search cancel

ACF2 INSERT and CONNECT of certificate getting RC 0 but not working?

book

Article ID: 214515

calendar_today

Updated On:

Products

ACF2 - z/OS

Issue/Introduction

 Trying to do a INSERT or CONNECT of a certificate using TSO, ACF or TSO BATCH gets 0 return codes, no CERTDATA records or messages returned. For example:

 READY
  ACF
 ACF
  set profile(user) div(certdata)
 PROFILE
  insert SITECERT.DIG2025 dsn('PROD.CERT.CERT')   pass(Nopass) Label(siteplex99) trust
 PROFILE
  set profile(user) div(keyring)
 PROFILE
   Connect certdata(SITECERT.DIG2025) keyring(PLEX.RING)    usage(personal)
 PROFILE
 END

Versus:

READY                                                                         
 ACF                                                                           
ACF                                                                           
  SET PROFILE(USER) DIV(CERTDATA)                                              
PROFILE                                                                       
  INSERT SITECERT.DIGI2021 DSN('SECMF.SITECERT.DIGI2021.CERT')   PASS(test) LABE
 CERTDATA / SITECERT.DIGI2021 LAST CHANGED BY BLAMI02 ON 05/06/21-12:30       
                      CERTNSER(0000000000000001) ISSUERDN(CN=DIGI2021A.OU=Audit.
                      LABEL(SITE-DIGIPLEX2) SERIAL#(00) SUBJDN(CN=DIGI2021A.OU=A
ACF6D074 CERTDATA / SITECERT.DIGI2021 RECORD INSERTED                         
PROFILE                                                                        
 SET PROFILE(USER) DIV(KEYRING)                                                 
PROFILE                                                                       
   CONNECT CERTDATA(SITECERT.DIGI2021) KEYRING(ABC.RING1)  USAGE(PERSONAL)     
ACF68011 Certificate successfully connected to the key ring                   
PROFILE                                                                        
END                                                                           
READY                                                                           
END                              

Environment

Release : 16.0

Component : CA ACF2 for z/OS

Resolution

If a site is using CPF Command Propagation and the commands are DFTCMD(NODE1, NODE2, NODE3) parameter specifies other nodes and not the home node the commands will be propagated to the other nodes and not executed on the home nodes which will result in not records listed or messages returned on the home node were the command was executed.

If the DFTCMDS is changed to DFTCMD(NODE1, NODE2, NODE3, HOMENODE) then the commands will be issued on the home node as well and the records listed and the messages will appear after the commands.