How to resolve the TSS0301I and CAS20C1E error message when using the TSS GENCERT command.
TSS GENCERT(CERTAUTH) DIGICERT(CERTCAU) -
Causes the following error:
TSS0301I GENCERT FUNCTION FAILED, RETURN CODE = 8
CAS20C1E Invalid data in PKCS #10 request - RSN - 212
Looking up error message CAS20C1E, I don't see a reason code of 212:
The data set contains a PKCS #10 request that does not meet the requirements for a PKCS #10 certificate request. The reason code specified by rsn will indicate to CA Top Secret Technical Support where the invalid data is occurring.
•0 -- Function was successful
•4 -- Certificate length error or no certificate address supplied
•8 -- PEM translation error
•12 -- Error parsing certificate
•16 -- Invalid cert version number
•20 -- Output field was truncated
•24 -- Routine could not be found
•28 -- Signature check failed
Contact CA Top Secret Technical Support.
Release: TOPSEC00200-15-Top Secret-Security
The 3rd party Certificate Authority that signs the certificates needs to return the signed certificate in a PKCS10 certificate package.
Then the certificate package needs to be uploaded to variable block and DSORG=DS dataset.
Specify the dataset name in the DCDSN keyword and it ****must**** be a formatted PKCS10 certificate package.