ERROR = Unable to find valid certification path to requested target ../BroadcomProdInfo.txt
search cancel

ERROR = Unable to find valid certification path to requested target ../BroadcomProdInfo.txt

book

Article ID: 211000

calendar_today

Updated On:

Products

COMMON SERVICES FOR Z/OS Common Services MAINFRAME MISCELLANEOUS

Issue/Introduction

You are setting up IBM z/OSMF to manage our Broadcom CA products for the first time and followed the instructions.

Trying to import Broadcom product information file into z/OSMF directly from the Broadcom FTP directory...

Load the File from the Broadcom URL

 

While attempting to retrieve the End-Of-Service information this error is received..

The request could not be completed because an error occurred.
Error: An unexpected error occurred while connecting to the End Of Service file server
Error = unable to find valid certification path to requested target
 
The z/OSMF STDERR shows..
CWPKI0823E: SSL HANDSHAKE FAILURE:
The extended error message from the SSL handshake exception is: .unable to find valid certification path to requested target.
 
 
There are no instructions for obtaining/adding the required Broadcom signer to the local trust store. What was missed with the setup?

Environment

z/OSMF Software Management

Cause

The keyring does not contain a Digicert Intermediate CA certificate.

To confirm, get list of keyring that is attached to IZUSVR, which should be the ACID that the z/OSMF task runs under.

Resolution

This process is using the same Digicert Intermediate CA certificate that was defined to the keyring for the SMP/E Internet Service Retrieval.

Connect this same certificate to the keyring that is attached to the ACID being used for z/OSMF.

** Be sure to connect as USAGE(CERTAUTH) **

This z/OSMF related information has been added to the Mainframe Common Maintenance Procedures documentation...See Import Product Information into z/OSMF