Invalid Client Certificate for CA SMP/E Internet Service Retrieval

Document ID : KB000100621
Last Modified Date : 08/06/2018
Show Technical Document Details
Issue:
I am setting up CA SMP/E Internet Service Retrieval. I download the SMPE Client Certificate ca-receive-order.cer and then ftp in binary mode into dataset TS.CA.DCERT.PFX. The RACDCERT ADD commands fails : RACDCERT ID(DC351) ADD('TS.CA.DCERT.PFX') WITHLABEL('SMPE Client Certificate') TRUST The input data set does not contain a valid certificate. 

 
Resolution:
First verify that the LRECL for the dataset is correct otherwise truncation may occur making the certificate invalid. For this client certificate LRECL=2048 is long enough and use ascii mode for the download. The first line in the dataset after the download should be:
-----BEGIN CERTIFICATE-----
 
The last line should be:
-----END CERTIFICATE-----
Please refer ro link: 
https://docops.ca.com/mainframe-common-maintenance/en/configure-ca-smp-e-internet-service-retrieval/import-a-user-certificate-from-ca-support-online 

The link for the client certificate download is in step 2.