BusinessConnect Certificate Rotation - TIBCO BusinessConnect 7.5.0 hotfix 2 is now available

book

Article ID: KB0138659

calendar_today

Updated On:

Products Versions
TIBCO BusinessConnect 7.5.0

Description

Customers entitled to Support will be able to download the Hotfix from the TIBCO Support Customer Portal Web UI using their username and password for the TIBCO Support Web page. Once logged on they can find the Hotfix under the Download Menu:

AvailableDownloads/BusinessConnect/7.5.0/hotfix-02

For instructions on how can TIBCO customers download / access all GA hotfixes , Refer to Article KB0070772 :  https://support.tibco.com/s/article/hotfix.

Listed below is a summary of updates included. Refer to the associated readme document for any additional information.

================================================================================
Closed Issues in 7.5.0_HF-002 (This Release)
BC-12099 Support BC Cert Rotation in Key Vault Management

================================================================================
Closed Issues in 7.5.0_HF-001

BC-11996 Interior Server doesn't start due to a missing library
The issue was identified as the BC 7.5.0 version using an outdated libstdc++.so.5 library, which was replaced by libstdc++.so.6 and addressed in BC 7.5.0 HF-1.

BC-12056 Upgrade Tomcat to latest version
Tomcat has been updated to latest version 9.0.117 which has the fix for vulnerabilities found in previous version.

BC-12058 Upgrade Log4j2 to latest version
Log4j has been upgraded to 2.25.4 which has the fix for vulnerabilities found in previous version.

BC-11997  Can't connect to SMTP server
Fixed SMTP ssl email connectivity issue for credential expiry alerter, tcm emails and email transport with STARTTLS AND TLS 1.2, 1.3.

BC-12004 Error while exporting the installation
There was as issue with exporting csx due to limitation of the TripleDES algorithm in FIPS mode.This has fixed.

BC-11995
With Business Connect 7.5.0 HF01, java system property variable support has been added for
license activation using variable "java.property.TIB_ACTIVATION". The user must map either a
TAS URL or an IPA directory path to enforce licensing when no license system
property value is specified in the .tra files (bcengine.tra).

Note: User can also use java.property.license.url property to enforce licensing.

Note:Following the upgrade of the WSS4J libraries in ebXML 6.4.0 HF-001, encrypted SOAP transactions are currently failing for SOAP protocol.
(This issue is only encountered when you install ebXML 6.4.0 HF-001 protocol and SOAP protocol 7.2.0)

Environment

all platforms

Issue/Introduction

TIBCO BusinessConnect 7.5.0 hotfix 2 is now available.  This hotfix implements a new certificate rotation scheme to help customers manage the upcoming 47-day certificate expiration that is currently being implemented by the CA/Browser Forum that is to take full effect in 2029.

This feature allows the server certificate for the BusinessConnect Gateway Server (GS) to be updated automatically from an external key vault.  At the present time, only Azure Key Vault is supported, but we may consider others based on customer interest.

The instructions for implementation are documented in the attachment to this KB article.

Attachments

cert-rotation-howto.pdf get_app