Classification: Confidential

1)      Re: PCKS11 support.  You need to set up a TKDS for use by ICSF. Check 
the fine manuals for details.
2)      TLS 1.3 requires specific ciphers (IIRC 3 specific ciphers) and is 
controlled by the TCPIP Policy Agent. Again, check the fine manuals for details

HTH

-----Original Message-----
From: IBM Mainframe Discussion List <[email protected]> On Behalf Of 
Paul Gorlinsky
Sent: Wednesday, June 19, 2024 11:01 AM
To: [email protected]
Subject: Re: EZZ6034I ERR 1030

[CAUTION: This Email is from outside the Organization. Unless you trust the 
sender, Don’t click links or open attachments as it may be a Phishing email, 
which can steal your Information and compromise your Computer.]

15.52.06 STC07201  EZZ6034I TN3270 CONN 000005B5 LU **N/A**  CONN DROP  ERR 1030
  IP..PORT: 172.31.123.97..59419                             EZBTTXPL

is the entire content of the message.

These are in the SYSOUT for both TN3270 and TCPIP STCs


System SSL: SHA-1 crypto assist is available System SSL: SHA-224 crypto assist 
is available System SSL: SHA-256 crypto assist is available System SSL: SHA-384 
crypto assist is available System SSL: SHA-512 crypto assist is available 
System SSL: DES crypto assist is available System SSL: DES3 crypto assist is 
available System SSL: AES 128-bit crypto assist is available System SSL: AES 
256-bit crypto assist is available System SSL: AES-GCM crypto assist is 
available System SSL: Cryptographic accelerator is not available System SSL: 
Cryptographic coprocessor is not available System SSL: Public key hardware 
support is not available System SSL: ECC secure key support is not available.
System SSL: ICSF Secure key PKCS11 support is not available System SSL: ICSF 
FMID is HCR77D0


What would help determine the issue ...

BTW SSL ( TLS 1.0 ) works -- It is on PORT 992

We are trying to configure port 2023 for TLS 1.2 TLS 1.3

----------------------------------------------------------------------
For IBM-MAIN subscribe / signoff / archive access instructions, send email to 
[email protected] with the message: INFO IBM-MAIN
::DISCLAIMER::
________________________________
The contents of this e-mail and any attachment(s) are confidential and intended 
for the named recipient(s) only. E-mail transmission is not guaranteed to be 
secure or error-free as information could be intercepted, corrupted, lost, 
destroyed, arrive late or incomplete, or may contain viruses in transmission. 
The e mail and its contents (with or without referred errors) shall therefore 
not attach any liability on the originator or HCL or its affiliates. Views or 
opinions, if any, presented in this email are solely those of the author and 
may not necessarily reflect the views or opinions of HCL or its affiliates. Any 
form of reproduction, dissemination, copying, disclosure, modification, 
distribution and / or publication of this message without the prior written 
consent of authorized representative of HCL is strictly prohibited. If you have 
received this email in error please delete it and notify the sender 
immediately. Before opening any email and/or attachments, please check them for 
viruses and other defects.
________________________________

----------------------------------------------------------------------
For IBM-MAIN subscribe / signoff / archive access instructions,
send email to [email protected] with the message: INFO IBM-MAIN

Reply via email to