EZD0937I   Could not add certificate with label ( label ) to the supported certificate authority list

Explanation

The IKE server could not find a certificate with the specified label on the key ring identified by the Key ring setting for the z/OS® Image. This label was defined to be in the specified Key Ring database. In the IKE daemon configuration file, this label corresponds to the SupportedCertAuth parameter of the IkeConfig statement.

label is the label of this certificate.

System action

The IKE server will ignore the label; IKE daemon processing continues.

Operator response

Verify that the label is correct.

When configured without the IBM® Configuration Assistant for z/OS Communications Server:
  • Verify that the label specified on the SupportedCertAuth parameter of the IkeConfig statement is correct.
  • Verify that the key ring identified by the KeyRing parameter of the IkeConfig statement is correct.
See the information about the IKE daemon in z/OS Communications Server: IP Configuration Reference for more information about the IkeConfig statement.
When configured with the IBM Configuration Assistant for z/OS Communications Server:
  • Verify that a certificate with that label is connected to the key ring identified by the Key ring database configured on the IPSec: IKE Daemon Settings panel.
  • Verify that the key ring database name and location are configured correctly.
See the online helps in the GUI for additional information.

System programmer response

None.

Module

cacache.cpp

Procedure name

None.