After assigning a new Entrust certificate in ACF2 for CICS, CICS receives the message 'FHPA1909 FMA1CICS DATA INVALID FOR 'KEYRING'. RESPECIFY KEYWORD AND DATA OR BYPASS WITH '.END': 'XXXXSYSX'.
Release : 2.3
Component : CA ACF2 for z/OS
According to IBM documentation for CICS Transaction Server section 'Building a key ring manually' "The key ring must be associated with the CICS region user ID."
Also from IBM Support 'DFHPA1909 when attempting to use SSL':
Resolving The Problem
Change the Owner of the KEYRING Name to that of the CICS Region UserID as specified in Creating new certificates in the CICS information center.