Messages
PKI Services message
numbers begin with the three-character component prefix (IKY),
followed by a fourth character that identifies the subcomponent. The
following table lists the characters representing various subcomponents
and describes where the messages appear.
Character | Meaning | Component producing messages | Where messages appear |
---|---|---|---|
C | CORE | Core subcomponent | PKI Services log |
D | DB | Database accessing subcomponent | PKI Services log |
I | INTERFACE | PKISERV CGIs or JSPs | In the user's web browser window |
L | LDAP | LDAP bind subcomponent | PKI Services log |
O | POLICY | Certificate creation and revocation policy subcomponent | PKI Services log |
P | PKID | PKI Services daemon address space controller |
|
S | SAF | SAF interfacing subcomponent | PKI Services log |
U | UTILITY | Utility programs | UNIX standard error (stderr) |
Characters five through seven are numeric. The eighth character
is the message type:
Character | Meaning | Action required |
---|---|---|
I | Informational (status message) | No action required |
E | Eventual action | Possible problem that might require eventual action |
A | Action required | Problem that requires immediate attention |
For information about setting messages options using environment variables, see _PKISERV_MSG_LOGGING.
- IKYC001I
Error nnnn action-being-performed: error-code-description - IKYC002I
Error nnnn returned from CP_NewCertCreate: error-code-description - IKYC003I
Error nnnn registering the next CRL cutting job: error-code-description - IKYC004I
Error nnnn creating and sending CRLs: error-code-description - IKYC005I
Error nnnn posting {User | CA} Certificate to LDAP for distinguished-name: error-code-description - IKYC007I
Error nnnn posting {CRL | ARL} to LDAP: error-code-description - IKYC008I
Error nnnn creating an entry for {CA Certificate | User Cert | CRL | ARL} to LDAP for distinguished-name: error-code-description - IKYC009I
LDAP post unsuccessful for object id = nnnn, state = nnnn, status = nnnn: status-code-description - IKYC010I
Error nnnn returned from action-being-performed: error-code-description - IKYC011I
Bad TimeBetweenCRLs value in pkiserv.conf file: incorrect-value - IKYC012I
Bad CRLDuration value in pkiserv.conf file: incorrect-value - IKYC013I
Bad CreateInterval value in pkiserv.conf file - IKYC014I
Bad RemoveCompletedReqs or RemoveInactiveReqs value in pkiserv.conf file - IKYC015I
Bad PostInterval value in pkiserv.conf file - IKYC016I
action-being-performed returned nnnn in sub-function: error-code-description - IKYC017I
JNH_inquire_certreq_startdate (object-id) found neither certificate request nor response (nnnn): error-code-description - IKYC018I
{read | get_value} of certificate-or-CRL-extension-name returned nnnn: error-code-description - IKYC020I
Retrieving CA value failed nnnn: error-code-description - IKYC021I
CRL claims to have only User and only CA certs - IKYC022I
Invalid type for object object-id in JNH_set_revreq_invalidityDate: error-code-description - IKYC023I
Request index (index-number) greater than number of revocations (nnnn) in JNH_set_revreq_invalidityDate - IKYC024I
Failed to schedule event in nnnn seconds, status = nnnn: error-code-description - IKYC025I
Failed to schedule event status = nnnn: error-code-description - IKYC026I
Deleting {inactive | completed} object object-id. Last changed at YYYY/MM/DD HH:MM:SS - IKYC027I
Removing certificate post request after nnnn unsuccessful attempts - IKYC028I
Export for CertId certificate-id unsuccessful. Request is still pending approval or yet to be issued - IKYC029I
Error: certificate request type is invalid for certificate creation - IKYC030I
Error nnnn retrieving LDAP attribute-name attribute data from distinguished-name: error-code-description - IKYC031I
Error nnnn invoking sendmail with email address email-address retrieved from LDAP entry distinguished-name - IKYC032I
Error nnnn invoking sendmail with email address email-address provided by distinguished-name - IKYC033I
Error nnnn accessing {ReadyMessageForm | RejectMessageForm | ExpiringMessageForm | AdminNotifyForm | RenewCertForm} form-value - IKYC034I
Error issuing DEQ for resource resource-name, return code was return-code - IKYC035I
Bad ExpireWarningTime value in pkiserv.conf file - IKYC036I
Bad MaxSuspendDuration value in pkiserv.conf file - IKYC037I
Bad RemoveExpiredCerts or RemoveExpiredCertsAndKeys value in pkiserv.conf file - IKYC038I
Deleting expired certificate with serial number certificate-serial-number - IKYC039I
Bad CRLDistName value in pkiserv.conf file - IKYC040I
Bad CRLDistURIn value in pkiserv.conf file: LdapServern - IKYC041I
Bad CRLDistURIn value in pkiserv.conf file, exceeds the number of LDAP servers: LdapServern - IKYC042I
Bad CRLDistURIn format in pkiserv.conf file: CRLDistURIn - IKYC043I
Error nnnn in creating HFS file file name to store distribution point CRL - IKYC044I
Bad OCSPType value in pkiserv.conf file: value - IKYC045I
Unknown section or keyword in pkiserv.conf file: Section: [section], Keyword keyword - IKYC046I
Incorrect encoding of SCEP {request | PKCS10} - IKYC047I
Incorrect signature on SCEP {request | PKCS10} - IKYC048I
Unsupported algorithm in SCEP {request | PKCS10} - IKYC049I
SCEP signing certificate is {expired | revoked | not known to PKI Services} - IKYC050I
Requested SCEP certificate is {expired | revoked} - IKYC051I
Error 0xnnnn decrypting SCEP request - IKYC052I
Unsupported SCEP message type: nn - IKYC053I
SCEP key or name mismatch. SCEP transaction ID: SCEP-transaction-ID - IKYC054I
Incorrect reuse of SCEP transaction ID by client name: client-name - IKYC055I
Bad PREREGISTER section in certificate template, nickname: template-nickname - IKYC056I
Template missing from certificate templates file, nickname: template-nickname - IKYC057I
SCEP request for client name client-name rejected by {SemiauthenticatedClient | UnauthenticatedClient | SubsequentRequest | RenewalRequest} directive. - IKYC058I
No preregistration record found for SCEP request, client name: client-name - IKYC059I
No previous SCEP request found for SCEP GetCertInitial, client name: client-name - IKYC060I
CONSTANT section of certificate template, nickname: template-nickname contains an incorrect value: field-name=value - IKYC061I
Can not generate a certificate or a request with automatic renewal - IKYC062I
Can not enable or set up automatic renewal service for this request or certificate - IKYC063I
The list of the pending approval requests may not be complete - IKYC064I
Error nnnn invoking sendmail to notify the administrator with email address email-address of requests awaiting approval - IKYC065I
The value value specified for tag tag in template template-nickname is ignored - IKYC066I
Can not find the template for GENRENEW or REQRENEW with nickname: template-nickname - IKYC067I
An attempt to check if the templates file has been updated failed - IKYC068I
The templates file used may not be current - IKYC069I
The renewed certificate with transaction id transaction-id can not be sent to email address email-address - IKYC070I
The exit program {exit-program} was cancelled for {pre | post} processing - IKYC071I
Bad ExitTimeout value in pkiserv.conf file: {value} - IKYC072I
Unexpected return value from automatic renewal exit program {exit-program}: {unexpected-value} - IKYC073I
A problem was encountered during automatic renewal {pre | post} exit processing in program {exit program} - IKYC074I
Error nnnn accessing the required {ReadyMessageForm | RecoverForm} form-value - IKYC075I
Bad MaintRunTime value in pkiserv.conf file: {value} - IKYC076I
Bad MaintRunDays value in pkiserv.conf file: {value} - IKYC077I
Incorrect DBType value in pkiserv.conf file: value - IKYC078I
Incorrect DBSubsystem value in pkiserv.conf file: value - IKYC079I
Incorrect DBPackage value in pkiserv.conf file: value - IKYC080I
Error nnnn in creating UNIX file file_name to post CRL - IKYC081I
Error nnnn in reading UNIX file file_name to post CRL - IKYC082I
Bad URI CRL posting path and DP name value in pkiserv.conf file. - IKYC083I
Bad Large CRL posting path and DP name value in pkiserv.conf file. - IKYC084I
Large CRL posting object found while large CRL posting is not enabled. - IKYC086I
Requests for CA certificates are prohibited by path length constraint. - IKYC087I
Bad CRLWTONotification value in pkiserv.conf file: value - IKYC088I
CRL notification can not be enabled - IKYC089I
Invalid RSA key size value key-size-value specified for secure key generation. - IKYC090I
The number of required approvals value specified is not valid in certificate template, nickname: template-nickname. - IKYC801I
nnnn bytes of unconsumed data transferring extensions to certificate template - IKYC802I
Error nnnn {getting certificate-section from old certificate | setting certificate-section in certificate template | removing unnecessary extension from certificate template}: error-code-description - IKYC901I
Error nnnn initializing sub-function-name: error-code-description - IKYC902I
Error initializing the configuration file - IKYC903I
Error nnnn adding CA certificate to ICL: error-code-description - IKYD001I
Unable to open VSAM data set data-set-name - IKYD002I
DB2 RRSAF failure: Command rrsaf_cmd failed with return code 0xnnnn, reason code 0xnnnn - IKYD003I
DB2 SQL failure: Instruction SQL_instruction failed with SQLCODE sqlcode, SQLSTATE sqlstate - IKYI001I
Request denied by installation exit. RC = nn - IKYI002I
SAF Service IRRSPX00 Returned SAF RC = nn RACF RC = nn RACF RSN = nn {diagnostic-information} - IKYI003I
PKI Services CGI error in cgi-program-name: diagnostic-error-information - IKYI004I
Installation exit failed. RC = nn - IKYI005I
Invalid return type specified for certificate retrieval - IKYI006I
PKI Services JSP error in jsp-filename: diagnostic-information - IKYI007I
PKI Services web pages have not been configured for the client authentication needed for this function. - IKYK001I
Unexpected PKCS#11 function-name return code 0xnnnn. The request is not processed. - IKYK002I
PKCS#11 token unavailable for function-name with return code 0xnnnn . The request is not processed. - IKYK003I
{Certificate | key | PKCS12 package} with KEYID keyid is not deleted from TKDS object {Certificate object | Public key object | Private key object | Data object}. - IKYK004I
PKI Services can not generate certificates with secure keys. - IKYL001I
Error nnnn {importing | converting} LDAP username user's-distinguished-name: error-code-description - IKYL002I
LDAP bind to LDAP-server-domain-name:port failed, status = nnnn: status-code-description - IKYL003I
Incorrect value specified for LDAPBIND or FACILITY Class profile profile-name - IKYL004I
Bad LDAP Server value server-value in pkiserv.conf file - IKYO001I
Error nnnn {setting | getting} certificate-field {in certificate | from template}: error-code-description - IKYO002I
nnnn bytes of unconsumed data transferring certificate-field to certificate - IKYO003I
The certificate request failed validity checks. Status is nnnn: status-code-description - IKYO004I
action-being-performed returned nnnn: error-code-description - IKYO005I
PKI CA certificate last used serial number was regressed. - IKYO006I
Unsupported character(s) in the UserNoticeTextn value in the pkiserv.conf file - IKYP001E
ICSF UNAVAILABLE. CERTIFICATE PROCESSING SUSPENDED - IKYP002I
PKI SERVICES INITIALIZATION COMPLETE - IKYP003I
PKI SERVICES SHUTDOWN REQUESTED - IKYP004I
LOG OPTION PROCESSED: log-option - IKYP005I
INCORRECT LOG OPTION SPECIFIED - IKYP006I
UNRECOGNIZED PKI SERVICES COMMAND: SPECIFY LOG, DISPLAY, OR STOP - IKYP007E
INSUFFICIENT STORAGE AVAILABLE - IKYP008E
DIRECTORY POST UNSUCCESSFUL. LDAP DATA LIBRARY MODULE RC = nnnn - IKYP009I
PKI SERVICES IS STARTING, FMID product-fmid - IKYP010I
THE CONFIGURATION FILE NAME EXCEEDS THE MAXIMUM LENGTH OF nnnn CHARACTERS - IKYP011I
PKI SERVICES ADDRESS SPACE COULD NOT BE MADE NON-SWAPPABLE: ERROR nnnn - IKYP012I
SYSTEM FUNCTION function-name DETECTED ERROR - error-string - IKYP013I
PKI SERVICES DETECTED AN ERROR DURING INITIALIZATION: ERROR nnnn, REASON 0xnnnn - IKYP014I
PKI Services detected an error during termination: Error nnnn, Reason nnnn - IKYP015I
A PKI Services program call request failed: Error nnnn - IKYP016I
THE PKI SERVICES RUNTIME ENVIRONMENT COULD NOT BE INITIALIZED - IKYP017I
PKI SERVICES IS ALREADY RUNNING - IKYP018I
PKI Services initialization failed because the program is not APF authorized - IKYP019I
PKI Services dump created. - IKYP020I
PKI SERVICES RESTART REGISTRATION COMPLETE ON system-name - IKYP021I
PKI SERVICES RESTARTING ON system-name - IKYP022I
UNABLE TO REGISTER PKI SERVICES FOR RESTART: ERROR nnnn, REASON 0xnnnn - IKYP023I
PKI Services failed to format the display message - IKYP024I
PKI SERVICES DUMPING FOR ABEND abend-code RC nnnn - IKYP025I
PKI SERVICES SETTINGS: - IKYP026E
PKI SERVICES {CA | RA} CERTIFICATE EXPIRES ON yyyy/mm/dd - IKYP027E
ERROR ACCESSING PKI SERVICES CA CERTIFICATE - IKYP028E
PKI SERVICES DISTINGUISHED NAME OR KEY CHANGE ERROR - IKYP029I
PKI Services can only be started from a started procedure - IKYP030I
CRL APPROACHING MAXIMUM SIZE - IKYP031E
[RSA | DSA | ECC] signing key algorithm error - IKYP032I
PKI SERVICES DOES NOT HAVE RA CAPABILITY. SCEP PROCESSING SUSPENDED - IKYP033I
Incorrect value specified for CA domain name - IKYP034E
ICSF UNAVAILABLE. SCEP PROCESSING SUSPENDED - IKYP035I
Unsupported character(s) in CA’s name - IKYP036I
UNSUPPORTED CHARACTER(S) in RA’S NAME. SCEP PROCESSING SUSPENDED - IKYP037I
ONE OR MORE AUTOMATICALLY RENEWED CERTIFICATES CAN NOT BE SENT - IKYP038I
THE DIRECTORY OR FILE SPECIFIED EXCEEDS THE MAXIMUM LENGTH OF nnn CHARACTERS - IKYP039E
DIRECTORY POST UNSUCCESSFUL. ERROR CODE = nnnn - IKYP040I
PKI SERVICES DOES NOT HAVE KEY GENERATION CAPABILITY - IKYP041E
PKI SERVICES CA CERTIFICATE HAS nnnn SERIAL NUMBERS REMAINING. - IKYP042E
PKI SERVICES HAS NO REMAINING SERIAL NUMBERS FOR CERTIFICATE GENERATION. - IKYP043I
PKI Services CA certificate cannot be a Diffie-Hellman certificate. - IKYP044I
CRL NUMBER crl-serial-number PROCESSING {FOR CA DOMAIN cadomain} COMPLETED SUCCESSFULLY - IKYP045I
CRL NUMBER crl-serial-number PROCESSING {FOR CA DOMAIN cadomain} FAILED - IKYP046I
PERFORMANCE OF ADMINISTRATIVE FUNCTIONS MIGHT BE DEGRADED. SAF RC nn, RACF RC nn, RACF RSN nn - IKYS001I
Error nnnn {attaching | detaching} OCSF-service-provider-description - IKYS002I
Error nnnn in OCSF-API-name - IKYS003I
Error nnnn in getting {subject name | public key} from certificate: error-code-description - IKYS004I
Error 0xnnnn in opening key ring key-ring-name - IKYS005I
Error 0xnnnn in closing key ring - IKYS006I
Cannot delete the signing context - IKYS007I
No KeyRing value specified under SAF section in pkiserv.conf file - IKYS008I
Signing key is from unknown crypto service provider - IKYS009I
Profile for key ring key-ring-name not found - IKYS010I
Profile for key ring or default certificate or private key not found - IKYS011I
Error error-description in pthread_rwlock_rdlock/wrlock - IKYS012I
Error error-description in pthread_rwlock_unlock - IKYS013I
Cannot find the private key associated with the {default | RA} certificate - IKYS014I
Cannot find the {default | RA} certificate with private key associated in key ring - IKYS015I
RACF callable service, R_datalib, with function code nnnn returns with SAF return code=nnnn, RACF return code=nnnn, RACF reason code=nnnn - IKYS016I
Error 0xnnnn getting the {default | RA | CA} key - IKYS017I
Error 0xnnnn exporting the {default | RA} key - IKYS018I
Error 0xnnnn signing Certificate/CRL - IKYS019I
The CA certificate does not have path length constraint capabilities - IKYS020I
The specified PathLength value {none | value1} conflicts with the CA path length constraint value value2. - IKYS021I
The value specified for the PathLength keyword is not allowed. - IKYS022I
This CA is restricted from creating intermediate CA certificates. - IKYU001I
Unable to open file file-pathname for {READ | WRITE} - IKYU002I
SAF Service IRRSPX00 Returned SAF RC = nn RACF RC = nn RACF RSN = nn {diagnostic-information} - IKYU003I
Unknown field name found in SCEP data file, error-field-name - IKYU004I
Required field name {ClientName | Template} missing from input file at line nnn - IKYU005I
Duplicate ClientName=error-value entry found in SCEP data file at line nnn - IKYU006I
Preregistration record for ClientName=error-value not found in PKI Services - IKYU007I
Incorrect field-name=error-value entry found in SCEP data file - IKYU008I
Template nickname template not found in certificate templates file - IKYU009I
Out of memory - IKYU010I
Internal error occurred in function function-name: diagnostic-information - IKYU011I
System function function-name detected error -- error-string - IKYU012I
Unable to open message catalog message-catalog-filename -- error-string - IKYU013I
Incorrect command syntax. The error-value parameter is {unknown | missing | incorrectly specified} Usage: command-usage - IKYU014I
pkiprereg complete. nnn preregistration records processed. mmm successful. 000 errors found - IKYU015I
Template with nickname template cannot be used for preregistration - IKYU016I
pkiprereg complete. nnn passwords generated - IKYU017I
program-name terminated abnormally - IKYU018I
Conversion from VSAM to DB2 failed at record record-key in VSAM file vsam-file-name
Parent topic: Reference information