I am trying to do a GENCERT of a Personal certificate with the SIGNWITH parameter and I am getting error message 'ACF68028 ERROR RETRIEVING SIGNWITH CERTIFICATE', what causes this?

Document ID : KB000014088
Last Modified Date : 14/02/2018
Show Technical Document Details
Question:

I am trying to do a GENCERT of a Personal certificate with the SIGNWITH parameter and I am getting error message 'ACF68028 ERROR RETRIEVING SIGNWITH CERTIFICATE', what causes this?

Answer:

If the signing certificate is not a CERTAUTH or SITECERT certificate, or if the GENCERT is not being done by the signing certificate's owner the Error 'ACF68028 ERROR RETRIEVING SIGNWITH CERTIFICATE' message will be issued.

The SIGNWITH parameter requires a value in the format CERTAUTH.RECORDID, CERTAUTH LABEL(value), SITECERT.RECORDID, SITECERT LABEL(value) or (Label(label-name)). If CERTAUTH or SITECERT are not specified, Label must be specified and the label will identify the user certificate that will sign the new certificate. The user id associated with the label is the user generating the certificate.

For example:

Logon to TSO using loginid USER002, issue the GENCERT:

GENCERT USER002.CERT1 SUBJ(CN='AMSCALocalzOSCA'                                
    OU='Auditing Department' O='Company Name' C=US)  
   LABEL(ABCCA CA) KEYSIZE(2,048)

CERTDATA / USER002.CERT1 LAST CHANGED BY USER002 ON 04/12/17-12:53            
                      CERTNSER(0000000000000001) ISSUERDN(CN=AMSCALocalzOSCA.OU
                      =Auditing Department.O=Company Name.C=US) KEYSIZE(2,048)
                      LABEL(ABCCA CA) SERIAL#(00) SUBJDN(CN=AMSCALocalzOSCA.OU=
                      Auditing Department.O=Company Name.C=US) TRUST           

  Certificate is not connected to any key rings                                 

 PROFILE                                                                        

GENCERT TESTK.CERT SUBJ(CN=‘KSOperations’ OU=‘MyCo’ C=US)                      
   LABEL(TESTServer) SIGNWITH(LABEL(ABCCA CA))   

CERTDATA / TESTK.CERT LAST CHANGED BY USER002 ON 04/12/17-12:53              
                      ISSUERDN(CN=AMSCALocalzOSCA.OU=Auditing Department.O=Comp
                      any Name.C=US) KEYSIZE(2,048) LABEL(TESTServer)        
                       SERIAL#(01) SUBJDN(CN=KSOperations.OU=MyCo.C=US) TRUST   

  Certificate is not connected to any key rings