differences between the IBMJSSE2 Provider and Sun's version of JSSE</a></h2>
<p>The IBMJSSE2 Provider differs from the Sun JSSE in the following ways:</p>
<ul>
<li>The IBM JSSE Provider is called com.ibm.jsse2.IBMJSSEProvider2.</li>
<li>The IBM KeyManagerFactory is called IbmX509.</li>
<li>The IBM TrustManagerFactory is called IbmX509 or IbmPKIX.</li>
<li>The IBM HTTPS protocol handler is called com.ibm.net.ssl.www2.protocol.Handler.</li>
<li>IBMJSSE2 does not support the com.sun.net.ssl framework;
use the javax.net.ssl framework instead.</li>
<li>You can use PKIK revocation checking by setting the system property <em>com.ibm.jsse2.checkRevocation</em> to
"true".</li>
<li>The IBM implementation supports the following protocols for
the engine class SSLContext, for the api setEnabledProtocols in the SSLSocket,
and for SSLServerSocket classes: 

<ul>
<li>SSL</li>
<li>SSLv3</li>
<li>TLS</li>
<li>TLSv1</li>
<li>SSL_TLS</li></ul>The IBM implementation <em>does not</em> support the "SSLv2Hello" protocol.
 The IBM implementation supports the SSL v2 protocol.  You can use the IBM SSLContext <tt class="xph">getInstance()</tt> factory
method to control which protocols are enabled for an SSL connection.  Using SSLContext's <tt class="xph">getInstance()</tt> or
the <tt class="xph">setEnabledProtocols()</tt> methods provides the same result.
 With Sun's JSSE, the protocol is controlled through <tt class="xph">setEnabledProtocols()</tt>.</li>
<li>IBM and Sun support different cipher suites.</li>
<li>The IBM JSSE TrustManager does not allow
anonymous ciphers. To handshake with an anonymous cipher, a custom TrustManager that
allows anonymous ciphers must be provided.</li>
<li>When a null KeyManager is passed to SSLContext,
the IBM JSSE KeyManagerFactory implemention will check
system properties, then jssecacerts, if it exists, and finally uses the cacerts
file to find the key material.  Sun's JSSE creates an empty KeyManager.</li>
<li>The IBM JSSE X509TrustManager and X509KeyManager throws
an exception if the TrustStore or KeyStore specified by the system properties
does not exist, if the password is incorrect, or if the keystore type is inappropriate
for the actual keystore. Sun's X509TrustManager creates
a default TrustManager or KeyManager with
an empty keystore.</li>
<li>The IBM JSSE implementation verifies the entire server or
client certificate chain, including trusted certificates.  For example, if
a trusted certificate has expired, the handshake fails, even though the expired
certificate is trusted.  Sun's JSSE verifies the certificate chain up to the
trusted certificate.  Verification stops when it reaches a trusted certificate
and the trusted certificate and beyond are not verified.</li>
<li>The IBM JSSE implementation returns the same set of supported
ciphers for the methods <tt class="xph">getDefaultCiphersSuites()</tt> and <tt class="xph">getSupportedCipherSuites()</tt>.
 Sun's JSSE <tt class="xph">getDefaultCipherSuites()</tt> returns the list of
cipher suites that provide confidentiality protection and server authentication
(that is, no anonymous cipher suites).  Sun's <tt class="xph">getEnabledCipherSuites()</tt> returns
the entire list of cipher suites that Sun supports.</li>
<li>For Sun's implementation, DSA server certificates can use
only *_DH*_* cipher suites.  For the IBM implementation, if the server has
a DSA certificate only and only RSA* ciphers are enabled, the connection succeeds
with an RSA cipher.  DSA will be used for authentication and ephemeral RSA
will be used for the key exchange.</li>
<li>The IBM SDK supports the NTLM authentication
scheme. To switch off NTLM authentication, specify the system property <em>com.ibm.NONTLM</em>.</li>
<li>To use a hardware keystore or truststore with IBM's hardware
crypto provider by means of system properties, set the <strong>javax.net.ssl.keyStoreType</strong> and <strong>javax.net.ssl.trustStoreType</strong> system properties, respectively, to "PKCS11IMPLKS".  For the Sun implementation,
the system property is set to "PKCS11".</li>
<li>The IBM JSSE Provider can be enabled to run in FIPS mode.
 The Sun JSSE cannot.</li></ul>
<a name="ibmjsse2_new"></a>
<h2 id="ibmjsse2_new"><a href="#ToC_27">What's new?</a></h2>
<p>The following change takes effect from v5.0 Service Refresh
5:</p>
<ul>
<li>When IBMJSSE2 is used as a server, if the SSLv3 protocol is to be used
for the handshake, it will no longer agree to use any of the AES cipher suites.
Previously, the selection of the cipher suite was independent of the protocol
selected so you could do an old-style SSLv3 handshake with a more modern AES
cipher suite. The TLS protocol is not affected by this change. This change
was required to support Microsoft Vista clients.</li></ul>
<p>The following changes have been added in v5.0 
</p>
<ul>
<li>The IBMJSSE Provider is removed for v5.0. Use the IBMJSSE2 Provider instead.</li>
<li>The IBMJSSE2 implementation now uses the Java Cryptography Extension (JCE)
for all its cryptographic algorithms.  In v1.4.2, only the IBMJCE providers
were supported.</li>
<li>The IBMJSSE2 implementation now supports any hardware crypto provider.
 This support will require applications that ran in v1.4.2 using the IBMPKCS11Impl
provider to use a configuration file in order to run successfully.</li>
<li>SSLEngine (non-blocking I/O) allows SSL/TLS applications to choose their
own I/O and compute models.</li>
<li>Enhanced TrustManager support HTTP/HTTPS enhancements.</li>
<li>New and updated Methods and Classes.</li>
<li>Kerberos cipher suites are available, if supported by the operating system.</li></ul>
<p>The IBMJSSE2 Provider was new for v1.4.2.</p>
<a name="ibmjsse2_doc"></a>
<h2 id="ibmjsse2_doc"><a href="#ToC_28">Documentation</a></h2>
<p>For detailed information, including API documentation and samples, see <a href="http://www.ibm.com/developerworks/java/jdk/security/index.html" target="_blank">http://www.ibm.com/developerworks/java/jdk/security/index.html</a>.</p>
<a name="ibmpkcs11"></a>
<h1 id="ibmpkcs11"><a href="#ToC_29"> IBMPKCS11Impl Provider</a></h1>
<div>
<p>The IBMPKCS11Impl Provider uses the Java
Cryptography Extension (JCE) and Java Cryptography Architecture (JCA) frameworks
to add the ability to use hardware cryptography through the Public Key Cryptographic
Standards #11 (PKCS #11) standard.</p></div>
<p>This provider takes advantage of hardware cryptography within the existing
JCE architecture and gives Java programmers the significant security and performance
advantages of hardware cryptography with minimal changes to existing Java
applications. Because the complexities of hardware cryptography are handled
within the normal JCE, advanced security and performance using hardware cryptographic
devices is available readily.</p>
<p>PKCS#11 is a standard that provides a common application interface to cryptographic
services on various platforms through several hardware cryptographic devices.
See the IBMPKCS11Impl provider user guide for a list of supported devices.</p>
<a name="ibmpkcs11_differences_sun"></a>
<h2 id="ibmpkcs11_differences_sun"><a href="#ToC_30">Differences between IBM and Sun versions of IBMPKCS11Impl</a></h2>
<p>The most significant difference between the Sun PKCS11 provider
and the IBM PKCS11Impl provider is in the area of keystore.
Sun has a keystore named PKCS11 and IBM has one called IBMPKCS11KS.
Sun requires that all trusted certificates have the attribute <strong>CKA_TRUSTED</strong> set
to true. The IBM keystore assumes that any certificates on the device are
trusted. So, this assumption should allow IBM's keystore to work with data
that was saved using the Sun PKCS11 provider keystore,
but not the other way around.</p>
<a name="ibmpkcs11_new"></a>
<h2 id="ibmpkcs11_new"><a href="#ToC_31">What's new?</a></h2>
<p>The following changes were made in v5.0.</p>
<p>IBMPKCS11Impl has been updated to allow
more algorithms and to allow the Sun 5.0 methods of initialization of the
provider. The new algorithms are:  
</p>
<ul>
<li>AES</li>
<li>Diffie-Hellman</li>
<li>RC4, also known as ArcFour</li>
<li>Blowfish</li>
<li>SHA-256</li>
<li>SHA-384</li>
<li>SHA-512</li>
<li>SHA256withRSA</li>
<li>SHA384withRSA</li>
<li>SHA512withRSA</li>
<li>HmacMD5</li>
<li>HmacSHA1</li>
<li>HmacSHA256</li>
<li>HmacSHA384</li>
<li>HmacSHA512</li></ul>
<p>In v5.0, the ability to pass in a configuration file to the
provider is added. This configuration file can contain a significant amount
of information about the device; for example, what it should or should not
do. After the provider is created, the application can log in to the card
in different ways. Some devices allow you to perform some cryptographic functions
without logging into the device. The v1.4.2 ways to initialize the device
still work. However, you can no longer have more than one of these providers
at a time. Instead, with this release, you can initialize more than one IBMPKCS11Impl provider
using the 5.0 configuration file and login methods.</p>
<p>The classes DESPKCS11KeyParameterSpec and DESedePKCS11KeyParameterSpec have
been deprecated. Use the GeneralPKCS11KeyParameterSpec class for all symmetric
key types (for instance, DES, DESede, AES, RC4, Blowfish).</p>
<p>The IBMPKCS11Impl Provider was new for v1.4.2.</p>
<a name="ibmpkcs11_doc"></a>
<h2 id="ibmpkcs11_doc"><a href="#ToC_32">Documentation</a></h2>
<p>For detailed information, including API documentation, see the developerWorks
Web site at  <a href="http://www.ibm.com/developerworks/java/jdk/security/index.html" target="_blank">http://www.ibm.com/developerworks/java/jdk/security/index.html</a>.</p>
<a name="ibmjcefips"></a>
<h1 id="ibmjcefips"><a href="#ToC_33"> IBMJCEFIPS Provider</a></h1>
<div>
<p>The IBM Java JCE (Java Cryptographic Extension) FIPS Provider (IBMJCEFIPS)
for multi-platforms is a scalable, multi-purpose cryptographic module that
supports FIPS-approved cryptographic operations through Java APIs.</p></div>
<p>The IBMJCEFIPS includes the following Federal Information Processing Standards
(FIPS) 140-2 [Level 1] compliant components:  
</p>
<ul>
<li>IBMJCEFIPS for Solaris,</li>
<li>IBMJCEFIPS for HP</li>
<li>IBMJCEFIPS for Windows</li>
<li>IBMJCEFIPS for z/OS</li>
<li>IBMJCEFIPS for AS/400</li>
<li>IBMJCEFIPS for Linux (Red Hat and SUSE)</li></ul><p class="indatacontent">To meet the requirements specified in the FIPS publication 140-2, the
encryption algorithms used by the IBMJCEFIPS Provider are isolated into the
IBMJCEFIPS Provider cryptographic module, which you can access using the product
code from the Java JCE framework APIs. Because the IBMJCEFIPS Provider uses
the cryptographic module in an approved manner, the product complies with
the FIPS 140-2 requirements. 
</p>
<a name="wq12"></a>
<table id="wq12" width="100%" summary="" border="1" frame="border" rules="all">
<thead valign="bottom">
<tr>
<th id="wq13" align="left" valign="top">Type</th>
<th id="wq14" align="left" valign="top">Algorithm</th>
<th id="wq15" align="left" valign="top">Specification</th>
</tr>
</thead>
<tbody valign="top">
<tr>
<td headers="wq13">Symmetric Cipher</td>
<td headers="wq14">AES (ECB, CBC, OFB, CFB and PCBC)</td>
<td headers="wq15">FIPS 197</td>
</tr>
<tr>
<td headers="wq13">Symmetric Cipher</td>
<td headers="wq14">Triple DES (ECB, CBC, OFB, CFB and PCBC)</td>
<td headers="wq15">FIPS 46-3</td>
</tr>
<tr>
<td headers="wq13">Message Digest</td>
<td headers="wq14">
<div class="lines">SHA1<br />
SHA-256<br />
SHA-384<br />
SHA-512<br />
HMAC-SHA1<br />
</div></td>
<td headers="wq15">
<div class="lines">FIPS 180-2<br />
<br />
<br />
<br />
FIPS 198a<br />
</div></td>
</tr>
<tr>
<td headers="wq13">Random Number Generator</td>
<td headers="wq14">FIPS 186-2 Appendix 3.1</td>
<td headers="wq15">FIPS 186-2</td>
</tr>
<tr>
<td headers="wq13">Digital Signature</td>
<td headers="wq14">DSA (512 - 1024)</td>
<td headers="wq15">FIPS 186-2</td>
</tr>
<tr>
<td headers="wq13">Digital Signature</td>
<td headers="wq14">RSA (512 - 2048)</td>
<td headers="wq15">FIPS 186-2</td>
</tr>
</tbody>
</table>
<p>In addition, the IBMJCEFIPS supports the following unapproved algorithms: 
</p>
<a name="wq16"></a>
<table id="wq16" width="100%" summary="" border="1" frame="border" rules="all">
<thead valign="bottom">
<tr>
<th id="wq17" width="33%" align="left" valign="top">Type</th>
<th id="wq18" width="32%" align="left" valign="top">Algorithm</th>
<th id="wq19" width="33%" align="left" valign="top">Specification</th>
</tr>
</thead>
<tbody valign="top">
<tr>
<td headers="wq17">Asymmetric Cipher</td>
<td headers="wq18">RSA</td>
<td headers="wq19">PKCS#1</td>
</tr>
<tr>
<td headers="wq17">Key Agreement</td>
<td headers="wq18">Diffie-Hellman</td>
<td headers="wq19">PKCS #3 (Allowed in Approved mode)</td>
</tr>
<tr>
<td headers="wq17">Digital Signature</td>
<td headers="wq18">	DSAforSSL</td>
<td headers="wq19">Allowed for use within the TLS protocol</td>
</tr>
<tr>
<td headers="wq17">Digital Signature</td>
<td headers="wq18">	RSAforSSL</td>
<td headers="wq19">Allowed for use within the TLS protocol</td>
</tr>
<tr>
<td headers="wq17">Message Digest</td>
<td headers="wq18">	MD5</td>
<td headers="wq19">FIPS 180-2</td>
</tr>
<tr>
<td headers="wq17">Random Number Generation</td>
<td headers="wq18">Universal Software Based  Random Number Generator</td>
<td headers="wq19">Available upon request from IBM. Patented by
IBM, EC Pat. No. EP1081591A2, U.S. pat. Pend.</td>
</tr>
</tbody>
</table>
<a name="wq20"></a>
<div class="note-noindent" id="wq20">
<span class="notetitle">Important:</span> <span class="notebody"> The com.ibm.crypto.fips.provider.IBMJCEFIPS class
does not include a keystore (such as JKS or JCEKS) because of FIPS requirements
and algorithms. Therefore, if you are using com.ibm.crypto.fips.provider.IBMJCEFIPS
and require JKS, you must specify the com.ibm.crypto.provider.IBMJCE in the
provider list.</span></div>
<p>For more detailed information on the FIPS certified provider IBMJCEFIPS,
see the <em>IBM Java JCE FIPS 140-2 Cryptographic Module Security Policy</em>.
 For usage information and details of the API, see the <em>IBM Java JCE FIPS
(IBMJCEFIPS) Cryptographic Module API</em> document. These documents are available
at <a href="http://www.ibm.com/developerworks/java/jdk/security/index.html" target="_blank">http://www.ibm.com/developerworks/java/jdk/security/index.html</a>.</p>
<a name="ibmjcefips_differences_sun"></a>
<h2 id="ibmjcefips_differences_sun"><a href="#ToC_34">Differences between IBM and Sun versions of IBMJCEFIPS</a></h2>
<p>Sun does not provide IBMJCEFIPS.</p>
<a name="ibmjcefips_new"></a>
<h2 id="ibmjcefips_new"><a href="#ToC_35">What's new?</a></h2>
<p>No updates since v1.4.2.</p>
<a name="ibmjcefips_doc"></a>
<h2 id="ibmjcefips_doc"><a href="#ToC_36">Documentation</a></h2>
<p>For detailed information, including API documentation and Security Policy,
see the developerWorks Web site, at <a href="http://www.ibm.com/developerworks/java/jdk/security/index.html" target="_blank">http://www.ibm.com/developerworks/java/jdk/security/index.html</a>.</p>
<a name="sasl"></a>
<h1 id="sasl"><a href="#ToC_37"> IBM SASL Provider</a></h1>
<div>
<p>Simple Authentication and Security Layer, or SASL, is an Internet
standard (RFC 2222) that specifies a protocol for authentication and optional
establishment of a security layer between client and server applications.
SASL defines how authentication data is to be exchanged but does not itself
specify the contents of that data. It is a framework into which specific authentication
mechanisms that specify the contents and semantics of the authentication data
can fit.</p></div>
<p>The Java SASL API defines classes and interfaces for applications that
use SASL mechanisms. It is defined to be mechanism-neutral: the application
that uses the API need not be hardwired into using any particular SASL mechanism.
The API supports both client and server applications. It allows applications
to select the mechanism to use based on desired security features, such as
whether they are susceptible to passive dictionary attacks or whether they
accept anonymous authentication. The Java SASL API also allows developers
to use their own, custom SASL mechanisms. SASL mechanisms are installed by
using the Java Cryptography Architecture (JCA).</p>
<p>The IBMSASL provider supports the following client and server mechanisms.</p>
<dl>
<dt class="bold">Client mechanisms </dt>
<dd> 

<ul>
<li>PLAIN (RFC 2595). This mechanism supports cleartext username/password
authentication.</li>
<li>CRAM-MD5 (RFC 2195). This mechanism supports a hashed username/password
authentication scheme.</li>
<li>DIGEST-MD5 (RFC 2831). This mechanism defines how HTTP Digest Authentication
can be used as a SASL mechanism.</li>
<li>GSSAPI (RFC 2222). This mechanism uses the GSSAPI for obtaining authentication
information. It supports Kerberos v5 authentication.</li>
<li>EXTERNAL (RFC 2222). This mechanism obtains authentication information
from an external channel (such as TLS or IPsec).</li></ul>
</dd>
<dt class="bold">Server mechanisms </dt>
<dd> 

<ul>
<li>CRAM-MD5</li>
<li>DIGEST-MD5</li>
<li>GSSAPI (Kerberos v5)</li></ul>
</dd>
</dl>
<a name="sasl_differences_sun"></a>
<h2 id="sasl_differences_sun"><a href="#ToC_38">Differences between Sun and IBM SASL Provider</a></h2>
<p>Only the package names, for example com.ibm.security.sasl,
and the provider name are different from the Sun Implementation: com.ibm.security.sasl.IBMSASL.</p>
<a name="sasl_new"></a>
<h2 id="sasl_new"><a href="#ToC_39">What's new</a></h2>
<p>The IBM SASL Provider is new for v5.0</p>
<a name="sasl_doc"></a>
<h2 id="sasl_doc"><a href="#ToC_40">Documentation</a></h2>
<p>Detailed information, including API documentation and samples, is on the
developerWorks Web site, at <a href="http://www.ibm.com/developerworks/java/jdk/security/index.html" target="_blank">http://www.ibm.com/developerworks/java/jdk/security/index.html</a>.</p>
<a name="keycert"></a>
<h1 id="keycert"><a href="#ToC_41"> Key Certificate Management utilities</a></h1>
<div>
<p>Uses of the Key Certificate Management utilities.</p></div>
<p>The Key Certificate Management utilities make up a set of packages used
to: 
</p>
<ul>
<li>Access keys and certificates stored in any format</li>
<li>Extract information from a KeyStore, given a Subject Key Identifier (SKI)
and a set of certificate generation APIs, to create a self-signed certificate</li>
<li>Generate a CertificateRequest</li>
<li>Obtain a certificate signed by a CA</li></ul>
<p>The Key Certificate Management utilities can: 
</p>
<ul>
<li>Generate a CertificateRequest, and submit the request to a CA using the
Java PKI to sign a certificate and then receive the signed certificate</li>
<li>Generate a PKCS10 request</li>
<li>Generate a Self-Signed Certificate</li>
<li>Revoke a signed certificate from a CA using the Java PKI</li>
<li>Import certificates from the input stream to the KeyStore or export certificates
from the KeyStore to the output stream</li>
<li>Copy a keystore from one keystore format to another keystore format.</li>
<li>Extract information from a KeyStore given a Subject Key Identifier</li></ul>
<p>The Subject Key Identifier is specified in RFC 3820, Section 4.2.1.2, <a href="http://www.faqs.org/rfcs/rfc3820.html" target="_blank">http://www.faqs.org/rfcs/rfc3820.html</a>.</p>
<a name="keycert_new"></a>
<h2 id="keycert_new"><a href="#ToC_42">What's new</a></h2>
<p>The Key Certificate Management utilities are new for Version 5.0, Service
Refresh 1.</p>
<a name="keycert_doc"></a>
<h2 id="keycert_doc"><a href="#ToC_43">Documentation</a></h2>
<p>The <em>Key Certificate Management How-to Guide</em> and Javadoc are on the
developerWorks Web site, at <a href="http://www.ibm.com/developerworks/java/jdk/security/index.html" target="_blank">http://www.ibm.com/developerworks/java/jdk/security/index.html</a>.</p>
<a name="notices"></a>
<h1 id="notices"><a href="#ToC_44">Notices</a></h1>
<p> This information was developed for products and services offered in the
U.S.A.   IBM may
not offer the products, services, or features discussed in this document in
other countries. Consult your local IBM representative for information on the
products and services currently available in your area. Any reference to an IBM product,
program, or service is not intended to state or imply that only that IBM product, program,
or service may be used. Any functionally equivalent product, program, or service
that does not infringe any IBM intellectual property right may be used instead.
However, it is the user's responsibility to evaluate and verify the operation
of any non-IBM product, program, or service.</p>
<p>IBM may
have patents or pending patent applications covering subject matter in this
document. The furnishing of this document does not give you any license to
these patents. You can send license inquiries, in writing, to:</p>
<ul class="simple">
<li>IBM Director
of Licensing</li>
<li>IBM Corporation</li>
<li>North Castle Drive, Armonk</li>
<li>NY 10504-1758 U.S.A.</li></ul>
<p>For license inquiries regarding double-byte (DBCS) information, contact
the IBM Intellectual
Property Department in your country or send inquiries, in writing, to:</p>
<ul class="simple">
<li>IBM World
Trade Asia Corporation Licensing</li>
<li>2-31 Roppongi 3-chome, Minato-ku</li>
<li>Tokyo 106-0032, Japan</li></ul>
<p>The following paragraph does not apply to the United Kingdom or any other
country where such provisions are inconsistent with local law:</p>
<p>INTERNATIONAL BUSINESS MACHINES CORPORATION PROVIDES THIS PUBLICATION "AS
IS" WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESS OR IMPLIED, INCLUDING, BUT
NOT LIMITED TO, THE IMPLIED WARRANTIES OF NON-INFRINGEMENT, MERCHANTABILITY
OR FITNESS FOR A PARTICULAR PURPOSE. Some states do not allow disclaimer of
express or implied warranties in certain transactions, therefore, this statement
may not apply to you.</p>
<p>This information could include technical inaccuracies or typographical
errors. Changes are periodically made to the information herein; these changes
will be incorporated in new editions of the information. IBM may make improvements
and/or changes in the product(s) and/or the program(s) described in this information
at any time without notice.</p>
<p>Any references in this information to non-IBM Web sites are provided for
convenience only and do not in any manner serve as an endorsement of those
Web sites. The materials at those Web sites are not part of the materials
for this IBM product
and use of those Web sites is at your own risk.</p>
<p>IBM may
use or distribute any of the information you supply in any way it believes
appropriate without incurring any obligation to you.</p>
<p>Licensees of this program who wish to have information about it for the
purpose of enabling (i) the exchange of information between independently
created programs and other programs (including this one) and (ii) the mutual
use of the information which has been exchanged, should contact:</p>
<ul class="simple">
<li>JIMMAIL@uk.ibm.com</li>
<li>[Hursley Java Technology Center (JTC) contact]</li></ul>
<p>Such information may be available, subject to appropriate terms and conditions,
including in some cases, payment of a fee.</p>
<p>The licensed program described in this document and all licensed material
available for it are provided by IBM under terms of the IBM Customer Agreement, IBM International
Program License Agreement or any equivalent agreement between us.</p>
<p>Any performance data contained herein was determined in a controlled environment.
Therefore, the results obtained in other operating environments may vary significantly.
Some measurements may have been made on development-level systems and there
is no guarantee that these measurements will be the same on generally available
systems. Furthermore, some measurement may have been estimated through extrapolation.
Actual results may vary. Users of this document should verify the applicable
data for their specific environment.</p>
<p>Information concerning non-IBM products was obtained from the suppliers
of those products, their published announcements or other publicly available
sources. IBM has
not tested those products and cannot confirm the accuracy of performance,
compatibility or any other claims related to non-IBM products. Questions on
the capabilities of non-IBM products should be addressed to the suppliers
of those products.</p>
<a name="trademarks"></a>
<h2 id="trademarks"><a href="#ToC_45">Trademarks</a></h2>
<p>IBM is a trademark of International Business Machines
Corporation in the United States, or other countries, or both.</p>
<p>IBM is a trademark of International Business Machines
Corporation in the United States, or other countries, or both.</p>
<p>Java and
all Java-based trademarks and logos are trademarks or registered trademarks
of  Sun Microsystems, Inc. in the United States, other countries, or both.</p>
<p>Microsoft<sup>(R)</sup>, Windows<sup>(R)</sup> and the Windows logo
are trademarks of Microsoft Corporation in the United States, other
countries, or both.</p>
<p>Other company, product, or service names may be trademarks or service marks
of others.</p>
<p>This product is also based in part on the work of the FreeType
Project. For more information about Freetype, see <a href="http://www.freetype.org" target="_blank">http://www.freetype.org</a>.</p>
<a id="Bot_Of_Page" name="Bot_Of_Page"></a>
</body>
</html>
