IBM Support

The KeyRing record is not found.

Troubleshooting


Problem

The KeyRing record is not found.

Symptom

CSPA202E SSL handshake failure, reason=GSK_INVALID_STATE REQ=SSLSOINI RC=6 RS=GSK_KEY_LABEL_NOT_FOUND GSK_KEY_LABEL_NOT_FOUND

Cause

Either the requested key label is not found in the key database or SAF KeyRing, or the Remote Parmfile entry is defaulting to the Local Parmfile entry, but the Local entry is not a valid Certificate Label in the KeyRing or is not set to trusted status.

Resolving The Problem

Specify a label that exists in the key database or SAF KeyRing, and verify the label for the server certificate in the KeyRing and that it is trusted. If needed, modify the certificate label on the Local Node. Verify the certificate label for both KeyRings. Note RACF commands to list KeyRing and Certificate Information or use RACF Panels. The following RACDCERT command displays the certificate added to the RACF data base: RACDCERT ID(userid) LIST(LABEL('certificate name')) The following RACDCERT command lists a KeyRing: RACDCERT ID(certownerid) LISTRING(keyringname)

[{"Product":{"code":"SSFGBN","label":"IBM Sterling Connect:Direct for z\/OS"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Component":"Not Applicable","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All","Edition":"","Line of Business":{"code":"LOB59","label":"Sustainability Software"}}]

Historical Number

PRI6958

Product Synonym

Connect:Direct for z/OS All Releases.

Document Information

Modified date:
17 December 2019

UID

swg21533878