IKYS020I   The specified PathLength value {none | value1} conflicts with the CA path length constraint value value2.

Explanation

During PKI Services initialization, the value specified for PathLength in the CertPolicy section of the pkiserv.conf file is validated against the path length constraint value in the basic constraints extension of the PKI Services CA certificate. The PathLength value must be positive and smaller than the path length constraint value of the CA certificate. If the PathLength value in the message is none, the CA certificate has a path length constraint value but the PathLength keyword was not specified in the pkiserv.conf file.

System action

PKI Services stops.

System programmer response

Specify the value of the PathLength keyword in the pkiserv.conf file, or correct it to a value smaller than the CA value shown in the message (value2), and restart PKI Services. For more information about the PathLength keyword, see (Optional) Steps for updating the configuration file.