An attempt was made to use z/OSMF with portable software instances to retrieve common services, following the procedures documented by Broadcom. However, after executing the download job IZUD01DL, the process reported the following status: "Was the signature verified? No.
Despite installing the certificate as specified in the "Mainframe Common Maintenance Procedures" and utilizing the signaturekeyring= keyword to point to the signature, the logs provide no diagnostic information on the cause of the verification failure. Furthermore, an inspection of the download directory in UNIX System Services (USS) reveals that the GIMPAF2.XML file, which should contain the signature data, is missing. In several instances, the SMP/E job concluded with a Return Code (RC) of 0, despite the missing file and failed verification.
A similar issue occurred during the download of the Broadcom ACF2 for Db2 product via z/OSMF. While the job ended with RC 0 and other components appeared to download correctly, the GIMPAF2.XML file was again absent from the package.
z/OSMF
Broadcom mainframe product package
Broadcom currently supports signing SMP/E Receive Order packages and is gradually rolling out signed Product Portable Software Instances (PSWIs). It is suggested to check the Products with Signed PSWIs or Broadcom support portal for the current signature status of specific software packages.
When starting the download of the package via z/OSMF and then the job IZUD01DL is started.
According to the manual, there should be a message:
GIM69270I SIGNATURE VALIDATION FOR FILE file-name WAS SUCCESSFUL. THE GIMZIP PACKAGE WAS SIGNED BY A CERTIFICATE WITH SUBJECT NAME subject-name, SERIAL NUMBER serial AND SHA256 FINGERPRINT fingerprint. THE SIGNING CERTIFICATE WAS ISSUED BY CN=Broadcom Mainframe Software Root CA.
See Products with Signed PSWIs