z/OS Communications Server: IP Messages Volume 2 (EZB, EZD)
Previous topic | Next topic | Contents | Contact z/OS | Library | PDF


EZD1770I

z/OS Communications Server: IP Messages Volume 2 (EZB, EZD)
SC27-3655-01

EZD1770I
Transform transform_name value for attribute type local_attribute_type in local proposal local_proposal_number does not match value for attribute type remote_attribute_type in remote proposal remote_proposal_number

Explanation

The Internet Key Exchange (IKE) daemon was unable to accept a proposal because the local and remote IKEv2 Security Association (SA) transform attribute values are not the same. IKE daemon processing continues to the next proposal. If no proposals are accepted, the SA negotiation fails. This failure is indicated by message EZD0985I, EZD1021I, or EZD1022I being issued later in syslog.

In the message text:
transform_name
The name of the transform for which the mismatch occurred.
local_attribute_type and remote_attribute_type
The attribute types.
local_proposal_number and remote_proposal_number
The proposal numbers.

The attribute values are not included in the message because they are variable length and might be as large as 64 kilobytes of data. To obtain the remote proposal value, activate the formatting of IKE messages by using IKE syslog level 8 and attempt the SA negotiation.

System action

IKE daemon processing continues.

Operator response

Contact the system programmer.

System programmer response

If the proposal that contains the mismatch is the one that should be accepted, either alter the local policy to accept the value in this proposal or notify the administrator of the remote security endpoint about the mismatch and ask the administrator to alter the remote configuration to use the correct values. See the information about Policy Agent and policy applications in z/OS Communications Server: IP Configuration Reference for more information about configuring policy and the IkeSyslogLevel statement.

User response

None.

Problem determination

None.

Source

z/OS® Communications Server TCP/IP: IKE daemon

Module

IKEv2SAAttribute.cpp

Routing code

11

Descriptor code

7

Automation

This message is output to the syslog.

Example

EZD1770I Transform ENCR_AES_CBC value for attribute type 16384 in local  proposal 1 does not match 
         value for attribute type 16384 in remote proposal 2

Go to the previous page Go to the next page




Copyright IBM Corporation 1990, 2014