z/OS Security Server RACF Messages and Codes
Previous topic | Next topic | Contents | Contact z/OS | Library | PDF


IRRH277I

z/OS Security Server RACF Messages and Codes
SA23-2291-00

IRRH277I
No exceptions are detected. Expired certificates that are not trusted or are associated with only a virtual key ring are not exceptions

Explanation

The RACF_CERTIFICATE_EXPIRATION check lists each certificate that has an ending date before the current date or that has an ending date that is before the current date adjusted by the warning period that the installation specified as a parameter to the RACF_CERTIFICATE_EXPIRATION check. If a parameter is not specified, a default warning period of 60 days is used.

Only certificates that are marked as trusted result in exceptions. These certificates have an "E" in the "S" (Status) column. The trust status of the certificate is shown in the "Trust" column. The number of key rings to which the certificate is connected (other than the virtual key ring) is shown in the "Rings" column.

Use the RACDCERT LIST command to list complete information about any certificate. The RACDCERT command syntax is:

RACDCERT CERTAUTH LIST(LABEL('label-name'))
or
RACDCERT SITE LIST(LABEL('label-name'))
or
RACDCERT ID(user-id) LIST(LABEL('label-name'))

See z/OS Security Server RACF Security Administrator's Guide and z/OS Security Server RACF Command Language Reference for more information about digital certificates.

System action

The check continues processing. There is no effect on the system.

Operator response

None.

System programmer response

None.

Problem determination

None.

Source

Module

IRRHCR10

Routing code

N/A

Descriptor code

N/A

Automation

None.

Go to the previous page Go to the next page




Copyright IBM Corporation 1990, 2014