Setting up user key. Listchain shows "chain is incomplete". Problem?
search cancel

Setting up user key. Listchain shows "chain is incomplete". Problem?

book

Article ID: 219814

calendar_today

Updated On:

Products

COMMON SERVICES FOR Z/OS

Issue/Introduction

Trying to set up a personal key and keyring to enable me to download maintenance via the SMP/E Internet Service Retrieval.

The 3 required certificates were downloaded.  This includes the Digicert root and intermediate certificates. The 2 digicert keys chains are complete and have been added to my keyring.

However my personal key a couple of times but it always indicates that the chain is not complete.

READY
 RACDCERT ID(A041696) LISTCHAIN(LABEL('CAI User Cert1'))
Certificate 1:
Digital certificate information for user USER001:

  Label: CAI User Cert1
Certificate ID: --------------------------------
  Status: TRUST
  Start Date: 2021/07/15 14:34:55
  End Date:   2022/07/15 14:34:55
  Serial Number:
     >--------<
  Issuer's Name:
       >CN=CA Receive Order.OU=CA Receive Order<
  Subject's Name:
       >CN=connectUserId:[email protected] siteID:123456 sapID:.OU=CA.<

       >O=CA Inc.L=Islandia.SP=NewYork.C=USA<
  Signing Algorithm: sha256RSA
  Key Type: RSA
  Key Size: 2048
  Private Key: NO

  Ring Associations:
    Ring Owner: USER001
  Ring:
       >SMPESharedRing<

Chain information:
  Chain contains 1 certificate(s), chain is incomplete
Chain contains ring in common: USER001/SMPESharedRing

What am I missing or doing incorrectly?

Environment

Release : 15.0
Component : CA RECEIVE ORDER

Security: IBM RACF

Resolution

The message stating "chain is incomplete" is not an indication of a problem and should cause no concerns.

Additional Information

KB Article: 138007 - Broadcom Internet Service Retrieval sample RACF Commands