Using CA Top secret utility TSSXTEND it abends with U3044

Document ID : KB000113121
Last Modified Date : 05/09/2018
Show Technical Document Details
Question:
Why do we get an abend U3044 from the CA Top secret utility TSSXTEND? 
Environment:
z/OS
Answer:
The old security files were defined with the AES feature. The new security files were defined without the AES feature.
It's not allowed to copy an AES secfile to a non-AES secfile, hence the abend U3044.

You have to defined the new security file with the AESENCRYPTION  or AES256ENCRYPT TSSXTEND option .

See the links below: 

DES to AES128 conversion:

https://docops.ca.com/ca-top-secret-for-z-os/16-0/en/using/managing-passwords-and-password-phrases/convert-triple-des-to-128-bit-aes-encryption-for-passwords-password-phrases

To AES256 conversion:
 
https://docops.ca.com/ca-top-secret-for-z-os/16-0/en/using/managing-passwords-and-password-phrases/implement-256-bit-aes-encryption-for-passwords-password-phrases