EZD0995I   Phase 1 Security Association sa_id is expired

Explanation

The Internet Key Exchange (IKE) daemon detected a request to access a phase 1 Security Association (SA) that has expired.

Additional diagnostic messages that have the same message instance number will be issued to identify the impacted SA. The message instance number precedes the message number in the log output and is used to group related messages from the IKE daemon.

sa_id is the phase 1 SA ID.

System action

The request failed; IKE daemon processing continues.

Operator response

To satisfy the request, the SA must be refreshed or re-started. Use the ipsec -k refresh or ipsec -k activate command to refresh or activate a phase 1 SA. See the information about the managing network security in z/OS Communications Server: IP System Administrator's Commands or issue the man ipsec command in a z/OS® UNIX shell to obtain information about the ipsec command syntax and options.

System programmer response

None.

Module

oakley_kep.cpp, sa.cpp

Procedure name

None.