How To
Summary
This document describes how to backup/replicate your DCM environment.
Steps
1. The DCM certificate store files containing your TLS certificates.
The certificate store files are all located in the following IFS location:
/QIBM/UserData/ICSS/Cert
This directory can be backed up/migrated/replicated with the following SAV (save) and RST (restore) CL commands.
CRTSAVF FILE(QGPL/DCMIFS)
SAV DEV('/QSYS.LIB/QGPL.LIB/DCMIFS.FILE') OBJ(('/QIBM/UserData/ICSS/Cert')) DTACPR(*HIGH) PVTAUT(*YES)
RST DEV('/QSYS.LIB/QGPL.LIB/DCMIFS.FILE') OBJ(('/QIBM/UserData/ICSS/Cert')) PVTAUT(*YES)===================================
To save the certificate store system password stash,you can use either the SAVSYS or SAVSECDTA commands.
To restore the DCM password stash,use the following restore user profile command:
RSTUSRPRF USRPRF(*NONE) SECDTA(*DCM)NOTE: The above command requires your IBM i server to be in restricted state (ENDSBS *ALL).
3. The user index containing the TLS certificate to IBM i application assignments.
The TLS certificate to IBM i application assignments are stored in the following user index object:
QUSRSYS/QYCDCERTIThis can be saved with the SAVOBJ command and restored with the RSTOBJ command.
CRTSAVF FILE(QGPL/DCMUSRIDX)
SAVOBJ OBJ(QYCDCERTI) LIB(QUSRSYS) DEV(*SAVF) SAVF(QGPL/DCMUSRIDX) PVTAUT(*YES)
RSTOBJ OBJ(QYCDCERTI) SAVLIB(QUSRSYS) DEV(*SAVF) SAVF(QGPL/DCMUSRIDX) PVTAUT(*YES)Run the following command on the IBM i command line:
CALL QICSS/QYCUMIGREX4. (OPTIONAL) - All DCM Application IDs are stored under the exit point, QIBM_QSY_CERT_APPS, in the QUSRSYS/QUSEXRGOBJ object. WARNING!!! The QUSRSYS/QUSEXRGOBJ object contains information for ALL exit points. If this object is migrated, ALL exit point information is also migrated. Use caution when migrating/replication this object since this will migrate/replicate ALL exit point information which might negatively affect your IBM i server if not handled properly.
This can be saved with the SAVOBJ command and restored with the RSTOBJ command.
CRTSAVF FILE(QGPL/DCMAPPS)
SAVOBJ OBJ(QUSEXRGOBJ) LIB(QUSRSYS) DEV(*SAVF) SAVF(QGPL/DCMAPPS) PVTAUT(*YES)
RSTOBJ OBJ(QUSEXRGOBJ) SAVLIB(QUSRSYS) DEV(*SAVF) SAVF(QGPL/DCMAPPS) PVTAUT(*YES)
IBM Documentation - Backup and recovery considerations for DCM data
Document Location
Worldwide
Was this topic helpful?
Document Information
Modified date:
29 September 2026
UID
ibm16614285