CTGKS0069E Client certificate chain not received. Ensure that the client is configured to send a certificate to IBM® Security Guardium® Key Lifecycle Manager that it can trust, and retry the operation.

Explanation

TLS connection fails because the server did not receive any certificate from the client to authenticate the client. This error can happen only if the clientAuthentication property is set to 2 (required) in SKLMConfig.properties file for key server. Note that for the KMIP protocol, clientAuthentication is always set to required.

System action

TLS handshake fails and TLS connection cannot be established.

Administrator response

Ensure that the client is configured to send a certificate to IBM Security Guardium Key Lifecycle Manager that it can trust. Use the Certificate List REST Service to list the trusted TLSClient certificates. Also, refer to the logs for more information. Correct the problem and restart the server.