A fix is available
APAR status
Closed as new function.
Error description
The CERTMGR Enhancements provide expanded certificate management capabilities in z/VM, including stash file enhancements. The use of stash files in GSKKYMAN are enhanced to eliminate repeated password entry and enable easier automation. New functions such as receiving and renewing certificates have been added to the GSKKYMAN interface, while CERTMGR itself now supports receiving, renewing, importing, and exporting certificates. These improvements primarily benefit system administrators and security teams, as they simplify usage, reduce manual effort, and streamline the overall certificate management process.
Local fix
Problem summary
**************************************************************** * USERS AFFECTED: All z/VM users * **************************************************************** * PROBLEM DESCRIPTION: * **************************************************************** * RECOMMENDATION: APPLY PTF * **************************************************************** The objective of CERTMGR Command Enhancements is following - 1. Porting of z/OS System SSL 3.1 support into z/VM System SSL 3.1 Under this section we are importing all the z/OS system SSL support in which GSKKYMAN use stash file instead of requiring the password and having to enter the password for each invocation to easily automate the certificate management process. 2. Implement new functions on the z/VM GSKKYMAN command line interface a.'Receive' - receive certificate using GSKKYMAN command line interface b.'Renew' - generate certificate renewal request using GSKKYMAN command line interface 3. Add new functionality on the CERTMGR command a. Receive a certificate b. Create a certificate renewal request c. Import a Certificate d. Export a Certificate
Problem conclusion
Temporary fix
Comments
To read more about these CERTMGR enhancements, refer to the 1. z/VM: TCP/IP Planning and Customization (SC24-6331-74) 2. z/VM: TCP/IP User's Guide (SC24-6333-74) 3. z/VM: TCP/IP Messages and Code (GC24-6330-74) 4. z/VM: General Information (GC24-6286-74) 5. z/VM: Migration Guide (GC24-6294-74)
APAR Information
APAR number
PH68728
Reported component name
TCP/IP FOR Z/VM
Reported component ID
5735FAL00
Reported release
740
Status
CLOSED UR1
PE
NoPE
HIPER
NoHIPER
Special Attention
YesSpecatt / New Function / Xsystem
Submitted date
2025-10-29
Closed date
2026-04-30
Last modified date
2026-05-15
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
UO07642
Modules/Macros
CERTMGR DTCUME DTCUMEB GSKCMS31 GSKC31 GSKC31F GSKKYMAN GSKMSGA GSKMSGS GSKSSL GSKSUS31 GSKS31 GSKS31F GSKTRACE LDPCBSD LDPCCLD LDPCSRV LDPCUTS LDPICRAN LDPIFPTS LDPIRACS LDPIRDV LDPISNPR LDPIWRTV LDPNCHKL LDPNSMSG LDPXBINT SSLADMIO SSLADMNP SSLCACHE SSLCIPHS SSLCTLIO SSLDPUMP SSLDSPTC SSLGSKCF SSLMNTOR SSLPARGS SSLREPRT SSLSCBEX SSLSTART SSLTOOLS SSLTRACE SSLTRSIT SSLXBINT TCVMVER 7VMTCP40
| GC24629474 | GC24633074 | SC24633174 | GC24628674 | SC24633374 |
Fix information
Fixed component name
TCP/IP FOR Z/VM
Fixed component ID
5735FAL00
Applicable component levels
R740 PSY UO07642
UP26/05/05 I 1000
Fix is available
Select the PTF appropriate for your component level. You will be required to sign in. Distribution on physical media is not available in all countries.
[{"Business Unit":{"code":"BU029","label":"Software"},"Product":{"code":"SG27M","label":"APARs - z\/VM Environment"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"740","Line of Business":{"code":"LOB16","label":"Mainframe HW"}}]
Document Information
Modified date:
16 May 2026