Previous Topic: TE_VRFY_ICSF_CHECKAUTH@BESn—Verify CHECKAUTH(NO) is Specified

Next Topic: TE_VRFY_LPA_MODULES@BESn—Check LPA Module Level

TE_VRFY_KEYS_DB@BESn—Check KeysDatabase StartUp Attribute

Use TE_VRFY_KEYS_DB@BESn to check that your KeysDatabase StartUp attribute correctly identifies the keys database.

Default Interval

Once when the BES address space starts up.

Exception interval

System default.

Best Practice

Normally, when you specify KeysDatabase=BES, you would expect the BES primary and mirror databases contain the encryption keys required by CA Tape Encryption. However, the specification SecureKeysOnly=Y as a global attribute causes CA Tape Encryption to use the CKDS as the Keys database. That means the CKDS contains all the keys and the BES database does not. In the event of a disaster recovery, the keys cannot be recovered from the BES database. A backup of the ICSF CKDS must be available to recover the keys. If you specify SecureKeysOnly=K, then the CKDS contains the keys that have the SecureKeysOnly=Y at the key level. If either of these conditions exist, you will need a backup of your ICSF CKDS.

Parameters Accepted

None.

Debug Support

Yes.

Verbose Support

Yes.

Message

BESH0061E The BESn database in use does not match the KeysDatabase attribute specified in the <StartupOptions>.

For more information see the Configuration Guide and the Messages Guide.