ACF2 KEYRING change In sysplex with shared ACF2 database requirement to rebuild OMVS tables.
search cancel

ACF2 KEYRING change In sysplex with shared ACF2 database requirement to rebuild OMVS tables.

book

Article ID: 204654

calendar_today

Updated On:

Products

ACF2 ACF2 - z/OS

Issue/Introduction

Have 2 systems A and B with a shared ACF2 database.
The security administrator deleted old certificates and changed a keyring on system A. 
System A acknowledges this and dynamically refreshes anything that needs refreshing on system A. 


On system B noted inability to find certificates when performing SSL handshaking when using the virtual keyring:

CAS2206I Function=DataGetNext   ,Userid=*AUTH*           
CAS2205I REQUEST=R_datalib       ,EXIT=POST,RC=8/8:44    
CAS2205I REQUEST=R_datalib       ,EXIT=PRE ,RC=N/A       

Problem was fixed by explicitly issuing a F ACF2,OMVS on system B.
Is this a requirement?

Environment

Release : 16.0
Component : CA ACF2 for z/OS

Resolution

When sharing the ACF2 databases and making changes to certificates/keyrings on one LPAR,
the other LPARs require a rebuild of the OMVS tables via 'F ACF2,OMVS'.