z/OS Security Server RACF Messages and Codes
Previous topic | Next topic | Contents | Contact z/OS | Library | PDF


IRRD135I

z/OS Security Server RACF Messages and Codes
SA23-2291-00

IRRD135I
ICSF is not operational. The request is not processed.

Explanation

The following situations might occur:
  1. You issued a command to generate a certificate or add a certificate to the RACF® database and you indicated that you want to use ICSF for key management. ICSF key management support is not available.
  2. You issued a command to generate a certificate or certificate request for which the private key required to sign the information is stored in the PKDS (public key data set) or TKDS (token key data set). Either ICSF key management support is not available, or the master key is absent or not set up correctly.
  3. You issued a RACDCERT ADD, RACDCERT CHECKCERT, or RACDCERT LISTCHAIN command, but RACF is unable to invoke the ICSF PKCS #11 function to verify the signature of an elliptic curve cryptography (ECC) certificate found in the data set or in the RACF database.

System action

The command is not processed.

System programmer response

Ensure that ICSF is configured for PKA support and operational and that the master key of the PKDS or TKDS is set up correctly. For more information, see z/OS Cryptographic Services ICSF System Programmer's Guide.

User response

For situation 1, if ICSF key management is not required, reissue the command without requesting the key to be stored in the PKDS or TKDS.

If ICSF key management is required for situation 1, and for situations 2 and 3, report the error to your system programmer. Reissue the command after the problem has been corrected. For more information, see the description of the command that you entered in ../com.ibm.zos.v2r1.icha400/ich2a410.htm.

Go to the previous page Go to the next page




Copyright IBM Corporation 1990, 2014