Not that I am advocating plowing thru source code or generating more work for Greg, but it "seems" fairly straightforward to follow the program from when the parm for CSF domain is interpreted or assigned in absentia.
I am guessing that it is in a control block done at IPL time at least for z9 and below or one of the instructions that are ICSF/Crypto specific that are not documented for the public domain. Although I am thinking that planning is probably a more pertinent solution. When ICSF fails to initialize due to improper master key, it is either the wrong domain or never been done. Additionally, if you are using a DR provider, you'll need to ensure that the domain is "cleared" or set multiple times to a fake key. Probably a bit paranoid... but then again it is more about the weakest link in security/cryptography ... people. Rob Schramm ---------------------------------------------------------------------- For IBM-MAIN subscribe / signoff / archive access instructions, send email to [EMAIL PROTECTED] with the message: GET IBM-MAIN INFO Search the archives at http://bama.ua.edu/archives/ibm-main.html

