Thank you Roger - I have exactly what you posted. I believe the issue is that I can't just use the Google-generated JSON file unchanged as input to GDKUTIL...IBM's code seems to want extra or different tags, but I can't find them actually described anywhere.
Just as a test, I took my setup to a system with a crypto processor online and ran it there...it generated a gdkkeyf.json, but it's empty - there's an entry for the cloud provider (GCP) and my user ID, but there are no authentication parameters in the file beyond that. If I compare this to an AWS S3 environment (which I do have working), with AWS, I see things like "key" and "secretkey" in the gdkkeyf entry for S3. I don't seem to be getting anything like that with my Google service account JSON input file as input. ---------------------------------------------------------------------- For IBM-MAIN subscribe / signoff / archive access instructions, send email to [email protected] with the message: INFO IBM-MAIN
