Key check utility
The key check utility validates each key in the key data set in the same manner as the KDS reencipher utility without reenciphering the key. The utility can be run prior to reenciphering on a key data set to ensure the KDS reencipher and change master key utilities will complete successfully. The utility checks the active key data sets. The results of the check are written to the ICSF joblog.
The key check utility can be invoked from the CKDS Management and PKDS Management panels or by writing an application to invoke the ICSF Multi-Purpose Service (CSFMPS) callable service. For more information, see z/OS Cryptographic Services ICSF Application Programmer's Guide.
Steps for checking the CKDS
- Enter option 2, KDS MANAGEMENT, on the ICSF Primary Menu panel: ICSF Primary Menu panel to access the Key Data Set Management panel: CSFMKM10 — Key Data Set Management panel
- Enter option 1, CKDS MK MANAGEMENT and the CKDS Management panel appears: CSFMKM20 — CKDS Management panel
- Enter option 7 for CKDS KEY CHECK to run the utility on the active CKDS.
The panel message will indicate if the check was successful or if there are errors. CSFM661I messages are written to the ICSF joblog with warnings and errors.
Steps for checking the PKDS
- Enter option 2, KDS MANAGEMENT, on the ICSF Primary Menu panel: ICSF Primary Menu panel to access the Key Data Set Management panel: CSFMKM10 — Key Data Set Management panel
- Enter option 2, PKDS MK MANAGEMENT and the PKDS Management panel appears: CSFMKM30 — PKDS Management panel
- Enter option 7 for PKDS KEY CHECK to run the utility on the active PKDS.
The panel message will indicate if the check was successful or if there are errors. CSFM661I messages are written to the ICSF joblog with warnings and errors.