I know very little about GSKit...

There is a security advisory for another IBM product and the team that supports this product wants to upgrade it which will upgrade GSKit. They're asking if upgrading GSKit would impact DB2. I checked DB2 IC/technotes and based on my understanding, GSKit is shipped/installed with DB2 server and GSKit under sqllib (pointed by LIBPATH) is for use by DB2 server/applications.

It looks like DB2 uses its own GSKit libraries and not the system/global GSKit, so there should be no impact. But when I check GSK version under sqllib and /usr/opt/ibm, gskit location is the same - /usr/opt/ibm/gsk8_64/lib64


Example from v9.7 server:

Code:
host:/xxx/db2/db2inst1/sqllib/gskit/bin>$ ./gsk8ver_64 | more
Details of gskit in /usr/opt/ibm/gsk8_64/lib64

libgsk8sys_64.so
============
@(#)CompanyName:      IBM Corporation
@(#)LegalTrademarks:  IBM
@(#)FileDescription:  IBM Global Security Toolkit
@(#)FileVersion:      8.0.14.27
....


host:/usr/opt/ibm/gsk8_64/bin>$ ./gsk8ver_64 | more
Details of gskit in /usr/opt/ibm/gsk8_64/lib64

libgsk8sys_64.so
============
@(#)CompanyName:      IBM Corporation
@(#)LegalTrademarks:  IBM
@(#)FileDescription:  IBM Global Security Toolkit
@(#)FileVersion:      8.0.14.27
....


host: $ lslpp -l GSKit*
  Fileset                      Level  State      Description
  ----------------------------------------------------------------------------
Path: /usr/lib/objrepos
  GSKit8.gskcrypt32.ppc.rte
                           8.0.14.27  COMMITTED  IBM GSKit Cryptography Runtime
  GSKit8.gskcrypt64.ppc.rte
                           8.0.14.27  COMMITTED  IBM GSKit Cryptography Runtime
  GSKit8.gskssl32.ppc.rte  8.0.14.27  COMMITTED  IBM GSKit SSL Runtime With
                                                 Acme Toolkit
  GSKit8.gskssl64.ppc.rte  8.0.14.27  COMMITTED  IBM GSKit SSL Runtime With
                                                 Acme Toolkit


Can someone please clarify if DB2 uses its own GSKit libraries and not the system/global GSKit libraries? Does upgrading system/global GSKit have any impact to DB2?