Troubleshooting FICON® encryption

Provisioning Guide for Mainframe Systems for VSP One Block 85

Version
10.5.x
File Size
1619 KB
Audience
anonymous
Part Number
MK-26VSP1B034-03
ft:lastEdition
2026-06-23

The following table summarizes troubleshooting information about the FICON® encryption functions.

Problem Causes Solutions
An abnormal termination occurs after enabling Fibre Channel Endpoint Security for Mainframe. Fibre Channel Endpoint Security for Mainframe is enabled for the port where the channel path is online. Take the channel path for the target port offline, and then retry the operation.
  • Fibre Channel Endpoint Security for Mainframe is enabled correctly. However, the security status does not meet the expected status.
  • The port whose Fibre Channel Endpoint Security for Mainframe state was previously either "port authentication is enabled" or "port authentication and encryption of data-in-flight are enabled" has changed to a different status.
The combination of the port with Fibre Channel Endpoint Security for Mainframe enabled and the HBA type on the host connected to the target port does not meet the expected endpoint security encryption settings. Verify the security settings for the target port or the destination to which the target port is connected by referring to Host requirements and Verifying the port authentication and encryption of data-in-flight settings on the host.
A SIM code listed in the table in SIM codes for Fibre Channel Endpoint Security for Mainframe is output. Take actions for the SIM code by referring to SIM codes for Fibre Channel Endpoint Security for Mainframe.
A failure occurs in the channel board, or in the cable or the switch between the host and the storage system. Contact customer support to take actions.
There is a problem with the shared key. Verify with the KMS administrator that the shared key has been generated correctly.
The client certificate configured on the storage system is updated, however, the required operations are not performed on the KMS.

Verify whether the required operations are performed on the KMS.

For the operations required on the KMS when updating the client certificate, see the IBM® documentation.

Fibre Channel Endpoint Security for Mainframe is enabled correctly, and the expected security status is achieved. However, the channel path status of some or all volumes are not brought online (PATH AVAILABLE). A temporary path failure might have occurred.

Take the channel paths for the target ports offline, and then bring the channel paths back online. After bringing the channel paths on the target port online, verify that the security status is as expected and that the channel path status of all volumes is online (PATH AVAILABLE).

If this problem occurs again even after taking corrective actions, contact customer support to take actions.

During the operation, a SIM code is output. A SIM code listed in the table in SIM codes for Fibre Channel Endpoint Security for Mainframe is output. Take actions for the SIM code by referring to SIM codes for Fibre Channel Endpoint Security for Mainframe.
A failure occurs in the channel board, or in the cable or the switch between the host and the storage system. Contact customer support to take actions.
During the operation, I/O operations end abnormally, or a channel path is not available. A failure occurs in the channel board, or in the cable or the switch between the host and the storage system. Contact customer support to take actions.
There is a problem with the shared key. Verify with the KMS administrator that the shared key has been generated correctly.