z/OS Communications Server: IP Messages Volume 2 (EZB, EZD)
Previous topic | Next topic | Contents | Contact z/OS | Library | PDF


EZD1019I

z/OS Communications Server: IP Messages Volume 2 (EZB, EZD)
SC27-3655-01

EZD1019I
Could not open certificate repository ( name ) ( description ) ( gsk_rc )

Explanation

The Internet Key Exchange (IKE) daemon was unable to open the certificate repository identified by the key ring database setting.

name is the name of the certificate repository (key ring database) that IKE was unable to open.

description describes the meaning of gsk_rc.

gsk_rc is the hexadecimal Certificate Management Services (CMS) status code. See the information about the CMS status codes in z/OS Cryptographic Services System SSL Programming.

System action

The IKE daemon will not support RSA signature mode authentication; IKE daemon processing continues.

Operator response

Ensure that the repository name is defined correctly and that the user under which the IKE daemon was started is authorized to access the repository.

When configured without the IBM® Configuration Assistant for z/OS® Communications Server, the certificate repository name is set on the KeyRing parameter of the IkeConfig statement. See the information about the Policy Agent and policy applications in z/OS Communications Server: IP Configuration Reference for more information.

When configured with the IBM Configuration Assistant for z/OS Communications Server, the certificate repository name is set in the key ring database name located in the IPSec: IKE Daemon Settings panel.

System programmer response

None.

Module

cert_rep.cpp

Procedure name

None.

Go to the previous page Go to the next page




Copyright IBM Corporation 1990, 2014