IBM Support

FTP session secured with Kerberos fails with message 534

Question & Answer


Question

A user's attempt to start an FTP session with our z/OS Communications Server FTP server is failing. This 534 failure message appears after the client issues the AUTH GSSAPI command:

534 Server is not willing to accept security mechanism

Answer

The message returned by the FTP server, 534 Server is not willing to accept security mechanism, is issued because the FTP.DATA configuration file that the FTP server is using does not have EXTENSIONS AUTH_GSSAPI coded. The IP Configuration Guide points out that specifying EXTENSIONS AUTH_GSSAPI is one of the steps necessary to configure the FTP server for Kerberos.

[{"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Product":{"code":"SSSN3L","label":"z\/OS Communications Server"},"Platform":[{"code":"PF035","label":"z\/OS"}],"Component":"","Version":"","Line of Business":{"code":"LOB35","label":"Mainframe SW"}}]

Product Synonym

ZOSCS COMMSERVER

Document Information

Modified date:
05 August 2016

UID

dwa1293559