SFTP with Expired ACF2 Digital Certifcates

Discussion of Co:Z sftp, a port of OpenSSH sftp for z/OS
Post Reply
husachde
Posts: 1
Joined: Thu Jun 04, 2015 1:51 pm

SFTP with Expired ACF2 Digital Certifcates

Post by husachde »

Hi,
We have we have ACF2 Digital Certificates connected to KEYRINGs that we are using in our batch Co:Z SFTP. But the certificates are long expired in ACF2, some a couple of years ago. However there are no issues in the jobs until.. we deleted a few certificates ( thinking these are expired ) in ACF2 and job fails with :
SafSshAgentÝE¨: Keyring: 'xxxx/xxxx' was not found .

We are wondering, how was it working successfully with expired certs and failed after the cert was deleted. Is there something that can explain this ?

Any help is appreciated

Regards,
Hunny
dovetail
Site Admin
Posts: 2022
Joined: Thu Jul 29, 2004 12:12 pm

Re: SFTP with Expired ACF2 Digital Certifcates

Post by dovetail »

What version of Co:Z are you using?

If you are using Co:Z with the SafSshAgent prior to version 2.1.1, there was a bug where certificate expiry was not checked.

For more information, see: http://dovetail.com/docs/cozinstall/changes.html

Note: IBM Ported Tools OpenSSH doesn't use X.509 certificates, but can support storing SSH keys in them on z/OS.
Post Reply