Question & Answer
Question
Any idea why CICS Configuration Manager for z/OS (CICS CM) ISPF client and batch jobs cannot connect to the CICS CM server when trying to connect using Secure Sockets Layer (SSL)? ISPF users receive short message SSL Socket Open and PF1 for the associated long message returns Establishing a secure socket connection failed.
The CICS CM Explorer Plug-in connects fine to the SSL port.
Answer
For information regarding SSL connectivity and set up, refer to the following topics:
Configuring CICS to use SSL within CICS Transaction Server for z/OS in the CICS TS documentation.
Steps for setting up PKI Services to encrypt returned private keys with certificates in a key ring within z/OS Cryptographic Services in the z/OS Cryptographic Services PKI Services Guide and Reference.
Ensure that the userID associated with a batch or ISPF (TSO) client has appropriate access to the SSL keyring. The permissions required vary depending upon the method used to control keyring usage:
If a profile for ring_owner.ring_name.LST in CLASS(RDATALIB) has been implemented, then the batch or ISPF (TSO) userID must have READ access to the profile.
If a profile for IRR.DIGTCERT.LISTRING in CLASS(FACILITY) has been implemented, then the ISPF (TSO) userID must have UPDATE access to the profile.
Product Synonym
CICSCM CICS CM
Was this topic helpful?
Document Information
Modified date:
14 April 2016
UID
dwa1263093