Troubleshooting
Problem
The KeyRing record is not found.
Symptom
CSPA202E SSL handshake failure, reason=GSK_INVALID_STATE REQ=SSLSOINI RC=6 RS=GSK_KEY_LABEL_NOT_FOUND GSK_KEY_LABEL_NOT_FOUND
Cause
Either the requested key label is not found in the key database or SAF KeyRing, or the Remote Parmfile entry is defaulting to the Local Parmfile entry, but the Local entry is not a valid Certificate Label in the KeyRing or is not set to trusted status.
Resolving The Problem
Specify a label that exists in the key database or SAF KeyRing, and verify the label for the server certificate in the KeyRing and that it is trusted. If needed, modify the certificate label on the Local Node. Verify the certificate label for both KeyRings. Note RACF commands to list KeyRing and Certificate Information or use RACF Panels. The following RACDCERT command displays the certificate added to the RACF data base: RACDCERT ID(userid) LIST(LABEL('certificate name')) The following RACDCERT command lists a KeyRing: RACDCERT ID(certownerid) LISTRING(keyringname)
Historical Number
PRI6958
Product Synonym
Connect:Direct for z/OS All Releases.
Was this topic helpful?
Document Information
Modified date:
17 December 2019
UID
swg21533878