I'm glad you've had good results with AWS. The Azure should be equally 
straightforward if you are using the Shared Key stuff. 

As to the GCP side. If you are using Google's recommended JSON key type, then 
yes, the systems need to have a crypto domain assigned to it in order to 
process the private key. I think there is a way to use an API Key with it, but 
after spending 30 minutes being frustrated with their interface, I gave up. I 
think most of the GDKUTIL users that have Google Cloud Platform actually use 
their 'XML compatibility API', which is their way to say S3-compatible. That's 
why I ship the GOOGS3.json sample.

Sincerely,
Andrew Wilt

DFSMSdfp CDA (Cloud Data Access) Product Owner
IBM Z Content Solutions | IBM z/OS Cloud Data Access
z/OS DFSMS Community

-----Original Message-----
From: IBM Mainframe Discussion List <[email protected]> On Behalf Of 
Vince Re
Sent: Friday, February 20, 2026 3:10 PM
To: [email protected]
Subject: [EXTERNAL] Re: Help configuring GDKUTIL on system with no crypto 
processor

Okay, I changed the input file as you described and got : 

GDKU0101E ERROR DURING CREDENTIALS(ADD) REQUEST. GDKRC=122: ICSF error 
occurred. 
ERROR: CSNDPKI error: rc: 12, e_rc: xC, e_rsn: x2B34                            
                         
ERROR: CSNDPKB result: rc:12, e_rc:12, e_rsn: 11060  
 
If I'm understanding you correctly, does this mean that there's no way to use 
GDKUTIL with Google from a system that doesn't have a crypto processor 
configured? Is there another type of authentication that's not a GCP service 
account that we might use? Is there a way to store the key in a KDB file or 
something like that? 

Thanks again for your help - I've had good results with your stuff on AWS, so 
I'm hoping there's a way we can use it from GCP and Azure too.


Vince

----------------------------------------------------------------------
For IBM-MAIN subscribe / signoff / archive access instructions, send email to 
[email protected] with the message: INFO IBM-MAIN

----------------------------------------------------------------------
For IBM-MAIN subscribe / signoff / archive access instructions,
send email to [email protected] with the message: INFO IBM-MAIN

Reply via email to