GIM44336S no private key
search cancel

GIM44336S no private key

book

Article ID: 91713

calendar_today

Updated On:

Products

CIS COMMON SERVICES FOR Z/OS 90S SERVICES DATABASE MANAGEMENT SOLUTIONS FOR DB2 FOR Z/OS COMMON PRODUCT SERVICES COMPONENT Common Services Datacom/AD CA ECOMETER SERVER COMPONENT FOC Easytrieve Report Generator for Common Services INFOCAI MAINTENANCE IPC UNICENTER JCLCHECK COMMON COMPONENT Mainframe VM Product Manager CHORUS SOFTWARE MANAGER CA ON DEMAND PORTAL CA Service Desk Manager - Unified Self Service PAM CLIENT FOR LINUX ON MAINFRAME MAINFRAME CONNECTOR FOR LINUX ON MAINFRAME GRAPHICAL MANAGEMENT INTERFACE WEB ADMINISTRATOR FOR TOP SECRET Xpertware

Issue/Introduction

After installing all required definitions for the SMPE Receive Order still getting the error message:

GIM44336S ** AN UNUSUAL CONDITION OCCURRED. GIMJVCNI - java.io.IOException: The private key of "SMPE Client Certificate for CA" is not available or no authority to access the private key .

In RACF you see that the generated certificate from CA has no private key. What's the problem ?
This error can occur with IBM or Broadcom SMP/E Internet Service Receive Order with RACF or Broadcom security products: ACF2 and Top Secret.

Environment

z/OS any supported release
CCS 15.0

Cause

The installation instructions were not completely followed.

Resolution

The most common cause of the GIM44336S error is the certificate connection to the Keyring, both the client user certificate and the Certificate Authority certificate need to be connected to the Keyring as USAGE(CERTAUTH).

When using Top Secret, the ORDERSERVER certificate="user certificate label" must match the LABEL of the user certificate. 

The Techdoc Configure SMP/E Internet Service Retrieval provides all the information necessary to set up the SMP/E Internet Service Retrieval with the three major External Security Managers.