IBM Support

What are the MustGather for Remote Connection Emulator issues in IBM Developer for z/OS?

Question & Answer


Question

What logs could be collected when you experience issues with the Remote Connection Emulator (RCE) in IBM Developer for z/OS (IDz)?

Cause

The most common problem is failure to connect to the host when the Remote Connection Emulator uses encrypted communication configuration like TLS.
 
 
 

Answer

 
When usingTraces to collect
IDz Eclipse client
 
  • .trace file with com.ibm.remote.connection.emulator =FINEST (1)
  • Test connection output (2)
  • z/OS SYSLOG with AT-TLS traces enabled when applicable (3)
 
IDz in VS code
 
Z Open Editor
 
  • The output view log of the "Z Open Editor" extension in Visual Studio Code with DEBUG level enabled (4).
  • RSEAPI access log (5) and catalina log
  • RSEAPI STC joblog
  • RSEAPI rce.log (7) (with RSEAPI v1.2.5 and later)

Optional:

  • Test connection output when possible (2)
  • z/OS SYSLOG with AT-TLS traces enabled when applicable (3)
  • RSEAPI catalina log with RCE HTTP traces enabled (6)
 
 

Possible causes and solutions
 
See the link section for the z/OS documentation of these errors.
 
Some possible causes for errors that can be found on the z/OS SYSLOG:
 
ErrorPossible causeResolution
  • EZD1287I TTLS Error RC:  406 Initial Handshake
  • Connection failed: TLS: InitializeSecurityContext: error 0x80090325 (The certificate chain was issued by an authority that is not trusted.)
The error can indicate that the client side broke the connection. For example if the server certificate is not trusted by the client and the client side is configured to check it
 
Add the server certificate to the client key store. On Windows (a)
 
  • EZD1287I TTLS Error RC:  403 Initial Handshake
  • Connection failed: TLS: recv: error 10054 (An existing connection was forcibly closed by the remote host.)
The host closed the connection because no client certificate was provided
 
Select a client certificate on the RCE connection properties
 
image-20250514143125-2
  • EZD1287I TTLS Error RC:  441 Initial Handshake
image-20250514195222-1
When launched from Z Open Editor, the host TN3270 closed the connection because it requires a client certificate but RSEAPI doesn't support it 
 
In rseapi.env, configure a TN3270 port that do not require a client certificate
 
  • EZD1287I TTLS Error RC:  435 Initial Handshake
The host closed the connection because the client certificate was not recognized
 
 
  • Connection failed: TLS: CertFindCertificateInStore: error 0x80092004 (Cannot find object or property.)
The client certificate alias was not found the keystore
 
On Windows, verify in certmgr that your client certificate alias  is listed under Personal > Certificate in column Friendly Name
 
CommonPropertiesRESTService EXCEPTION : Exception in GET - Get a list of all Common Properties Namespaces with userid USERXYZ
com.ibm.rse.rest.exception.RestWAFunctionDisabledException: Common Properties service is not enabled.
 
Error is printed to the RSEAPI STC joblog if common properties is not enabled in rse.env.
 
The error can be ignored and should not prevent a successful connection with RCE 
Set variable RSE_COMMON_PROPERTIES in rseapi.env
 
Menu "Launch 3270 emulator in Web browser" is not available in Zower Explorer
 
image-20250514162754-1
  • No activation key has been found
 
  • or RSEAPI version is not compatible
 
  • Zowe connection uses zOSMF instead of RSEAPI
  • Open the Z Open Editor Welcome screen and verify that an activation key is active:
 
image-20250514163124-2
 
  • RSE API 1.2.1 or higher is required.
  • zOSMF is not supported by the Remote Connection Emulator
Failure to connect to TN3270

The Tomcat RCE app on z/OS failed to communicate with the TN3270 server.

 

Verify that the RCE_HOST, RCE_PORT, RCE_SECURITY parameters in rseapi.env are correct.

If the error "Couldn't open a socket" can be found on the RSEAPI STC joblog then it would mean that RCE app on z/OS failed to communicate with its s3270 spawned process.

Verify in your TCPIP configuration that RSEAPI* jobs can open a random port. Error will happen with PORT UNRSV TCP rules excluding RSEAPI from opening an unreserved port. It can be resolved by adding a specific rule for RSEAPI like PORT UNRSV TCP RSEAPI* WHENLISTEN

BPXP023I THREAD 0F52C00000000000, IN PROCESS 33555905, WAS 815
TERMINATED BY SIGNAL SIGKILL, SENT FROM THREAD
0F52D80000000040, IN PROCESS 50332759, UID 1, IN JOB RSEAPIT1.
IEF450I RSEAPIT8 STEP1 - ABEND=SEC6 U0000 REASON=0000FF09 816

ABEND SEC6 happens when the RSEAPI RCE app on z/OS detects that a 3270 session already exists and kills the related s3270 process.

 

This is working as designed.
Wrong RCE URI

/rceapp is not a valid URI

Launch RCE from Z Open Editor menu

image-20250514162754-1

 

a) Verify your certificates in the Microsoft Windows-MY keystore
 
From a command line, enter command
 
certmgr /s my
 
 
certmgr
 
 
  • Host certificate has to be trusted
 
image 12069
 
Verify that your host CA certificate is trusted (installed under Trusted Root)
 
  • When using Client certificate
 
If your host requires a client certificate, then import it into Windows-MY under Personal > Certificates
 
image 12070
 
Select it on the Remote Connection Emulator
 
image-20250515092909-1

 
 
1) Enable tracing in IDz Eclipse client 
 
  • Enable tracing with menu Window > Preferences > Tracing and set com.ibm.remote.connection.emulator to FINEST
image 12065
 
Output is printed to
 
<your workspace>\.metadata\.trace
 
 
2) Test connection in RCE 
 
Perform a test connection on the Remote Connection Emulator
 
image-20250514132727-1
 
 
3) Enable AT-TLS traces on z/OS
 
When using AT-TLS, add a trace statement to the TTLSConnectionAction of your policy file, like for example:
 
TTLSConnectionAction  TN3270_conn
{
 HandshakeRole Server
 TTLSCipherParmsRef  TN3270_cipherparms
 TTLSConnectionAdvancedParmsRef TN3270_Conn_adv
 CtraceClearText  Off
 Trace  255
}
 
Traces are printed to the z/OS system console, like for example:
 
image-20250514133316-2
 
 
 
(4) To collect the output view log of the "Z Open Editor" extension in Visual Studio Code
  • Enable DEBUG level from menu File > Preferences > Settings > Extension > IBM Z Open Editor and set Logger=DEBUG
image-20250403110138-1
  • Reproduce the problem;
  • Open the output view from menu View > Output and send the content for "IBM Z Open Editor"
image-20241119120234-1
  
5) RSEAPI access log
 
The location of the log depends on the configuration of OUTPUT_DIR in rseapi.env:
 
$OUTPUT_DIR/rseapi_<port>.1/server/localhost_access_log.<date>.txt
 
The log is in UTF-8.
 
 
 
6) RSEAPI catalina log with RCE HTTP traces enabled
 
  • Add the following statement to your rseapi.env:
#trace HTTP requests from rceapp to rseapi in catalina.log
JAVA_OPTS="$JAVA_OPTS -Djdk.httpclient.HttpClient.log=errors,requests,headers"
 
  • Restart the RSEAPI started task
  • Reproduce the problem
  • Collect the catalina log which location depends on the configuration of OUTPUT_DIR in rseapi.env:
$OUTPUT_DIR/rseapi_<port>.1/server/catalina.<date>.log
 
Example of traces:
 
17-Jun-2025 07:51:53.275 INFO [HttpClient-1-Worker-0] jdk.internal.net.http.Http1Request.logHeaders HEADERS: REQUEST HEADERS:
POST /rseapi/api/v1/auth/login HTTP/1.1
Content-Length: 42
Host: host1.ibm.com:6834
User-Agent: Java-http-client/11.0.23
Accept: application/json
Content-Type: application/json
17-Jun-2025 07:51:53.523 INFO [HttpClient-1-Worker-0] jdk.internal.net.http.Http1Response.lambda$readHeadersAsync$0 HEADERS: RESPONSE HEADERS:
    authorization: Bearer eyJhbGci......
    date: Tue, 17 Jun 2025 11:51:53 GMT
    set-cookie: apimlAuthenticationToken=eyJhbGci.......;Version=1
    strict-transport-security: max-age=0
    token-expiration-time: Tue Jun 17 15:51:53 EDT 2025
    vary: Origin
    x-content-type-options: nosniff
    x-frame-options: DENY
    x-xss-protection: 1; mode=block
 
 
(7) RSEAPI rce.log 
 
  • Add the following statement to your rseapi.env:
# enable RCE debug level 
RCE_LOG_LEVEL=DEBUG
  • Restart the RSEAPI started task
  • Reproduce the problem
  • Collect the rce.log which location depends on the configuration of OUTPUT_DIR in rseapi.env:
$OUTPUT_DIR/rseapi_<port>.1/server/rce.log
 
Example of traces:
 
2026-09-09 03:19:03.680 [exec-9] INFO  com.ibm.host.connect.s3270.tomcat.LoginRegistry - Inside ConnectToHostAction - get the user session - rceSessionGroupId is: 1788938343339
2026-09-09 03:19:03.684 [exec-9] INFO  com.ibm.host.connect.s3270.tomcat.LoginRegistry - Inside ConnectToHostAction - data from the Web UI: - rceSessionGroupId is: 1788938343339
2026-09-09 03:19:03.684 [exec-9] INFO  com.ibm.host.connect.s3270.tomcat.LoginRegistry - Inside ConnectToHostAction - Successfully extracted the user session - rceSessionGroupId is: 1788938343339
2026-09-09 03:19:03.685 [exec-9] INFO  com.ibm.host.connect.s3270.tomcat.LoginRegistry - Inside ConnectToHostAction - Successfully extracted the connection properties. Invoking screenWrapper.connectToHost - rceSessionGroupId is: 1788938343339
2026-09-09 03:19:03.685 [exec-9] INFO  com.ibm.host.connect.s3270.tomcat.LoginRegistry - ------Attempt to disconnect previous session - rceSessionGroupId is: 1788938343339
2026-09-09 03:19:03.685 [exec-9] INFO  com.ibm.host.connect.s3270.tomcat.LoginRegistry - ------Done attempting to disconnect previous session - rceSessionGroupId is: 1788938343339
2026-09-09 03:19:03.686 [exec-9] INFO  com.ibm.host.connect.s3270.tomcat.LoginRegistry - ----- Starting the s3270 session ----- rceSessionGroupId is: 1788938343339
 Location of executable is: /u/sandbox/usr/rseapi/v12x/tomcat.base/webapps/rceapp/WEB-INF/executable/s3270
2026-09-09 03:19:03.688 [exec-9] INFO  com.ibm.host.connect.s3270.tomcat.LoginRegistry - ---------   Beginning of startProcess ---------- rceSessionGroupId is: 1788938343339
2026-09-09 03:19:03.911 [exec-9] INFO  com.ibm.host.connect.s3270.tomcat.LoginRegistry - rceSessionGroupId is: 1788938343339 ------ Seting session parms: 
model=3279-2-E,codepage=037
2026-09-09 03:19:03.911 [exec-9] INFO  com.ibm.host.connect.s3270.tomcat.LoginRegistry - ------Connecting to host after session parms have been set - rceSessionGroupId is: 1788938343339
2026-09-09 03:19:04.318 [exec-9] INFO  com.ibm.host.connect.s3270.tomcat.LoginRegistry - Inside ConnectToHostAction - Successfully got the response from screenWrapper.connectToHost. jsonString is:
{"command":"Connect(C:L:Y:[myTN3270.ibm.com]:992)","processEnded":false,"okReceived":true,"errorReceived":false,"timeout":false,"lockedKeyboard":false,"internalError":false,"connectionState":"","keyboardState":"unlocked","responseStatus":....

 

 

 

[{"Type":"MASTER","Line of Business":{"code":"LOB70","label":"Z TPS"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSTRMM","label":"IBM Developer for z\/OS"},"ARM Category":[{"code":"a8mKe000000002gIAA","label":"IBM Developer for Z\/OS-\u003ETerminal Emulator (RCE)"}],"ARM Case Number":"","Platform":[{"code":"PF033","label":"Windows"}],"Version":"17.0.0"},{"Type":"MASTER","Line of Business":{"code":"LOB70","label":"Z TPS"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSG28P4","label":"IBM Developer for z\/OS (Eclipse)"},"ARM Category":[{"code":"a8mKe000000002gIAA","label":"IBM Developer for Z\/OS-\u003ETerminal Emulator (RCE)"}],"ARM Case Number":"","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"and future releases;17.0.0"},{"Type":"MASTER","Line of Business":{"code":"LOB70","label":"Z TPS"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSGGZRF","label":"IBM Developer for zOS Select"},"ARM Category":[{"code":"a8mKe000000002gIAA","label":"IBM Developer for Z\/OS-\u003ETerminal Emulator (RCE)"}],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":""}]

Product Synonym

IDz;IDz on VS Code;IDz EE

Document Information

Modified date:
09 September 2026

UID

ibm16514447