EZD1021I
No proposal chosen with KeyExchangeRule ( rule )
and KeyExchangeAction ( action )
EZD1022I
No proposal chosen with IpFilterRule ( rule )
and IpDynVpnAction ( action )
EZD1025I
Cannot be an initiator of a phase 2 Security Association
negotiation
EZD1026I
Cannot be a responder in a phase 2 Security Association negotiation
EZD1027I
Unsupported security endpoint identity type id_type
EZD1029I
Certificate usage value ( usage_value ) not supported
EZD1030I
The IKE daemon is not set up to support RSA signature mode
of authentication for stack stackname using the
local keyring
EZD1031I
DVIPA dvipa_addr added to the IKE daemon for stack stackname
EZD1032I
DVIPA dvipa_addr deleted from the IKE daemon for
stack stackname
EZD1033I
IKE configuration file parameter pname contains
value val which exceeds the maximum allowed character
length max_len on line linenum
EZD1034I
Phase 1 Security Association for DVIPA dvipa_addr is
already re-established with its remote security endpoint ip_addr
EZD1035I
Certificate cannot be used for RSA signature mode of authentication
EZD1036I
Phase 2 Security Association for DVIPA dvipa_address is
not re-established with remote security endpoint ip_addr
EZD1037I
The IKE daemon has no matching certificate entry for the
specified LocalSecurityEndpoint identity ( id_string )
and certificate authority ( X.500_string )
EZD1038I
Remote security endpoint's certificate is not valid because
the security association's lifetime is not in the certificate's lifetime
EZD1039I
IKE configuration file repeatable parameter pname was
specified more than the allowed maximum of max_num times
EZD1040I
Phase phase Security Association retransmit timeout
src IP : src_spec dest IP : dest_spec src port
: src_port dest port : dest_port protocol : protocol
EZD1041I
Error encountered when sending ike_event between
src IP : src_spec dest IP : dest_spec src
port : src_port dest port : dest_port protocol
: protocol - errno | errnojr | description
EZD1042I
IKE CONFIGURATION FILE ERROR : MODIFY REFRESH COMMAND IS
REJECTED - IKE DAEMON IS USING CONFIGURATION VALUES PRIOR TO COMMAND
EZD1043I
Unable to open message catalog ( catalog_name ) errno | errnojr | description
- default messages will be used
EZD1044I
The ID ( id_X.500_string ) sent by the remote security
endpoint in the ID payload does not match the subject name or any
of the subject alternate names in the certificate used by the remote
security endpoint to generate its signature
EZD1081I
Could not find the IpLocalStartAction named name
EZD1082I
Could not find the LocalDynVpnRule named name
EZD1083I
Local policy ( p1_action_name ) does not
allow local initiation of a phase 1 Security Association negotiation
EZD1085I
A message was discarded because it was received from a remote
peer behind an NAPT - src IP : sourceIP src port : sourceport
dest IP :destIP dest port : destport
EZD1086I
Negotiating a phase 1 Security Association due to a remote
security endpoint IP address change - original IP address / port
: origip / origport changed
IP address / port : changedip / changedport
EZD1087I
Negotiation of a phase 1 Security Association due to a remote
security endpoint IP address change succeeded - original IP address
/ port : origip / origport
new IP address / port : newip / newport
EZD1088I
IKE received an unsupported identity
address type ( idtype - idtypestr )
for a Security Association traversing a NAT
EZD1089I
A tunnel mode Security Association traversing a NAT does
not have its local IPSec traffic endpoint residing on this node
EZD1090I
Initiation of a phase 2 Security Association negotiation
for a new dynamic tunnel failed because the remote security endpoint
is a security gateway
EZD1095I
Unsupported configuration : location data
endpoint dataaddr does not match security endpoint endptaddr
for a transport mode Security Association initiated method
EZD1099I
A message generated dump has been created titled : title
EZD1100I
A message generated dump was suppressed for message : message_number
EZD1101I
NAT detected and no valid IpDataOffers found
EZD1102I
Negotiation of a phase 1 Security Association due to a remote
security endpoint IP address change failed - original IP address
/ port : origip / origport
failed IP address / port : filaedip / failedport
EZD1103I
Informational exchange ignored because phase 1 Security Association
is still being negotiated
EZD1104I
IKE detected a NAT while initiating a new dynamic tunnel
using only tunnel mode IpDataOffers with a non-z/OS peer
EZD1105I
IKE detected a NAT while initiating a new dynamic tunnel
using both tunnel and transport mode IpDataOffers with a non-z/OS
peer
EZD1106I
Tentative KeyExchangeRule ( tentativeKER )
and final KeyExchangeRule ( finalKER ) preshared
keys do not match
EZD1107I
IKE detected a NAT while initiating a narrow Security Association
negotiation for a new dynamic tunnel with a non-z/OS peer
EZD1108I
Unable to retransmit message - associated phase 1 security
association has expired
EZD1109I
ICSF service CSNBSYD failed for AES decryption : return code
= rc reason code = rsn
EZD1110I
An IPv6 address was configured in an IP Security policy file
for stackname that was not configured with IPCONFIG6
IPSECURITY
EZD1111I
KeyExchangeRule rulename cannot specify
a multicast address
EZD1112I
IpFilterRule rulename cannot specify a
multicast address
EZD1113I
A delete message is being sent with LocalIp ANY for phase
1 security association p1sa_id (LocalIp : local_ip
RemoteIp : remote_ip)
EZD1114I
Policy mismatch : statementstate_num requires
parameter parameter that is not supported by proposal prop_num
EZD1115I
Policy mismatch : Proposal prop_num requires
parameter parameter that is not supported by statementstate_num
EZD1116I
IKE detected an NAPT in front of the remote security endpoint
while initiating a new phase phase tunnel
EZD1117I
Initiation of a phase 2 negotiation with a remote security
endpoint behind an NAPT is prohibited - the pending phase 2 request
was deleted
EZD1118I
Missing required keyword keyword for
IKE configuration file parameter pname on line linenum
EZD1119I
Missing required parameter pname for statement sname in
IKE configuration file fname on line linenum
EZD1120I
IKE configuration file contains more than one IkeConfig statement
- values in last specified statement will be used
EZD1121I
IKE configuration file contains more than one NssStackConfig
statement for stack sname - values in last specified
statement will be used
EZD1122I
Error initializing NMI - monitoring support is not available
EZD1123I
NMI connection from user username closed
- num_conns connections remain open
EZD1124I
NMI connection received from user username - num_conns connections
open
EZD1125I
SERVAUTH check for user username and profile profile failed
during an NMI request
EZD1126I
Unable to send NMI message because of a memory shortage
EZD1127I
NMI connection from user username closed
- maximum number of NMI connections open
EZD1128I
IKE STATUS FOR STACK stackname IS ACTIVE
WITHOUT POLICY
EZD1141I
The keyword identity ident does
not match the subject name or any of the subject alternate names
in the certificate used by the NSS server
EZD1142I
Name resolution failed for keyword hostname hostname
EZD1143A
The IKE daemon cannot locate the NSS server
EZD1144I
The NSS certificate service is available for stack stackname
EZD1145I
The NSS certificate service is not available for stack stackname
EZD1146I
The NSS remote management service is available for stack stackname
EZD1147I
The NSS remote management service is not available stack stackname
EZD1148A
THE IKE DAEMON CANNOT CONNECT TO THE NSS SERVER FOR stackname
BECAUSE THE STACK DOES NOT SUPPORT IPV6
EZD1149I
The IKE daemon connection to the NSS server at ipaddr port port
for stack stackname is not secure
EZD1150I
THE IKE DAEMON FAILED TO CONNECT retries TIMES
TO THE server_type NSS SERVER AT host PORT port
FOR STACK stackname
EZD1151I
KeyExchangeAction actionname prevents
the creation of a dynamic tunnel with source data endpoint specification source_ip and
destination data endpoint specification dest_ip
EZD1152I
The IKE daemon is resolving server hostname name
EZD1153I
The IKE daemon resolved the server hostname name to count addresses
EZD1154I
The remote data endpoint rip with identity rid does
not match the remote security endpoint rsip using
KeyExchangeAction actionname
EZD1155I t_name transform t_num in
proposal p_num does not include an integrity algorithm
EZD1156I
Extraneous text ignored on line linenum after keywordvalue
EZD1157I
IKE message received from remote_ip port remote_port
to local_ip port local_port
with length message_length is too short to contain
the IKE header
EZD1159I
Remote security endpoint id_type identity
length id_length is longer than the maximum of id_max
EZD1160I
Policy mismatch: IpDynVpnAction statement_name requires
parameter parameter_name with value policy_value but
the value selected by the IKE peer is peer_value
EZD1161I
DCAS CONFIGURATION SERVERTYPE IS UNDEFINED
EZD1162I
DCAS CONFIGURATION SERVERTYPE value IS
NOT SUPPORTED
EZD1163I ip_version DYNAMIC XCF INTERFACE xcfinterface_name WAS
CREATED BUT THE SPECIFIED SOURCEVIPAINTERFACE interface_name WILL
NOT BE USED
EZD1164I
IPV6 TCPSTACKSOURCEVIPA INTERFACE interface_name WAS
NOT USED BY tcp_jobname
EZD1165I
DVIPA INTERFACE interface_name IS ALREADY DEFINED
WITH ip_addr
EZD1166E tcpstackname DELAYING SYSPLEX PROFILE
PROCESSING - application IS NOT ACTIVE
EZD1167I
DVIPA INTERFACE interface_name IS CONFIGURED
FROM A VIPARANGE
EZD1168I
VIPADISTRIBUTE WITH THE PORT KEYWORD REJECTED FOR INTERFACE interface_name
EZD1169I
VIPADISTRIBUTE WITHOUT THE PORT KEYWORD REJECTED FOR INTERFACE interface_name
EZD1170E tcpstackname WAS NOT ABLE TO GET TCP/IP storagetype STORAGE
EZD1171I
THERE IS NO ROUTE AVAILABLE FOR VIPAROUTE dxcf_addresstarget_ipaddress
EZD1172E tcpstackname DETERMINED THAT ALL PARTNERS
WERE UNREACHABLE FOR AT LEAST
timevalue SECONDS
EZD1173I
VIPAROUTE IS NOT ENABLED FOR dxcf_addresstarget_ipaddress -
TARGET IP ADDRESS IS NOT VALID
EZD1174I
THE ROUTE FOR VIPAROUTE dxcf_addresstarget_ipaddress IS
NOW ACTIVE
EZD1175I
VARY TCPIP,,SYSPLEX,JOINGROUP COMMAND IGNORED BECAUSE tcpstackname IS
ALREADY A MEMBER OF A TCP/IP SYSPLEX GROUP
EZD1176I tcpstackname HAS SUCCESSFULLY JOINED THE
TCP/IP SYSPLEX GROUP groupname
EZD1177I tcpstackname SYSPLEX PROFILE DEFINITIONS
ARE IGNORED BECAUSE THE STACK IS NO LONGER A MEMBER OF A TCP/IP SYSPLEX
GROUP
EZD1178I
THE VARY TCPIP,,SYSPLEX,JOINGROUP COMMAND WAS ACCEPTED
EZD1179I
VIPAROUTE DEFINE REJECTED - dxcf_address IS ALREADY
DEFINED
EZD1180I
VIPAROUTE DELETE REJECTED - dxcf_addresstarget_ipaddress IS
NOT DEFINED
EZD1182I
TARGET SERVER FOR dvipa_or_intfname PORT portnum AT tcp_name ON host_name IS
NOT RESPONSIVE - TCSR tcsr_value CER cer_value SEF sef_value
EZD1183I
TARGET SERVER FOR dvipa_or_intfname PORT portnum AT tcp_name ON host_name IS
NOW RESPONSIVE
EZD1185I
THE VARY TCPIP,,SYSPLEX,DEACTIVATE, DVIPA COMMAND WAS IGNORED
BECAUSE THE DVIPA IS ALREADY DEACTIVATED
EZD1186I
THE VARY TCPIP,,SYSPLEX,DEACTIVATE,DVIPA COMMAND WAS REJECTED
BECAUSE THE DVIPA IS NOT DEFINED BY VIPADEFINE OR VIPABACKUP ON THIS
STACK
EZD1187E tcpstackname WAS NOT ABLE TO GET TCP/IP storagetype STORAGE
EZD1188I
THE VARY TCPIP,,SYSPLEX,REACTIVATE,DVIPA COMMAND FAILED
EZD1189I
THE VARY TCPIP,,SYSPLEX,REACTIVATE,DVIPA COMMAND COMPLETED
SUCCESSFULLY
EZD1190I
THE VARY TCPIP,,SYSPLEX,LEAVEGROUP COMMAND WAS IGNORED BECAUSE
THE STACK IS NOT A MEMBER OF A TCP/IP SYSPLEX GROUP
EZD1191I
THE VARY TCPIP,,SYSPLEX,JOINGROUP COMMAND WAS IGNORED BECAUSE
SYSPLEX PROBLEM DETECTION CLEANUP HAS NOT FINISHED
EZD1192I
THE VIPADYNAMIC CONFIGURATION WAS SUCCESSFULLY RESTORED FOR tcpstackname
EZD1193I
ALL OF THE VIPADYNAMIC CONFIGURATION DEFINITIONS FOR tcpstackname COULD
NOT BE RESTORED
EZD1194E tcpstackname SYSPLEX PROCESSING ENCOUNTERED
A NONRECOVERABLE ERROR WHILE TRYING TO RESTORE THE SAVED SYSPLEX
CONFIGURATION
EZD1195I
THE VARY TCPIP,,SYSPLEX,JOINGROUP COMMAND WAS REJECTED.
THE STACK MUST BE RESTARTED TO JOIN A TCP/IP SYSPLEX GROUP
EZD1196I
THE VARY TCPIP,,SYSPLEX,REACTIVATE,DVIPA COMMAND WAS IGNORED
BECAUSE THE DVIPA IS NOT DEACTIVATED
EZD1197I
THE VARY TCPIP,,SYSPLEX,DEACTIVATE,DVIPA COMMAND COMPLETED
SUCCESSFULLY
EZD1198I
THE VARY TCPIP,,SYSPLEX,cmdtype COMMAND
COMPLETED SUCCESSFULLY
EZD1199I
THE VARY TCPIP,,SYSPLEX,cmdtype COMMAND
WAS IGNORED BECAUSE NO APPLICATION WAS FOUND LISTENING WITH THE SPECIFIED
COMMAND PARAMETERS
EZD1200I
THE VARY TCPIP,,SYSPLEX,cmdtype COMMAND
WAS REJECTED BECAUSE MORE THAN ONE LISTENING APPLICATION WAS FOUND
MATCHING THE COMMAND PARAMETERS
EZD1201I
THE VARY TCPIP,,SYSPLEX,RESUME,PORT COMMAND WAS REJECTED
BECAUSE IT FOLLOWS A VARY TCPIP,,SYSPLEX,QUIESCE,TARGET COMMAND
EZD1202I
THE VARY TCPIP,,SYSPLEX,RESUME,TARGET COMMAND WAS REJECTED
BECAUSE IT WAS NOT PRECEDED BY A CORRESPONDING VARY TCPIP,,SYSPLEX,QUIESCE,TARGET
COMMAND
EZD1203I
VIPADISTRIBUTE NOT ALLOWED BECAUSE dvipa_or_intfname IS
CURRENTLY DEACTIVATED
EZD1204I
DYNAMIC VIPA dvipa WAS CREATED USING
IOCTL BY jobname ON tcpstackname
EZD1205I
DYNAMIC VIPA dvipa WAS CREATED USING
BIND BY jobname ON tcpstackname
EZD1206I
DYNAMIC VIPA dvipa WAS DELETED USING
IOCTL BY jobname ON tcpstackname
EZD1207I
DYNAMIC VIPA dvipa WAS DELETED USING
CLOSE API BY jobname ON tcpstackname
EZD1208I
VIPADISTRIBUTE WITH BOTH TIMEDAFFINITY AND OPTLOCAL REJECTED
EZD1209E tcpstackname DETERMINED THAT ALL MONITORED
INTERFACES WERE NOT ACTIVE FOR AT LEAST timevalue SECONDS
EZD1210E tcpstackname DETERMINED THAT NO DYNAMIC
ROUTES OVER MONITORED INTERFACES WERE FOUND FOR AT LEAST timevalue SECONDS
EZD1211E tcpstackname DELAYING SYSPLEX PROFILE
PROCESSING - ALL MONITORED INTERFACES WERE NOT ACTIVE
EZD1212E tcpstackname DELAYING SYSPLEX PROFILE
PROCESSING - NO DYNAMIC ROUTES OVER MONITORED INTERFACES WERE FOUND
EZD1213I
A DISTMETHOD OF distribution_method AND
AN OPTLOCAL VALUE OTHER THAN ZERO ARE NOT COMPATIBLE ON A VIPADISTRIBUTE
STATEMENT - THE OPTLOCAL VALUE IS SET TO ZERO
EZD1214I
INITIAL DYNAMIC VIPA PROCESSING HAS COMPLETED FOR tcpipstackname
EZD1215I
MLSCHK STARTED STACK tcpjobname USER stkuser SECLABEL stksl
EZD1216I
MLSCHK SUCCEEDED STACK tcpjobname IS MULTILEVEL
SECURE
EZD1217I
MLSCHK FAILED STACK tcpjobname - count MESSAGES
WRITTEN TO JOBLOG
EZD1338I
NSS SERVER IS USING THE KEY RING keyringvalue
EZD1339I
THE LENGTH partlength OF THE parttype PORTION
OF THE KEYRING PARAMETER keyringvalue IS OUTSIDE
OF THE ACCEPTABLE RANGE OF lowvalue - highvalue
EZD1340I
THE keyword VALUE keyvalue CONTAINS
CHARACTERS THAT ARE NOT 0-9
EZD1341I
THE NSS SERVER PORT VALUE portvalue IS
INCORRECT BECAUSE IT IS OUTSIDE OF THE ALLOWABLE RANGE 1-maxport
EZD1342I
THE NSS SERVER CANNOT PROVIDE CERTIFICATE SERVICES USING
THE CURRENTLY CONFIGURED CERTIFICATE REPOSITORY NAME (repositoryname)
EZD1343I
THE VALUE IS MISSING FOR NETWORK SECURITY SERVER CONFIGURATION
KEYWORD keywordname
EZD1344I
AN ERROR OCCURRED WHILE READING THE NSS SERVER CONFIGURATION
FILE configfile - RETURN CODE retcode
EZD1345I
THIS INSTANCE OF THE NSS SERVER CANNOT START BECAUSE THERE
IS ALREADY ANOTHER INSTANCE OF THE SERVER RUNNING ON THIS SYSTEM
- TOKEN tokenname LEVEL level
PERSIST persist RETURN CODE retcode
EZD1602I
Internal Error err_id in module modname
- unable to obtain memory of size size
EZD1603I
THE DEFENSE MANAGER DAEMON FAILED TO WRITE ITS PROCESS ID pid
TO filename - ERRNO errno
ERRNO DESCRIPTION description
EZD1604I
THE DEFENSE MANAGER DAEMON SHUTDOWN SEQUENCE HAS BEGUN
EZD1605I
THE DEFENSE MANAGER DAEMON SHUTDOWN SEQUENCE HAS COMPLETED
EZD1606I
The ExcludeAddress value value on line linenum
is not valid - reason
EZD1607I
The ExcludeAddress value value on line linenum cannot
be accepted because the limit of limit exclusion
addresses for a single stack has already been reached
EZD1608I
THE DEFENSE MANAGER DAEMON FAILED TO START BECAUSE THE DAEMON
IS ALREADY RUNNING - TOKEN tokenname LEVEL level
PERSIST persist RETURN CODE retcode
EZD1609I
DEFENSE MANAGER DAEMON RELEASE release
SERVICE LEVEL level CREATED ON date
EZD1610I
THE DEFENSE MANAGER DAEMON INITIALIZATION SEQUENCE HAS BEGUN
EZD1611I
THE DEFENSE MANAGER DAEMON INITIALIZATION SEQUENCE HAS COMPLETED
EZD1612I
ERROR ( errno | errnojr
| description ) WHILE OPENING MESSAGE CATALOG name
- DEFAULT MESSAGES WILL BE USED
EZD1613I
A message-generated dump has been created with the title title
EZD1614I
A message-generated dump was suppressed for message message
EZD1615I
INCORRECT SYNTAX FOR THE FILE= PORTION OF THE DEFENSE MANAGER
DAEMON MODIFY COMMAND ( specification )
EZD1616I
AN ERROR OCCURRED WHILE READING THE DEFENSE MANAGER DAEMON
CONFIGURATION FILE filename - RETURN CODE rc
- MODIFY REFRESH COMMAND IS REJECTED
EZD1617I
AN ERROR OCCURRED WHILE READING THE DEFENSE MANAGER DAEMON
CONFIGURATION FILE filename - RETURN CODE rc
EZD1618I
Configuration keyword keyword on line linenum
requires a value
EZD1619I
The configuration value value for keyword keyword
on line linenum contains one or more characters
that are not allowed
EZD1620I
The keyword value value
on line linenum is outside of the allowable range
lowvalue - highvalue
EZD1621I
AN ERROR OCCURRED WHILE TRYING TO ACCESS DEFENSIVE FILTER
DIRECTORY dirname - ERRNO errnodescription
EZD1622I
DEFENSE MANAGER DAEMON CONFIGURATION PROCESSING IS COMPLETE
USING FILE filename
EZD1623I
DEFENSE MANAGER DAEMON CONFIGURATION FILE NOT SPECIFIED AND
DEFAULT CONFIGURATION FILE filename MISSING OR
NOT VALID - USING DEFAULTS FOR CONFIGURATION PARAMETERS
EZD1624I
The Defense Manager daemon socket directory directory
does not exist and cannot be created - errno errnodescription
EZD1625I
THE DEFENSE MANAGER DAEMON COULD NOT INITIALIZE MODIFY AND
STOP COMMAND SUPPORT
EZD1626I
THE DEFENSE MANAGER DAEMON CTRACE PARMLIB MEMBER pname
WAS NOT FOUND
EZD1627I
SYNTAX ERROR IN THE DEFENSE MANAGER DAEMON CTRACE PARMLIB
MEMBER pname
EZD1628I
DEFENSE MANAGER DAEMON CTRACE INITIALIZATION ERROR - FUNCTION function
RETURN CODE rc REASON CODE rsn
EZD1629I
Keyword or value rejected - Keyword keyword
Value value
EZD1751I exchange_type exchange retransmit timed
out from src_ip port src_port to
dest_ip port dest_port
EZD1752I
No applicable policy for IKEv2 negotiation using policy_object_typepolicy_object_name
EZD1753I
IKE version ike_version exchange exchange_type message message_id from
remote_ip port remote_port
to local_ip port local_port is
incorrect because reason
EZD1754I
Validation failed for COOKIE notify payload received from remote_ip
port remote_port to local_ip port local_port
EZD1755I
Transform transform_namelocal_attribute_name attribute
value local_attibute_value in local proposal local_proposal_number does
not match remote_attribute_name attribute value remote_attibute_value in
remote proposal remote_proposal_number
EZD1756I
The message_type for exchange_type exchange
with message ID message_id from remote_ip
port remote_port to local_ip port local_port will
not be processed because reason
EZD1757I
The protection_typepayload_type payload
is ignored because reason
EZD1758I
Transform transform_name attribute type local_attribute_type in
local proposal local_proposal_number does not
match attribute type remote_attribute_type in
remote proposal remote_proposal_number
EZD1759I
Transform transform_name attribute type local_attribute_type with
local_attribute_format format in local proposal local_proposal_number
does not match attribute type remote_attribute_type with remote_attribute_format format
in remote proposal remote_proposal_number
EZD1760I
Proposal proposal_number contains an unsupported
transform ID transform_id for transform type transform_type
EZD1761I protocol_name protocol proposal proposal_number
is incorrectly formatted - reason
EZD1762I
In the response SA payload there is more than one transform
type transform_type
EZD1763I
There is more than one proposal in the response SA payload
EZD1764I
Multiple proposals with proposal number proposal_num
were received in the SA payload
EZD1765I
Received an IKEv2 notify payload with status type notify_type in exchange_typemessage_type
EZD1766I
The payload_type payload length is reason
EZD1767I
A required payload_type payload is missing
for a exchange_typemessage_type
EZD1768I
Transform transform_name attribute type local_attribute_type length
local_attribute_length in local proposal local_proposal_number
does not match the length remote_attribute_length
of attribute type remote_attribute_type in remote
proposal remote_proposal_number
EZD1769I
An unsupported transform type transform_type was
found in proposal proposal_num
EZD1770I
Transform transform_name value for attribute
type local_attribute_type in local proposal local_proposal_number
does not match value for attribute type remote_attribute_type in
remote proposal remote_proposal_number
EZD1771I
IKE version version Security Association sa_generation for
tunnel tunnel_id rekeyed
EZD1772I
IKE version version Security Association sa_generation for
tunnel tunnel_id reauthenticated
EZD1773I
Received an IKEv2 notify payload with error type notify_type in exchange_typemessage_type
EZD1774I
IKEv2 payload type payload_type was received
but was ignored because it is not supported
EZD1775I
IKE version version Security Association sa_generation
for tunnel tunnel_id created for protecting proto_name traffic
between local_iplocal_selector_typelocal_selectors
and remote_ipremote_selector_typeremote_selectors
EZD1776I
IKE version version Security Association sa_generation for
tunnel tunnel_id deleted
EZD1777I
IKE version version Security Association sa_generation for
tunnel tunnel_id has the following attributes
- identities : id_protection local authentication
: local_auth_method remote authentication : remote_auth_method
encryption : encr_function integrity : integ_function PRF
: psuedo_random_function DH : dh_group_name lifetime
: lifetime lifesize : lifesize
EZD1778I exchange_namemessage_type message
ID msg_id replay detected from remote_ip
port remote_port to local_ip
port local_port
EZD1779I
IKE version version Security Association sa_generation for
tunnel tunnel_id has the following attributes -
encapsulation : encap_mode encryption : encr_function integrity
: integ_function lifetime : lifetime lifesize
: lifesize VpnLife : vpn_life PFS
: dh_group_name
EZD1780I
The message_type for exchange_type exchange
with message ID message_id from remote_ip
port remote_port to local_ip port local_port
is outside the expected window of lowest_expected
to highest_expected
EZD1781I
Received a delete payload with an unrecognized SPI value
for protocol protocol
EZD1782I
Received a delete payload with SPI spi_value for
protocol protocol that does not belong to this
IKE_SA
EZD1783I
Received a notify payload with an unrecognized SPI value for
protocol protocol
EZD1784I
Received optional IDr payload but could not find applicable
KeyExchangeRule - LocalIp : LSIP RemoteIp : RSIP LocalID
: LSID RemoteID : RSID
EZD1785I
Tentative KeyExchangeRule rule1 replaced
with final KeyExchangeRule rule2
EZD1786I
Cannot negotiate IKEv1 tunnel for filter rule rulename using
specific types or codes
EZD1787I
Received unsupported IKEv2 traffic selector specification
EZD1788I
Received an IKEv2 traffic selector in a response that does
not match the local proposal
EZD1789I
The remote security endpoint requested_ep is
not included within the address rule_ep taken
from rule_name
EZD1790I
Error event IKE version
Security Association sa_generation for tunnel
tunnel_id
EZD1791I
IKE version version Security Association sa_generation for
tunnel tunnel_id will not be action
EZD1792I
IKE version version Security Association phase2_generation for
tunnel phase2_tunnel_id rekeyed due to reauthentication
of Security Association phase1_generation for
tunnel phase1_tunnel_id
EZD1793I
Obsolete IKE configuration file parameter param on
line linenum is ignored
EZD1794I
Local activation of a dynamic tunnel failed for proto_name traffic
between local_iplocal_selector_typelocal_selector
and remote_ipremote_selector_typeremote_selector
EZD1795I
A matching IpFilterRule with an IpDynVpnAction was not found
for protecting proto_name traffic between local_iplocal_selector_typelocal_selector
and remote_ipremote_selector_typeremote_selector
EZD1796I
Simultaneous rekeying of IKE version version
Security Association sa_generation for tunnel tunnel_id
detected
EZD1797I
Traffic specification requires NON_FIRST_FRAGMENTS_ALSO but
IKEv2 peer did not send it
EZD1798I PolicySource policy requires the SharedKey
parameter but none is specified in KeyExchangeRule KERname
EZD1799I
IKE cannot initiate with local data addresses ipaddress_range for
a Security Association traversing a NAT
EZD1800I
Remote security endpoint at remote_ip port remote_port
is using a digital signature for authentication but did not send
its certificate in a certificate payload
EZD1858I jobname STORAGE SHORTAGE DETECTED IN THE addrJobName ADDRESS
SPACE
EZD1859I jobname STORAGE SHORTAGE RELIEVED IN THE addrJobname ADDRESS
SPACE
EZD1860I jobname STORAGE SHORTAGE DETECTED IN
THE z/OS UNIX FILE SYSTEM DEAD LETTER DIRECTORY
EZD1861I jobname STORAGE SHORTAGE RELIEVED IN
THE z/OS UNIX FILE SYSTEM DEAD LETTER DIRECTORY
EZD1862I jobname STORAGE SHORTAGE DETECTED IN THE
z/OS UNIX FILE SYSTEM MAIL DIRECTORY
EZD1863I jobname STORAGE SHORTAGE RELIEVED IN THE
z/OS UNIX FILE SYSTEM MAIL DIRECTORY
EZD1901I
Remote security endpoint at remote_ip port remote_port
is using an unsupported authentication method auth_method_stringauth_method
EZD1902I
Delayed rekey attempt for IKE tunnel tunnel_id;
proceeding with incomplete exchanges: half_open_count
half-open, half_closed_count half-closed, rekey_requested_count rekeying
EZD1903I
A request_type request message sent to
the NSS server with correlator ID corr_id timed
out
EZD1904E
IKED NSS client API version clientAPIversion does
not match NSS server API version serverAPIversion for
stack stackname
EZD1905I
IKE version version tunnel activation
for stackname using KeyExchangeRule kername requires
the NSS certificate service but the service is not available - return
code = retcode
EZD1906I
FIPS140 support is not enabled for the IKE daemon
EZD1907I
FIPS140 support is enabled for the IKE daemon
EZD1908I
Tunnel activation for stackname using
KeyExchangeRule kername failed because the identity
type is not compatible with the authentication method
EZD1909I
IP validation failed: the remote identity peer_id
does not match remote IP address peer_ip_addr
EZD1910I
FIPS140 support is enabled for the IKE daemon and no valid
KeyExchangeOffers were found in KeyExchangeAction ( KEAname )
EZD1911I
FIPS140 support is enabled for the IKE daemon and no valid
IpDataOffers were found in IpDynVpnAction ( IDVAname )
EZD1912I
No SharedKey was specified in KeyExchangeRule ( KERname )
and KeyExchangeOffers in KeyExchangeAction ( KEAname ) require PresharedKey
authentication
EZD1913I
ICSF callable service routine failed RC: return_code RSN: reason_code
EZD1914I
Remote security endpoint at remote_ip port remote_port sent
a signing certificate with encoding encoding that
is not allowed
EZD1915I
Rekey attempt for IKE tunnel tunnel_id rejected
because of incomplete exchanges: half_open_count half-open, half_closed_count half-closed, rekey_requested_count rekeying
EZD1916I
NSS server cryptographic services are disabled for stack tcpname -
FIPS140 support is enabled for the IKE daemon but is not enabled
for the NSS server
EZD1917I
IKE status for stack tcpname is FIPS140
enabled but IKED is not FIPS140 enabled
EZD1918I
A cryptographic key in use is too short for the chosen Auth
or PRF algorithm when FIPS140 is enabled: key length keylen bytes,
minimum required minlen bytes
EZD1919I
FIPS140 support is enabled for the IKE daemon but it has
read access to CRYPTOZ resource FIPSEXEMPT.SYSTOK-SESSION-ONLY
EZD1920I
Attempting an on-demand activation for IKE outbound UDP traffic
from source_ipaddr port source_port
to dest_ipaddr port dest_port
using anchor filter filtername
EZD1921I
Certificate ( label ) contains a key
that is too short for FIPS 140 mode
EZD1922I
IKE STATUS FOR STACK stackname IS ACTIVE
WITHOUT PORTS
EZD1923I
A create signature request to the NSS server failed; no matching
certificate was found for local security endpoint identity local_id and
authentication method auth_method
EZD1924I
IKE detected a NAT while initiating a new tunnel mode IKEv2
dynamic tunnel with a non-z/OS peer
EZD1925I
IKE detected a NAT while initiating a new transport mode
IKEv2 dynamic tunnel with a non-z/OS peer
EZD1926I
CONTROL CONNECTION TO DESTINATION IP ADDRESS ip_addr
ESTABLISHED
EZD1927I
CONTROL CONNECTION TO DESTINATION IP Address ip_addr
IS CLOSED
EZD1928I tcpstackname WILL NOT JOIN THE SYSPLEX
- GLOBALCONFIG SYSPLEXMONITOR NOJOIN IS CONFIGURED
EZD1929I tcpstackname SECURITY DOMAIN NAME NOT
DEFINED
EZD1930I
HOT STANDBY SERVER FOR destipaddr PORT portnum AT tcpstackname ON mvsname
IS INACTIVE - reason
EZD1965I
CertBundleOptions statement beginning on line line_number does
not support both CertificateLabel and CertificateChain parameters
EZD1966I parameter parameter unexpected on line new_line because
the parameter is already set to value on line old_line
EZD1967I
Unbalanced or extra quote found on line line_number
EZD1968I
CertBundleOptions statement beginning on line line_number references
a self-signed certificate ( label ) but contains
no CRLFile statement - bundle creation might be unnecessary
EZD1969I
Unexpected parameter parameter found on
line line_number
EZD1970I
HOT STANDBY SERVER FOR destipaddr PORT portnum
AT tcpstackname ON mvsname
IS ACTIVE
EZD1971I
SYSPLEX DISTRIBUTOR CONTROL CONNECTION TO DESTINATION IP
ADDRESS ip_addr FAILED WITH RETURN CODE errno REASON
CODE errnojr
EZD1972I
VIPADISTRIBUTE keyword IS NOT VALID BECAUSE
THE CURRENT DISTRIBUTION METHOD IS NOT HOTSTANDBY
EZD1973E
MULTIPLE tcpstackname NONRECOVERABLE ERRORS
ARE ADVERSELY AFFECTING SYSPLEX PROCESSING
EZD1974E tcpstackname CSM HAS BEEN CONSTRAINED
FOR AT LEAST timevalue SECONDS
EZD1980I
CertBundleOptions statement beginning on line line_number is
missing a closing brace (})