z/OS Cryptographic Services ICSF Application Programmer's Guide
Previous topic | Next topic | Contents | Index | Contact z/OS | Library | PDF


Retained Key Delete (CSNDRKD and CSNFRKD)

z/OS Cryptographic Services ICSF Application Programmer's Guide
SA22-7522-16

Use the retained key delete callable service to delete a key that has been retained within the PCICC, PCIXCC, CEX2C, or CEX3C. This service also deletes the record that contains the associated key token from the PKDS. It also allows the deletion of a retained key in the PCICC, PCIXCC, CEX2C, or CEX3C even if there isn't a PKDS record, or deletion of a PKDS record for a retained key even if the PCICC, PCIXCC, CEX2C, or CEX3C holding the retained key is not online. Use the rule_array parameter specifying the FORCE keyword and serial number of the PCICC, PCIXCC, CEX2C, or CEX3C that contains the retained key to be deleted. If a PKDS record exists for the same label, but the serial number doesn't match the serial number in rule_array, the service will fail. If any applications still need the public key, use public key extract to create a public key token prior to deletion of the retained key.

The callable service name for AMODE(64) invocation is CSNFRKD.

Go to the previous page Go to the next page




Copyright IBM Corporation 1990, 2014