z/OS Cryptographic Services System SSL Programming
Previous topic | Next topic | Contents | Contact z/OS | Library | PDF


8

z/OS Cryptographic Services System SSL Programming
SC14-7495-00

8
Certificate validation error.

Explanation

An error is detected while validating a certificate. This error can occur if a root CA certificate is not found in the key database, SAF key ring, or z/OS® PKCS #11 token or if the certificate is not marked as a trusted certificate or if the certificate requires an algorithm or key size that is non-FIPS while executing in FIPS mode.

User response

Verify that the root CA certificate is in the key database, SAF key ring, or z/OS PKCS #11 token and is marked as trusted. Check all certificates in the certification chain and verify that they are trusted and are not expired. If the error occurred while executing in FIPS mode, check that only FIPS algorithms and key sizes are used by the certificate. If using RACF® key rings and the DIGTCERT and DIGTRING classes are RACLIST'ed, issue the SETROPTS RACLIST (DIGTCERT, DIGTRING) REFRESH command to refresh the profiles to ensure that the latest changes are available. Collect a System SSL trace that contains the error and then contact your service representative if the problem persists.

For more information, see System SSL and FIPS 140-2.

Go to the previous page Go to the next page




Copyright IBM Corporation 1990, 2014