GDDR: GDDR Tape script GDDRPCCT fails with error message RXSCLI054
Summary: GDDR Tape script GDDRPCCT fails with error message RXSCLI054.
Symptoms
The user performed GDDR Tape script GDDRPCCT in a 2-site DLM VNX-DD long-distance configuration. This script performs Workload Management Profile (WMP) validation for all defined WMPs.
The script failed with the following RXSCLI054E error:
20181-09:47:39 GDDR721I GDDR Starting Validate Tape Profiles
profparm = *
failsite = DC9
20181-09:47:39 GDDT014W Profile xxxxx has no corresponding member
>RDLMV> Sending TCP/IP req at 09:47:41 (CONNECT)
>RDLMV> Waiting for response until 9:57:41
>RDLMV> Response received at 09:47:41 (CONNECT)
>RDLMV> Sending TCP/IP req at 09:47:41 (WRITE)
>RDLMV> Waiting for response until 9:57:41
>RDLMV> Response received at 09:47:41 (WRITE)
>RDLMV> Sending TCP/IP req at 09:47:41 (READ)
>RDLMV> Waiting for response until 9:57:41
>RDLMV> Response received at 09:47:41 (READ)
***---------------------------------------------------------***
===> Error: RXSCLI054E SOCKET(READ) rc=54 Connection reset by peer
***---------------------------------------------------------***
20181-09:47:41 GDDR639I GDDR Completed Validate Tape Profiles with rc 12
20181-09:47:41 GDDR721I GDDR Starting Script Function Call Stats
20181-09:47:41 GDDR639I GDDR Function Status ===>
Jun 29 09:47:41 vte1 /opt/dlmaut/dlm_aut_con.pl[136686]: DLmAutTools:I: Info: Upgrading socket to SSL (starting SSL handshake)
Jun 29 09:47:41 vte1 /opt/dlmaut/dlm_aut_con.pl[136686]: DLmAutTools:I: CONFIG SSL_VERSION: final version = {SSLv23:!SSLv2:!SSLv3:!TLSv1}
Jun 29 09:47:41 vte1 /opt/dlmaut/dlm_aut_con.pl[136686]: DLmAutTools:E: DLMAUT0144E: Request rejected. SSL handshake error: SSL accept attempt failed with unknown errorerror:00000000:lib(0):func(0):reason(0) Connection reset by peer
Jun 29 09:47:41 vte1 /opt/dlmaut/dlm_aut_con.pl[136686]: DLmAutTools:E: DLMAUT0146E: Failed to upgrade socket to SSL.
Jun 29 09:47:41 vte1 /opt/dlmaut/dlm_aut_con.pl[136686]: DLmAutTools:I: Info: Generating ERROR DLMAUT0146E callhome...
Jun 29 09:47:51 vte1 /opt/dlmaut/dlm_aut_con.pl[136686]: DLmAutTools:I: Info: Sending 'Failed to upgrade socket to SSL.' to DLMHOST...
Also, TCP/IP logged the following EZD1287I error;
09.47.41 S0012259 EZD1287I TTLS Error RC: 472 Initial Handshake 769
769 LOCAL: xx.xx.xx.xx..yyyy
769 REMOTE: xxx.xx.xx.xxxx..yyyyy0
769 JOBNAME: GDDRPCCT RULE: zclient_GDDR
USERID: uuuuuuuu GRPID: 00000002 ENVID: 0000026F CONNID: 0010CE2C
The EZD1287I error message has the following information detailed for RC=472 - 'Clear key support not available due to ICSF key policy'.
Explanation
Unable to generate clear keys or PKCS #11 objects because of the caller's RACF access to CRYPTOZ class resource CLEARKEY.SYSTOK-SESSION-ONLY does not allow the generation of non-secure (clear) PKCS #11 keys.
Cause
The error occurred because the user id which the GDDRPCCT script was running under, did not have access to the RACF CRYPTOZ class resource CLEARKEY.SYSTOK-SESSION-ONLY. The customer was running the script under the wrong user id.
Resolution
Ensure that the user id of the application has appropriate access to the RACF CRYPTOZ class resource CLEARKEY.SYSTOK-SESSION-ONLY.