How to recover an accidentally deleted Digital Certificate.

book

Article ID: 4002

calendar_today

Updated On:

Products

CA Cleanup CA Datacom - DB CA Datacom CA Datacom - AD CA Datacom - Server CA CIS CA Common Services for z/OS CA 90s Services CA Database Management Solutions for DB2 for z/OS CA Common Product Services Component CA Common Services CA Datacom/AD CA ecoMeter Server Component FOC CA Easytrieve Report Generator for Common Services CA Infocai Maintenance CA IPC Unicenter CA-JCLCheck Common Component CA Mainframe VM Product Manager CA Chorus Software Manager CA On Demand Portal CA Service Desk Manager - Unified Self Service CA PAM Client for Linux for zSeries CA Mainframe Connector for Linux on System z CA Graphical Management Interface CA Web Administrator for Top Secret CA CA- Xpertware CA Top Secret CA Top Secret - LDAP CA Top Secret - VSE

Issue/Introduction

A client has accidentally deleted the wrong certificate and needs to reinstate it if possible.

Environment

Release: TOPSEC00200-15-Top Secret-Security
Component:

Resolution

A client has accidentally deleted the wrong certificate and needs to reinstate it if possible.

Solution:

The Delete of a certificate is actually a remove command.

If you remove the certificate from the owning acid, such as:

TSS REMOVE(owning acid) DIGICERT(certificate)

The certificate will no longer exist in Top Secret.

The certificate will still reside in the dataset because that is outside of Top Secret. In order to completely delete a certificate you would have to delete the dataset where the certificate resides.

You can add the certificate back to the owning acid:

TSS ADD(owning acid) DIGICERT(digicert) DCDSN('dataset where digicert resides')

You will then have to add the certificate back to any keyrings it previously was on:

TSS ADD(acid) KEYRING(keyring) RINGDATA(owner of cert,digicert) USAGE(personal) DEFAULT

 

Additional Information