
Chapter 5. Operations 133
– A certificate has expired.
– The key type associated with the certificate is not valid for the cipher algorithm
requested in the policy.
– The certificate private key is stored in the ICSF PKDS, but ICSF was not started.
– There is a logical inconsistency between the policy statements for the “client” and
“server” portions of the policy.
The TLS handshake is run on both systems, and the error might have occurred on only
one of the systems. Therefore, be sure to look in the trace log on the remote system if
there is no helpful information about the system you are currently logged on to.
Whenever an error is encountered, ...