<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/css" href="../../resources/stylesheets/wasmsgxml.css"?>
<TMSSource name="TivoliMessages" tmsVersion="1.0" xml:lang="en">
<!-- CMVC MSG File Name = ws/code/runtime/src/com/ibm/ejs/resources/security.nlsprops -->
<!-- DO NOT EDIT THIS FILE - This file was generated by the XML/Html & Property emitter -->
<!-- BEGIN MESSAGES -->
<Message ID="SECJ7083I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.Security.properties" varFormat="Java">
    security.configrpt.core.Security.properties=SECJ7083I: Properties
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0172E" severity="E" prefix="yes">
  <MsgText pgmKey="security.policy.parser.encodeFilePath" varFormat="Java">
    security.policy.parser.encodeFilePath=SECJ0172E: Error {0} in encoding the FilePath
  </MsgText>
  <Explanation>
    While encoding the FilePath, there was an error.
  </Explanation>
  <UserResponse>
    Check the specified syntax.  To identify which policy file has a problem, enable security trace for the component com.ibm.ws.security.policy.*. trace.log will show the policy file name.
  </UserResponse>
</Message>
<Message ID="SECJ7185I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.range" varFormat="Java">
    security.configrpt.core.range=SECJ7185I: Range
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0158I" severity="I" prefix="yes">
  <MsgText pgmKey="security.wsaccessmanager.classloadingaudit" varFormat="Java">
    security.wsaccessmanager.classloadingaudit=SECJ0158I: Problem loading class {0}, using default authorization table provided by WebSphere
  </MsgText>
  <Explanation>
    The Vendor specified Authorization Table could not be loaded successfully. The WebSphere provided authorization table will be used.
  </Explanation>
  <UserResponse>
    Make sure that the vendor&apos;s implementation of Authorization Table is in the CLASSPATH and that it could be loaded.
  </UserResponse>
</Message>
<Message ID="SECJ6215E" severity="E" prefix="yes">
  <MsgText pgmKey="security.zos.saf.credtoken.finalize.error" varFormat="Java">
    security.zos.saf.credtoken.finalize.error=SECJ6215E: The SAF credential token {0} has been finalized but the underlying native credential has not been destroyed.
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ6221E" severity="E" prefix="yes">
  <MsgText pgmKey="security.zos.saf.authen.refresh.failed.error" varFormat="Java">
    security.zos.saf.authen.refresh.failed.error=SECJ6221E: A native credential for user &quot;{0}&quot; cannot be recreated.  The native service results related to this failure are: {1}.
  </MsgText>
  <Explanation>
    An authorized service used to create a native z/OS credential has failed.  The credential cannot be used by the caller.
  </Explanation>
  <UserResponse>
    Use the provided SAF service information to determine the cause of the failure.  If the problem persists, contact the IBM support center.
  </UserResponse>
</Message>
<Message ID="SECJ7470E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.InvalidWrapBehavior" varFormat="Java">
    security.admintask.InvalidWrapBehavior=SECJ7470E: An invalid value has been specified for the binary audit log wrapping behavior.
  </MsgText>
  <Explanation>
    An invalid value was specified for the binary audit log wrapping behavior.  Valid values are: WRAP, NOWRAP or SILENT_FAIL.
  </Explanation>
  <UserResponse>
    Specify a valid value for the binary audit log wrapping behavior.
  </UserResponse>
</Message>
<Message ID="SECJ7004I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.activeProtocol" varFormat="Java">
    security.configrpt.core.activeProtocol=SECJ7004I: Active RMI/IIOP authentication protocol
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7236I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.krb5Config" varFormat="Java">
    security.configrpt.core.krb5Config=SECJ7236I: Kerberos configuration file
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0049E" severity="E" prefix="yes">
  <MsgText pgmKey="security.sasconfig.startup.error" varFormat="Java">
    security.sasconfig.startup.error=SECJ0049E: Configuration error encountered while starting the server
  </MsgText>
  <Explanation>
    An unexpected RemoteException, OpException or IOException occurred during server startup. There could be problems with loading or writing of security configuration URL property files.
  </Explanation>
  <UserResponse>
    Verify that the file associated with security configuration URL property file (typically sas.server.props) has read permission and is writable.
  </UserResponse>
</Message>
<Message ID="SECJ7321E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.InvalidLDAPServerType" varFormat="Java">
    security.admintask.InvalidLDAPServerType=SECJ7321E: Invalid LDAP user registry type
  </MsgText>
  <Explanation>
    LDAP registry type was not a valid type
  </Explanation>
  <UserResponse>
    Ensure user registry type is a valid type
  </UserResponse>
</Message>
<Message ID="SECJ7060I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.serverAuthentication" varFormat="Java">
    security.configrpt.core.serverAuthentication=SECJ7060I: Server Authentication
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ4040W" severity="W" prefix="yes">
  <MsgText pgmKey="security.jaas.update" varFormat="Java">
    security.jaas.update=SECJ4040W: {0} :Warning: update() method passed either a null or empty string.
  </MsgText>
  <Explanation>
    null or empty string was passed to update() method.
  </Explanation>
  <UserResponse>
    This is a warning.
  </UserResponse>
</Message>
<Message ID="SECJ6010W" severity="W" prefix="yes">
  <MsgText pgmKey="security.audit.service.extra.warning" varFormat="Java">
    security.audit.service.extra.warning=SECJ6010W: Extra AuditServiceProvider definition detected and discarded: {0}.
  </MsgText>
  <Explanation>
    Extra AuditServiceProvider was defined and is discarded.
  </Explanation>
  <UserResponse>
    The com.ibm.wsspi.security.audit.auditServiceProvider properties contains extra information than necessary.  Any information following the valid AuditServiceProvider definition is discarded.
  </UserResponse>
</Message>
<Message ID="SECJ0080E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.userentry.notfound" varFormat="Java">
    security.registry.userentry.notfound=SECJ0080E: User entry is not found in the registry
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7044I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.loginModules" varFormat="Java">
    security.configrpt.core.loginModules=SECJ7044I: JAAS login modules
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0198E" severity="E" prefix="yes">
  <MsgText pgmKey="security.policy.perminstance.exception" varFormat="Java">
    security.policy.perminstance.exception=SECJ0198E: An exception was caught while constructing the permission object. The exception is {0}.
  </MsgText>
  <Explanation>
    An Exception occurred while constructing the permission object.
  </Explanation>
  <UserResponse>
    Check the exception.
  </UserResponse>
</Message>
<Message ID="SECJ7231I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.No.AdminSecurityManager.Role.User" varFormat="Java">
    security.configrpt.No.AdminSecurityManager.Role.User=SECJ7231I: No AdminSecurityManager user or group
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0130E" severity="E" prefix="yes">
  <MsgText pgmKey="security.web.ta.srcpatherr" varFormat="Java">
    security.web.ta.srcpatherr=SECJ0130E: Unable to get source path from request header &apos;via&apos;
  </MsgText>
  <Explanation>
    When using WebSealTrustAssociationInterceptor,  the &quot;via&quot; HTTP header in the HTTP Request object is examined. This message appears when the value for this header is not valid or corrupted.
  </Explanation>
  <UserResponse>
    Make sure that WebSeal, the HTTP Server or both are properly working.
  </UserResponse>
</Message>
<Message ID="SECJ7758E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.naming.invalid.users.groups.SECJ7758E" varFormat="Java">
    security.admintask.naming.invalid.users.groups.SECJ7758E=SECJ7758E: The following users or groups or special subjects {0} cannot be added to role {1}.
  </MsgText>
  <Explanation>
    The users or groups are already assigned to this role.
  </Explanation>
  <UserResponse>
    Run the command by correcting the user, group or specialSubject list.
  </UserResponse>
</Message>
<Message ID="SECJ0124E" severity="E" prefix="yes">
  <MsgText pgmKey="security.web.ta.nointclass" varFormat="Java">
    security.web.ta.nointclass=SECJ0124E: Trust Association Init No interceptor class {0} found
  </MsgText>
  <Explanation>
    The interceptor class file specified in trustedservers.properties cannot be found.
  </Explanation>
  <UserResponse>
    Verify that the appropriate Trust Association classes are installed and the class path is correct. Also verify that the class specified in the trustedservers.properties file is correct and that the file has at least read permission.
  </UserResponse>
</Message>
<Message ID="SECJ0189E" severity="E" prefix="yes">
  <MsgText pgmKey="security.policy.app.parserexception" varFormat="Java">
    security.policy.app.parserexception=SECJ0189E: Caught ParserException while creating template for Application Policy {0}. The exception is {1}.
  </MsgText>
  <Explanation>
    ParserException occurred when creating the application policy template in the hashmap of all the templates.
  </Explanation>
  <UserResponse>
    Check the ParserException data. Check the specified policy file.
  </UserResponse>
</Message>
<Message ID="SECJ6219I" severity="I" prefix="yes">
  <MsgText pgmKey="security.zos.saf.authen.pw.check.failed.info" varFormat="Java">
    security.zos.saf.authen.pw.check.failed.info=SECJ6219I: Basic authentication failed for user &quot;{0}&quot;.  The native service results related to the authentication failure are: {1}.
  </MsgText>
  <Explanation>
    WebSphere was unable to authenticate the user with the password that was presented.  It is likely that the user ID or password were not valid.
  </Explanation>
  <UserResponse>
    Verify that the user ID is valid.  If the user is valid, use the provided SAF serivce information to get more information about the cause of the failure.
  </UserResponse>
</Message>
<Message ID="SECJ4003E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaas.invalidLocalOSToken" varFormat="Java">
    security.jaas.invalidLocalOSToken=SECJ4003E: Credential token login is not valid for LocalOS
  </MsgText>
  <Explanation>
    JAAS Login failure occurred while invoking login() with token for LocalOS.
  </Explanation>
  <UserResponse>
    LocalOS does not support login with token. Make sure that the application program is valid.
  </UserResponse>
</Message>
<Message ID="SECJ0213E" severity="E" prefix="yes">
  <MsgText pgmKey="security.init.wccmjaas.wrongclasserror" varFormat="Java">
    security.init.wccmjaas.wrongclasserror=SECJ0213E: Unexpected JAAS login provider class {0} is currently configured. The expected configured class is {1}. When WebSphere security is enabled, this class is required.
  </MsgText>
  <Explanation>
    WebSphere provides an implementation of javax.security.auth.login.Configuration and dynamically installs this class at server startup. Either some application code has installed a different login provider class or a problem occurred when WebSphere tried to dynamically install the class.
  </Explanation>
  <UserResponse>
    Check for other server startup warning or error messages.
  </UserResponse>
</Message>
<Message ID="SECJ7200I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.keyAlias" varFormat="Java">
    security.configrpt.core.keyAlias=SECJ7200I: Key Alias
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7016I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.authContextImplClass" varFormat="Java">
    security.configrpt.core.authContextImplClass=SECJ7016I: Authentication context implementation class
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7411E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.NoKeyStorePathValue" varFormat="Java">
    security.admintask.NoKeyStorePathValue=SECJ7411E: No key store location was specified for the audit key store.
  </MsgText>
  <Explanation>
    Must specify a key store location for the audit key store
  </Explanation>
  <UserResponse>
    Supply a key store location for the audit key store
  </UserResponse>
</Message>
<Message ID="SECJ0139E" severity="E" prefix="yes">
  <MsgText pgmKey="security.ssl.config.initialization" varFormat="Java">
    security.ssl.config.initialization=SECJ0139E: Error to get initial naming context
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7372E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.GetFiltersFailure" varFormat="Java">
    security.admintask.GetFiltersFailure=SECJ7372E: Failure to retrieve the audit specifications.
  </MsgText>
  <Explanation>
    Failure while retrieving the audit specifications.
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7276I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.Session.Security" varFormat="Java">
    security.configrpt.core.Session.Security=SECJ7276I: Session Security
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7141I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.trustAssociation" varFormat="Java">
    security.configrpt.core.trustAssociation=SECJ7141I: Trust association
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7280I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.Session.Management" varFormat="Java">
    security.configrpt.core.Session.Management=SECJ7280I: Session management
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0215I" severity="I" prefix="yes">
  <MsgText pgmKey="security.init.wccmjaas.setcfg" varFormat="Java">
    security.init.wccmjaas.setcfg=SECJ0215I: Successfully set JAAS login provider configuration class to {0}.
  </MsgText>
  <Explanation>
    WebSphere provides an implementation of the javax.security.auth.login.Configuration class.  This class was successfully set at server startup.
  </Explanation>
  <UserResponse>
    None. Informational only.
  </UserResponse>
</Message>
<Message ID="SECJ7350E" severity="E" prefix="yes">
  <MsgText pgmKey="security.profiletask.ExceptionAddAdminIdToUserRegObj" varFormat="Java">
    security.profiletask.ExceptionAddAdminIdToUserRegObj=SECJ7350E: Exception raised while adding adminId to user registry
  </MsgText>
  <Explanation>
    Exception raised while adding adminId to user registry
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7471W" severity="W" prefix="yes">
  <MsgText pgmKey="security.admintask.checkpoint.not.enabled" varFormat="Java">
    security.admintask.checkpoint.not.enabled=SECJ7471W: Warning:  automatic repository checkpoints is not enabled.  To capture changes to the configuration repository and emit the corresponding audit records, you must enable automatic repository checkpoints of the extended repository service.
  </MsgText>
  <Explanation>
    Admin repository save changes will not be audited if checkpointing is not enabled.
  </Explanation>
  <UserResponse>
    Verify that checkpointing is enabled.
  </UserResponse>
</Message>
<Message ID="SECJ7824E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.checkCluster.SECJ7824E" varFormat="Java">
    security.admintask.checkCluster.SECJ7824E=SECJ7824E: The {0} cluster is mapped to the {1} security domain.  The cluster member being added to the {2} cluster must be on a node that is version 7.0 or higher if the cluster is mapped to a security domain.
  </MsgText>
  <Explanation>
    When a cluster is mapped to a security domain all members of that cluster have to be running on a version 7.0 or higner.
  </Explanation>
  <UserResponse>
    Ensure the node of the cluster member is version 7.0 or higher.
  </UserResponse>
</Message>
<Message ID="SECJ6109I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.service.everyone.audit" varFormat="Java">
    security.audit.service.everyone.audit=SECJ6109I: Access to a web resource is allowed because either the EVERYONE Special Subject was mapped to at least one of the required security role or if there is no auth constraint.
  </MsgText>
  <Explanation>
    Access to a web resource is granted to any user without requiring authentication when the Everyone Special Subject was mapped to at least one of the required security role.
  </Explanation>
  <UserResponse>
    Modify the security constraint if the current behavior does not fit your needs.
  </UserResponse>
</Message>
<Message ID="SECJ0292E" severity="E" prefix="yes">
  <MsgText pgmKey="security.servcomp.get.rar" varFormat="Java">
    security.servcomp.get.rar=SECJ0292E: Failed to retrieve the information of Resource Adapter of {0} to call setupPolicy().
  </MsgText>
  <Explanation>
    An unexpected exception occurred when trying to retrieve the information of the Resource Adapter to call the setupPolicy() method.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ0269E" severity="E" prefix="yes">
  <MsgText pgmKey="security.SecurityContext.getActualCreds.invoke" varFormat="Java">
    security.SecurityContext.getActualCreds.invoke=SECJ0269E: Failed to get actual credentials. The exception is {0}.
  </MsgText>
  <Explanation>
    java.lang.reflect.InvocationTargetException occurred when trying to run getActualCredential() method.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ0262E" severity="E" prefix="yes">
  <MsgText pgmKey="security.swam.remove.prin.ex" varFormat="Java">
    security.swam.remove.prin.ex=SECJ0262E: Exception occurred when removing {0} during cleanup. The exception is {1}
  </MsgText>
  <Explanation>
    Unexpected exception occurred when removing the specified principal during cleanup.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ0141E" severity="E" prefix="yes">
  <MsgText pgmKey="security.ssl.config.initialization.fatal" varFormat="Java">
    security.ssl.config.initialization.fatal=SECJ0141E: Error to initialize default SSL configuration
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ0303E" severity="E" prefix="yes">
  <MsgText pgmKey="security.sa.get.realm" varFormat="Java">
    security.sa.get.realm=SECJ0303E: Error getting registry&apos;&apos;s realm. The exception is {0}
  </MsgText>
  <Explanation>
    Exception occurred when getting registry&apos;s realm.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ6123I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.basic.challenge.audit" varFormat="Java">
    security.audit.basic.challenge.audit=SECJ6123I: HTTP authorization header is missing.  Send out 401 challenge.
  </MsgText>
  <Explanation>
    The authentication failed because there is no authorization header in the HTTP header. WebSphere Application Server will send a 401 challenge to the web client.
  </Explanation>
  <UserResponse>
    No action is required.
  </UserResponse>
</Message>
<Message ID="SECJ0422I" severity="I" prefix="yes">
  <MsgText pgmKey="security.merge.node.signer.not.exchanged" varFormat="Java">
    security.merge.node.signer.not.exchanged=SECJ0422I: During addNode from node &quot;{0}&quot; the default node certificate did not exchange its signer with the cell default truststore.  This might cause a handshake failure when the cell tries to communicate with the node.  Manual signer exchange might need to occur.
  </MsgText>
  <Explanation>
    It&apos;s likely the TrustStore named CellDefaultTrustStore or KeyStore named NodeDefaultKeyStore does not exist in the configuration.
  </Explanation>
  <UserResponse>
    The node&apos;s signer certificates need to be added to the cell&apos;s truststores.
  </UserResponse>
</Message>
<Message ID="SECJ0068E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.ldap.initerror" varFormat="Java">
    security.registry.ldap.initerror=SECJ0068E: LDAP initialization error. The exception is {0}.
  </MsgText>
  <Explanation>
    An unexpected exception occurred when configuring for LDAP.
  </Explanation>
  <UserResponse>
    Verify that the WebSphere LDAP configuration settings such as the provider URL are correct in the Security Center GUI. If using SSL, make sure that the SSL configuration is correct.
  </UserResponse>
</Message>
<Message ID="SECJ7417E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.AutogenCertFailure" varFormat="Java">
    security.admintask.AutogenCertFailure=SECJ7417E: Failure creating the self signed certificate for audit encryption
  </MsgText>
  <Explanation>
    Failed to create the self signed certificate for audit encryption
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0193E" severity="E" prefix="yes">
  <MsgText pgmKey="security.policy.ratemplate.parserexception" varFormat="Java">
    security.policy.ratemplate.parserexception=SECJ0193E: Caught ParserException while creating template for resource adaptor(read from ra.xml) {0}. The line is [{1}]. The exception is {2}.
  </MsgText>
  <Explanation>
    ParserException occurred when putting the resource adaptor template in the hashmap of all the templates.
  </Explanation>
  <UserResponse>
    Check the ParserException data. Check the ra.xml&apos;s permission specification.
  </UserResponse>
</Message>
<Message ID="SECJ7823E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.mustSpecifyDomain.SECJ7823E" varFormat="Java">
    security.admintask.mustSpecifyDomain.SECJ7823E=SECJ7823E: A security domain name must be specified when not in an AdminAgent process
  </MsgText>
  <Explanation>
    To obtain the pathname of a security domain belonging to a non-AdminAgent process, a security domain name must be specified.
  </Explanation>
  <UserResponse>
    Ensure a security domain name has been specified if the process is not an AdminAgent.
  </UserResponse>
</Message>
<Message ID="SECJ7266I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.domain.trustAssociation" varFormat="Java">
    security.configrpt.domain.trustAssociation=SECJ7266I: Trust Association
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ5016E" severity="E" prefix="yes">
  <MsgText pgmKey="security.ltpa.factory.tokencreate.error" varFormat="Java">
    security.ltpa.factory.tokencreate.error=SECJ5016E: The LTPA TokenFactory {0} could not create a new LTPA token.  The exception is {1}.
  </MsgText>
  <Explanation>
    The LTPA TokenFactory implementation had a problem in the createToken method or the keys used to create a token were not present.
  </Explanation>
  <UserResponse>
    Ensure that the LPTA keys are configured properly and check the createToken implementation on the TokenFactory interface.
  </UserResponse>
</Message>
<Message ID="SECJ0253E" severity="E" prefix="yes">
  <MsgText pgmKey="security.getting.remote.server.ex" varFormat="Java">
    security.getting.remote.server.ex=SECJ0253E: Generic Exception while getting remote security server. The exception is {0}.
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ8042E" severity="E" prefix="yes">
  <MsgText pgmKey="security.saml.element.id.negative.SECJ8042E" varFormat="Java">
    security.saml.element.id.negative.SECJ8042E=SECJ8042E: {0} {1} is not valid, specify a non-negative value.
  </MsgText>
  <Explanation>
    The parameter value must be non-negative.
  </Explanation>
  <UserResponse>
    Specify a non-negative value for the given parameter.
  </UserResponse>
</Message>
<Message ID="SECJ7177I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.algorithm" varFormat="Java">
    security.configrpt.core.algorithm=SECJ7177I: Algorithm
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7520I" severity="I" prefix="yes">
  <MsgText pgmKey="security.scanner.risk.adminid.ok" varFormat="Java">
    security.scanner.risk.adminid.ok=SECJ7520I: Multiple Administrative user IDs are configured. When WebSphere Application Server security is enabled, a single security ID under the Administrator role is initially configured as the Security Server ID. Configuring multiple administrative user ids as Administrator can protect this server ID and enable more effective audit logging
  </MsgText>
  <Explanation>
    Multiple Administrative user IDs are configured. When WebSphere Application Server security is enabled, a single security ID under the Administrator role is initially configured as the Security Server ID. Configuring multiple administrative user ids as Administrator can protect this server ID and enable more effective audit logging
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0242I" severity="I" prefix="yes">
  <MsgText pgmKey="security.init.svcstart" varFormat="Java">
    security.init.svcstart=SECJ0242I: Security service is starting
  </MsgText>
  <Explanation>
    Security service  started.
  </Explanation>
  <UserResponse>
    None. Informational only
  </UserResponse>
</Message>
<Message ID="SECJ0047E" severity="E" prefix="yes">
  <MsgText pgmKey="security.sas.configurl.missing" varFormat="Java">
    security.sas.configurl.missing=SECJ0047E: Missing or malformed security configuration URL specified by property {0}
  </MsgText>
  <Explanation>
    The URL used to specify Secure Association Service properties is missing or malformed.
  </Explanation>
  <UserResponse>
    The URL is usually specified as a property name when starting WebSphere from the command line with the -D argument. For example: -Dcom.ibm.CORBA.ConfigURL=file:/C:/wastd/AppServer/properties/sas.server.props. Verify that the property and URL is specified and refers to a valid file and the file has the read permission.
  </UserResponse>
</Message>
<Message ID="SECJ7336E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.ExceptionIsAppSecEnabled" varFormat="Java">
    security.admintask.ExceptionIsAppSecEnabled=SECJ7336E: Exception raised while getting Application Security setting
  </MsgText>
  <Explanation>
    Caught exception while getting Application Security setting
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0070E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.nt.noprivid" varFormat="Java">
    security.registry.nt.noprivid=SECJ0070E: No privilege id configured for: {0}
  </MsgText>
  <Explanation>
    Unable to find a SID for the specified user in the Windows user registry.  The user might not exist in the user registry.
  </Explanation>
  <UserResponse>
    If appropriate create the user in the user registry.
  </UserResponse>
</Message>
<Message ID="SECJ7779E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.mismatch.krbConfig.SECJ7779E" varFormat="Java">
    security.admintask.mismatch.krbConfig.SECJ7779E=SECJ7779E: Mismatch Kerberos configuration file (krb5.ini/krb5.conf). The krb5.ini/krb5.conf file for Kerberos authentication mechanism is {0} but the krb5.ini/krb5.conf file for SPNEGO Web authentication is {1}
  </MsgText>
  <Explanation>
    The Kerberos configuration file (krb5.ini/krb5.conf) for Kerberos authentication mechanism is not the same with the SPNEGO Web authentication.
  </Explanation>
  <UserResponse>
    Verify the krb5.ini/krb5.conf file for Kerberos authentication and SPNEGO Web authentication are the same one.
  </UserResponse>
</Message>
<Message ID="SECJ7504E" severity="E" prefix="yes">
  <MsgText pgmKey="security.scanner.error.invalid.class" varFormat="Java">
    security.scanner.error.invalid.class=SECJ7504E: The security ConfigChecker class &quot;{0}&quot; could not be loaded due to the following exception: {1}
  </MsgText>
  <Explanation>
    The class could not be loaded.  Check exception message for details
  </Explanation>
  <UserResponse>
    Check that the class name exists and the class has been added to the plugin.xml.  Check the exception message for details
  </UserResponse>
</Message>
<Message ID="SECJ0424E" severity="E" prefix="yes">
  <MsgText pgmKey="security.merge.node.keystore.creation.failed" varFormat="Java">
    security.merge.node.keystore.creation.failed=SECJ0424E: During addNode from node &quot;{0}&quot; the default keystore and truststore were not already created.  An attempt to create them on the DMGR failed with exception: {1}.
  </MsgText>
  <Explanation>
    The creation of keystore and truststore with self-signed certificate failed.
  </Explanation>
  <UserResponse>
    The node agent did not have certificates created when it was federated into the cell.  The attempt to create them during addNode failed.
  </UserResponse>
</Message>
<Message ID="SECJ7240I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.krb5SpnPassword" varFormat="Java">
    security.configrpt.core.krb5SpnPassword=SECJ7240I: Kerberos service name password
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0394E" severity="E" prefix="yes">
  <MsgText pgmKey="security.web.ta.invalidprincipal" varFormat="Java">
    security.web.ta.invalidprincipal=SECJ0394E: Principal exists in Subject returned by TAI.getSubject() but it does not implement java.security.Principal.
  </MsgText>
  <Explanation>
    The Trust Association Interceptor did not have the correct principal in the Subject. The principal must implement java.security.Principal.
  </Explanation>
  <UserResponse>
    Contact the provider of the Trust Association Interceptor to ensure this problem gets resolved.
  </UserResponse>
</Message>
<Message ID="SECJ7217I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.general.settings" varFormat="Java">
    security.configrpt.general.settings=SECJ7217I: General settings
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7465E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.CertificateException" varFormat="Java">
    security.admintask.CertificateException=SECJ7465E: A certificate exception was raised while trying to load the keystore.
  </MsgText>
  <Explanation>
    The keystore could not be loaded due to a certificate exception.
  </Explanation>
  <UserResponse>
    none
  </UserResponse>
</Message>
<Message ID="SECJ0091E" severity="E" prefix="yes">
  <MsgText pgmKey="security.authtbl.apphomefinder" varFormat="Java">
    security.authtbl.apphomefinder=SECJ0091E: Error looking up Application home
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7251I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.filterCriteria" varFormat="Java">
    security.configrpt.core.filterCriteria=SECJ7251I: SPNEGO Filter criteria
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0126E" severity="E" prefix="yes">
  <MsgText pgmKey="security.web.ta.validationfailed" varFormat="Java">
    security.web.ta.validationfailed=SECJ0126E: Trust Association failed during validation. The exception is {0}. Make sure that the setup is correct and that the user credentials are valid.
  </MsgText>
  <Explanation>
    When the appropriate interceptor is found for a given request, that interceptor then validates its trust with the reverse proxy server. This error message  suggests that the validation has failed and therefore the reverse proxy cannot be trusted. For example, an incorrect or expired password might  have been provided.
  </Explanation>
  <UserResponse>
    In a production environment, the user might be alerted to check if there is an intruder in the system. In a development environment in which testing is underway, verify if the expected inputs from the  reverse proxy server is in fact being passed to the interceptor correctly.  The nature of these inputs really depends on how trust association is being established. For example, the simplest method would be to  pass a user name/password through the Basic Authentication header.
  </UserResponse>
</Message>
<Message ID="SECJ7773E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.badCustomProp.SECJ7773E" varFormat="Java">
    security.admintask.badCustomProp.SECJ7773E=SECJ7773E: Custom property string {0} is not formatted correctly.
  </MsgText>
  <Explanation>
    The custom property string is not formatted correctly.  The format needs to be a comma separated string of attribute=value pairs, each pair should be in quotes.
  </Explanation>
  <UserResponse>
    Ensure the custom property string is formatted correctly.
  </UserResponse>
</Message>
<Message ID="SECJ0264E" severity="E" prefix="yes">
  <MsgText pgmKey="security.util.get.reg" varFormat="Java">
    security.util.get.reg=SECJ0264E: fillAccessids: Error getting user registry. The exception is {0}
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7155I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.useRegistryServerId" varFormat="Java">
    security.configrpt.core.useRegistryServerId=SECJ7155I: Use the registry server id instead of the internal server id
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0182W" severity="W" prefix="yes">
  <MsgText pgmKey="security.policy.fileCanonicalPath" varFormat="Java">
    security.policy.fileCanonicalPath=SECJ0182W: An exception was caught while trying to get the Canonical path for the file {1}. The exception is {0}.
  </MsgText>
  <Explanation>
    Could not get the Canonical path for the specified file
  </Explanation>
  <UserResponse>
    Check the specified file name passed to security. It could be caused by incorrect data in xml file. Enable security trace with com.ibm.ws.security.policy.* to get more detailed information.
  </UserResponse>
</Message>
<Message ID="SECJ8030E" severity="E" prefix="yes">
  <MsgText pgmKey="security.adminapp.jaspi.unsuppoterd.version.SECJ8030E" varFormat="Java">
    security.adminapp.jaspi.unsuppoterd.version.SECJ8030E=SECJ8030E: Applications with JASPI bindings can be deployed only on nodes at version 8 and higher.
  </MsgText>
  <Explanation>
    An application to be deployed contains JASPI bindings in ibm-application-bnd or in ibm-web-bnd files.
  </Explanation>
  <UserResponse>
    JASPI authentication is supported on version 8 and higher nodes. Verify JASPI bindings are not defined in the application&apos;s bindings.
  </UserResponse>
</Message>
<Message ID="SECJ7363E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.InvalidEventFormatterClassName" varFormat="Java">
    security.admintask.InvalidEventFormatterClassName=SECJ7363E: Non valid or no reference specified for the event formatter class name.
  </MsgText>
  <Explanation>
    The eventFormatterClassName reference is a required field.
  </Explanation>
  <UserResponse>
    Verify that a valid reference has been specified for the eventFormatterClassName
  </UserResponse>
</Message>
<Message ID="SECJ0191E" severity="E" prefix="yes">
  <MsgText pgmKey="security.policy.was.parserexception" varFormat="Java">
    security.policy.was.parserexception=SECJ0191E: Caught ParserException while creating template for was.policy {0} . The exception is {1}.
  </MsgText>
  <Explanation>
    ParserException occurred when putting the was.policy template in the hashmap of all the templates.
  </Explanation>
  <UserResponse>
    Check the ParserException data. Check the specified was.policy file.
  </UserResponse>
</Message>
<Message ID="SECJ7505E" severity="E" prefix="yes">
  <MsgText pgmKey="security.scanner.error.check.exception" varFormat="Java">
    security.scanner.error.check.exception=SECJ7505E: The security check, {0}, threw the following exception: {1}
  </MsgText>
  <Explanation>
    A security check threw an unexpected exception
  </Explanation>
  <UserResponse>
    Examine the associated exception to determine the cause
  </UserResponse>
</Message>
<Message ID="SECJ0235E" severity="E" prefix="yes">
  <MsgText pgmKey="security.sambean.expltpakeys" varFormat="Java">
    security.sambean.expltpakeys=SECJ0235E: An unexpected exception occurred when trying to export the LTPA Keys from the security mbean. The exception is {0}.
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7369E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.InvalidProvider" varFormat="Java">
    security.admintask.InvalidProvider=SECJ7369E: Non valid or no reference specified for the audit service provider.
  </MsgText>
  <Explanation>
    The provider field is required.
  </Explanation>
  <UserResponse>
    Verify that a valid reference has been specified for the audit service provider
  </UserResponse>
</Message>
<Message ID="SECJ0207E" severity="E" prefix="yes">
  <MsgText pgmKey="security.loadresource.error" varFormat="Java">
    security.loadresource.error=SECJ0207E: Failed to load {0} resource from cell.  The exception is {1}
  </MsgText>
  <Explanation>
    The specified resource could not be loaded due to an exception.
  </Explanation>
  <UserResponse>
    The failure might be related to a configuration problem related to the resource.
  </UserResponse>
</Message>
<Message ID="SECJ0282E" severity="E" prefix="yes">
  <MsgText pgmKey="security.secsrv.get.initCtx" varFormat="Java">
    security.secsrv.get.initCtx=SECJ0282E: Error getting initial context. The exception is {0}.
  </MsgText>
  <Explanation>
    javax.naming.NamingException occurred while getting the initial naming context.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ6150I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.authz.role.success.audit" varFormat="Java">
    security.audit.authz.role.success.audit=SECJ6150I: The user has the required roles {0}.
  </MsgText>
  <Explanation>
    The user has been granted to one or more of the required roles.
  </Explanation>
  <UserResponse>
    No action is required.
  </UserResponse>
</Message>
<Message ID="SECJ7265I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.domain.CSI" varFormat="Java">
    security.configrpt.domain.CSI=SECJ7265I: RMI/IIOP Security
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ4042E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaas.parser.stringreader" varFormat="Java">
    security.jaas.parser.stringreader=SECJ4042E: {0} :ERROR: A file parser exception occurred with file : {1}. The exception is {2}
  </MsgText>
  <Explanation>
    IOException occurred trying to connect the specified stringreader.
  </Explanation>
  <UserResponse>
    Investigate the exception. Check the specified string.
  </UserResponse>
</Message>
<Message ID="SECJ0154E" severity="E" prefix="yes">
  <MsgText pgmKey="security.formlogin.badconfig" varFormat="Java">
    security.formlogin.badconfig=SECJ0154E: SSO Configuration error. FormLogin is configured for web application {0} but SSO is not enabled in the global security settings.  SSO must be enabled to use FormLogin.
  </MsgText>
  <Explanation>
    When LTPA is the authentication mechanism SSO must also be enabled if any web applications use FORM login.
  </Explanation>
  <UserResponse>
    Enable SSO in the global security settings and restart WebSphere
  </UserResponse>
</Message>
<Message ID="SECJ7218I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.CORBA.Naming.Users" varFormat="Java">
    security.configrpt.CORBA.Naming.Users=SECJ7218I: CORBA Naming Service Users
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7463E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.NoSuchProviderException" varFormat="Java">
    security.admintask.NoSuchProviderException=SECJ7463E: Exception was raised while trying to get an instance of the keystore with the specified provider.  No such provider exists.
  </MsgText>
  <Explanation>
    No such provider exists for this keystore.
  </Explanation>
  <UserResponse>
    Verify that the provider is valid and that the keystore does exist.
  </UserResponse>
</Message>
<Message ID="SECJ7239I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.krb5Spn" varFormat="Java">
    security.configrpt.core.krb5Spn=SECJ7239I: Kerberos service name
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0078E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.notexist" varFormat="Java">
    security.registry.notexist=SECJ0078E: User registry does not exist
  </MsgText>
  <Explanation>
    Unable to lookup RegistryHome in name space or narrow failed.  The class for the user registry was not registered in the name space correctly or the class file for the user registry cannot be found.
  </Explanation>
  <UserResponse>
    Verify that the class path is correct and that the required classes exist.
  </UserResponse>
</Message>
<Message ID="SECJ5005E" severity="E" prefix="yes">
  <MsgText pgmKey="security.sap.error.uniqueid.not.found.in.hashtable" varFormat="Java">
    security.sap.error.uniqueid.not.found.in.hashtable=SECJ5005E: Cannot create WSCredential without a valid com.ibm.wsspi.security.cred.uniqueId property value.
  </MsgText>
  <Explanation>
    The com.ibm.wsspi.security.cred.uniqueId property has not been found during a properties login attempt.
  </Explanation>
  <UserResponse>
    Ensure that the java.util.Hashtable used for a properties login contains a valid property value for com.ibm.wsspi.security.cred.uniqueId.
  </UserResponse>
</Message>
<Message ID="SECJ7380E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.ProviderInUse" varFormat="Java">
    security.admintask.ProviderInUse=SECJ7380E: Unable to delete audit service provider: provider in use
  </MsgText>
  <Explanation>
    Audit service provider is in use by an audit event factory implementation and cannot be deleted.
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7232I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.AdminSecurityManager.Role.Group" varFormat="Java">
    security.configrpt.AdminSecurityManager.Role.Group=SECJ7232I: AdminSecurityManager Group
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0157I" severity="I" prefix="yes">
  <MsgText pgmKey="security.wsaccessmanager.classloaded" varFormat="Java">
    security.wsaccessmanager.classloaded=SECJ0157I: Loaded Vendor AuthorizationTable: {0}
  </MsgText>
  <Explanation>
    The vendor specified Authorization Table is loaded successfully.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ5012E" severity="E" prefix="yes">
  <MsgText pgmKey="security.sap.error.single.signon.token.not.mapped" varFormat="Java">
    security.sap.error.single.signon.token.not.mapped=SECJ5012E: Could not create default SingleSignonToken during propagation login.  The following exception occurred: {0}
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ0055E" severity="E" prefix="yes">
  <MsgText pgmKey="security.authn.failed.foruser" varFormat="Java">
    security.authn.failed.foruser=SECJ0055E: Authentication failed for {0}. The user id or password might have been entered incorrectly or misspelled.  The user id might not exist, the account could have expired or disabled.  The password might have expired.
  </MsgText>
  <Explanation>
    The user could not be authenticated.  The user id or password might have been entered incorrectly.  The user might not exist in the user registry that WebSphere is configured to authenticate to. If WebSphere security is configured to use LDAP as the user registry, the WebSphere security LDAP user and group search filter configuration might not match what the LDAP directory expects.
  </Explanation>
  <UserResponse>
    Verify that the user id and password are entered correctly and exist in the user registry. If LDAP is configured as the security user registry, verify the WebSphere security LDAP user and group filters configuration match what the LDAP directory expects. Consult with the administrator of the user registry that WebSphere is configured to use if the problem persist.
  </UserResponse>
</Message>
<Message ID="SECJ7415E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.CreateKeyStoreObjectFailure" varFormat="Java">
    security.admintask.CreateKeyStoreObjectFailure=SECJ7415E: Failure creating the audit keystore object
  </MsgText>
  <Explanation>
    Failed to create the audit keystore ObjectName
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ6003I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.service.provider.info" varFormat="Java">
    security.audit.service.provider.info=SECJ6003I: Successfully loaded {0} name {1} and class name {2}.
  </MsgText>
  <Explanation>
    Indicate that the specified provider class was loaded.
  </Explanation>
  <UserResponse>
    No action is required.
  </UserResponse>
</Message>
<Message ID="SECJ0265E" severity="E" prefix="yes">
  <MsgText pgmKey="security.util.remove.reg" varFormat="Java">
    security.util.remove.reg=SECJ0265E: removeAccessIds: Error getting user registry. The exception is {0}.
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ0184W" severity="W" prefix="yes">
  <MsgText pgmKey="security.policy.removepolicy.rarpath" varFormat="Java">
    security.policy.removepolicy.rarpath=SECJ0184W: An exception was caught while trying to get the absolute path for the resource adaptor {1} in removePolicy(). The exception is {0}.
  </MsgText>
  <Explanation>
    Could not get the absolute path for the resource adaptor in removePolicy().
  </Explanation>
  <UserResponse>
    Check the specified path.  It could be caused by incorrect data in xml file. Enable security trace with com.ibm.ws.security.policy.* to get more detailed information.
  </UserResponse>
</Message>
<Message ID="SECJ6130I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.authz.success.audit" varFormat="Java">
    security.audit.authz.success.audit=SECJ6130I: Access is allowed.
  </MsgText>
  <Explanation>
    Access to the resource is allowed because the user or the groups the user is in have the required security role.
  </Explanation>
  <UserResponse>
    No action required if this is the desired behavior.
  </UserResponse>
</Message>
<Message ID="SECJ0351E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.uniqueusrid.error" varFormat="Java">
    security.registry.uniqueusrid.error=SECJ0351E: Could not get the uniqueId of the user {0} due to the following exception {1}.
  </MsgText>
  <Explanation>
    Internal Error.
  </Explanation>
  <UserResponse>
    Make sure that the user is valid. Contact your service representative if the problem persists.
  </UserResponse>
</Message>
<Message ID="SECJ8002E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.jaspi.provider.undefined.SECJ8002E" varFormat="Java">
    security.admintask.jaspi.provider.undefined.SECJ8002E=SECJ8002E: Authentication provider {0} is not defined in the cell.
  </MsgText>
  <Explanation>
    An authentication provider with the specified name does not exist in the security configuration.
  </Explanation>
  <UserResponse>
    Specify the name of an existing authentication provider. Use the displayJaspiProviderNames command to list the names of defined authentication providers.
  </UserResponse>
</Message>
<Message ID="SECJ7020I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.timeout" varFormat="Java">
    security.configrpt.core.timeout=SECJ7020I: Timeout of authentication data forwarded between servers
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7011I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.issuePermissionWarning" varFormat="Java">
    security.configrpt.core.issuePermissionWarning=SECJ7011I: Warn if applications are granted custom permissions
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ8043E" severity="E" prefix="yes">
  <MsgText pgmKey="security.saml.idp.element.already.exist.SECJ8043E" varFormat="Java">
    security.saml.idp.element.already.exist.SECJ8043E=SECJ8043E: {0} already exists in the SAML TAI IdP security configuration.
  </MsgText>
  <Explanation>
    An element can only be added in one security configuration.
  </Explanation>
  <UserResponse>
    Rerun the command using an element that is not already defined in a SAML TAI configuration.
  </UserResponse>
</Message>
<Message ID="SECJ0421I" severity="I" prefix="yes">
  <MsgText pgmKey="security.registry.ldap.updated.audit" varFormat="Java">
    security.registry.ldap.updated.audit=SECJ0421I: Security run time has successfully updated LDAP registry binding information.
  </MsgText>
  <Explanation>
    new LDAP bind information has been pushed to security run time.
  </Explanation>
  <UserResponse>
    No user action is required.
  </UserResponse>
</Message>
<Message ID="SECJ7383E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.InvalidNotificationName" varFormat="Java">
    security.admintask.InvalidNotificationName=SECJ7383E: Non valid name for Audit Notification.
  </MsgText>
  <Explanation>
    Non valid name for audit notification specified.
  </Explanation>
  <UserResponse>
    Verify that a valid name has been specified for the audit notification
  </UserResponse>
</Message>
<Message ID="SECJ7443E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.InvalidCertRef" varFormat="Java">
    security.admintask.InvalidCertRef=SECJ7443E: Non valid or no value specified for the audit encryption certificate reference.
  </MsgText>
  <Explanation>
    The reference ID for the audit encryption certificate has not been specified correctly
  </Explanation>
  <UserResponse>
    Specify a valid value for the audit encryption certificate reference.
  </UserResponse>
</Message>
<Message ID="SECJ7216I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.primaryAdminId" varFormat="Java">
    security.configrpt.core.primaryAdminId=SECJ7216I: Primary administrative user name
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0426E" severity="E" prefix="yes">
  <MsgText pgmKey="security.merge.node.internal.serverid.used" varFormat="Java">
    security.merge.node.internal.serverid.used=SECJ0426E: InternalServerId is used in the current dmgr configuration.  Cannot add an older node.  Modify the dmgr security configuration to use the serverID/passwd before adding an older version node.
  </MsgText>
  <Explanation>
    An earlier leveled node cannot be added to a dmgr whose configuration is using the internalServerId.
  </Explanation>
  <UserResponse>
    The dmgr configuration needs to be modified to use the serverID/password before an older version node can be added
  </UserResponse>
</Message>
<Message ID="SECJ0395E" severity="E" prefix="yes">
  <MsgText pgmKey="security.securityserver.error" varFormat="Java">
    security.securityserver.error=SECJ0395E: Could not locate the SecurityServer at host/port: {0} to validate the userid and password entered. You might need to specify valid securityServerHost/Port in WAS_INSTALL_ROOT/profiles/profile_name/properties/sas.client.props file.
  </MsgText>
  <Explanation>
    A SecurityServer could not be located for login.
  </Explanation>
  <UserResponse>
    In some cases it is necessary to specify a valid bootstrap host/port in the com.ibm.CSI.securityServerHost and com.ibm.CSI.securityServerPort properties in the ${WAS_INSTALL_ROOT}/profiles/profile_name/properties/sas.client.props file. See sas.client.props for details.
  </UserResponse>
</Message>
<Message ID="SECJ7109I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.Operator.Role.Group" varFormat="Java">
    security.configrpt.Operator.Role.Group=SECJ7109I: Operator Group
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ6050E" severity="E" prefix="yes">
  <MsgText pgmKey="security.audit.eventfactory.init.error" varFormat="Java">
    security.audit.eventfactory.init.error=SECJ6050E: Audit Event Factory did not initialize. Exception = {0}.
  </MsgText>
  <Explanation>
    Audit Event Factory was not initialized, which occurred most likely due to incorrect class definition, incorrect class path, or missing class files.
  </Explanation>
  <UserResponse>
    Examine the exception for the cause of the problem.
  </UserResponse>
</Message>
<Message ID="SECJ7432E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.ClassNotDefaultEventFactory" varFormat="Java">
    security.admintask.ClassNotDefaultEventFactory=SECJ7432E: Cannot change the default audit event factory implementation classname.
  </MsgText>
  <Explanation>
    The classname specified does not match the default audit event factory implementation classname.
  </Explanation>
  <UserResponse>
    Ensure that when specifying class name on the modify command and the implementation is the default audit event factory implementation, that it matches the default classname.
  </UserResponse>
</Message>
<Message ID="SECJ0169W" severity="W" prefix="yes">
  <MsgText pgmKey="security.policy.parser.expandperm" varFormat="Java">
    security.policy.parser.expandperm=SECJ0169W: Expand exception occurred. Skip the permission entry. The exception is {0}
  </MsgText>
  <Explanation>
    While expanding the permission, caught an expand exception
  </Explanation>
  <UserResponse>
    Check the permission entry syntax in your policy file. To identify which policy file has a problem, enable security trace for the component com.ibm.ws.security.policy.*. The trace.log file will show the policy file name.
  </UserResponse>
</Message>
<Message ID="SECJ7247I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.reloadTimeout" varFormat="Java">
    security.configrpt.core.reloadTimeout=SECJ7247I: SPNEGO Configuration reload timeout
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ6153I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.form.login.redirect.audit" varFormat="Java">
    security.audit.form.login.redirect.audit=SECJ6153I: Redirect to form based login page {0} to prompt for web client authentication data.
  </MsgText>
  <Explanation>
    The web resource requires Form based authentication.  Typically a web user will be redirected to a login page to enter user id and password.
  </Explanation>
  <UserResponse>
    No action is required.
  </UserResponse>
</Message>
<Message ID="SECJ7461E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.UnknownHost" varFormat="Java">
    security.admintask.UnknownHost=SECJ7461E: Failed to get the host name of the machine on which the Audit Reader is running.
  </MsgText>
  <Explanation>
    An exception was raised while attempting to obtain the host name of the machine on which the Audit Reader is running.
  </Explanation>
  <UserResponse>
    none
  </UserResponse>
</Message>
<Message ID="SECJ7057I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.confidentiality" varFormat="Java">
    security.configrpt.core.confidentiality=SECJ7057I: Confidentiality
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0061E" severity="E" prefix="yes">
  <MsgText pgmKey="security.ltpaconfig.createexcp" varFormat="Java">
    security.ltpaconfig.createexcp=SECJ0061E: LTPAConfig creation exception
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ6134I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.csi.session.not.exist.audit" varFormat="Java">
    security.audit.csi.session.not.exist.audit=SECJ6134I: Session does not exist on server.
  </MsgText>
  <Explanation>
    The client context id (= 0) in a MessageInContext message is not valid.
  </Explanation>
  <UserResponse>
    No action required.
  </UserResponse>
</Message>
<Message ID="SECJ7751E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.rsaTokenNotPresent.SECJ7751E" varFormat="Java">
    security.admintask.rsaTokenNotPresent.SECJ7751E=SECJ7751E: The RSAToken authentication mechanism is missing from the security.xml configuration which may cause problems with administrative security.
  </MsgText>
  <Explanation>
    A security configuration does not have the required RSAToken authentication mechanism configured.
  </Explanation>
  <UserResponse>
    This may be a problem with a migrated configuration that needs correction.
  </UserResponse>
</Message>
<Message ID="SECJ7113I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.Naming.Role.Name" varFormat="Java">
    security.configrpt.Naming.Role.Name=SECJ7113I: CORBA Naming Role Name
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ4066E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaas.IdentityAssertion.identity" varFormat="Java">
    security.jaas.IdentityAssertion.identity=SECJ4066E: Could not find identity to perform identity assertion.
  </MsgText>
  <Explanation>
    A Custom Login module must provide an identity to perform identity assertion.
  </Explanation>
  <UserResponse>
    Check a Custom Login module to make sure an idenity is provided to the perform identity assertion.
  </UserResponse>
</Message>
<Message ID="SECJ7754E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.notExist.SECJ7754E" varFormat="Java">
    security.admintask.notExist.SECJ7754E=SECJ7754E: {0} does not exist.
  </MsgText>
  <Explanation>
    The realm name or resource name provided does not exist.
  </Explanation>
  <UserResponse>
    Ensure the realm name or resource name being used exists.
  </UserResponse>
</Message>
<Message ID="SECJ0287E" severity="E" prefix="yes">
  <MsgText pgmKey="security.servcomp.setupPolicy" varFormat="Java">
    security.servcomp.setupPolicy=SECJ0287E: Failed to call setupPolicy for {0}.
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ6007E" severity="E" prefix="yes">
  <MsgText pgmKey="security.audit.service.undefined.error" varFormat="Java">
    security.audit.service.undefined.error=SECJ6007E: Undefined {0} = {1}.
  </MsgText>
  <Explanation>
    The specified properties was not defined properly in the global security customer properties.
  </Explanation>
  <UserResponse>
    Verified that the specified properties is defined properly in the global security custom properties.
  </UserResponse>
</Message>
<Message ID="SECJ0237E" severity="E" prefix="yes">
  <MsgText pgmKey="security.secsrv.badltpconfig" varFormat="Java">
    security.secsrv.badltpconfig=SECJ0237E: One or more vital LTPAServerObject configuration attributes are null or not available. The attributes and values are password : {0}, expiration time {1}, private key {2}, public key {3}, and shared key {4}.
  </MsgText>
  <Explanation>
    LTPA is the configurated authentication mechanism but it has not yet been properly configured.  Keys or other LTPA configuration attributes are missing.
  </Explanation>
  <UserResponse>
    Disable WebSphere security, restart the application server and properly configure LTPA authentication.
  </UserResponse>
</Message>
<Message ID="SECJ0177W" severity="W" prefix="yes">
  <MsgText pgmKey="security.policy.malformedURL" varFormat="Java">
    security.policy.malformedURL=SECJ0177W: An exception was caught while converting class path {1} to URL. The exception is {0}.
  </MsgText>
  <Explanation>
    Could not convert the above class path to a URL
  </Explanation>
  <UserResponse>
    Check the class path. Usually, this path was picked up from xml file. Enable security trace with com.ibm.ws.security.policy.* to get more detailed information.
  </UserResponse>
</Message>
<Message ID="SECJ7784W" severity="W" prefix="yes">
  <MsgText pgmKey="security.admintask.oldZDomainPropsConfigured.SECJ7784W" varFormat="Java">
    security.admintask.oldZDomainPropsConfigured.SECJ7784W=SECJ7784W: The security custom properties security.zOS.domainName and security.zOS.domainType are specified in the security configuration, but these properties are deprecated. For backwards compatibilty, these values will override the one specified in the new custom property com.ibm.security.SAF.profilePrefix.
  </MsgText>
  <Explanation>
    The security custom properties security.zOS.domainName and security.zOS.domainType are deprecated, but they are currently specified in the security configuration. For backwards compatibilty, the values of these old properties will override whatever is specified in the the new custom property com.ibm.security.SAF.profilePrefix.
  </Explanation>
  <UserResponse>
    The deprecated properties should be deleted from the security configuration, unless the configuration is part of a mixed-version cell that has a member at 6.1 or previous.
  </UserResponse>
</Message>
<Message ID="SECJ0432I" severity="I" prefix="yes">
  <MsgText pgmKey="security.rolebauthz.authzfail.checkTrustedAppsProfile" varFormat="Java">
    security.rolebauthz.authzfail.checkTrustedAppsProfile=SECJ0432I: Check that the Trusted Applications Profile Facility has been configured properly.
  </MsgText>
  <Explanation>
    Through the use of the FACILITY class and BBO.TRUSTEDAPPS class profile, trusted applications, as a general rule, are needed when using SAF as the local operating system user registry or when you plan to use SAF authorization.
  </Explanation>
  <UserResponse>
    You must enable the trusted applications by ensuring that the WebSphere Application Server has SAF access of READ to the RACF class of FACILITY and profile of BBO.TRUSTEDAPPS.&lt;cell short name&gt;.&lt;cluster short name&gt;.
  </UserResponse>
</Message>
<Message ID="SECJ0339E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.groupdisplayname.notfound" varFormat="Java">
    security.registry.groupdisplayname.notfound=SECJ0339E: Could not get the display name of the group {0}.
  </MsgText>
  <Explanation>
    Problem getting display name of a group.
  </Explanation>
  <UserResponse>
    Make sure that the group is valid and has a display name.
  </UserResponse>
</Message>
<Message ID="SECJ0081E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.exception" varFormat="Java">
    security.registry.exception=SECJ0081E: Registry exception
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7768E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.mismatch.krbRealm.SECJ7768E" varFormat="Java">
    security.admintask.mismatch.krbRealm.SECJ7768E=SECJ7768E: Mismatch Kerberos realm name. The krb5Realm is {0} but the default Kerberos realm in the {1} is {2}
  </MsgText>
  <Explanation>
    The Kerberos realm name is not the same with default Kerberos realm in the Kerberos configuration file (krb5.ini/krb5.conf).
  </Explanation>
  <UserResponse>
    Verify the Kerberos realm name against the default Kerberos default realm in the Kerberos configuration file.
  </UserResponse>
</Message>
<Message ID="SECJ7131I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.Certificate.Alias" varFormat="Java">
    security.configrpt.Certificate.Alias=SECJ7131I: Certificate Alias
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7156I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.trustedId" varFormat="Java">
    security.configrpt.core.trustedId=SECJ7156I: Trusted identity
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ5017E" severity="E" prefix="yes">
  <MsgText pgmKey="security.sap.error.ltapserver.null" varFormat="Java">
    security.sap.error.ltapserver.null=SECJ5017E: The Lightweight Third Party Authentication (LTPA) token could not be validated because the LTPA services are not available.
  </MsgText>
  <Explanation>
    This error most likely occurs when the Simple WebSphere Authentication Mechanism (SWAM) authentication mechanism is the active authentication mechanism.  SWAM is meant for stand-alone servers and is not supported by WebSphere Process Server or by an environment that requires cross server (server-to-server) secure communications.
  </Explanation>
  <UserResponse>
    Ensure that the active authentication mechanism is LTPA.
  </UserResponse>
</Message>
<Message ID="SECJ7230I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.AdminSecurityManager.Role.User" varFormat="Java">
    security.configrpt.AdminSecurityManager.Role.User=SECJ7230I: AdminSecurityManager User
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0171W" severity="W" prefix="yes">
  <MsgText pgmKey="security.policy.parser.expandsignedby" varFormat="Java">
    security.policy.parser.expandsignedby=SECJ0171W: Expand exception occurred. Skip the signedby key entry. The exception is {0}.
  </MsgText>
  <Explanation>
    An expand exception occurred while expanding the signedby entry.
  </Explanation>
  <UserResponse>
    Check the signedby entry syntax in your policy file. To identify which policy file has a problem, enable security trace for the component com.ibm.ws.security.policy.*. The trace.log file will show the policy file name.
  </UserResponse>
</Message>
<Message ID="SECJ7095I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.Console.Users.Groups" varFormat="Java">
    security.configrpt.Console.Users.Groups=SECJ7095I: Administrative users and groups
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7122I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.Security.Naming.Navigation" varFormat="Java">
    security.configrpt.core.Security.Naming.Navigation=SECJ7122I: CORBA Naming Service Groups
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0284E" severity="E" prefix="yes">
  <MsgText pgmKey="security.secsrv.find.registry" varFormat="Java">
    security.secsrv.find.registry=SECJ0284E: Error trying to find User Registry. The exception is {0}.
  </MsgText>
  <Explanation>
    javax.naming.NamingException occurred while finding the user registry.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ6052E" severity="E" prefix="yes">
  <MsgText pgmKey="security.audit.auditorId.change.ws.error" varFormat="Java">
    security.audit.auditorId.change.ws.error=SECJ6052E: Workspace error occurred attempting to change the primary auditor ID.
  </MsgText>
  <Explanation>
    An error occurred accessing the workspace.
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0324E" severity="E" prefix="yes">
  <MsgText pgmKey="security.j2sec.init.error" varFormat="Java">
    security.j2sec.init.error=SECJ0324E: Error during Java 2 Security and Dynamic Policy initialization. The exception is {0}.
  </MsgText>
  <Explanation>
    An unexpected error occurred during Java 2 Security and Dynamic Policy initialization.
  </Explanation>
  <UserResponse>
    This is a general error.  Look for previous messages that might be related to the failure or a configuration problem.  Enabling security debug trace for security component  com.ibm.ws.security.* might yield additional information.
  </UserResponse>
</Message>
<Message ID="SECJ7337E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.ExceptionGetGlobalSec" varFormat="Java">
    security.admintask.ExceptionGetGlobalSec=SECJ7337E: Exception raised while getting Global Security setting
  </MsgText>
  <Explanation>
    Caught exception while getting Global Security setting
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0090E" severity="E" prefix="yes">
  <MsgText pgmKey="security.authtbl.getmg" varFormat="Java">
    security.authtbl.getmg=SECJ0090E: Error obtaining method group for method {0}
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7705E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.InvalidLoginModuleType.SECJ7705E" varFormat="Java">
    security.admintask.InvalidLoginModuleType.SECJ7705E=SECJ7705E: Login module type is not valid.
  </MsgText>
  <Explanation>
    Valid login module types are: system, application.
  </Explanation>
  <UserResponse>
    Ensure that the login module type is a valid type.
  </UserResponse>
</Message>
<Message ID="SECJ7395E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.InvalidMaxLogsValue" varFormat="Java">
    security.admintask.InvalidMaxLogsValue=SECJ7395E: Non valid value for maximum number of audit logs was specified.
  </MsgText>
  <Explanation>
    The maximum number of audit logs needs to a number greater than 0.
  </Explanation>
  <UserResponse>
    Supply a valid value for maximum number of audit logs
  </UserResponse>
</Message>
<Message ID="SECJ0370E" severity="E" prefix="yes">
  <MsgText pgmKey="security.ltpa.validate.nulltoken" varFormat="Java">
    security.ltpa.validate.nulltoken=SECJ0370E: Validation of the token failed because the token is null.
  </MsgText>
  <Explanation>
    Cannot validate the token since the token is null.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ0062E" severity="E" prefix="yes">
  <MsgText pgmKey="security.ltpaconfig.removeexcp" varFormat="Java">
    security.ltpaconfig.removeexcp=SECJ0062E: LTPAConfig remove exception
  </MsgText>
  <Explanation>
    This is an internal error. The ejbRemove() operation failed on the LTPAConfigBean.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ0178E" severity="E" prefix="yes">
  <MsgText pgmKey="security.policy.rarfile" varFormat="Java">
    security.policy.rarfile=SECJ0178E: An exception was caught while retrieving the data from the hashmap for the keyword {1}. The exception is {0}.
  </MsgText>
  <Explanation>
    Could not retrieve the resource adaptor policy file from the hashmap passed to setupPolicy().
  </Explanation>
  <UserResponse>
    Check the data stored in the hashmap for the resource adaptor keyword. It could be caused by incorrect xml file. Enable security trace with com.ibm.ws.security.policy.* to get more detailed information.
  </UserResponse>
</Message>
<Message ID="SECJ7413E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.NoKeyStorePasswordValue" varFormat="Java">
    security.admintask.NoKeyStorePasswordValue=SECJ7413E: No key store password was specified for the audit key store.
  </MsgText>
  <Explanation>
    Must specify a key store password for the audit key store
  </Explanation>
  <UserResponse>
    Supply a key store password for the audit key store
  </UserResponse>
</Message>
<Message ID="SECJ7165I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.initializeAtStartup" varFormat="Java">
    security.configrpt.core.initializeAtStartup=SECJ7165I: Initialize at startup
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0317W" severity="W" prefix="yes">
  <MsgText pgmKey="security.policy.imcomplete.filter.permission" varFormat="Java">
    security.policy.imcomplete.filter.permission=SECJ0317W: The permission {0} specified in the application policy file({1}) is a part of the permission {2} specified in filter.policy.
  </MsgText>
  <Explanation>
    The permission class specified in the application policy is not be removed. However, it is a part of the permission specified in filter.policy.
  </Explanation>
  <UserResponse>
    If the permission should be filtered out, divide the permission specified in the application policy.
  </UserResponse>
</Message>
<Message ID="SECJ8052I" severity="I" prefix="yes">
  <MsgText pgmKey="security.saml.existing.cert.alias.is.used.SECJ8052I" varFormat="Java">
    security.saml.existing.cert.alias.is.used.SECJ8052I=SECJ8052I: The existing alias name {0} is used because the certificate already exists in the trust store.
  </MsgText>
  <Explanation>
    The certificate already exists in the trust store. You cannot assign a new alias to this certificate. The existing alias name is used.
  </Explanation>
  <UserResponse>
    Use the same alias for the same certificate that is already in the trust store.
  </UserResponse>
</Message>
<Message ID="SECJ0223E" severity="E" prefix="yes">
  <MsgText pgmKey="security.formlogin.nostoredurl" varFormat="Java">
    security.formlogin.nostoredurl=SECJ0223E: User {0} authenticated successfully but unable to send redirect to the original request page. The {1} cookie is not present.
  </MsgText>
  <Explanation>
    The HTTP cookie that contains the originally requested page was not found.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ0140E" severity="E" prefix="yes">
  <MsgText pgmKey="security.ssl.config.initialization.failed" varFormat="Java">
    security.ssl.config.initialization.failed=SECJ0140E: Failed to initialize Default SSL Settings
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ0333E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.mapcert.failed" varFormat="Java">
    security.registry.mapcert.failed=SECJ0333E: The mapCertificate method failed.
  </MsgText>
  <Explanation>
    The mapCertificate method failed to return a user  from the certificate chain.
  </Explanation>
  <UserResponse>
    Make sure that the certificate should contain a valid user in the registry. This problem should have preceeded with other exception(s). Looking into them would help in narrowing down the problem. In addition if a custom registry is being used make sure you return a valid userId after successfully mapping the certificate.
  </UserResponse>
</Message>
<Message ID="SECJ4044E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaas.wccm.notLoaded" varFormat="Java">
    security.jaas.wccm.notLoaded=SECJ4044E: WCCM jaas objects is not yet load.
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ4008E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaas.missingAuthData" varFormat="Java">
    security.jaas.missingAuthData=SECJ4008E: Missing some of the authentication data
  </MsgText>
  <Explanation>
    Some of the authentication data is missing.
  </Explanation>
  <UserResponse>
    Check the next message. It identifies what is missing.
  </UserResponse>
</Message>
<Message ID="SECJ0168W" severity="W" prefix="yes">
  <MsgText pgmKey="security.policy.parser.keystore" varFormat="Java">
    security.policy.parser.keystore=SECJ0168W: Keystore {0} of type {1} is being ignored
  </MsgText>
  <Explanation>
    Keystore of the above type is not supported.
  </Explanation>
  <UserResponse>
    Use the supported type of keystores.
  </UserResponse>
</Message>
<Message ID="SECJ7219I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.baseDN" varFormat="Java">
    security.configrpt.core.baseDN=SECJ7219I: Base distinguished name
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0320E" severity="E" prefix="yes">
  <MsgText pgmKey="security.policy.parser.syntax.error" varFormat="Java">
    security.policy.parser.syntax.error=SECJ0320E: Error parsing {0}: {1}
  </MsgText>
  <Explanation>
    There is a syntax error in the policy file.
  </Explanation>
  <UserResponse>
    Use ${java.home}/jre/bin/policytool to verify the syntax or edit the policy file and correct the syntax error.
  </UserResponse>
</Message>
<Message ID="SECJ8062W" severity="W" prefix="yes">
  <MsgText pgmKey="security.saml.idp.http.post.notexistent.SECJ8062W" varFormat="Java">
    security.saml.idp.http.post.notexistent.SECJ8062W=SECJ8062W: There is not a SingleSignOnService binding for HTTP POST in the IdP metadata file {0}.
  </MsgText>
  <Explanation>
    The SingleSignOnService binding for HTTP POST is missing from the IdP metadata file.
  </Explanation>
  <UserResponse>
    Verify the IdP metadata file.
  </UserResponse>
</Message>
<Message ID="SECJ0341E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.uniquegrpid.error" varFormat="Java">
    security.registry.uniquegrpid.error=SECJ0341E: Could not get the uniqueId for the group {0} because of the following exception {1}.
  </MsgText>
  <Explanation>
    Problem getting uniqueId of a group.
  </Explanation>
  <UserResponse>
    Make sure that the group is valid in the registry and if it is a custom registry make sure it also has an uniqueId.
  </UserResponse>
</Message>
<Message ID="SECJ4043W" severity="W" prefix="yes">
  <MsgText pgmKey="security.jaas.close.stream" varFormat="Java">
    security.jaas.close.stream=SECJ4043W: {0} :Warning: An unexpected IOException occurred when closing a stream.
  </MsgText>
  <Explanation>
    Unexpected IOException occurred trying to close a stream.
  </Explanation>
  <UserResponse>
    This is a warning.
  </UserResponse>
</Message>
<Message ID="SECJ7765E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.timeout.SECJ7765E" varFormat="Java">
    security.admintask.timeout.SECJ7765E=SECJ7765E: The timeout value must have a minimum value of {0}.
  </MsgText>
  <Explanation>
    The value should be the minimum value specified.
  </Explanation>
  <UserResponse>
    Ensure the timeout value has the minimum value specified.
  </UserResponse>
</Message>
<Message ID="SECJ7097I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.Console.Role.Value" varFormat="Java">
    security.configrpt.Console.Role.Value=SECJ7097I: Administrative Role Value
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7078I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.cryptoHardware" varFormat="Java">
    security.configrpt.core.cryptoHardware=SECJ7078I: Cryptographic token
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7401E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.ReadOnlyCreate" varFormat="Java">
    security.admintask.ReadOnlyCreate=SECJ7401E: Creating a read only key store object.  File should already exist.
  </MsgText>
  <Explanation>
    When creating a hardware key store object the file in the path specified should already exist.
  </Explanation>
  <UserResponse>
    Rerun the command with a specifying a file that already exists.
  </UserResponse>
</Message>
<Message ID="SECJ0230E" severity="E" prefix="yes">
  <MsgText pgmKey="security.policy.parser.methodinvocationfailed" varFormat="Java">
    security.policy.parser.methodinvocationfailed=SECJ0230E: Invoking reflection method {0} of object type {1} throws exception {2}.
  </MsgText>
  <Explanation>
    Reflection method invocation failed.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ8027E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaspi.configuration.file.missing.SECJ8027E" varFormat="Java">
    security.jaspi.configuration.file.missing.SECJ8027E=SECJ8027E: The path and name of file where JASPI persistent registrations are stored must be specified using property {0}.
  </MsgText>
  <Explanation>
    The named property must specify path and name of file where JASPI persistent registrations are stored.
  </Explanation>
  <UserResponse>
    Specify the path and name of a file where JASPI persistent registrations are stored.
  </UserResponse>
</Message>
<Message ID="SECJ0103E" severity="E" prefix="yes">
  <MsgText pgmKey="security.methodgroups.nohome" varFormat="Java">
    security.methodgroups.nohome=SECJ0103E: MethodGroupHome does not exist
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ0007E" severity="E" prefix="yes">
  <MsgText pgmKey="security.init.error" varFormat="Java">
    security.init.error=SECJ0007E: Error during security initialization. The exception is {0}.
  </MsgText>
  <Explanation>
    An unexpected error occurred during security initialization.
  </Explanation>
  <UserResponse>
    This is a general error.  Look for previous messages that might be related to the failure or to a configuration problem.  Enabling security debug trace for components  com.ibm.ws.security.* and com.ibm.ejs.security.* might yield additional information.
  </UserResponse>
</Message>
<Message ID="SECJ4035E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaas.getProperty" varFormat="Java">
    security.jaas.getProperty=SECJ4035E: {0} :ERROR: Could not get System property: {1}
  </MsgText>
  <Explanation>
    Failed to get the specified property.
  </Explanation>
  <UserResponse>
    Check if you defined the specified property correctly.
  </UserResponse>
</Message>
<Message ID="SECJ7330E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.IsAdminLockedOut" varFormat="Java">
    security.admintask.IsAdminLockedOut=SECJ7330E: Failed to verify admin user would not be locked out of console
  </MsgText>
  <Explanation>
    Exception raised while verifying at least one admin id in the admin-authz.xml exists in the user registry
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7144I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.keyStore" varFormat="Java">
    security.configrpt.core.keyStore=SECJ7144I: Key stores
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ6120I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.cert.registry.audit" varFormat="Java">
    security.audit.cert.registry.audit=SECJ6120I: Authentication failed becasue the user registry was not defined.
  </MsgText>
  <Explanation>
    The authentication failed because there is no active user registry defined to map the client certificate user name to a valid WebSphere Application Server user.
  </Explanation>
  <UserResponse>
    Verify that the registry and mapping configuration.
  </UserResponse>
</Message>
<Message ID="SECJ0121I" severity="I" prefix="yes">
  <MsgText pgmKey="security.web.ta.loadclass" varFormat="Java">
    security.web.ta.loadclass=SECJ0121I: Trust Association Init class {0} loaded successfully
  </MsgText>
  <Explanation>
    Self Explanatory.
  </Explanation>
  <UserResponse>
    None, informational only.
  </UserResponse>
</Message>
<Message ID="SECJ0254E" severity="E" prefix="yes">
  <MsgText pgmKey="security.getting.initctx.error" varFormat="Java">
    security.getting.initctx.error=SECJ0254E: Error getting Initial Naming Context. The exception is {0}.
  </MsgText>
  <Explanation>
    javax.naming.NamingException occurred when getting Initial Naming Context.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7757E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.noTrustedRealm.SECJ7757E" varFormat="Java">
    security.admintask.noTrustedRealm.SECJ7757E=SECJ7757E: There are no trusted realms in {0}.
  </MsgText>
  <Explanation>
    There are no trusted realms for the realm, resource, or domain provided.
  </Explanation>
  <UserResponse>
    Run the command on realm, resourse, or domain that has trusted realms.
  </UserResponse>
</Message>
<Message ID="SECJ7427E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.ListCertFailure" varFormat="Java">
    security.admintask.ListCertFailure=SECJ7427E: Failed to list the certificate aliases.
  </MsgText>
  <Explanation>
    Could not list the certificate aliases in the referenced keystore.
  </Explanation>
  <UserResponse>
    Verify that at least one certificate alias exists in the keystore.
  </UserResponse>
</Message>
<Message ID="SECJ7448E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.InvalidBinaryAuditLog" varFormat="Java">
    security.admintask.InvalidBinaryAuditLog=SECJ7448E: Non valid or no value specified for the fully qualified path of the Binary Audit Log.
  </MsgText>
  <Explanation>
    The expected fully qualified filename for the Binary Audit Log was specified incorrectly.
  </Explanation>
  <UserResponse>
    Check the pathname specified for the location of the Binary Audit Log.
  </UserResponse>
</Message>
<Message ID="SECJ0170W" severity="W" prefix="yes">
  <MsgText pgmKey="security.policy.parser.expandgrant" varFormat="Java">
    security.policy.parser.expandgrant=SECJ0170W: Expand exception occurred. Skip the grant entry. The exception is {0}.
  </MsgText>
  <Explanation>
    While expanding the grant entry, caught an expand exception
  </Explanation>
  <UserResponse>
    Check the grant entry syntax in your policy file. To identify which policy file has a problem, enable security trace for the component com.ibm.ws.security.policy.*. The trace.log file will show the policy file name.
  </UserResponse>
</Message>
<Message ID="SECJ7766E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.authMechNotConfigured.SECJ7766E" varFormat="Java">
    security.admintask.authMechNotConfigured.SECJ7766E=SECJ7766E: The authentication mechanism is not configured.
  </MsgText>
  <Explanation>
    The specified authentication mechanism needs to be configured before it can be used.
  </Explanation>
  <UserResponse>
    Ensure that an authentication mechanism is configured.
  </UserResponse>
</Message>
<Message ID="SECJ7472E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.InvalidCryptoAlgorithmInPassword" varFormat="Java">
    security.admintask.InvalidCryptoAlgorithmInPassword=SECJ7472E: LDAP bind password could not be encoded.
  </MsgText>
  <Explanation>
    An invalid value was specified for the LDAP bind password or an invalid cryptographic algorithm was used.
  </Explanation>
  <UserResponse>
    If you are using a WebSphere Application Server assigned algorithm, ensure that your password does not contain a bracket character. The bracket character conflicts with the cryptographic algorithm WebSphere Application Server assigns. If you are using custom password encryption, verify you have assigned a valid algorithm.
  </UserResponse>
</Message>
<Message ID="SECJ0280E" severity="E" prefix="yes">
  <MsgText pgmKey="security.secsrv.get.realm" varFormat="Java">
    security.secsrv.get.realm=SECJ0280E: Error getting realm from registry. The exception is {0}.
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7032I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.useJACCProvider" varFormat="Java">
    security.configrpt.core.useJACCProvider=SECJ7032I: External authorization using a JACC provider
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7207I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.logToSystemOut" varFormat="Java">
    security.configrpt.core.logToSystemOut=SECJ7207I: Log to SystemOut
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7755E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.noTrustedRealm.SECJ7755E" varFormat="Java">
    security.admintask.noTrustedRealm.SECJ7755E=SECJ7755E: The trusted realm object does not exist.
  </MsgText>
  <Explanation>
    The trusted realm object does not exist.
  </Explanation>
  <UserResponse>
    Run the command on a security domain that has the trusted realm object defined.
  </UserResponse>
</Message>
<Message ID="SECJ0236E" severity="E" prefix="yes">
  <MsgText pgmKey="security.sambean.impltpakeys" varFormat="Java">
    security.sambean.impltpakeys=SECJ0236E: An unexpected exception occurred when trying to import the LTPA Keys from the security mbean with properties {0}. The exception is {1}.
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ0389E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jacc.provider.pcontextkey.error" varFormat="Java">
    security.jacc.provider.pcontextkey.error=SECJ0389E: Problem getting the PolicyContext key {0}. The exception is {1}.
  </MsgText>
  <Explanation>
    The policy context key cannot be obtained to make the access decision.
  </Explanation>
  <UserResponse>
    Make sure that the Policy Context Key in question is registered by the container.
  </UserResponse>
</Message>
<Message ID="SECJ7370E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.InvalidFilterRef" varFormat="Java">
    security.admintask.InvalidFilterRef=SECJ7370E: Non valid or no value specified for the audit specification reference.
  </MsgText>
  <Explanation>
    The audit specification reference field is required.
  </Explanation>
  <UserResponse>
    Verify that a valid value has been specified for the audit specification reference
  </UserResponse>
</Message>
<Message ID="SECJ7764E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.noAuthConfig.SECJ7764E" varFormat="Java">
    security.admintask.noAuthConfig.SECJ7764E=SECJ7764E: The authorization configuration object does not exist.
  </MsgText>
  <Explanation>
    The authorization configuration object does not exist in the configuration.
  </Explanation>
  <UserResponse>
    Ensure an authorization configuration object exists.
  </UserResponse>
</Message>
<Message ID="SECJ7259I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.domain.securitySettings" varFormat="Java">
    security.configrpt.domain.securitySettings=SECJ7259I: Application and Java 2 Security
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7181I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.firstClass" varFormat="Java">
    security.configrpt.core.firstClass=SECJ7181I: Class name
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0214W" severity="W" prefix="yes">
  <MsgText pgmKey="security.init.wccmjaas.wrongclasswarning" varFormat="Java">
    security.init.wccmjaas.wrongclasswarning=SECJ0214W:  Unexpected JAAS login provider class {0} is currently configured. The expected configured class is {1}. When WebSphere security is enabled, this class is required.
  </MsgText>
  <Explanation>
    WebSphere provides an implementation of javax.security.auth.login.Configuration and dynamically installs this class at server startup. Either some application code has installed a different login provider class or a problem occurred when WebSphere tried to dynamically install the class.
  </Explanation>
  <UserResponse>
    Check for other server startup warning or error messages.
  </UserResponse>
</Message>
<Message ID="SECJ0364E" severity="E" prefix="yes">
  <MsgText pgmKey="security.ltpa.init.error" varFormat="Java">
    security.ltpa.init.error=SECJ0364E: Cannot initialize ltpa object because of the following exception {0}.
  </MsgText>
  <Explanation>
    The LTPA server object cannot be initialized.
  </Explanation>
  <UserResponse>
    In most cases, this error occurs because the LTPA keys cannot be decrypted using the LTPA password. The password that is used to encrypt the keys is not the same password that is saved in the repository. The server might not come up when this problem occurs. If this happens, disable security, start the server, and then enter a new password for LTPA. Save the password, generate the keys, and then save again. Finally, turn on security and then stop and restart the server. Contact your service representative if the problem persists.
  </UserResponse>
</Message>
<Message ID="SECJ0089E" severity="E" prefix="yes">
  <MsgText pgmKey="security.authtbl.listerror" varFormat="Java">
    security.authtbl.listerror=SECJ0089E: Error obtaining all permissions
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ6108I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.service.no.auth.constraint.audit" varFormat="Java">
    security.audit.service.no.auth.constraint.audit=SECJ6108I: Access to a web resource is allowed because there is no auth constraint.
  </MsgText>
  <Explanation>
    According to Servlet V2.4 Spec, access to a web resource should be permitted if there is no auth constraint in the security constraint.
  </Explanation>
  <UserResponse>
    Modify the security constraint if the current behavior does not fit your needs.
  </UserResponse>
</Message>
<Message ID="SECJ7424E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.NoAuditXML" varFormat="Java">
    security.admintask.NoAuditXML=SECJ7424E: Audit.xml is not found.
  </MsgText>
  <Explanation>
    No audit.xml was found for this profile. Auditing is not configured.
  </Explanation>
  <UserResponse>
    Ensure auditing is configured properly.
  </UserResponse>
</Message>
<Message ID="SECJ6035E" severity="E" prefix="yes">
  <MsgText pgmKey="security.audit.logger.write.error" varFormat="Java">
    security.audit.logger.write.error=SECJ6035E: Failure to write to the Audit log.
  </MsgText>
  <Explanation>
    Could not write the audit record to the Audit log.
  </Explanation>
  <UserResponse>
    Verify the log exists.  Check the error logs for any possible IO exceptions.
  </UserResponse>
</Message>
<Message ID="SECJ4061W" severity="W" prefix="yes">
  <MsgText pgmKey="security.j2c.mappingFailed" varFormat="Java">
    security.j2c.mappingFailed=SECJ4061W: Exception {0} was thrown during mapping.
  </MsgText>
  <Explanation>
    An exception was created by the WebSphere default principal/credential mapping function.
  </Explanation>
  <UserResponse>
    This is most likely caused by incorrect authentcaiton data configuration.
  </UserResponse>
</Message>
<Message ID="SECJ0385W" severity="W" prefix="yes">
  <MsgText pgmKey="security.addprovider.error" varFormat="Java">
    security.addprovider.error=SECJ0385W: Cannot find and load the FIPS approved IBM JSSE or JCE providers.  This can be a problem if your environment must use FIPS approved cryptographic algorithms and you are not using your own FIPS approved providers.  The error status/exception is {0}.
  </MsgText>
  <Explanation>
    Cannot find and load the FIPS approved IBM JSSE or JCE providers.  This is a problem when the IBM FIPS approved JCE provider is missing.  Websphere Application Server depends on it when a FIPS approved provider is required.  However, a missing FIPS approved IBM JSSE provider might not be a problem provided that you have configured it to use your own FIPS approved JSSE provider.
  </Explanation>
  <UserResponse>
    Make sure that the missing provider jar, if needed, is in the JDK ext directory.
  </UserResponse>
</Message>
<Message ID="SECJ7703E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.scope.in.domain.SECJ7703E" varFormat="Java">
    security.admintask.scope.in.domain.SECJ7703E=SECJ7703E: {0} already exists in the {1} security configuration.
  </MsgText>
  <Explanation>
    A scope can only be mapped in one security configuration at time.
  </Explanation>
  <UserResponse>
    Rerun the command using a scope that is not already mapped to a security configuration.
  </UserResponse>
</Message>
<Message ID="SECJ7246I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.autoReload" varFormat="Java">
    security.configrpt.core.autoReload=SECJ7246I: Automatically reload SPNEGO Configuration
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7164I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.hostList" varFormat="Java">
    security.configrpt.core.hostList=SECJ7164I: Host list
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7089I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.Security.Console.Name" varFormat="Java">
    security.configrpt.core.Security.Console.Name=SECJ7089I: Console Name
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ5015E" severity="E" prefix="yes">
  <MsgText pgmKey="security.ltpa.factory.null.error" varFormat="Java">
    security.ltpa.factory.null.error=SECJ5015E: The LTPA TokenFactory {0} returned is null.
  </MsgText>
  <Explanation>
    The LTPA TokenFactory implementation is likely not present in the class path or it cannot be initialized.
  </Explanation>
  <UserResponse>
    Ensure that the LTPA TokenFactory implementation is located in the WebSphere class path. Typically these implementations are put in the ${WAS_INSTALL_ROOT}/classes directory.
  </UserResponse>
</Message>
<Message ID="SECJ7072I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.keyFileName" varFormat="Java">
    security.configrpt.core.keyFileName=SECJ7072I: Key file name
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7410E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.NoKeyStoreNameValue" varFormat="Java">
    security.admintask.NoKeyStoreNameValue=SECJ7410E: No name was specified for the audit key store.
  </MsgText>
  <Explanation>
    Must specify a name for the audit key store
  </Explanation>
  <UserResponse>
    Supply a name for the audit key store
  </UserResponse>
</Message>
<Message ID="SECJ7419E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.CertAliasExists" varFormat="Java">
    security.admintask.CertAliasExists=SECJ7419E: Found certificate with the same alias in the keystore.
  </MsgText>
  <Explanation>
    A certificate with the same alias name already exists in the keystore.  Cannot add.
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7713E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.serverIdAndPassword.SECJ7713E" varFormat="Java">
    security.admintask.serverIdAndPassword.SECJ7713E=SECJ7713E: Password and server id must be provided at the same time.
  </MsgText>
  <Explanation>
    When a server id is proviced then a password must be specified as well.
  </Explanation>
  <UserResponse>
    Ensure a server id and password are provided.
  </UserResponse>
</Message>
<Message ID="SECJ6047E" severity="E" prefix="yes">
  <MsgText pgmKey="security.audit.fatal.error" varFormat="Java">
    security.audit.fatal.error=SECJ6047E: Unrecoverable error occurred in the audit subsystem.
  </MsgText>
  <Explanation>
    An unrecoverable error occurred in the audit subsystem.  Auditing is discontinued.
  </Explanation>
  <UserResponse>
    Examine the error logs for the cause of the problem.
  </UserResponse>
</Message>
<Message ID="SECJ4052E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaas.invalidType.cred.exception" varFormat="Java">
    security.jaas.invalidType.cred.exception=SECJ4052E: InvalidCredentialType exception is caught while serialized Subject is being restored. The exception is {0}.
  </MsgText>
  <Explanation>
    InvalidCredentialType exception occurred while restoring the credential.
  </Explanation>
  <UserResponse>
    Investigate the SAS problem. Contact your service representative if the problem persist.
  </UserResponse>
</Message>
<Message ID="SECJ6006E" severity="E" prefix="yes">
  <MsgText pgmKey="security.audit.service.config.error" varFormat="Java">
    security.audit.service.config.error=SECJ6006E: Security auditing is REQUIRED but {0} was not defined.
  </MsgText>
  <Explanation>
    At least one AuditEventFactory and an AuditServiceProvider must be defined when the security auditing policy is set to REQUIRED.
  </Explanation>
  <UserResponse>
    Verify that the two properties com.ibm.websphere.security.audit.auditEventFactory and com.ibm.wsspi.security.audit.auditServiceProvider are defined proerly in the global security custom properties.
  </UserResponse>
</Message>
<Message ID="SECJ0094E" severity="E" prefix="yes">
  <MsgText pgmKey="security.adminapp.notexist" varFormat="Java">
    security.adminapp.notexist=SECJ0094E: Admin Application does not exist
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7147I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.managementScope" varFormat="Java">
    security.configrpt.core.managementScope=SECJ7147I: Management scope
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0273E" severity="E" prefix="yes">
  <MsgText pgmKey="security.load.secConfig" varFormat="Java">
    security.load.secConfig=SECJ0273E: Failed to load SecurityServer.xml. The exception is {0}.
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ4063E" severity="E" prefix="yes">
  <MsgText pgmKey="security.j2c.reflectionFailure" varFormat="Java">
    security.j2c.reflectionFailure=SECJ4063E: Exception {0} caught in processing callback {1}
  </MsgText>
  <Explanation>
    Unexpected problem occured when processing a WebSphere Application Server V5 mapping callback type.
  </Explanation>
  <UserResponse>
    Contact your service representative with information present in the error log.
  </UserResponse>
</Message>
<Message ID="SECJ6223E" severity="E" prefix="yes">
  <MsgText pgmKey="security.zos.saf.threadid.sync.error" varFormat="Java">
    security.zos.saf.threadid.sync.error=SECJ6223E: Thread identity synchronization of user &quot;{0}&quot; failed.  The native service results related to this failure are: {1}.
  </MsgText>
  <Explanation>
    An authorized service used to perform thread identity synchronization has failed.  The thread security environment might not have been associated with the current thread of execution.
  </Explanation>
  <UserResponse>
    User the provided SAF service information to determine the cause of the failure.  If the problem persists, contact the IBM support center.
  </UserResponse>
</Message>
<Message ID="SECJ7009I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.enforceFineGrainedJCASecurity" varFormat="Java">
    security.configrpt.core.enforceFineGrainedJCASecurity=SECJ7009I: Restrict access to resource authentication data
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ6126I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.basic.success.audit" varFormat="Java">
    security.audit.basic.success.audit=SECJ6126I: Basic authentication was successful.
  </MsgText>
  <Explanation>
    Authentication using the user id and password in the HTTP header was successful.
  </Explanation>
  <UserResponse>
    No action is required.
  </UserResponse>
</Message>
<Message ID="SECJ8032W" severity="W" prefix="yes">
  <MsgText pgmKey="security.jaspi.configuration.factory.undefined.SECJ8032W" varFormat="Java">
    security.jaspi.configuration.factory.undefined.SECJ8032W=SECJ8032W: AuthConfigFactory implementation is not defined, using the default JASPI factory implementation class: {0}.
  </MsgText>
  <Explanation>
    The JASPI factory implementation is not defined. The default JASPI factory implementation has been set in the server runtime. However, JASPI may not function for a client.
  </Explanation>
  <UserResponse>
    Set the fully qualified class name of the default JASPI factory implementation class as the value for the property authconfigprovider.factory in java.security.
  </UserResponse>
</Message>
<Message ID="SECJ6054E" severity="E" prefix="yes">
  <MsgText pgmKey="security.audit.enforcing.silent_fail.error" varFormat="Java">
    security.audit.enforcing.silent_fail.error=SECJ6054E: The audit log wrapping behavior is set to SILENT_FAIL and the maximum number of audit logs has been reached.  Audit logging will stop.
  </MsgText>
  <Explanation>
    Audit logging stopped: maximum number of audit logs has been reached and the wrapping behavior is set to SILENT_FAIL.
  </Explanation>
  <UserResponse>
    Determine whether the maximum number of audit logs needs to be increased.  Archive all the saved audit logs to a safe repository and restart the server to restart the auditing service
  </UserResponse>
</Message>
<Message ID="SECJ0147E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.ldap.mapcredentialBadFilter" varFormat="Java">
    security.registry.ldap.mapcredentialBadFilter=SECJ0147E: Cannot map the credential of the given credential token for certificate subject DN {0} into LDAP because of an LDAP filter mapping exception. The CertificateMapperException is {1}
  </MsgText>
  <Explanation>
    The Certificate mapping filter specified by the user in the global security settings is missing or malformed.
  </Explanation>
  <UserResponse>
    Review the certificate mapping filter configuration in the LDAP Advanced properties in the Security Center and verify it is present and correct.
  </UserResponse>
</Message>
<Message ID="SECJ0225W" severity="W" prefix="yes">
  <MsgText pgmKey="security.webseal.nopdauth" varFormat="Java">
    security.webseal.nopdauth=SECJ0225W: PD Authentication disabled.
  </MsgText>
  <Explanation>
    PD Authentication disabled.
  </Explanation>
  <UserResponse>
    None, informational only.
  </UserResponse>
</Message>
<Message ID="SECJ7523W" severity="W" prefix="yes">
  <MsgText pgmKey="security.scanner.risk.admin.role.improve" varFormat="Java">
    security.scanner.risk.admin.role.improve=SECJ7523W: Multiple Administrative User Roles are not configured. A number of administrative roles are defined to provide degrees of authority that are needed to perform certain administrative functions from either the Web-based administrative console or the system management scripting interface. The authorization policy is only enforced when administrative security is enabled.
  </MsgText>
  <Explanation>
    Multiple Administrative User Roles are not configured. A number of administrative roles are defined to provide degrees of authority that are needed to perform certain administrative functions from either the Web-based administrative console or the system management scripting interface. The authorization policy is only enforced when administrative security is enabled.
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ4041E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaas.open.stringreader" varFormat="Java">
    security.jaas.open.stringreader=SECJ4041E: {0} :ERROR: Could not create or open StringReader: {1}. The exception is {2}.
  </MsgText>
  <Explanation>
    Could not create or open the specified StringReader.
  </Explanation>
  <UserResponse>
    Investigate the exception.
  </UserResponse>
</Message>
<Message ID="SECJ7524I" severity="I" prefix="yes">
  <MsgText pgmKey="security.scanner.risk.admin.security.ok" varFormat="Java">
    security.scanner.risk.admin.security.ok=SECJ7524I: Administrative Security is enabled. Only users with specific rights can use the WebSphere Application Server administrative tools to perform any administrative operation
  </MsgText>
  <Explanation>
    This message is for informational purposes only.
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7501I" severity="I" prefix="yes">
  <MsgText pgmKey="security.scanner.risk.need.admin.security" varFormat="Java">
    security.scanner.risk.need.admin.security=SECJ7501I: Administrative Security is not being used, therefore this option is not being used
  </MsgText>
  <Explanation>
    Administrative Security is not being used, therefore this option is not being used
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7117I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.Naming.Everyone" varFormat="Java">
    security.configrpt.Naming.Everyone=SECJ7117I: Everyone
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7142I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.TrustAssociation.interceptors" varFormat="Java">
    security.configrpt.core.TrustAssociation.interceptors=SECJ7142I: Interceptors
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7810E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.unableToRunCommand.SECJ7810E" varFormat="Java">
    security.admintask.unableToRunCommand.SECJ7810E=SECJ7810E: The {0} command can not be run on the {1} security domain.
  </MsgText>
  <Explanation>
    Security configuration operation can not be run on the special security domain.
  </Explanation>
  <UserResponse>
    This operation can not be performed on the security domain.
  </UserResponse>
</Message>
<Message ID="SECJ7414E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.NoKeyStoreConfirmPasswordValue" varFormat="Java">
    security.admintask.NoKeyStoreConfirmPasswordValue=SECJ7414E: No key store confirmation password was specified for the audit key store.
  </MsgText>
  <Explanation>
    Must specify a confirmation key store password to for the audit key store
  </Explanation>
  <UserResponse>
    Supply a confirmation key store password for the audit key store
  </UserResponse>
</Message>
<Message ID="SECJ7540W" severity="W" prefix="yes">
  <MsgText pgmKey="security.scanner.risk.samples.improve" varFormat="Java">
    security.scanner.risk.samples.improve=SECJ7540W: WebSphere Application Server Sample Applications are installed. WebSphere Application Server ships with examples to demonstrate various parts of WebSphere Application Server. These samples might be installed by default and are not intended for use in a production environment. Some of these samples can provide an intruder with information about your system.
  </MsgText>
  <Explanation>
    WebSphere Application Server Sample Applications are installed. WebSphere Application Server ships with examples to demonstrate various parts of WebSphere Application Server. These samples might be installed by default and are not intended for use in a production environment. Some of these samples can provide an intruder with information about your system.
  </Explanation>
  <UserResponse>
    Un-install sample application if not needed.
  </UserResponse>
</Message>
<Message ID="SECJ7544I" severity="I" prefix="yes">
  <MsgText pgmKey="security.scanner.write.to.file" varFormat="Java">
    security.scanner.write.to.file=SECJ7544I: Output is logged in the following location: {0}
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0231I" severity="I" prefix="yes">
  <MsgText pgmKey="security.init.secdm.init" varFormat="Java">
    security.init.secdm.init=SECJ0231I: The Security component&apos;&apos;s FFDC Diagnostic Module {0} registered successfully: {1}.
  </MsgText>
  <Explanation>
    Describes whether the Security component&apos;s FFDC Diagnostic module was successfully registered.
  </Explanation>
  <UserResponse>
    None. Informational only.
  </UserResponse>
</Message>
<Message ID="SECJ0064E" severity="E" prefix="yes">
  <MsgText pgmKey="security.ltpa.credmap.failed" varFormat="Java">
    security.ltpa.credmap.failed=SECJ0064E: Credential mapping failed
  </MsgText>
  <Explanation>
    The credential mapping can fail for a number of reasons: The credential token is not an instance of a supported CredentialToken type for a mapping.  The principal identified in the credential cannot be mapped to an entry or found in the user registry.  A user registry exception occurs if the user registry has been stopped.
  </Explanation>
  <UserResponse>
    Verify that the user registry is operational.  Also verify that the principal exists in the target user registry if appropriate.  The exception reported with this error message might help to diagnose the problem.
  </UserResponse>
</Message>
<Message ID="SECJ0152W" severity="W" prefix="yes">
  <MsgText pgmKey="security.ssl.config.initialization.warning.badSecurityLevel" varFormat="Java">
    security.ssl.config.initialization.warning.badSecurityLevel=SECJ0152W: SecurityLevel was either missing or set to a wrong value (valid values are: high, medium, low); default to high.
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7194I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.aliasPrefix" varFormat="Java">
    security.configrpt.core.aliasPrefix=SECJ7194I: Key alias prefix name
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0420I" severity="I" prefix="yes">
  <MsgText pgmKey="security.registry.ldap.update.audit" varFormat="Java">
    security.registry.ldap.update.audit=SECJ0420I: Security run time is unable to update LDAP registry binding information.
  </MsgText>
  <Explanation>
    new bind information might be incorrect.
  </Explanation>
  <UserResponse>
    Verify bind DN and password are correct.
  </UserResponse>
</Message>
<Message ID="SECJ0357E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.initerror" varFormat="Java">
    security.registry.initerror=SECJ0357E: The registry initialization failed with the following exception {0}.
  </MsgText>
  <Explanation>
    Registry cannot be initialized. Internal Error.
  </Explanation>
  <UserResponse>
    Make sure that the user who is running WebSphere Application Server has administrative and &quot;act as part of operating system&quot; privileges in the Windows machine and is also an administrator in the domain machine. Contact your service representative if the problem persists.
  </UserResponse>
</Message>
<Message ID="SECJ7176I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.serverKeyAlias" varFormat="Java">
    security.configrpt.core.serverKeyAlias=SECJ7176I: Default server certificate alias
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7707E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.strategyTypeMismatch.SECJ7707E" varFormat="Java">
    security.admintask.strategyTypeMismatch.SECJ7707E=SECJ7707E: The number of authentication startegies in the list must match the number of login modules in the list.
  </MsgText>
  <Explanation>
    Each login module provided must have a corresponding authentication strategy.
  </Explanation>
  <UserResponse>
    Ensure that there is an authenticatino startegy type for each login module.
  </UserResponse>
</Message>
<Message ID="SECJ7744E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.notClassProvided.SECJ7744E" varFormat="Java">
    security.admintask.notClassProvided.SECJ7744E=SECJ7744E: A custom registry class name must be provided.
  </MsgText>
  <Explanation>
    When configuring a custom user registry a class name must be provided.
  </Explanation>
  <UserResponse>
    Run the command providing custom registry class name.
  </UserResponse>
</Message>
<Message ID="SECJ0239I" severity="I" prefix="yes">
  <MsgText pgmKey="security.init.startinit" varFormat="Java">
    security.init.startinit=SECJ0239I: Security service initialization started
  </MsgText>
  <Explanation>
    Security service initialization started.
  </Explanation>
  <UserResponse>
    None. Informational only
  </UserResponse>
</Message>
<Message ID="SECJ7503E" severity="E" prefix="yes">
  <MsgText pgmKey="security.scanner.error.invalid.file" varFormat="Java">
    security.scanner.error.invalid.file=SECJ7503E: Unable access file or directory &quot;{0}&quot;.  The file or directory might be missing or corrupted.
  </MsgText>
  <Explanation>
    Unable to fine the specified file or directory.
  </Explanation>
  <UserResponse>
    Ensure that the file or directory reported exists and is not corrupted before continuing.
  </UserResponse>
</Message>
<Message ID="SECJ0180E" severity="E" prefix="yes">
  <MsgText pgmKey="security.policy.deployedapp.appobj" varFormat="Java">
    security.policy.deployedapp.appobj=SECJ0180E: An exception was caught while trying to get the data from the hashmap using the keyword {1}. The exception is {0}.
  </MsgText>
  <Explanation>
    Could not retrieve the deployed application policy file from the hashmap passed to setupPolicy().
  </Explanation>
  <UserResponse>
    This is an internal error. However, it could be caused by incorrect data in xml file. Check the type of the policy file and the hashmap being passed to setupPolicy().  Enable security trace with com.ibm.ws.security.policy.* to get more detailed information.
  </UserResponse>
</Message>
<Message ID="SECJ7826E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.globalfedoption.globalnonfedchange.SECJ7826E" varFormat="Java">
    security.admintask.globalfedoption.globalnonfedchange.SECJ7826E=SECJ7826E: Cannot change the user registry at the global security domain to be a non-federated repository.  The following application security domains are configured to use the global federated repository option: {0}.
  </MsgText>
  <Explanation>
    The global security domain was originally configured to use a federated repository as the user registry and one or more application security domains were configured to use the global federated repository.  The user registry at the global security domain cannot be changed when application security domains are using the global federated repository option.
  </Explanation>
  <UserResponse>
    Before changing the user registry configuration for the global security domain to not use a federated repository,  the following needs to be done: The application security domains which are using the global federated repository will have to be configured to use a different user registry.
  </UserResponse>
</Message>
<Message ID="SECJ0411E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jacc.tools.authzprovider.error" varFormat="Java">
    security.jacc.tools.authzprovider.error=SECJ0411E: An exception occurred when getting the authorization provider object from the configuration. The exception is {1}.
  </MsgText>
  <Explanation>
    Because of an exception, the security policy information might not have been updated to the provider.
  </Explanation>
  <UserResponse>
    Make sure that the provider is up and running and the JACC configuration is correct. Once the problem is fixed, one can also use the wsadmin tool to manually propagate the security policy information to the provider instead of reinstalling the application. See the information center documentation for more details on running this tool. If problem persists, contact your service representative.
  </UserResponse>
</Message>
<Message ID="SECJ4020E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaas.invalidCORBAAttribute" varFormat="Java">
    security.jaas.invalidCORBAAttribute=SECJ4020E: CORBA: Invalid Attribute Type: {0} {1}
  </MsgText>
  <Explanation>
    CORBA credential has attribute that is not valid.
  </Explanation>
  <UserResponse>
    Contact your service representative with exception stack trace information present in the error log.
  </UserResponse>
</Message>
<Message ID="SECJ7442E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.CannotDeleteEncryptionCert" varFormat="Java">
    security.admintask.CannotDeleteEncryptionCert=SECJ7442E: Empty value specified for encryption certificate reference. Cannot delete the encryption certificate when encryption is enabled or being enabled.
  </MsgText>
  <Explanation>
    Encryption is enabled or is being enabled. The encryption certificate is in use and cannot be deleted
  </Explanation>
  <UserResponse>
    Disable encryption before deleting the encryption certificate.
  </UserResponse>
</Message>
<Message ID="SECJ6212W" severity="W" prefix="yes">
  <MsgText pgmKey="security.zos.threadid.connmgmt.denied" varFormat="Java">
    security.zos.threadid.connmgmt.denied=SECJ6212W: Connection management thread identity synchronization has been disabled by the z/OS security product.
  </MsgText>
  <Explanation>
    The server has been configured to perform J2EE and operating system thread identity synchronization for connectors that are able to exploit it but the security product has not authorized the use of this support.
  </Explanation>
  <UserResponse>
    Contact your security product administrator to request authorization to use thread identity synchronization.
  </UserResponse>
</Message>
<Message ID="SECJ7225I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.customRegistryClassName" varFormat="Java">
    security.configrpt.core.customRegistryClassName=SECJ7225I: Custom registry class name
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7467E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.FileNotFound" varFormat="Java">
    security.admintask.FileNotFound=SECJ7467E: The named file &quot;{0}&quot; does not exist.
  </MsgText>
  <Explanation>
    Could not open or read the file.
  </Explanation>
  <UserResponse>
    Specify a valid filename.
  </UserResponse>
</Message>
<Message ID="SECJ7366E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.CreateObjFailure" varFormat="Java">
    security.admintask.CreateObjFailure=SECJ7366E: Failed to create object.
  </MsgText>
  <Explanation>
    Failure occurred trying to create a configuration object.
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7429E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.NoNameForFilter" varFormat="Java">
    security.admintask.NoNameForFilter=SECJ7429E: Missing unique name for audit specification.
  </MsgText>
  <Explanation>
    A unique name was not specified for the audit specification.
  </Explanation>
  <UserResponse>
    Specify a unique name for the audit specification.
  </UserResponse>
</Message>
<Message ID="SECJ0220W" severity="W" prefix="yes">
  <MsgText pgmKey="security.roleauthz.appalreadyload" varFormat="Java">
    security.roleauthz.appalreadyload=SECJ0220W: The role based authorizer for module {0} has already been loaded.
  </MsgText>
  <Explanation>
    The role based authorizer will load only once per module.
  </Explanation>
  <UserResponse>
    None, informational only.
  </UserResponse>
</Message>
<Message ID="SECJ0175E" severity="E" prefix="yes">
  <MsgText pgmKey="security.policy.param.setupPolicy" varFormat="Java">
    security.policy.param.setupPolicy=SECJ0175E: An exception was caught while retrieving data from the hashmap for the keyword {1}. The exception is {0}.
  </MsgText>
  <Explanation>
    The data stored for the keyword &quot;type&quot; in the hashmap is incorrect
  </Explanation>
  <UserResponse>
    This is an internal error. However, it could be caused by an incorrect xml file. Enable security trace with com.ibm.ws.security.policy.* to get more detailed information.
  </UserResponse>
</Message>
<Message ID="SECJ7796E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.cannotRemoveRealm.SECJ7796E" varFormat="Java">
    security.admintask.cannotRemoveRealm.SECJ7796E=SECJ7796E: The security domain default realm {0} can not be removed form the list of trusted realms.
  </MsgText>
  <Explanation>
    The security domain default realm is always trusted and can not be removed form the list of trusted realms.
  </Explanation>
  <UserResponse>
    Ensure the realm being removed is not domain default realm.
  </UserResponse>
</Message>
<Message ID="SECJ7043I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.alias" varFormat="Java">
    security.configrpt.core.alias=SECJ7043I: Alias
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ6031E" severity="E" prefix="yes">
  <MsgText pgmKey="security.audit.signing.error" varFormat="Java">
    security.audit.signing.error=SECJ6031E: Failure to sign the audit record.  Exception = {0}.
  </MsgText>
  <Explanation>
    Signing error generated while trying to sign the audit record.
  </Explanation>
  <UserResponse>
    Examine the exception for the cause of the problem.
  </UserResponse>
</Message>
<Message ID="SECJ7756E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.greater.SECJ7756E" varFormat="Java">
    security.admintask.greater.SECJ7756E=SECJ7756E: The {0} value must be greater then 0.
  </MsgText>
  <Explanation>
    The number of elements return by the task needs to be greater then 0.
  </Explanation>
  <UserResponse>
    Ensure the number is greater then 0.
  </UserResponse>
</Message>
<Message ID="SECJ0134E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jsecman.permdenied" varFormat="Java">
    security.jsecman.permdenied=SECJ0134E: The current Java 2 Security policy does not permit the requested action.{0}Java 2 Security Permission: {1}, denied with exception message: {2}.{3}Violating code: {4}
  </MsgText>
  <Explanation>
    The Java Security Manager checkPermission() threw a SecurityException on the subject Permission.
  </Explanation>
  <UserResponse>
    Verify that the attempted operation is permitted.
  </UserResponse>
</Message>
<Message ID="SECJ0060E" severity="E" prefix="yes">
  <MsgText pgmKey="security.ltpaconfig.notexist" varFormat="Java">
    security.ltpaconfig.notexist=SECJ0060E: LTPA configuration not found
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ6220I" severity="I" prefix="yes">
  <MsgText pgmKey="security.zos.saf.authen.cert.map.failed.info" varFormat="Java">
    security.zos.saf.authen.cert.map.failed.info=SECJ6220I: Certificate authentication failed for certificate with SubjectDN=&quot;{0}&quot; and IssuerDN=&quot;{1}&quot;.  The native service results related to the authentication failure are: {2}.
  </MsgText>
  <Explanation>
    WebSphere was unable to map the certificate that was presented to a valid user.  It is likely that the issuer of the certificate is not trusted or that the mapping rules do not account for issuer and subject distinguished names.
  </Explanation>
  <UserResponse>
    Verify that the certificate chain is trusted.  If the chain is valid and trusted, use the provided SAF service information to get more information about the cause of the failure.
  </UserResponse>
</Message>
<Message ID="SECJ0222E" severity="E" prefix="yes">
  <MsgText pgmKey="security.lc.create.err" varFormat="Java">
    security.lc.create.err=SECJ0222E: An unexpected exception occurred when trying to create a LoginContext. The LoginModule alias is {0} and the exception is {1}.
  </MsgText>
  <Explanation>
    A JAAS LoginContext could not be created due to the unexpected exception.
  </Explanation>
  <UserResponse>
    The problem could be due to a configuration error.
  </UserResponse>
</Message>
<Message ID="SECJ0136I" severity="I" prefix="yes">
  <MsgText pgmKey="security.custom.registry.initialized" varFormat="Java">
    security.custom.registry.initialized=SECJ0136I: Custom Registry:{0} has been initialized
  </MsgText>
  <Explanation>
    Reports the Custom User Registry implementation that is being used.
  </Explanation>
  <UserResponse>
    None, informational only.
  </UserResponse>
</Message>
<Message ID="SECJ4007E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaas.NoWSLoginHelperImpl" varFormat="Java">
    security.jaas.NoWSLoginHelperImpl=SECJ4007E: Not supposed to construct WSLoginHelperImpl object
  </MsgText>
  <Explanation>
    WSLoginHelperImpl object instance should not be constructed.
  </Explanation>
  <UserResponse>
    Check the user application. WSLoginHelperImpl should not be directly constructed.
  </UserResponse>
</Message>
<Message ID="SECJ6128I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.exception.audit" varFormat="Java">
    security.audit.exception.audit=SECJ6128I: Authentication failed due to internal error.
  </MsgText>
  <Explanation>
    Authentication failed and a runtime exception was caught.
  </Explanation>
  <UserResponse>
    Report this problem to IBM.
  </UserResponse>
</Message>
<Message ID="SECJ0161E" severity="E" prefix="yes">
  <MsgText pgmKey="security.wsaccessmanager.VendorAuthTableError" varFormat="Java">
    security.wsaccessmanager.VendorAuthTableError=SECJ0161E: Error returned from Vendor AuthorizationTable. The exception is {0}
  </MsgText>
  <Explanation>
    The vendor specified Authorization Table failed during authorization check.
  </Explanation>
  <UserResponse>
    Refer to the vendor&apos;s specific exception for details. If vendor&apos;s specific exception is not present, contact your service representative with the exception stack trace information present in the error log.
  </UserResponse>
</Message>
<Message ID="SECJ7795E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.cannotRemoveRealm.SECJ7795E" varFormat="Java">
    security.admintask.cannotRemoveRealm.SECJ7795E=SECJ7795E: The global security realm {0} can not be removed from the list of trusted realms.
  </MsgText>
  <Explanation>
    The global security configuration realm is always trusted and can not be removed form the list of trusted realms.
  </Explanation>
  <UserResponse>
    Ensure the realm being removed is not the global security realm.
  </UserResponse>
</Message>
<Message ID="SECJ0380W" severity="W" prefix="yes">
  <MsgText pgmKey="security.ssl.config.initialization.warning.invalidkeystoretype" varFormat="Java">
    security.ssl.config.initialization.warning.invalidkeystoretype=SECJ0380W: The keystore or truststore type specified is invalid.  Adjusting to use the correct type, however, correct the SSL configuration for performance reasons.
  </MsgText>
  <Explanation>
    The keystore or truststore type specified is not valid.
  </Explanation>
  <UserResponse>
    Modify the SSL configuration so that the keystore or truststore type is a valid type.  You can check the keystore and truststore types by loading them in WebSphere&apos;s IKeyMan tool.
  </UserResponse>
</Message>
<Message ID="SECJ0194E" severity="E" prefix="yes">
  <MsgText pgmKey="security.policy.filter.ioexception" varFormat="Java">
    security.policy.filter.ioexception=SECJ0194E: Caught IOException while adding permission to the set of filtered permissions. The exception is {0}.
  </MsgText>
  <Explanation>
    IOException occurred when adding permission to the set of filtered permissions.
  </Explanation>
  <UserResponse>
    Check the filter.policy file.
  </UserResponse>
</Message>
<Message ID="SECJ7547E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.invalidAuthMechType" varFormat="Java">
    security.admintask.invalidAuthMechType=SECJ7547E: Authentication mechanism type is not valid
  </MsgText>
  <Explanation>
    Valid authentication mechanism types are: KRB5, LTPA
  </Explanation>
  <UserResponse>
    Ensure user authentication mechanism type is a valid type
  </UserResponse>
</Message>
<Message ID="SECJ0234E" severity="E" prefix="yes">
  <MsgText pgmKey="security.sambean.getgrperr" varFormat="Java">
    security.sambean.getgrperr=SECJ0234E: An unexpected exception occurred when trying to get groups from the User Registry with pattern {0} and limit {1}. The exception is {2}.
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7767E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.invalid.SPN.SECJ7767E" varFormat="Java">
    security.admintask.invalid.SPN.SECJ7767E=SECJ7767E: serverSpn {0} is malformed, it must be in the format of &lt;service&gt;/&lt;host name&gt; or &lt;service&gt;/&lt;host name&gt;@KerberosRealm.
  </MsgText>
  <Explanation>
    The Kerberos service principal name format is malformed.
  </Explanation>
  <UserResponse>
    Verify the Kerberos service principal name (SPN)
  </UserResponse>
</Message>
<Message ID="SECJ7362E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.InvalidClassName" varFormat="Java">
    security.admintask.InvalidClassName=SECJ7362E: Non valid or no reference specified for the class name of this implementation.
  </MsgText>
  <Explanation>
    The className reference is a required field.
  </Explanation>
  <UserResponse>
    Verify that a valid reference has been specified for the className
  </UserResponse>
</Message>
<Message ID="SECJ7388E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.InvalidAuditPolicy" varFormat="Java">
    security.admintask.InvalidAuditPolicy=SECJ7388E: Non valid value specified for the audit policy.
  </MsgText>
  <Explanation>
    Valid values are WARN, NOWARN, and FATAL.
  </Explanation>
  <UserResponse>
    Specify a valid audit policy value
  </UserResponse>
</Message>
<Message ID="SECJ6207I" severity="I" prefix="yes">
  <MsgText pgmKey="security.zos.trusted.apps.enabled" varFormat="Java">
    security.zos.trusted.apps.enabled=SECJ6207I: Authorized credential management is enabled.
  </MsgText>
  <Explanation>
    Applications running in this server are considered &quot;trusted&quot;.  When applications are trusted, the security infrastructure will allow the creation of MVS credentials without a password, passticket, or certificate as an authenticator.  Trusted applications must be enabled in order to use the LTPA authentication mechanism, identity assertion, or a Trust Association Interceptor with a &quot;Local OS&quot; user registry on z/OS.  Trusted applications must also be enabled to use SAF authorization.
  </Explanation>
  <UserResponse>
    No user action is required.
  </UserResponse>
</Message>
<Message ID="SECJ0104E" severity="E" prefix="yes">
  <MsgText pgmKey="security.methodgroups.predef.createerror" varFormat="Java">
    security.methodgroups.predef.createerror=SECJ0104E: Error creating predefined method groups
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ0185W" severity="W" prefix="yes">
  <MsgText pgmKey="security.policy.removepolicy.modulepath" varFormat="Java">
    security.policy.removepolicy.modulepath=SECJ0185W: An exception was caught while trying to get the absolute path for the module {1} in removePolicy(). The exception is {0}
  </MsgText>
  <Explanation>
    Could not get the absolute path for the module in removePolicy().
  </Explanation>
  <UserResponse>
    Check the specified path. It could be caused by incorrect data in xml file. Enable security trace with com.ibm.ws.security.policy.* to get more detailed information.
  </UserResponse>
</Message>
<Message ID="SECJ0133E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jsecman.illegal.perm" varFormat="Java">
    security.jsecman.illegal.perm=SECJ0133E: Illegal {0} : {1}
  </MsgText>
  <Explanation>
    An illegal Permission was attempted.  Only the main thread can set the security manager.
  </Explanation>
  <UserResponse>
    Verify that the code that is trying to set the security manager is not trying to subvert the WebSphere security manager.
  </UserResponse>
</Message>
<Message ID="SECJ0250E" severity="E" prefix="yes">
  <MsgText pgmKey="security.create.server.error" varFormat="Java">
    security.create.server.error=SECJ0250E: Error creating security server. The exception is {0}.
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ0082E" severity="E" prefix="yes">
  <MsgText pgmKey="security.web.initerror" varFormat="Java">
    security.web.initerror=SECJ0082E: Error during web security initialization
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ0371W" severity="W" prefix="yes">
  <MsgText pgmKey="security.ltpa.validate.tokenexpired" varFormat="Java">
    security.ltpa.validate.tokenexpired=SECJ0371W: Validation of the LTPA token failed because the token expired with the following info: {0}. This warning might indicate expected behavior. Please refer to technote at {1}.
  </MsgText>
  <Explanation>
    Cannot validate the token since the token has expired.
  </Explanation>
  <UserResponse>
    Once the token timeout is reached, the token is not validated and you must authenticate again. This is normal. Make sure that all the WebSphere nodes and cell(s) are synchronized with respect to time, date and time zone. You can change the token expiration time if necessary.
  </UserResponse>
</Message>
<Message ID="SECJ0100E" severity="E" prefix="yes">
  <MsgText pgmKey="security.mg.updateerr" varFormat="Java">
    security.mg.updateerr=SECJ0100E: Error storing method group
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7124I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.Naming.Create.Name" varFormat="Java">
    security.configrpt.Naming.Create.Name=SECJ7124I: Create
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ4023E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaas.configNewInstance" varFormat="Java">
    security.jaas.configNewInstance=SECJ4023E: Failed to create a Configuration instance.
  </MsgText>
  <Explanation>
    Failed to create a configuration instance
  </Explanation>
  <UserResponse>
    Contact your service representative with exception stack trace information present in the error log.
  </UserResponse>
</Message>
<Message ID="SECJ0353E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.usersecurityname.notfound" varFormat="Java">
    security.registry.usersecurityname.notfound=SECJ0353E: Could not get the name of the user whose uniqueId is {0}.
  </MsgText>
  <Explanation>
    Internal Error.
  </Explanation>
  <UserResponse>
    Make sure that the user is valid. Contact your service representative if the problem persists.
  </UserResponse>
</Message>
<Message ID="SECJ4012E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaas.getCurrentException" varFormat="Java">
    security.jaas.getCurrentException=SECJ4012E: Error getting SecurityCurrent from the ORB {0}
  </MsgText>
  <Explanation>
    Getting security current caused an exception.
  </Explanation>
  <UserResponse>
    Make sure that the ORB is initialized correctly in the user application.
  </UserResponse>
</Message>
<Message ID="SECJ7158I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.clientAuthenticationSupported" varFormat="Java">
    security.configrpt.core.clientAuthenticationSupported=SECJ7158I: Client Authentication Supported
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0088E" severity="E" prefix="yes">
  <MsgText pgmKey="security.authtbl.deleteerror" varFormat="Java">
    security.authtbl.deleteerror=SECJ0088E: Error deleting permission
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ0399E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jacc.server.task.error" varFormat="Java">
    security.jacc.server.task.error=SECJ0399E: Error updating deployment.xml information with the appContextIDForSecurity for application {0}. The exception is {1}.
  </MsgText>
  <Explanation>
    The appContextIDForSecurity atribute is required when using JACC as the authorization.
  </Explanation>
  <UserResponse>
    If JACC will not be used for authorization then this should not impact anything. If JACC will be used for authorization, contact your IBM representative if this problem persists.
  </UserResponse>
</Message>
<Message ID="SECJ7702E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.config.does.not.exist.SECJ7702E" varFormat="Java">
    security.admintask.config.does.not.exist.SECJ7702E=SECJ7702E: Security domain {0} does not exist.
  </MsgText>
  <Explanation>
    The security configuration does not exist.
  </Explanation>
  <UserResponse>
    Run the command with a pre-existing security configuration.
  </UserResponse>
</Message>
<Message ID="SECJ6105I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.service.no.role.audit" varFormat="Java">
    security.audit.service.no.role.audit=SECJ6105I: Access to a web resource is denied because no security role is defined in the auth constraint.
  </MsgText>
  <Explanation>
    According to Servlet V2.4 Spec, access to a web resource should be precluded if there is an auth constraint in the security constraint but there is no security role defined in the auth constraint.
  </Explanation>
  <UserResponse>
    Modify the security constraint if the current behavior does not fit your needs.
  </UserResponse>
</Message>
<Message ID="SECJ7749E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.noKeyStore.SECJ7749E" varFormat="Java">
    security.admintask.noKeyStore.SECJ7749E=SECJ7749E: A key store must be specified when a certificate alias is specified.
  </MsgText>
  <Explanation>
    When a certificate alias is specified a key store object must be specified.
  </Explanation>
  <UserResponse>
    Run the command providing a key store.
  </UserResponse>
</Message>
<Message ID="SECJ7215I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.messages" varFormat="Java">
    security.configrpt.messages=SECJ7215I: messages
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0314W" severity="W" prefix="yes">
  <MsgText pgmKey="security.jsecman.permdeniedmsg" varFormat="Java">
    security.jsecman.permdeniedmsg=SECJ0314W: Current Java 2 Security policy reported a potential violation of Java 2 Security Permission. Refer to the InfoCenter for further information.{0}Permission:{1}Code:{2}{3}Stack Trace:{4}Code Base Location:{5}
  </MsgText>
  <Explanation>
    The Java Security Manager checkPermission() threw a SecurityException on the subject Permission. A caller on the call stack does not have the required permission.  This might not be a problem if the caller properly handles this exception.
  </Explanation>
  <UserResponse>
    Verify that the attempted operation is permitted by examining all Java 2 security policy files and application code.  Additional permissions might be required, a doPrivileged API might be needed in some code on the call stack, or the Security Manager properly prevented access to a resource the caller does not have permission to access.
  </UserResponse>
</Message>
<Message ID="SECJ0115W" severity="W" prefix="yes">
  <MsgText pgmKey="security.web.cred.nopubname" varFormat="Java">
    security.web.cred.nopubname=SECJ0115W: The credential has a null value for the public name
  </MsgText>
  <Explanation>
    The credential is possibly malformed or corrupted.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7789E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.multidomain.oldServerSecurity.SECJ7789E" varFormat="Java">
    security.admintask.multidomain.oldServerSecurity.SECJ7789E=SECJ7789E: Can not convert the server level security configuration to a domain configuration since the {0} server does not have a server level security configured.
  </MsgText>
  <Explanation>
    A server should contain the server level security configuration to be converted to a security domain.
  </Explanation>
  <UserResponse>
    Make sure that the server name is correct and it has a server level security configuration associated with it.
  </UserResponse>
</Message>
<Message ID="SECJ0336E" severity="E" prefix="yes">
  <MsgText pgmKey="security.authn.error" varFormat="Java">
    security.authn.error=SECJ0336E: Authentication failed for user {0} because of the following exception {1}
  </MsgText>
  <Explanation>
    Authentication failed with the specified reason.
  </Explanation>
  <UserResponse>
    Verify that the user id and password are entered correctly. Consult with the administrator of the user registry if the problem persist.
  </UserResponse>
</Message>
<Message ID="SECJ7204I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.hour" varFormat="Java">
    security.configrpt.core.hour=SECJ7204I: Hour
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0092E" severity="E" prefix="yes">
  <MsgText pgmKey="security.authtbl.apphome" varFormat="Java">
    security.authtbl.apphome=SECJ0092E: Application home not found
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7000I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.Security.Configuration.Name" varFormat="Java">
    security.configrpt.core.Security.Configuration.Name=SECJ7000I: Security Configuration Name
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0325W" severity="W" prefix="yes">
  <MsgText pgmKey="security.policy.unresolved.permission" varFormat="Java">
    security.policy.unresolved.permission=SECJ0325W: The permission {0} specified in the policy file {1} is unresolved.
  </MsgText>
  <Explanation>
    The permission class specified in the policy file was not loaded.
  </Explanation>
  <UserResponse>
    Confirm that the specified permission in then policy file is correct. If permission class is incorrect, this warning is issued.
  </UserResponse>
</Message>
<Message ID="SECJ7788E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.multidomain.oldServerSecurity.SECJ7788E" varFormat="Java">
    security.admintask.multidomain.oldServerSecurity.SECJ7788E=SECJ7788E: The {0} resource cannot be mapped to a domain since a server level security configuration is associated with the resource either directly or indirectly.
  </MsgText>
  <Explanation>
    A server that contains server lever security configuration is being associated with a domain. The server level security configuration is deprecated.
  </Explanation>
  <UserResponse>
    The offending server or a cluster member should not contain the server level security configuration if it needs to be mapped to a domain.
  </UserResponse>
</Message>
<Message ID="SECJ0343E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.getgrpsforuser.notfound" varFormat="Java">
    security.registry.getgrpsforuser.notfound=SECJ0343E: Could not get the groups that the user {0} belongs to.
  </MsgText>
  <Explanation>
    Internal Error.
  </Explanation>
  <UserResponse>
    Make sure that the user is valid. Contact your service representative if the problem persists.
  </UserResponse>
</Message>
<Message ID="SECJ0306E" severity="E" prefix="yes">
  <MsgText pgmKey="security.rolebauthz.nocred" varFormat="Java">
    security.rolebauthz.nocred=SECJ0306E: No received or invocation credential exist on the thread. The Role based authorization check will not have an accessId of the caller to check. The parameters are: access check method {0} on resource {1} and module {2}. The stack trace is {3}.
  </MsgText>
  <Explanation>
    No invocation or received credentials were established on this thread.  This might cause the role based authorization check to fail.
  </Explanation>
  <UserResponse>
    The stack trace is obtained by a local throw catch block that might be useful for debugging the problem.
  </UserResponse>
</Message>
<Message ID="SECJ0084W" severity="W" prefix="yes">
  <MsgText pgmKey="security.web.config.initerror" varFormat="Java">
    security.web.config.initerror=SECJ0084W: Error while initializing security web configuration.  The exception is {0}.
  </MsgText>
  <Explanation>
    An error internal occurred while initializing the security attributes of a Web Application.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ8005E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.jaspi.type.invalid.SECJ8005E" varFormat="Java">
    security.admintask.jaspi.type.invalid.SECJ8005E=SECJ8005E: The command result object type is not valid: {0}
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7747E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.RSAKeyStore.SECJ7747E" varFormat="Java">
    security.admintask.RSAKeyStore.SECJ7747E=SECJ7747E: {0} is not a RSA token key store.
  </MsgText>
  <Explanation>
    A RSA key store must be used on a RSA authorization mechanism.
  </Explanation>
  <UserResponse>
    Run the command specifying a RSA key store.
  </UserResponse>
</Message>
<Message ID="SECJ0352E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.getusers.error" varFormat="Java">
    security.registry.getusers.error=SECJ0352E: Could not get the users matching the pattern {0} because of the following exception {1}.
  </MsgText>
  <Explanation>
    Internal Error.
  </Explanation>
  <UserResponse>
    Make sure that the users matching the pattern exist in the registry. Contact your service representative if the problem persists.
  </UserResponse>
</Message>
<Message ID="SECJ7023I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.interceptorClassName" varFormat="Java">
    security.configrpt.core.interceptorClassName=SECJ7023I: Interceptor class name
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7737E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.cannotRemove.SECJ7737E" varFormat="Java">
    security.admintask.cannotRemove.SECJ7737E=SECJ7737E: Cannot remove {0}.
  </MsgText>
  <Explanation>
    The specified login module cannot be removed.  Certian login module cannot be removed.
  </Explanation>
  <UserResponse>
    Run the command with a login module that can be removed.
  </UserResponse>
</Message>
<Message ID="SECJ7334E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.ExceptionProcessingWizardSettings" varFormat="Java">
    security.admintask.ExceptionProcessingWizardSettings=SECJ7334E: Exception raised while applying wizard security settings
  </MsgText>
  <Explanation>
    Caught exception while applying wizard security settings
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7192I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.keySet" varFormat="Java">
    security.configrpt.core.keySet=SECJ7192I: Key set
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7445I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.report.EventType.name" varFormat="Java">
    security.audit.report.EventType.name=SECJ7445I: Event Type
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7364E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.InvalidFileLocation" varFormat="Java">
    security.admintask.InvalidFileLocation=SECJ7364E: Non valid or no reference specified for the location of the binary audit file.
  </MsgText>
  <Explanation>
    The fileLocation reference is a required field.
  </Explanation>
  <UserResponse>
    Verify that a valid reference has been specified for the fileLocation
  </UserResponse>
</Message>
<Message ID="SECJ0151E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.ldap.mapcredentialNSEE" varFormat="Java">
    security.registry.ldap.mapcredentialNSEE=SECJ0151E: Cannot create a credential for the mapped credential token into LDAP with subjectDN {0} and mapped name {1} using filter {2}. The exception is {3}
  </MsgText>
  <Explanation>
    The DN in the certificate was successfully mapped to an entry in LDAP but, an unexpected exception occurred when trying to create a credential for the mapped entry.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7426E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.NoKeyStoreRefValue" varFormat="Java">
    security.admintask.NoKeyStoreRefValue=SECJ7426E: No reference id was specified for the audit key store.
  </MsgText>
  <Explanation>
    Must specify a valid reference id for the audit key store
  </Explanation>
  <UserResponse>
    Supply a reference id for the audit key store
  </UserResponse>
</Message>
<Message ID="SECJ0344E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.getgrpsforuser.error" varFormat="Java">
    security.registry.getgrpsforuser.error=SECJ0344E: Could not get the groups that the user {0} belongs to because of the following exception {1}.
  </MsgText>
  <Explanation>
    Internal Error.
  </Explanation>
  <UserResponse>
    Make sure that the user is valid. Contact your service representative if the problem persists.
  </UserResponse>
</Message>
<Message ID="SECJ7320E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.InvalidUserRegType" varFormat="Java">
    security.admintask.InvalidUserRegType=SECJ7320E: Invalid user registry type
  </MsgText>
  <Explanation>
    Valid user registry types are: LDAPUserRegistry, LocalOSUserRegistry, CustomUserRegistry, WIMUserRegistry
  </Explanation>
  <UserResponse>
    Ensure user registry type is a valid type
  </UserResponse>
</Message>
<Message ID="SECJ7715E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.badUserOrPassword.SECJ7715E" varFormat="Java">
    security.admintask.badUserOrPassword.SECJ7715E=SECJ7715E: Unknown user name or bad password.
  </MsgText>
  <Explanation>
    User name or password are unable to authenticate to the user registry.
  </Explanation>
  <UserResponse>
    Ensure a valid user name and password are specified.
  </UserResponse>
</Message>
<Message ID="SECJ8040E" severity="E" prefix="yes">
  <MsgText pgmKey="security.saml.element.id.notavailable.SECJ8040E" varFormat="Java">
    security.saml.element.id.notavailable.SECJ8040E=SECJ8040E: {0} {1} is already defined in the SAML TAI configuration.
  </MsgText>
  <Explanation>
    The given parameter value has been defined in the SAML TAI configuration.
  </Explanation>
  <UserResponse>
    Verify the SAML TAI properties and specify a value that is not already used. If you do not use this option, a value is automatically selected.
  </UserResponse>
</Message>
<Message ID="SECJ4046E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaas.duplicate.config" varFormat="Java">
    security.jaas.duplicate.config=SECJ4046E: Duplicate login config name {0}. Will over write.
  </MsgText>
  <Explanation>
    Duplicate login configuration name was specified in the configuration data.
  </Explanation>
  <UserResponse>
    Check the configuration data.
  </UserResponse>
</Message>
<Message ID="SECJ0275E" severity="E" prefix="yes">
  <MsgText pgmKey="security.secsrv.find.reg" varFormat="Java">
    security.secsrv.find.reg=SECJ0275E: Error trying to find user registry. The exception is {0}.
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7416E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.CreateKeyStoreFileFailure" varFormat="Java">
    security.admintask.CreateKeyStoreFileFailure=SECJ7416E: Failure creating the audit keystore
  </MsgText>
  <Explanation>
    Failed to create the audit keystore
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ6106I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.service.secure.redirect.audit" varFormat="Java">
    security.audit.service.secure.redirect.audit=SECJ6106I: The request is redirected to {0} because the requested resource must be accessed via HTTPS.
  </MsgText>
  <Explanation>
    The requested resource has a Data Constraint and requires SSL connection to it.
  </Explanation>
  <UserResponse>
    No action is required.
  </UserResponse>
</Message>
<Message ID="SECJ5006E" severity="E" prefix="yes">
  <MsgText pgmKey="security.sap.error.securityname.not.found.in.hashtable" varFormat="Java">
    security.sap.error.securityname.not.found.in.hashtable=SECJ5006E: Cannot create WSCredential without a valid com.ibm.wsspi.security.cred.securityName property value.
  </MsgText>
  <Explanation>
    The com.ibm.wsspi.security.cred.securityName property has not been found during a properties login attempt.
  </Explanation>
  <UserResponse>
    Ensure that the java.util.Hashtable used for a properties login contains a valid property value for com.ibm.wsspi.security.cred.securityName.
  </UserResponse>
</Message>
<Message ID="SECJ7223I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.searchTimeout" varFormat="Java">
    security.configrpt.core.searchTimeout=SECJ7223I: Search timeout
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ6041E" severity="E" prefix="yes">
  <MsgText pgmKey="security.audit.signing.init.error" varFormat="Java">
    security.audit.signing.init.error=SECJ6041E: Failure to initialize Audit signing algorithm.  Exception = {0}.
  </MsgText>
  <Explanation>
    An error occurred during the initialization of the Audit signing algorithm.
  </Explanation>
  <UserResponse>
    Examine the exception for the cause of the problem.
  </UserResponse>
</Message>
<Message ID="SECJ7375E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.InvalidMonitorName" varFormat="Java">
    security.admintask.InvalidMonitorName=SECJ7375E: Non valid name for Audit Notification Monitor.
  </MsgText>
  <Explanation>
    Non valid name for audit notification monitor specified.
  </Explanation>
  <UserResponse>
    Verify that a valid name has been specified for the audit notification monitor
  </UserResponse>
</Message>
<Message ID="SECJ7811E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.cannotCreateDomain.SECJ7811E" varFormat="Java">
    security.admintask.cannotCreateDomain.SECJ7811E=SECJ7811E: Can not create a security domain named {0}.  The name is reserved for a special case security domain.
  </MsgText>
  <Explanation>
    The security domain name being used is reserved for a special case securty domain and can not be created with the command.
  </Explanation>
  <UserResponse>
    Endure another security domain name is used when running the command.
  </UserResponse>
</Message>
<Message ID="SECJ6208I" severity="I" prefix="yes">
  <MsgText pgmKey="security.zos.trusted.apps.disabled" varFormat="Java">
    security.zos.trusted.apps.disabled=SECJ6208I: Authorized credential management is disabled.
  </MsgText>
  <Explanation>
    Applications running in this server are not considered &quot;trusted&quot;.  Since applications are not trusted, the security infrastructure has disallowed the creation of MVS credentials without a password, passticket, or certificate as an authenticator.  Trusted applications must be enabled in order to use the LTPA authentication mechanism, identity assertion, or a Trust Association Interceptor with a &quot;Local OS&quot; user registry on z/OS.  Trusted applications must also be enabled to use SAF authorization.
  </Explanation>
  <UserResponse>
    No user action is required.
  </UserResponse>
</Message>
<Message ID="SECJ0146I" severity="I" prefix="yes">
  <MsgText pgmKey="security.ssl.initial_ssl.missing" varFormat="Java">
    security.ssl.initial_ssl.missing=SECJ0146I: ${WAS_HOME}/properties/initial_ssl.properties was not found
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7052I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.layers" varFormat="Java">
    security.configrpt.core.layers=SECJ7052I: Layers
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0366E" severity="E" prefix="yes">
  <MsgText pgmKey="security.init.nullprocesstype" varFormat="Java">
    security.init.nullprocesstype=SECJ0366E: Cannot obtain the WebSphere Application Server process type during initialization.
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7212I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.wsSchedule" varFormat="Java">
    security.configrpt.core.wsSchedule=SECJ7212I: Schedules
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7237I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.krb5Keytab" varFormat="Java">
    security.configrpt.core.krb5Keytab=SECJ7237I:  Kerberos keytab file
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ6044E" severity="E" prefix="yes">
  <MsgText pgmKey="security.audit.encryption.data.error" varFormat="Java">
    security.audit.encryption.data.error=SECJ6044E: Data that is not valid was passed into the encryption algorithm.
  </MsgText>
  <Explanation>
    A data stream that is not valid was passed into the encryption algorithm.
  </Explanation>
  <UserResponse>
    Verify that a non-null byte stream of data is being passed in.
  </UserResponse>
</Message>
<Message ID="SECJ0181W" severity="W" prefix="yes">
  <MsgText pgmKey="security.policy.ramodule.path" varFormat="Java">
    security.policy.ramodule.path=SECJ0181W: An exception was caught while trying to get the resource adaptor module {1} absolute filepath. The exception is {0}.
  </MsgText>
  <Explanation>
    Could not get the resource adaptor module&apos;s absolute filepath.
  </Explanation>
  <UserResponse>
    It could be caused by incorrect data in resources.xml file. Enable security trace with com.ibm.ws.security.policy.* to get more detailed information.
  </UserResponse>
</Message>
<Message ID="SECJ0431E" severity="E" prefix="yes">
  <MsgText pgmKey="security.web.authAlreadyEstablished" varFormat="Java">
    security.web.authAlreadyEstablished=SECJ0431E: Authentication had been already established.
  </MsgText>
  <Explanation>
    Authentication had been already established. If you want to login with another user, you need to logout first.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ4059W" severity="W" prefix="yes">
  <MsgText pgmKey="security.j2c.initFailureRecovery" varFormat="Java">
    security.j2c.initFailureRecovery=SECJ4059W: WSDefaultPrincipalMapping Initialization failed.  Fall back to use WSMappingCallbackHandler.
  </MsgText>
  <Explanation>
    WSDefaultPrincipalMapping initialization failed.  The JCA container managed principal/credential mapping most likely will not work properly.
  </Explanation>
  <UserResponse>
    Examine the cause of the exception and correct the problem. The most likely cause for this error is that the WSMappingCallbackHandlerFactory implementation class was not configured properly.
  </UserResponse>
</Message>
<Message ID="SECJ7733E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.noRealm.SECJ7733E" varFormat="Java">
    security.admintask.noRealm.SECJ7733E=SECJ7733E: Realm {0} does not exist.
  </MsgText>
  <Explanation>
    The specified realm does not exist.
  </Explanation>
  <UserResponse>
    Run the command with a realm that exists.
  </UserResponse>
</Message>
<Message ID="SECJ7106I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.Console.User" varFormat="Java">
    security.configrpt.Console.User=SECJ7106I: Administrative User Roles
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0188E" severity="E" prefix="yes">
  <MsgText pgmKey="security.policy.app.ioexception" varFormat="Java">
    security.policy.app.ioexception=SECJ0188E: Caught IOException while creating template for Application Policy {0}. The exception is {1}.
  </MsgText>
  <Explanation>
    IOException occurred when creating the application policy template in the hashmap of all the templates.
  </Explanation>
  <UserResponse>
    Check the specified policy file.
  </UserResponse>
</Message>
<Message ID="SECJ0322W" severity="W" prefix="yes">
  <MsgText pgmKey="security.config.missingAttributeCertFilter" varFormat="Java">
    security.config.missingAttributeCertFilter=SECJ0322W: Missing attribute in Security Configuration.
  </MsgText>
  <Explanation>
    Required attribute CertificateFilter is missing. Certificate Filter is required when CertificateMapMode is CERTIFICATE_FILTER.
  </Explanation>
  <UserResponse>
    Set CertificateFilter in the advanced LDAP settings.
  </UserResponse>
</Message>
<Message ID="SECJ7770E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.missingParameter.userRegistry.SECJ7770E" varFormat="Java">
    security.admintask.missingParameter.userRegistry.SECJ7770E=SECJ7770E: The {0} is missing in the active user registry object.
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7112I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.Naming.Console.Name" varFormat="Java">
    security.configrpt.Naming.Console.Name=SECJ7112I: CORBA Naming Console Name
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0192E" severity="E" prefix="yes">
  <MsgText pgmKey="security.policy.ratemplate.ioexception" varFormat="Java">
    security.policy.ratemplate.ioexception=SECJ0192E: Caught IOException while creating template for resource adaptor(read from WCCM) {1}. The exception is {0}.
  </MsgText>
  <Explanation>
    IOException occurred when creating the resource adaptor template in the hashmap of all the templates.
  </Explanation>
  <UserResponse>
    Check the specified ra.xml file&apos;s permission specification.
  </UserResponse>
</Message>
<Message ID="SECJ0433I" severity="I" prefix="yes">
  <MsgText pgmKey="security.rolebauthz.authzfail.checkTrustedAppsProfileAuthzFailure" varFormat="Java">
    security.rolebauthz.authzfail.checkTrustedAppsProfileAuthzFailure=SECJ0433I: If the authorization failure is not expected, ensure that the profile for the J2EE role in the EJBROLE class has been configured correctly, as well as the BBO.TRUSTEDAPPS profile in the FACILITY class.
  </MsgText>
  <Explanation>
    The role of the J2EE application must be defined as a profile in the EJBROLE class.  Additionally, through the use of the FACILITY class and BBO.TRUSTEDAPPS class profile, trusted application, as a general rule, are needed when you plan to use SAF authorization.
  </Explanation>
  <UserResponse>
    You must ensure the requesting user or group has READ access to the role in the EJBROLE class.  You must enable the trusted applications by ensuring that the WebSphere Application Server has SAF access of READ to the FACILITY class and profile of BBO.TRUSTEDAPP.&lt;cell short name&gt;.&lt;cluster short name&gt;.
  </UserResponse>
</Message>
<Message ID="SECJ0149E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.ldap.mapcredentialNamingEx" varFormat="Java">
    security.registry.ldap.mapcredentialNamingEx=SECJ0149E: Cannot map the credential of the given credential token for certificate subject DN {0} with filter {1} into LDAP because a NamingException occurred when searching LDAP.  The NamingException is {2}
  </MsgText>
  <Explanation>
    A naming exception occurred when searching LDAP.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ0095E" severity="E" prefix="yes">
  <MsgText pgmKey="security.beancache.adminperms.init" varFormat="Java">
    security.beancache.adminperms.init=SECJ0095E: Exception while initializing admin permissions
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ0374E" severity="E" prefix="yes">
  <MsgText pgmKey="security.ltpa.badtype" varFormat="Java">
    security.ltpa.badtype=SECJ0374E: The accessID in the token contains the wrong type. It should be either user or group. The exception is {0}.
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ6232E" severity="E" prefix="yes">
  <MsgText pgmKey="security.zos.saf.idprop.mapping.failed" varFormat="Java">
    security.zos.saf.idprop.mapping.failed=SECJ6232E: The distributed user could not be mapped to a SAF user, most likely because there was no match in the SAF database filters. The distributed user name is: {0}. The distributed realm name is: {1}.
  </MsgText>
  <Explanation>
    The distributed user could not be mapped to a SAF user, most likely because there was no match for the distributed user name and realm name in the RACMAP profiles of the SAF database.
  </Explanation>
  <UserResponse>
    Verify that a RACMAP profile exists in the SAF database for the distributed user name and realm name.
  </UserResponse>
</Message>
<Message ID="SECJ7257I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.supportedAuthMechList" varFormat="Java">
    security.configrpt.core.supportedAuthMechList=SECJ7257I: Supported message layer authentication mechanisms
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7437E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.CannotDeleteEncryptionKeyStore" varFormat="Java">
    security.admintask.CannotDeleteEncryptionKeyStore=SECJ7437E: Empty value specified for keystore.  Cannot delete the encryption keystore when encryption is enabled or being enabled.
  </MsgText>
  <Explanation>
    Encryption is enabled or is being enabled. The encryption keystore is in use and cannot be deleted
  </Explanation>
  <UserResponse>
    Disable encryption before deleting the encryption keystore.
  </UserResponse>
</Message>
<Message ID="SECJ4011E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaas.getORBInstanceReturnsNull" varFormat="Java">
    security.jaas.getORBInstanceReturnsNull=SECJ4011E: com.ibm.ejs.oa.EJSORB.getORBInstance() returns null
  </MsgText>
  <Explanation>
    com.ibm.ejs.oa.EJSORB.getORBInstance() returns null
  </Explanation>
  <UserResponse>
    Make sure that the ORB is initialized correctly in the user application.
  </UserResponse>
</Message>
<Message ID="SECJ6133I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.csi.cert.parse.audit" varFormat="Java">
    security.audit.csi.cert.parse.audit=SECJ6133I: Parsing client certificate failed.
  </MsgText>
  <Explanation>
    Access to the resource is denied because the user or the groups the user is in does not have any of the required security role.
  </Explanation>
  <UserResponse>
    No action required.
  </UserResponse>
</Message>
<Message ID="SECJ7051I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.stateful" varFormat="Java">
    security.configrpt.core.stateful=SECJ7051I: Stateful sessions
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0342E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.getgroups.error" varFormat="Java">
    security.registry.getgroups.error=SECJ0342E: Could not get the groups matching the pattern {0} because of the following exception {1}.
  </MsgText>
  <Explanation>
    Internal Error.
  </Explanation>
  <UserResponse>
    Make sure that the groups matching the pattern exist in the registry. Contact your service representative if the problem persists.
  </UserResponse>
</Message>
<Message ID="SECJ7399E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.PasswordNotConfirmed" varFormat="Java">
    security.admintask.PasswordNotConfirmed=SECJ7399E: Audit encryption key store password does not match verify password.
  </MsgText>
  <Explanation>
    Encryption key store password and the confirm password values do not match.
  </Explanation>
  <UserResponse>
    Confirm the audit encryption key store password
  </UserResponse>
</Message>
<Message ID="SECJ0073E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.entry.findererror.privid" varFormat="Java">
    security.registry.entry.findererror.privid=SECJ0073E: Error finding registry entry for privilege id {0}
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ0359E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.uniqueid.notfound" varFormat="Java">
    security.registry.uniqueid.notfound=SECJ0359E: Could not get the uniqueId for {0} because of the following exception {1}.
  </MsgText>
  <Explanation>
    An exception occurred when getting the uniqueId of a user or group.
  </Explanation>
  <UserResponse>
    Make sure that the user or group is valid in the registry. If the active user registry is a custom registry, make sure a uniqueIds exist for the user or group.
  </UserResponse>
</Message>
<Message ID="SECJ7224I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.sslEnabled" varFormat="Java">
    security.configrpt.core.sslEnabled=SECJ7224I: SSL enabled
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7075I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.trustFileFormat" varFormat="Java">
    security.configrpt.core.trustFileFormat=SECJ7075I: Trust file format
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7267I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.isCredentialForwardable" varFormat="Java">
    security.configrpt.core.isCredentialForwardable=SECJ7267I: Is Credential Forwardable
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ4039E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaas.parser.URL" varFormat="Java">
    security.jaas.parser.URL=SECJ4039E: {0} :ERROR: A file parser exception occurred with file : {1}. The exception is {2}
  </MsgText>
  <Explanation>
    IOException occurred trying to connect the specified URL.
  </Explanation>
  <UserResponse>
    Investigate the exception. Check the specified URL.
  </UserResponse>
</Message>
<Message ID="SECJ0318I" severity="I" prefix="yes">
  <MsgText pgmKey="security.policy.filtered.permission" varFormat="Java">
    security.policy.filtered.permission=SECJ0318I: The permission {0} specified in the application policy file({1}) were filtered out.
  </MsgText>
  <Explanation>
    The permission specified in the application policy was removed because filer.policy has the same entry.
  </Explanation>
  <UserResponse>
    none. This is an informational message.
  </UserResponse>
</Message>
<Message ID="SECJ0294E" severity="E" prefix="yes">
  <MsgText pgmKey="security.sa.set.props" varFormat="Java">
    security.sa.set.props=SECJ0294E: Error setting properties to file ({0}). The exception is {1}.
  </MsgText>
  <Explanation>
    An IOException occurred when setting properties to the specified file.
  </Explanation>
  <UserResponse>
    Verify that the property file exists, that it has read permission and is writable.
  </UserResponse>
</Message>
<Message ID="SECJ0065E" severity="E" prefix="yes">
  <MsgText pgmKey="security.encoding.notsupp" varFormat="Java">
    security.encoding.notsupp=SECJ0065E: Unsupported encoding
  </MsgText>
  <Explanation>
    This is an internal error. An UnsupportedEncodingException occurred when the LTPAServer tried to encode the token value.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ4057I" severity="I" prefix="yes">
  <MsgText pgmKey="security.j2c.calbackHandlerFactoryUndefined" varFormat="Java">
    security.j2c.calbackHandlerFactoryUndefined=SECJ4057I: WSMappingCallbackHandlerFactory implementation class {0} not defined.
  </MsgText>
  <Explanation>
    WSMappingCallbackHandlerFactory implementation class might be defined in security.xml to customize Mapping CallbackHandler.  This is not an error condition.  When the implementation class is not defined, a default WebSphere implementation will be used.
  </Explanation>
  <UserResponse>
    No action is required unless one wants to override the WebSphere default WSMappingCallbackHandlerFactory implementation.
  </UserResponse>
</Message>
<Message ID="SECJ0288E" severity="E" prefix="yes">
  <MsgText pgmKey="security.servcomp.init" varFormat="Java">
    security.servcomp.init=SECJ0288E: Error during security initialization.
  </MsgText>
  <Explanation>
    An unexpected exception occurred when updating the authorization table.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ6210W" severity="W" prefix="yes">
  <MsgText pgmKey="security.zos.threadid.app.denied" varFormat="Java">
    security.zos.threadid.app.denied=SECJ6210W: Application thread identity synchronization has been disabled by the z/OS security product.
  </MsgText>
  <Explanation>
    The server has been configured to perform J2EE and operating system thread identity synchronization for applications that request it but the security product has not authorized the use of this support.
  </Explanation>
  <UserResponse>
    Contact your security product administrator to request authorization to use thread identity synchronization.
  </UserResponse>
</Message>
<Message ID="SECJ7382E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.InvalidMonitorRef" varFormat="Java">
    security.admintask.InvalidMonitorRef=SECJ7382E: Non valid reference for Audit Notification Monitor.
  </MsgText>
  <Explanation>
    Non valid reference for audit notification monitor specified.
  </Explanation>
  <UserResponse>
    Verify that a valid reference has been specified for the audit notification monitor
  </UserResponse>
</Message>
<Message ID="SECJ0150E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.ldap.mapcredentialNotFound" varFormat="Java">
    security.registry.ldap.mapcredentialNotFound=SECJ0150E: Cannot map the credential of the given credential token for certificate subject DN {0} with filter {1} into LDAP because no entry in LDAP matches the DN or filter
  </MsgText>
  <Explanation>
    No entry in LDAP can be found with the subject DN in the certificate or found with the filter.
  </Explanation>
  <UserResponse>
    This might be the expected result depending on the subject DN in the certificate and filter.  If the response is unexpected, review the certificate mapping filter defined in the LDAP advanced properties in the Security Center.
  </UserResponse>
</Message>
<Message ID="SECJ0248I" severity="I" prefix="yes">
  <MsgText pgmKey="security.sas.orbssl.init.exception" varFormat="Java">
    security.sas.orbssl.init.exception=SECJ0248I: Caught unexpected exception in retrieving ORB SSL initialization. The exception is {0}.
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7812E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.naming.invalidAccessIdFormat.SECJ7812E" varFormat="Java">
    security.admintask.naming.invalidAccessIdFormat.SECJ7812E=SECJ7812E: AccessId is not formatted correctly.  It should bin the form: user:&lt;RealmName&gt;/&lt;uniqueId&gt; or group:&lt;RealmName&gt;/&lt;uniqueId&gt;.
  </MsgText>
  <Explanation>
    The AccessId of needs to be in the form of user: or group: followed by the realm name slash uniqueId.
  </Explanation>
  <UserResponse>
    Endure the AccessId is in the correct format.
  </UserResponse>
</Message>
<Message ID="SECJ7126I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.Environment" varFormat="Java">
    security.configrpt.Environment=SECJ7126I: Environment
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0267E" severity="E" prefix="yes">
  <MsgText pgmKey="security.role.config.get" varFormat="Java">
    security.role.config.get=SECJ0267E: Failed to get RoleBasedConfigurator. The exception is {0}.
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ0107W" severity="W" prefix="yes">
  <MsgText pgmKey="security.sasconfig.filenotexist" varFormat="Java">
    security.sasconfig.filenotexist=SECJ0107W: The {0} file does not exist
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If this message is from a warning, then it is a temporary problem which is usually recovered from automatically. If it is not a warning, then check the file permissions for the file to ensure that they are readable.  If the file is missing, restore it.
  </UserResponse>
</Message>
<Message ID="SECJ7099I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.No.Admin.Role.User" varFormat="Java">
    security.configrpt.No.Admin.Role.User=SECJ7099I: No Administrator User
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ4036E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaas.call.convertMapToString" varFormat="Java">
    security.jaas.call.convertMapToString=SECJ4036E: {0} : Error: An exception occurred when trying to reflect on or invoke convertMapToString(). The exception is {1}
  </MsgText>
  <Explanation>
    Exception occurred trying to reflect on or invoke convertMapToString().
  </Explanation>
  <UserResponse>
    Investigate the exception. Check class path.
  </UserResponse>
</Message>
<Message ID="SECJ4051E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaas.priv.exception" varFormat="Java">
    security.jaas.priv.exception=SECJ4051E: PrivilegedActionException is caught while serialized Subject is being restored. The exception is {0}.
  </MsgText>
  <Explanation>
    PrivilegedActionException occurred while restoring the credential. This exception is a wrapper of the exception created in doPrivileged block.
  </Explanation>
  <UserResponse>
    Investigate the real source of the exception. Contact your service representative if the problem persist.
  </UserResponse>
</Message>
<Message ID="SECJ7065I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.authenticationLayerRetryCount" varFormat="Java">
    security.configrpt.core.authenticationLayerRetryCount=SECJ7065I: Authentication Layer Retry Count
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7274I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.external" varFormat="Java">
    security.configrpt.core.external=SECJ7274I: External
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ6017E" severity="E" prefix="yes">
  <MsgText pgmKey="security.audit.service.event.exception.error" varFormat="Java">
    security.audit.service.event.exception.error=SECJ6017E: Unexpected Exception {0}.
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7431E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.CannotConfigSigning" varFormat="Java">
    security.admintask.CannotConfigSigning=SECJ7431E: Cannot configure signing when enable value is false.
  </MsgText>
  <Explanation>
    Signing for audit cannot be configured when the enable value is false.  Either use true for enable or, if the intention is to disable/delete signing, use the appropriate disable/delete tasks.
  </Explanation>
  <UserResponse>
    Specify true as the enable value if the intention is to configure signing for audit.
  </UserResponse>
</Message>
<Message ID="SECJ7822E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.safkeyring.cert.SECJ7822E" varFormat="Java">
    security.admintask.safkeyring.cert.SECJ7822E=SECJ7822E: The certificate with the {0} alias cannot be used because it is not connected to both the servant and control region key rings.
  </MsgText>
  <Explanation>
    To use the certificate, it must be connected to both the servant and control region key rings.
  </Explanation>
  <UserResponse>
    Ensure that the certificate is connected to both the servant and control region key rings.
  </UserResponse>
</Message>
<Message ID="SECJ0112W" severity="W" prefix="yes">
  <MsgText pgmKey="security.core.notauthzt" varFormat="Java">
    security.core.notauthzt=SECJ0112W: Authorization Table Not defined for Application {0}
  </MsgText>
  <Explanation>
    No security constraints or roles have been defined for this application.
  </Explanation>
  <UserResponse>
    If security is not necessary for this application, ignore this message.  Otherwise, review the security requirements of this application.
  </UserResponse>
</Message>
<Message ID="SECJ7310E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.WorkSpaceFailAddUsertoAdminAuthz" varFormat="Java">
    security.admintask.WorkSpaceFailAddUsertoAdminAuthz=SECJ7310E: Workspace exception while adding user to admin-authz.xml
  </MsgText>
  <Explanation>
    An error occuring accessing the Workspace
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0249E" severity="E" prefix="yes">
  <MsgText pgmKey="security.sas.cleanup.repository" varFormat="Java">
    security.sas.cleanup.repository=SECJ0249E: Failed to cleanup. The exception is {0}.
  </MsgText>
  <Explanation>
    An unexpected exception occurred during the cleanup of the specified repository.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7398E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.PasswordMissing" varFormat="Java">
    security.admintask.PasswordMissing=SECJ7398E: Missing password for the audit encryption key store.
  </MsgText>
  <Explanation>
    No password was supplied for the audit encryption key store.
  </Explanation>
  <UserResponse>
    Supply a password for the audit encryption key store
  </UserResponse>
</Message>
<Message ID="SECJ7537I" severity="I" prefix="yes">
  <MsgText pgmKey="security.scanner.risk.ldaplink.ok.unused" varFormat="Java">
    security.scanner.risk.ldaplink.ok.unused=SECJ7537I: User registry being used is not LDAP
  </MsgText>
  <Explanation>
    User registry being used is not LDAP
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7138I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.Ext.authorizationProviders" varFormat="Java">
    security.configrpt.core.Ext.authorizationProviders=SECJ7138I: External authorization providers
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7759E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.naming.invalid.users.groups.remove.SECJ7759E" varFormat="Java">
    security.admintask.naming.invalid.users.groups.remove.SECJ7759E=SECJ7759E: The following users or groups or special subjects {0} cannot be removed from role {1}.
  </MsgText>
  <Explanation>
    The users or groups are not assigned to this role and hence cannot be removed.
  </Explanation>
  <UserResponse>
    Run the command by correcting the user, group or specialSubject list.
  </UserResponse>
</Message>
<Message ID="SECJ7273I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.enableReplayDetection" varFormat="Java">
    security.configrpt.core.enableReplayDetection=SECJ7273I: Enable replay detection
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0400I" severity="I" prefix="yes">
  <MsgText pgmKey="security.jacc.server.task.information" varFormat="Java">
    security.jacc.server.task.information=SECJ0400I: Successfully updated the application {0} with the appContextIDForSecurity information.
  </MsgText>
  <Explanation>
    Information only.
  </Explanation>
  <UserResponse>
    Information only.
  </UserResponse>
</Message>
<Message ID="SECJ6023E" severity="E" prefix="yes">
  <MsgText pgmKey="security.audit.service.context.error" varFormat="Java">
    security.audit.service.context.error=SECJ6023E: Auditing is enabled but could not get a handle to the audit context objects.
  </MsgText>
  <Explanation>
    Could not obtain a handle to the Audit context objects in order to be able to populate with event data.
  </Explanation>
  <UserResponse>
    Examine the exception for the cause of the problem.
  </UserResponse>
</Message>
<Message ID="SECJ6043E" severity="E" prefix="yes">
  <MsgText pgmKey="security.audit.message.digest.error" varFormat="Java">
    security.audit.message.digest.error=SECJ6043E: Message digest data not valid
  </MsgText>
  <Explanation>
    Message digest is null or not valid.
  </Explanation>
  <UserResponse>
    Verify that the message digest is not null or not valid.
  </UserResponse>
</Message>
<Message ID="SECJ0396E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jacc.install.task.error" varFormat="Java">
    security.jacc.install.task.error=SECJ0396E: Error updating information to the JACC provider for application {0}. The exception is {1}.
  </MsgText>
  <Explanation>
    Cannot provide the security policy information to the JACC provider because of the exception. Without this information the authorization decisions, cannot be made correctly when security is enabled.
  </Explanation>
  <UserResponse>
    Make sure that the JACC provider is properly configured and can be accessed. After the problem is fixed, either re-install the application or run the propagatePolicyToJACCProvider tool to propagate the policy information to the JACC provider. For more information about this tool, search for propagatePolicyToJaccProvider in the information center documentation.
  </UserResponse>
</Message>
<Message ID="SECJ7721E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.authMechanismNotValid.SECJ7721E" varFormat="Java">
    security.admintask.authMechanismNotValid.SECJ7721E=SECJ7721E: The authentication mechanism is not valid.
  </MsgText>
  <Explanation>
    The authentication mechanism type is not valid it should be LTPA or KRB5.
  </Explanation>
  <UserResponse>
    Ensure the authentication mechanism type is valid.
  </UserResponse>
</Message>
<Message ID="SECJ7038I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.requiresEJBArgumentsPolicyContextHandler" varFormat="Java">
    security.configrpt.core.requiresEJBArgumentsPolicyContextHandler=SECJ7038I: Requires the EJB arguments policy context handler for access decisions
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0365E" severity="E" prefix="yes">
  <MsgText pgmKey="security.init.nullsecobject" varFormat="Java">
    security.init.nullsecobject=SECJ0365E: Cannot create security object during initialization.
  </MsgText>
  <Explanation>
    The security object cannot be created from the repository. This is an internal error.
  </Explanation>
  <UserResponse>
    The security.xml might be corrupted or missing. Contact your service representative.
  </UserResponse>
</Message>
<Message ID="SECJ0227E" severity="E" prefix="yes">
  <MsgText pgmKey="security.policy.parser.cannotcreateclass" varFormat="Java">
    security.policy.parser.cannotcreateclass=SECJ0227E: An exception occurred when creating class of type {0}. The exception is {1}.
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ0138E" severity="E" prefix="yes">
  <MsgText pgmKey="security.adminApp.installation.failed" varFormat="Java">
    security.adminApp.installation.failed=SECJ0138E: Failed to install the admin Application -
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7008I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.enabled" varFormat="Java">
    security.configrpt.core.enabled=SECJ7008I: Administrative security
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7438E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.CannotDeleteNotification" varFormat="Java">
    security.admintask.CannotDeleteNotification=SECJ7438E: Empty value specified for notification reference. Cannot delete the audit notification when audit notification is enabled or is being enabled.
  </MsgText>
  <Explanation>
    Audit notification is enabled or is being enabled.  The notification reference may be in use and cannot be deleted.
  </Explanation>
  <UserResponse>
    Disable audit notification before deleteing the audit notification reference.
  </UserResponse>
</Message>
<Message ID="SECJ0326E" severity="E" prefix="yes">
  <MsgText pgmKey="security.rolebauthz.nocred2" varFormat="Java">
    security.rolebauthz.nocred2=SECJ0326E: No received or invocation credential exist on the thread. The Role based authorization check will not have an accessId of the caller to check. The parameters are: role name {0}. The stack trace is {1}.
  </MsgText>
  <Explanation>
    No invocation or received credentials were established on this thread.  This might cause the role based authorization check to fail.
  </Explanation>
  <UserResponse>
    The stack trace is obtained by a local throw catch block that might be useful for debugging the problem.
  </UserResponse>
</Message>
<Message ID="SECJ7760E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.naming.invalid.roleName.SECJ7760E" varFormat="Java">
    security.admintask.naming.invalid.roleName.SECJ7760E=SECJ7760E: The role name {0} does not exist.
  </MsgText>
  <Explanation>
    The role name is not a valid role.
  </Explanation>
  <UserResponse>
    Use a valid role.
  </UserResponse>
</Message>
<Message ID="SECJ8050W" severity="W" prefix="yes">
  <MsgText pgmKey="security.saml.invalid.key.format.SECJ8050W" varFormat="Java">
    security.saml.invalid.key.format.SECJ8050W=SECJ8050W:  The {0} key format has the wrong format for SAML TAI custom property key. The key format should be sso_&lt;ID&gt;.idp_&lt;ID&gt;.* or sso_&lt;ID&gt;.sp.* .
  </MsgText>
  <Explanation>
    The SAML TAI custom property key format is invalid.
  </Explanation>
  <UserResponse>
    Verify the SAML TAI custom property key format.
  </UserResponse>
</Message>
<Message ID="SECJ7444I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.report.Record.name" varFormat="Java">
    security.audit.report.Record.name=SECJ7444I: Record Number
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7333E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.AdminNotFoundInReg" varFormat="Java">
    security.admintask.AdminNotFoundInReg=SECJ7333E: Could not find admin name in the specified user registry
  </MsgText>
  <Explanation>
    Admin name does not exist in the specified user registry
  </Explanation>
  <UserResponse>
    Ensure that the admin name exists in the user registry prior to executing command
  </UserResponse>
</Message>
<Message ID="SECJ6040E" severity="E" prefix="yes">
  <MsgText pgmKey="security.audit.build.event.object.error" varFormat="Java">
    security.audit.build.event.object.error=SECJ6040E: Unexpected exception while creating the audit record object. Exception = {0}.
  </MsgText>
  <Explanation>
    An error occurred while building the auditable record data.
  </Explanation>
  <UserResponse>
    Examine the exception for the cause of the problem.
  </UserResponse>
</Message>
<Message ID="SECJ0298E" severity="E" prefix="yes">
  <MsgText pgmKey="security.sa.chk.password.unknown" varFormat="Java">
    security.sa.chk.password.unknown=SECJ0298E: Error checking password for user :{0}. The exception is {1}.
  </MsgText>
  <Explanation>
    Unknown exception occurred when checking the password for specified user.
  </Explanation>
  <UserResponse>
    Verify that the password for the specified user.
  </UserResponse>
</Message>
<Message ID="SECJ4025E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaas.SystemInputError" varFormat="Java">
    security.jaas.SystemInputError=SECJ4025E: unable to get system input stream {0}
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7018I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.password" varFormat="Java">
    security.configrpt.core.password=SECJ7018I: Password
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7441E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.InvalidScopeName" varFormat="Java">
    security.admintask.InvalidScopeName=SECJ7441E: Empty or non valid value specified for scope name.
  </MsgText>
  <Explanation>
    Non valid value was specified for the scope name.  An empty value is not valid.
  </Explanation>
  <UserResponse>
    Specify a valid value for the scope name
  </UserResponse>
</Message>
<Message ID="SECJ7386E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.NotificationConfigured" varFormat="Java">
    security.admintask.NotificationConfigured=SECJ7386E: Audit notification already configured.
  </MsgText>
  <Explanation>
    Audit notification already exists.
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0105E" severity="E" prefix="yes">
  <MsgText pgmKey="security.sas.decode.error" varFormat="Java">
    security.sas.decode.error=SECJ0105E: An unexpected exception occurred when decoding the value [{0}] for password [{1}] in the security configured URL
  </MsgText>
  <Explanation>
    The encoded password cannot be decoded because it is missing or malformed.
  </Explanation>
  <UserResponse>
    Verify that the passwords in the security configuration URL are not corrupted or missing. Reset the affected password through the WebSphere Admin console if possible.  If all else fails, reset the password to its plain text value in the security configuration URL (which is usually sas.server.props).
  </UserResponse>
</Message>
<Message ID="SECJ7462E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.KeyStoreException" varFormat="Java">
    security.admintask.KeyStoreException=SECJ7462E: Exception was raised while trying to get an instance of the keystore with the specified keystore type and provider type.
  </MsgText>
  <Explanation>
    An instance of the keystore could not be obtained.
  </Explanation>
  <UserResponse>
    Verify that the encryption keystore does exist.
  </UserResponse>
</Message>
<Message ID="SECJ7045I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.authenticationStrategy" varFormat="Java">
    security.configrpt.core.authenticationStrategy=SECJ7045I: Authentication strategy
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ6149I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.mapping.success.audit" varFormat="Java">
    security.audit.mapping.success.audit=SECJ6149I: Principal/Credential mapping succeeded.
  </MsgText>
  <Explanation>
    The J2EE Connection principal/credential mapping was successful.
  </Explanation>
  <UserResponse>
    No action is required.
  </UserResponse>
</Message>
<Message ID="SECJ0391E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jacc.init.error" varFormat="Java">
    security.jacc.init.error=SECJ0391E: Error when setting the Policy object to the provider&apos;&apos;s policy implementation {0}. The exception is {1}.
  </MsgText>
  <Explanation>
    The provider&apos;s policy implementation cannot be loaded because of the exception.
  </Explanation>
  <UserResponse>
    Make sure that the JACC provider properties are set correctly and the provider classes are in the class path. If problem persists, contact your service representative.
  </UserResponse>
</Message>
<Message ID="SECJ4002E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaas.nullCreds" varFormat="Java">
    security.jaas.nullCreds=SECJ4002E: No CORBA Credentials for {0}/{1}
  </MsgText>
  <Explanation>
    Authentication failure occurred while invoking login() of realm/user since there is no CORBA credential.
  </Explanation>
  <UserResponse>
    Confirm if the user information(realm name, user name password) is valid.
  </UserResponse>
</Message>
<Message ID="SECJ0412E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jacc.initialize.error" varFormat="Java">
    security.jacc.initialize.error=SECJ0412E: An Error occured when initializing the initialization class {0} of the JACC provider. The exception or the error code is {1}.
  </MsgText>
  <Explanation>
    The initialization implementation of the provider failed with an exception or a non-zero error code.
  </Explanation>
  <UserResponse>
    Verify that the JACC provider properties are correctly set and that the initialization classes are in the class path. Check the provider implementation for problems. An error code of zero (0) indicates success.
  </UserResponse>
</Message>
<Message ID="SECJ7053I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.supportedQOP" varFormat="Java">
    security.configrpt.core.supportedQOP=SECJ7053I: Supported ciphers
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0315W" severity="W" prefix="yes">
  <MsgText pgmKey="security.policy.invalid.permission" varFormat="Java">
    security.policy.invalid.permission=SECJ0315W: The permission {0} specified in the application policy file:{1} does not exist.
  </MsgText>
  <Explanation>
    The permission class specified in the application policy file(was.policy or app.policy) does not exist.
  </Explanation>
  <UserResponse>
    Fix the specified application policy file.
  </UserResponse>
</Message>
<Message ID="SECJ7134I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.ejbAuth" varFormat="Java">
    security.configrpt.core.ejbAuth=SECJ7134I: RMI/IIOP security
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7111I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.Configurator.Role.Group" varFormat="Java">
    security.configrpt.Configurator.Role.Group=SECJ7111I: Configurator Group
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ6019I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.service.mapping.default.audit" varFormat="Java">
    security.audit.service.mapping.default.audit=SECJ6019I: AuditEventType = {0}, AuditOutcome = {1}, AuditOutcomeReason = {2}, unique Event ID = {3}, Cell Name = {4}, Node Name = {5}, Server Name = {6}, Component Name = {7}, App Name = {8}, Provider Name = {9}, Provider Successful = {10}, Original Realm = {11}, Original User Name = {12}, Mapped Realm = {13}, Mapped User Name = {14}, Exception = {15}.
  </MsgText>
  <Explanation>
    This message is intended to be used by the defaultAuditEventFactoryImpl sendMappingAuditEvent method only.
  </Explanation>
  <UserResponse>
    No action required.
  </UserResponse>
</Message>
<Message ID="SECJ0349E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.userdisplayname.error" varFormat="Java">
    security.registry.userdisplayname.error=SECJ0349E: Could not get the display name of the user {0} because of the following exception {1}.
  </MsgText>
  <Explanation>
    Internal Error.
  </Explanation>
  <UserResponse>
    Make sure that the user is valid and has a display name. Contact your service representative if the problem persists.
  </UserResponse>
</Message>
<Message ID="SECJ0392E" severity="E" prefix="yes">
  <MsgText pgmKey="security.web.authz.checkdataconstraint.failed" varFormat="Java">
    security.web.authz.checkdataconstraint.failed=SECJ0392E: Error when checking the dataconstraint requirement for the contextID {0}. The exception is {1}.
  </MsgText>
  <Explanation>
    Could not determine the dataconstraint requirements for this resource. The request will be denied.
  </Explanation>
  <UserResponse>
    Make sure that the dataconstraint requirements are correctly configured in the deployment descriptor.
  </UserResponse>
</Message>
<Message ID="SECJ6026E" severity="E" prefix="yes">
  <MsgText pgmKey="security.audit.keystore.open.error" varFormat="Java">
    security.audit.keystore.open.error=SECJ6026E: Exception while opening up audit keystore file.  Exception = {0}.
  </MsgText>
  <Explanation>
    Could not open the audit keystore.
  </Explanation>
  <UserResponse>
    Examine the exception for the cause of the problem.  Ensure that the audit keystore exists.
  </UserResponse>
</Message>
<Message ID="SECJ7332E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.FailedAutogenServerId" varFormat="Java">
    security.admintask.FailedAutogenServerId=SECJ7332E: Failed to auto-generate the Server Id
  </MsgText>
  <Explanation>
    Could not auto-generate a Server Id
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0010E" severity="E" prefix="yes">
  <MsgText pgmKey="security.invalid.creds" varFormat="Java">
    security.invalid.creds=SECJ0010E: Invalid credential
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ8058E" severity="E" prefix="yes">
  <MsgText pgmKey="security.saml.invalid.id.map.SECJ8058E" varFormat="Java">
    security.saml.invalid.id.map.SECJ8058E=SECJ8058E: Invalid SAML idMap value {0}. The valid value are idAssertion, localRealm, or localRealmThenIdAssertion.
  </MsgText>
  <Explanation>
    The value of idMap is invalid.
  </Explanation>
  <UserResponse>
    Specify a valid idMap value.
  </UserResponse>
</Message>
<Message ID="SECJ0119E" severity="E" prefix="yes">
  <MsgText pgmKey="security.web.form.noWebAppInfo" varFormat="Java">
    security.web.form.noWebAppInfo=SECJ0119E: Error getting the web app information for form login. The exception is {0}.
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7460E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.OutputLocationNotHTML" varFormat="Java">
    security.admintask.OutputLocationNotHTML=SECJ7460E: The output file location specified is not an HTML file.  The output log for the read audit records must be in HTML format.
  </MsgText>
  <Explanation>
    The output file specified was not in HTML format.
  </Explanation>
  <UserResponse>
    Specify an HTML file as the output file location.
  </UserResponse>
</Message>
<Message ID="SECJ0377E" severity="E" prefix="yes">
  <MsgText pgmKey="security.ltpa.exportkeys" varFormat="Java">
    security.ltpa.exportkeys=SECJ0377E: Error exporting LTPA keys. The exception is {0}.
  </MsgText>
  <Explanation>
    Cannot export LTPA keys.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7719E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.scope.not.in.domain.SECJ7719E" varFormat="Java">
    security.admintask.scope.not.in.domain.SECJ7719E=SECJ7719E: {0} is not mapped to the {1} security configuration.
  </MsgText>
  <Explanation>
    The scope is not mapped to the security configuration.
  </Explanation>
  <UserResponse>
    Rerun the command using a scope that is mapped to the security configuration.
  </UserResponse>
</Message>
<Message ID="SECJ6110I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.sso.validate.audit" varFormat="Java">
    security.audit.sso.validate.audit=SECJ6110I: SSO token {0} was validated successfully.
  </MsgText>
  <Explanation>
    Authentication was successful.
  </Explanation>
  <UserResponse>
    No action is required.
  </UserResponse>
</Message>
<Message ID="SECJ7730E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.noTrustAssociation.SECJ7730E" varFormat="Java">
    security.admintask.noTrustAssociation.SECJ7730E=SECJ7730E: No trust association was found.
  </MsgText>
  <Explanation>
    An LTPA auth mechanism must contain a trust association.
  </Explanation>
  <UserResponse>
    Ensure that an LTPA auth mechanism contains a trust association.
  </UserResponse>
</Message>
<Message ID="SECJ0345E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.getusrsforgrp.error" varFormat="Java">
    security.registry.getusrsforgrp.error=SECJ0345E: Could not get the users in the group {0} because of the following exception {1}.
  </MsgText>
  <Explanation>
    Internal Error.
  </Explanation>
  <UserResponse>
    Make sure that the group is valid. Contact your service representative if the problem persists.
  </UserResponse>
</Message>
<Message ID="SECJ0259E" severity="E" prefix="yes">
  <MsgText pgmKey="security.swam.callback.ex" varFormat="Java">
    security.swam.callback.ex=SECJ0259E: IOException from CallbackHandler. The exception is {0}
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ0406E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jacc.tools.earfile.error" varFormat="Java">
    security.jacc.tools.earfile.error=SECJ0406E: Cannot obtain the earFile for application {0}.
  </MsgText>
  <Explanation>
    The earFile is required to get the security policy information for the application. The configuration repository might be corrupted.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ8060W" severity="W" prefix="yes">
  <MsgText pgmKey="security.saml.idp.signing.cert.notexistent.SECJ8060W" varFormat="Java">
    security.saml.idp.signing.cert.notexistent.SECJ8060W=SECJ8060W: There is no signing certificate in the IdP metadata file {0}.
  </MsgText>
  <Explanation>
    The signing certificate is missing from the IdP metadata file.
  </Explanation>
  <UserResponse>
    Verify the IdP metadata file.
  </UserResponse>
</Message>
<Message ID="SECJ0405E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jacc.tools.object.error" varFormat="Java">
    security.jacc.tools.object.error=SECJ0405E: The {0} object cannot be obtained because of the following error {1}.
  </MsgText>
  <Explanation>
    Could not get the object required for security policy propagation.
  </Explanation>
  <UserResponse>
    Make sure that the JACC provider properties are set correctly in the JACC configuration. Also make sure that all the provider classes are in the class path of all the servers.
  </UserResponse>
</Message>
<Message ID="SECJ7828W" severity="W" prefix="yes">
  <MsgText pgmKey="security.admintask.globalfedoption.globalfedchange.SECJ7828W" varFormat="Java">
    security.admintask.globalfedoption.globalfedchange.SECJ7828W=SECJ7828W: Altering the existing federated repository configured at the global security domain may affect any application security domains configured to use the global federated repository option.
  </MsgText>
  <Explanation>
    Changing the federated repository configuration at the global security domain may affect any application security domain configured with the global federated repository option.
  </Explanation>
  <UserResponse>
    Ensure that changing the existing federated repository configuration at the global security domain does not affect an application security domain configured to use the global federated repository option.
  </UserResponse>
</Message>
<Message ID="SECJ7734E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.modeNotValid.SECJ7734E" varFormat="Java">
    security.admintask.modeNotValid.SECJ7734E=SECJ7734E: Certificate mode type is not valid.
  </MsgText>
  <Explanation>
    Valid certificate mode types are: EXACT_DN or CERTIFICATE_FILTER.
  </Explanation>
  <UserResponse>
    Ensure that the certificate mode type is a valid type.
  </UserResponse>
</Message>
<Message ID="SECJ0403E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jacc.tools.pcf.null" varFormat="Java">
    security.jacc.tools.pcf.null=SECJ0403E: The PolicyConfiguration object for the contextID {0} is null.
  </MsgText>
  <Explanation>
    Could not get the JACC provider PolicyConfiguration object. This object is required to propagate the security constraints information to the provider.
  </Explanation>
  <UserResponse>
    Make sure that the JACC provider property javax.security.jacc.PolicyConfigurationFactory.provider is set correctly to the PolicyConfigurationFactory implementation class. The preferred way to set this property is to use the JACC configuration properties panel or wsadmin tool. Also make sure that the provider classes are in the class path of all the servers.
  </UserResponse>
</Message>
<Message ID="SECJ7098I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.Admin.Role.User" varFormat="Java">
    security.configrpt.Admin.Role.User=SECJ7098I: Administrator User
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7405E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.NoCertKeyFileNameValue" varFormat="Java">
    security.admintask.NoCertKeyFileNameValue=SECJ7405E: No value was specified for the key file name for the certificate to import
  </MsgText>
  <Explanation>
    When selecting to import an existing certificate, a key file name for the certificate must be entered.
  </Explanation>
  <UserResponse>
    Supply a key file name for the certificate to import
  </UserResponse>
</Message>
<Message ID="SECJ0308I" severity="I" prefix="yes">
  <MsgText pgmKey="security.manager.install" varFormat="Java">
    security.manager.install=SECJ0308I: Java2 security is installed.
  </MsgText>
  <Explanation>
    JAVA2 security is enabled.
  </Explanation>
  <UserResponse>
    None, informational only.
  </UserResponse>
</Message>
<Message ID="SECJ7732E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.noAuthDataEntry.SECJ7732E" varFormat="Java">
    security.admintask.noAuthDataEntry.SECJ7732E=SECJ7732E: The specified auth data entry does not exist.
  </MsgText>
  <Explanation>
    The specified auth data entry does not exist.
  </Explanation>
  <UserResponse>
    Either create the auth data entry, or specify a different auth data entry which does exist.
  </UserResponse>
</Message>
<Message ID="SECJ7268I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.limit" varFormat="Java">
    security.configrpt.core.limit=SECJ7268I: Limit
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ6213I" severity="I" prefix="yes">
  <MsgText pgmKey="security.zos.threadid.skip.surrogate.enabled" varFormat="Java">
    security.zos.threadid.skip.surrogate.enabled=SECJ6213I: Thread identity synchronization will not subject to SURROGAT authorization.
  </MsgText>
  <Explanation>
    WebSphere will not perform SURROGAT class authorization checks prior to creating native security environments.
  </Explanation>
  <UserResponse>
    No user action is required.
  </UserResponse>
</Message>
<Message ID="SECJ0204I" severity="I" prefix="yes">
  <MsgText pgmKey="security.init.roleauthz" varFormat="Java">
    security.init.roleauthz=SECJ0204I: Rolebased authorizer initialized successfully
  </MsgText>
  <Explanation>
    The Rolebased authorizer initialized successfully
  </Explanation>
  <UserResponse>
    None. Informational only.
  </UserResponse>
</Message>
<Message ID="SECJ7745E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.noCertAlias.SECJ7745E" varFormat="Java">
    security.admintask.noCertAlias.SECJ7745E=SECJ7745E: A certificate alias must be provided when a key store is provided.
  </MsgText>
  <Explanation>
    When a key store object is provided a certificate alias must be provided.
  </Explanation>
  <UserResponse>
    Run the command providing a certificate alias.
  </UserResponse>
</Message>
<Message ID="SECJ7338E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.ExceptionSetGlobalSec" varFormat="Java">
    security.admintask.ExceptionSetGlobalSec=SECJ7338E: Exception raised while setting Global Security setting
  </MsgText>
  <Explanation>
    Caught exception while setting Global Security setting
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7036I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.name" varFormat="Java">
    security.configrpt.core.name=SECJ7036I: Name
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7198I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.maxKeyReferences" varFormat="Java">
    security.configrpt.core.maxKeyReferences=SECJ7198I: Maximum key references
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7178I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.trustManagerClass" varFormat="Java">
    security.configrpt.core.trustManagerClass=SECJ7178I: Class name
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7031I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.Auth.Config" varFormat="Java">
    security.configrpt.core.Auth.Config=SECJ7031I: Authorization configuration
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ4058E" severity="E" prefix="yes">
  <MsgText pgmKey="security.j2c.initFailure" varFormat="Java">
    security.j2c.initFailure=SECJ4058E: WSDefaultPrincipalMapping Initialization failed.  The exception is {0}.
  </MsgText>
  <Explanation>
    WSDefaultPrincipalMapping initialization failed.  The JCA container managed principal/credential mapping most likely will not work properly.
  </Explanation>
  <UserResponse>
    Examine the cause of the exception and correct the problem. The most likely cause for this error is that the WSMappingCallbackHandlerFactory implementation class was not configured properly.
  </UserResponse>
</Message>
<Message ID="SECJ7271I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.isStateful" varFormat="Java">
    security.configrpt.core.isStateful=SECJ7271I: Stateful sessions
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ5002W" severity="W" prefix="yes">
  <MsgText pgmKey="security.sap.warning.serializing.custom.objects.from.subject" varFormat="Java">
    security.sap.warning.serializing.custom.objects.from.subject=SECJ5002W: An error occurred while serializing the custom object {0} from the current Subject.  This does not cause the request to fail but this custom object will not get propagated.
  </MsgText>
  <Explanation>
    The object mentioned above probably does not implement the java.io.Serializable interface.
  </Explanation>
  <UserResponse>
    Ensure that the object implements the java.io.Serializable interface to ensure it gets propagated downstream.
  </UserResponse>
</Message>
<Message ID="SECJ7196I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.isKeyPair" varFormat="Java">
    security.configrpt.core.isKeyPair=SECJ7196I: Specifies a key pair instead of a key
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7807W" severity="W" prefix="yes">
  <MsgText pgmKey="security.multidomain.runtime.SECJ7807W" varFormat="Java">
    security.multidomain.runtime.SECJ7807W=SECJ7807W: The cell resource {0} is specified in the domain-security-map.xml file during addNode. This resource is converted to the server resource {1}.
  </MsgText>
  <Explanation>
    If a federated node contains a domain associated with the cell scope, it will be changed to the server scope for that node during the addNode operation so that current cell configuration is not impacted.
  </Explanation>
  <UserResponse>
    If the cell scope needs to be configured in the domain-security-map.xml file, you need to associate the cell resource after the node has been federated.
  </UserResponse>
</Message>
<Message ID="SECJ8055E" severity="E" prefix="yes">
  <MsgText pgmKey="security.saml.file.missing.SECJ8055E" varFormat="Java">
    security.saml.file.missing.SECJ8055E=SECJ8055E: You must specify a fully qualified path for the {0} file.
  </MsgText>
  <Explanation>
    The given parameter file name is not a fully qualified pathname or null.
  </Explanation>
  <UserResponse>
    Specify a fully qualified pathname for the file in the given parameter.
  </UserResponse>
</Message>
<Message ID="SECJ7258I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.DomainSecurity" varFormat="Java">
    security.configrpt.core.DomainSecurity=SECJ7258I: Security domains
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7093I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.Security.systemLogin" varFormat="Java">
    security.configrpt.core.Security.systemLogin=SECJ7093I: System logins
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7433E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.ClassNotDefaultEmitter" varFormat="Java">
    security.admintask.ClassNotDefaultEmitter=SECJ7433E: Cannot change the default audit service provider implementation classname.
  </MsgText>
  <Explanation>
    The classname specified does not match the default audit service provider implementation classname.
  </Explanation>
  <UserResponse>
    Ensure that when specifying class name on the modify command and the implementation is the default audit service provider implementation, that it matches the default classname.
  </UserResponse>
</Message>
<Message ID="SECJ7522I" severity="I" prefix="yes">
  <MsgText pgmKey="security.scanner.risk.admin.role.ok" varFormat="Java">
    security.scanner.risk.admin.role.ok=SECJ7522I: Multiple Administrative User Roles are configured. A number of administrative roles are defined to provide degrees of authority that are needed to perform certain administrative functions from either the Web-based administrative console or the system management scripting interface. The authorization policy is only enforced when administrative security is enabled.
  </MsgText>
  <Explanation>
    Multiple Administrative User Roles are configured. A number of administrative roles are defined to provide degrees of authority that are needed to perform certain administrative functions from either the Web-based administrative console or the system management scripting interface. The authorization policy is only enforced when administrative security is enabled.
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7145I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.trustManager" varFormat="Java">
    security.configrpt.core.trustManager=SECJ7145I: Trust managers
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ4064E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaas.IdentityAssertion.state" varFormat="Java">
    security.jaas.IdentityAssertion.state=SECJ4064E: Trust state information missing in shared state, unable to perform identity assertion.
  </MsgText>
  <Explanation>
    A Custom Login module must be provided and configured prior to this login module in the JAAS Login Configuration and should have provided trust information in shared state.
  </Explanation>
  <UserResponse>
    Check a Custom Login Module is provided and configured prior to this login module in the JAAS Login Configuration and make sure that the shared state information is set correctly based on the requirement.
  </UserResponse>
</Message>
<Message ID="SECJ6119I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.cert.mapping.audit" varFormat="Java">
    security.audit.cert.mapping.audit=SECJ6119I: Authentication failed becasue the client certicate user name cannot be mapped to WebSphere Application Server user.
  </MsgText>
  <Explanation>
    The authentication failed because the client certificate user name cannot be mapped to a valid WebSphere Application Server user.
  </Explanation>
  <UserResponse>
    The user might not be defined in the registry.  Otherwise, verify the registry and mapping configuration.
  </UserResponse>
</Message>
<Message ID="SECJ6020I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.service.provider.default.audit" varFormat="Java">
    security.audit.service.provider.default.audit=SECJ6020I: AuditEvent = {0} AuditEventFactory Name = {1}.
  </MsgText>
  <Explanation>
    This message is intended to be used by the defaultAuditServiceProviderImpl sendEvent method only.
  </Explanation>
  <UserResponse>
    No action required.
  </UserResponse>
</Message>
<Message ID="SECJ7423E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.NoKeyStore" varFormat="Java">
    security.admintask.NoKeyStore=SECJ7423E: No keystore found matching the supplied unique name or reference id.
  </MsgText>
  <Explanation>
    Cannot find a keystore with the supplied unique name or reference id.
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7114I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.Naming.Role.Value" varFormat="Java">
    security.configrpt.Naming.Role.Value=SECJ7114I: CORBA Naming Role Value
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7527W" severity="W" prefix="yes">
  <MsgText pgmKey="security.scanner.risk.app.security.improve" varFormat="Java">
    security.scanner.risk.app.security.improve=SECJ7527W: Application security is disabled. Application security enables security for the applications in your environment. This type of security provides application isolation and requirements for authenticating application users.
  </MsgText>
  <Explanation>
    Application security is disabled. Application security enables security for the applications in your environment. This type of security provides application isolation and requirements for authenticating application users.
  </Explanation>
  <UserResponse>
    Enable application security if applicable.
  </UserResponse>
</Message>
<Message ID="SECJ0335E" severity="E" prefix="yes">
  <MsgText pgmKey="security.authn.failed.user" varFormat="Java">
    security.authn.failed.user=SECJ0335E: Authentication failed for user {0}.
  </MsgText>
  <Explanation>
    The registry failed to return a user after authentication.
  </Explanation>
  <UserResponse>
    This would happen if the authentication was not successful and the custom registry did not throw exceptions to indicate this. Make sure you are entering a current userID and password for authentication. This problem might have preceeded by other problems. Looking at those problems might narrow the problem down.
  </UserResponse>
</Message>
<Message ID="SECJ6039E" severity="E" prefix="yes">
  <MsgText pgmKey="security.audit.emitter.config.error" varFormat="Java">
    security.audit.emitter.config.error=SECJ6039E: Configuration error: no audit service providers are defined.
  </MsgText>
  <Explanation>
    No Audit Service Providerimplementations are found in the configuration.
  </Explanation>
  <UserResponse>
    Ensure that there is at least one audit service provider configured.
  </UserResponse>
</Message>
<Message ID="SECJ7184I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.nlsRangeKey" varFormat="Java">
    security.configrpt.core.nlsRangeKey=SECJ7184I: NLS Range Key
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7806E" severity="E" prefix="yes">
  <MsgText pgmKey="security.multidomain.runtime.SECJ7806E" varFormat="Java">
    security.multidomain.runtime.SECJ7806E=SECJ7806E: The LTPA token validation fails because the current realm {0} does not match or trust the realm in the token {1}.
  </MsgText>
  <Explanation>
    LTPA validation checks to make sure that the current realm matches the realm in the token for validation to work.
  </Explanation>
  <UserResponse>
    For successful validation make sure that the realm in the token is configured in the trusted inbound realms list for the current realm.
  </UserResponse>
</Message>
<Message ID="SECJ0238E" severity="E" prefix="yes">
  <MsgText pgmKey="security.secsrv.ltpaconfigerr" varFormat="Java">
    security.secsrv.ltpaconfigerr=SECJ0238E: An unexpected exception occurred when trying to create the initial LTPAServerObject. The exception is {0}.
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7085I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.required" varFormat="Java">
    security.configrpt.core.required=SECJ7085I: Required
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7006I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.cacheTimeout" varFormat="Java">
    security.configrpt.core.cacheTimeout=SECJ7006I: Authentication cache timeout
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7776E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.oldResourceCluster.SECJ7776E" varFormat="Java">
    security.admintask.oldResourceCluster.SECJ7776E=SECJ7776E: The cluster has one or more members that is not version 7.0 or greater. One of the members is {0} in node {1} that is not version 7.0 or greater.
  </MsgText>
  <Explanation>
    The server must be running a 7.0 or greater version to be mapped to a domain.
  </Explanation>
  <UserResponse>
    Ensure that servers are at the correct level.
  </UserResponse>
</Message>
<Message ID="SECJ7528I" severity="I" prefix="yes">
  <MsgText pgmKey="security.scanner.risk.corba.ok" varFormat="Java">
    security.scanner.risk.corba.ok=SECJ7528I: CORBA Naming roles are configured
  </MsgText>
  <Explanation>
    CORBA Naming roles are configured
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0200E" severity="E" prefix="yes">
  <MsgText pgmKey="security.policy.ratemplate.parser" varFormat="Java">
    security.policy.ratemplate.parser=SECJ0200E: Caught a ParserException while adding the grant entry {1} to the policy template of the resource adaptor {0}. The exception is {2}.
  </MsgText>
  <Explanation>
    A ParserException occurred while adding the grant entry to the policy template of the resource adaptor.
  </Explanation>
  <UserResponse>
    Check the syntax of permission specification in the specified ra.xml
  </UserResponse>
</Message>
<Message ID="SECJ7805I" severity="I" prefix="yes">
  <MsgText pgmKey="security.multidomain.runtime.SECJ7805I" varFormat="Java">
    security.multidomain.runtime.SECJ7805I=SECJ7805I: The resource is not being accessed using secure HTTPS protocol.
  </MsgText>
  <Explanation>
    This message is for informational purposes only. It indicates that the security HTTPS protocol is not used when accessing the resource.
  </Explanation>
  <UserResponse>
    If the resource is implemented to be accessed using the non-secure HTTP protocol, no action is required. If this resource should only be accessed using HTTPS change the deployment descriptor to add appropriate data-constraints.
  </UserResponse>
</Message>
<Message ID="SECJ7724E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.verifyUserRegistry.SECJ7724E" varFormat="Java">
    security.admintask.verifyUserRegistry.SECJ7724E=SECJ7724E: Error in the user registry configuration unable to verify access to the user registry.
  </MsgText>
  <Explanation>
    An error occurred trying to access the user registry.  Unable to verify the registry is configured properly.
  </Explanation>
  <UserResponse>
    Ensure the user registry is configured correctly.
  </UserResponse>
</Message>
<Message ID="SECJ7132I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.Certificate.Expiry" varFormat="Java">
    security.configrpt.Certificate.Expiry=SECJ7132I: Certificate Expiry
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0331E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.initerr" varFormat="Java">
    security.registry.initerr=SECJ0331E: The registry implementation file {0} cannot be initialized because of the following exception {1}
  </MsgText>
  <Explanation>
    The specified custom registry implementation cannot be initialized.
  </Explanation>
  <UserResponse>
    Make sure all of the properties required for the custom registry initialization are passed through the GUI or scripting (whichever is being used). If this happens for WebSphere Application Server provided registries, contact your service representative if the problem persists.
  </UserResponse>
</Message>
<Message ID="SECJ0040E" severity="E" prefix="yes">
  <MsgText pgmKey="security.ErrorCreatingLTPAKeys" varFormat="Java">
    security.ErrorCreatingLTPAKeys=SECJ0040E: Error occurred while generating new LTPA keys.  The exception is {0}.
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ0311W" severity="W" prefix="yes">
  <MsgText pgmKey="security.policy.module.path" varFormat="Java">
    security.policy.module.path=SECJ0311W: An exception was caught while trying to get the module {1} absolute filepath. The exception is {0}.
  </MsgText>
  <Explanation>
    Could not get the module&apos;s absolute filepath.
  </Explanation>
  <UserResponse>
    Check the filepath given to load the module.
  </UserResponse>
</Message>
<Message ID="SECJ7735E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.loginDoesNotExist.SECJ7735E" varFormat="Java">
    security.admintask.loginDoesNotExist.SECJ7735E=SECJ7735E: The login object does not exist.
  </MsgText>
  <Explanation>
    The login object does not exist in the configuration.
  </Explanation>
  <UserResponse>
    Ensure that the login object exists.
  </UserResponse>
</Message>
<Message ID="SECJ7135I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.AuthMechanism" varFormat="Java">
    security.configrpt.core.AuthMechanism=SECJ7135I: Authentication mechanisms and expiration
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7741E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.SPNEGOFilterInvalid" varFormat="Java">
    security.admintask.SPNEGOFilterInvalid=SECJ7741E: Filter is malformed, verify syntax of the specified filter rules.
  </MsgText>
  <Explanation>
    The specified filter rules are not valid.
  </Explanation>
  <UserResponse>
    Verify the filter rules conform to the syntax supported by the default HTTPHeaderFilter class.
  </UserResponse>
</Message>
<Message ID="SECJ7195I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.deleteOldKeys" varFormat="Java">
    security.configrpt.core.deleteOldKeys=SECJ7195I: Delete key references that are beyond the maximum number of keys
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7458E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.InvalidTimeStamp" varFormat="Java">
    security.admintask.InvalidTimeStamp=SECJ7458E: Non valid timestamp specified.  Timestamp must be in &quot;MMddhhmmyyyy&quot; format.
  </MsgText>
  <Explanation>
    A non valid value was specified for timestamp of audit records to report
  </Explanation>
  <UserResponse>
    Specify a non-empty or valid value for the timestamp.
  </UserResponse>
</Message>
<Message ID="SECJ6117I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.form.login.failed.audit" varFormat="Java">
    security.audit.form.login.failed.audit=SECJ6117I: Authentication failed due to missing or incorrect user name and/or password.  Redirect to {0}.
  </MsgText>
  <Explanation>
    Form based Authentication failed due to missing or incorrect user id or password.  Typically a web user will be redirect to a login page to retry.
  </Explanation>
  <UserResponse>
    No action is required.
  </UserResponse>
</Message>
<Message ID="SECJ7804I" severity="I" prefix="yes">
  <MsgText pgmKey="security.multidomain.runtime.SECJ7804I" varFormat="Java">
    security.multidomain.runtime.SECJ7804I=SECJ7804I: The following security configuration {0} is configured at the security domain {1}.
  </MsgText>
  <Explanation>
    This message is for informational purposes only. It will list some of the security properties that are configured at the security domain level.
  </Explanation>
  <UserResponse>
    No action is required.
  </UserResponse>
</Message>
<Message ID="SECJ7245I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.tokenExpiration" varFormat="Java">
    security.configrpt.core.tokenExpiration=SECJ7245I: Token timeout
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7179I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.additionalTrustManagerAttrs" varFormat="Java">
    security.configrpt.core.additionalTrustManagerAttrs=SECJ7179I: Additional Trust Manager attributes
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7025I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.domainName" varFormat="Java">
    security.configrpt.core.domainName=SECJ7025I: Domain name
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0381I" severity="I" prefix="yes">
  <MsgText pgmKey="security.jsecman.debugnorethrow" varFormat="Java">
    security.jsecman.debugnorethrow=SECJ0381I: Warning, the com.ibm.websphere.java2secman.norethrow property is true. The WebSphere Java 2 Security Manager is not rethrowing AccessControl exceptions.  This debug setting should not be used in a production environment. See the InfoCenter for Java 2 Security debugging features.
  </MsgText>
  <Explanation>
    The com.ibm.websphere.java2secman.norethrow property, when it has a true value, instructs the Java 2 Security Manager to NOT rethrow AccessControl exceptions.  This property is intented to assist developers when they are preparing their applications for Java 2 Security.  When this property value is true, the Security Manager reports the AccessControl exception but does not rethrow or propagate the exception up the call stack.  This might permit applications to access resources that would they would otherwise not have access to. This property should not be specified in a production environment, only in a debug or application development environment.
  </Explanation>
  <UserResponse>
    If this message is unexpected or the application is running in a production environment, remove the com.ibm.ws.java2secman.norethrow property setting unless you understand the consequences.
  </UserResponse>
</Message>
<Message ID="SECJ6151I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.authz.role.failure.audit" varFormat="Java">
    security.audit.authz.role.failure.audit=SECJ6151I: The user does not have the required roles {0}.
  </MsgText>
  <Explanation>
    The user has not been granted any one of the required roles.
  </Explanation>
  <UserResponse>
    No action is required.
  </UserResponse>
</Message>
<Message ID="SECJ7412E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.NoKeyStoreTypeValue" varFormat="Java">
    security.admintask.NoKeyStoreTypeValue=SECJ7412E: No key store type was specified for the audit key store.
  </MsgText>
  <Explanation>
    Must specify a key store type for the audit key store
  </Explanation>
  <UserResponse>
    Supply a key store type for the audit key store
  </UserResponse>
</Message>
<Message ID="SECJ0051E" severity="E" prefix="yes">
  <MsgText pgmKey="security.sasconfig.currenterror" varFormat="Java">
    security.sasconfig.currenterror=SECJ0051E: IOException when determining whether configuration is current with property file {0} or {1}
  </MsgText>
  <Explanation>
    A loadProperties() operation probably failed.
  </Explanation>
  <UserResponse>
    Verify that the file associated with security configuration URL property file (typically sas.server.props) has read permission and is writable.
  </UserResponse>
</Message>
<Message ID="SECJ6025E" severity="E" prefix="yes">
  <MsgText pgmKey="security.audit.sharedkey.generation.error" varFormat="Java">
    security.audit.sharedkey.generation.error=SECJ6025E: Failure generated a shared key.  Exception = {0}.
  </MsgText>
  <Explanation>
    A failure occurred during shared key generation.
  </Explanation>
  <UserResponse>
    Examine the exception for the cause of the problem.
  </UserResponse>
</Message>
<Message ID="SECJ7368E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.InvalidOutcome" varFormat="Java">
    security.admintask.InvalidOutcome=SECJ7368E: Non valid or no reference specified for the audit outcome.
  </MsgText>
  <Explanation>
    The outcome field is required.
  </Explanation>
  <UserResponse>
    Verify that a valid reference has been specified for the audit outcome
  </UserResponse>
</Message>
<Message ID="SECJ7803I" severity="I" prefix="yes">
  <MsgText pgmKey="security.multidomain.runtime.SECJ7803I" varFormat="Java">
    security.multidomain.runtime.SECJ7803I=SECJ7803I: Application security is disabled in security domain {0}.
  </MsgText>
  <Explanation>
    This message is for informational purposes only.
  </Explanation>
  <UserResponse>
    No action is required.
  </UserResponse>
</Message>
<Message ID="SECJ4055E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaas.invalid.cred2.exception" varFormat="Java">
    security.jaas.invalid.cred2.exception=SECJ4055E: InvalidCredential exception is caught while serialized Subject is being restored. The exception is {0}.
  </MsgText>
  <Explanation>
    InvalidCredentialType exception occurred while restoring the credential.
  </Explanation>
  <UserResponse>
    Investigate the SAS problem. Contact your service representative if the problem persist.
  </UserResponse>
</Message>
<Message ID="SECJ6016I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.service.authn.default.audit" varFormat="Java">
    security.audit.service.authn.default.audit=SECJ6016I: AuditEventType = {0}, AuditOutcome = {1}, AuditOutcomeReason = {2}, unique Event ID = {3}, Cell Name = {4}, Node Name = {5}, Server Name = {6}, Component Name = {7}, App Name = {8}, Session ID = {9}, Resource Name = {10}, Resource Type = {11}, Realm = {12}, Authn Mechanism = {13}, Authn Method = {14}, User Name = {15}, Provider Name = {16}, Provider Successful = {17}, Subject = {18}, Caller List = {19}, Remote Addr = {20}, Remote Host = {21}, Remote Port = {22}, Exception = {23}.
  </MsgText>
  <Explanation>
    This message is intended to be used by the defaultAuditEventFactoryImpl sendAuthnAuditEvent method only.
  </Explanation>
  <UserResponse>
    No action required.
  </UserResponse>
</Message>
<Message ID="SECJ7013I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.useLocalSecurityServer" varFormat="Java">
    security.configrpt.core.useLocalSecurityServer=SECJ7013I: Use the local security server
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7063I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.sessionGCIdleTime" varFormat="Java">
    security.configrpt.core.sessionGCIdleTime=SECJ7063I: Session GC Idle Time
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7277I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.Http.Only" varFormat="Java">
    security.configrpt.core.Http.Only=SECJ7277I: HttpOnly custom property
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7394E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.InvalidEmailList" varFormat="Java">
    security.admintask.InvalidEmailList=SECJ7394E: Non valid email list specified.
  </MsgText>
  <Explanation>
    The email list specified is not valid, null or empty.
  </Explanation>
  <UserResponse>
    Supply a valid email list
  </UserResponse>
</Message>
<Message ID="SECJ0286W" severity="W" prefix="yes">
  <MsgText pgmKey="security.servcomp.init.warning" varFormat="Java">
    security.servcomp.init.warning=SECJ0286W: Error during security initialization.
  </MsgText>
  <Explanation>
    Unexpected exception occurred when initializing security server component.
  </Explanation>
  <UserResponse>
    None. This is warning.
  </UserResponse>
</Message>
<Message ID="SECJ7802I" severity="I" prefix="yes">
  <MsgText pgmKey="security.multidomain.runtime.SECJ7802I" varFormat="Java">
    security.multidomain.runtime.SECJ7802I=SECJ7802I: Application security is enabled in security domain {0}.
  </MsgText>
  <Explanation>
    This message is for informational purposes only.
  </Explanation>
  <UserResponse>
    No action is required.
  </UserResponse>
</Message>
<Message ID="SECJ7050I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.claims" varFormat="Java">
    security.configrpt.core.claims=SECJ7050I: Claims
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ4053E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaas.invalid.cred.exception" varFormat="Java">
    security.jaas.invalid.cred.exception=SECJ4053E: InvalidCredential exception is caught while serialized Subject is being restored. The exception is {0}.
  </MsgText>
  <Explanation>
    InvalidCredentialType exception occurred while restoring the credential.
  </Explanation>
  <UserResponse>
    Investigate the SAS problem. Contact your service representative if the problem persist.
  </UserResponse>
</Message>
<Message ID="SECJ7331E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.FailedAutogenLTPA" varFormat="Java">
    security.admintask.FailedAutogenLTPA=SECJ7331E: Failed to auto-generate the LTPA password
  </MsgText>
  <Explanation>
    Could not auto-generate an LTPA password
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7069I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.clientAuthentication" varFormat="Java">
    security.configrpt.core.clientAuthentication=SECJ7069I: Client authentication
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7723E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.noUserRegistry.SECJ7723E" varFormat="Java">
    security.admintask.noUserRegistry.SECJ7723E=SECJ7723E: {0} is not configured unable to set it to the active user registry.
  </MsgText>
  <Explanation>
    Unable to set the active user registry because the user registry provide is not configured.
  </Explanation>
  <UserResponse>
    Ensure the user registry is configured before setting it to the active user registry.
  </UserResponse>
</Message>
<Message ID="SECJ7015I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.authConfig" varFormat="Java">
    security.configrpt.core.authConfig=SECJ7015I: Authentication configuration
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ4006E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaas.invaldCredType" varFormat="Java">
    security.jaas.invaldCredType=SECJ4006E: Invalid Credential Type {0}
  </MsgText>
  <Explanation>
    Getting the JAAS subject from CORBA credential failed with exception.
  </Explanation>
  <UserResponse>
    Contact your service representative with exception stack trace information present in the error log.
  </UserResponse>
</Message>
<Message ID="SECJ0232E" severity="E" prefix="yes">
  <MsgText pgmKey="security.sambean.urerr" varFormat="Java">
    security.sambean.urerr=SECJ0232E: An unexpected exception occurred when trying to get the User Registry from the Security Server.  The exception is {0}.
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7801I" severity="I" prefix="yes">
  <MsgText pgmKey="security.multidomain.runtime.SECJ7801I" varFormat="Java">
    security.multidomain.runtime.SECJ7801I=SECJ7801I: Java 2 security is enabled in security domain {0}.
  </MsgText>
  <Explanation>
    This message is for informational purposes only.
  </Explanation>
  <UserResponse>
    No action is required.
  </UserResponse>
</Message>
<Message ID="SECJ7261I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.domain.User.Registry" varFormat="Java">
    security.configrpt.domain.User.Registry=SECJ7261I: User Realm
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7786E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.multidomain.clusterMapping.SECJ7786E" varFormat="Java">
    security.admintask.multidomain.clusterMapping.SECJ7786E=SECJ7786E: The {0} member cannot be added to the {1} cluster since the cluster is associated with a security domain.
  </MsgText>
  <Explanation>
    A server from previous releases cannot be added to a cluster when the cluster is associated with a security domain either directly or indirectly.
  </Explanation>
  <UserResponse>
    Mixed clusters are not supported with security domains.
  </UserResponse>
</Message>
<Message ID="SECJ7163I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.fileBased" varFormat="Java">
    security.configrpt.core.fileBased=SECJ7163I: File-based key store
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0067E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.ldap.mapcredential" varFormat="Java">
    security.registry.ldap.mapcredential=SECJ0067E: Cannot map the credential of the given credential token for subject DN {0} into LDAP because of an LDAP filter mapping exception.
  </MsgText>
  <Explanation>
    The credential mapping can fail for a number of reasons: The credential token is not an instance of a supported CredentialToken type for a mapping.  The principal identified in the credential cannot be mapped to an entry or found in the user registry.  A user registry exception occurs or if the user registry has been stopped.
  </Explanation>
  <UserResponse>
    Verify that the user registry is operational.  Also verify that the principal exists in the target user registry if appropriate.  The exception reported with this error message might help to diagnose the problem.
  </UserResponse>
</Message>
<Message ID="SECJ0402E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jacc.tools.rcf" varFormat="Java">
    security.jacc.tools.rcf=SECJ0402E: Error getting the RoleConfiguration object for the contextID {0}. The exception is {1}.
  </MsgText>
  <Explanation>
    Could not get the JACC provider RoleConfiguration object. This object is required to propagate the authorizationTable information to the provider.
  </Explanation>
  <UserResponse>
    If the authorizationTable information is required by the provider, make sure that the JACC provider properties related to the RoleConfigurationFactoryImplClass is set correctly. Also make sure that the implementation classes are in the class path of all the servers.
  </UserResponse>
</Message>
<Message ID="SECJ0293E" severity="E" prefix="yes">
  <MsgText pgmKey="security.sa.no.registry" varFormat="Java">
    security.sa.no.registry=SECJ0293E: No registry.
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7800I" severity="I" prefix="yes">
  <MsgText pgmKey="security.multidomain.runtime.SECJ7800I" varFormat="Java">
    security.multidomain.runtime.SECJ7800I=SECJ7800I: The following login configurations {0} are available for security domain {1}.
  </MsgText>
  <Explanation>
    This message is for informational purposes only.
  </Explanation>
  <UserResponse>
    No action is required.
  </UserResponse>
</Message>
<Message ID="SECJ0409E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jacc.install.task" varFormat="Java">
    security.jacc.install.task=SECJ0409E: An exception occurred when propagating the security policy information for application {0} to the JACC provider. The exception is {1}.
  </MsgText>
  <Explanation>
    Because of an exception, the security policy information might not have been propapated to the provider during the application installation.
  </Explanation>
  <UserResponse>
    Make sure that the provider is up and running and the JACC configuration is correct. Once the problem is fixed, one can also use the wsadmin tool to manually propagate the security policy information to the provider instead of reinstalling the application. See the information center documentation for more details on running this tool. If problem persists, contact your service representative.
  </UserResponse>
</Message>
<Message ID="SECJ7746E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.nonceValue.SECJ7746E" varFormat="Java">
    security.admintask.nonceValue.SECJ7746E=SECJ7746E: The nonce cache timeout value must be greater than the token timeout value.
  </MsgText>
  <Explanation>
    If the nonce cache timeout is less than the token timeout, then the token could be used multiple times since the nonce value would have expired prior to the token becoming not valid.
  </Explanation>
  <UserResponse>
    Run the command specifying a nonce value greater than the token expiration.
  </UserResponse>
</Message>
<Message ID="SECJ4018E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaas.removeCORBACredException" varFormat="Java">
    security.jaas.removeCORBACredException=SECJ4018E: Removing CORBA Credential during cleanup {0}
  </MsgText>
  <Explanation>
    Exception occurred while removing CORBA credential.
  </Explanation>
  <UserResponse>
    Contact your service representative with exception stack trace information present in the error log.
  </UserResponse>
</Message>
<Message ID="SECJ7725E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.noRealm.SECJ7725E" varFormat="Java">
    security.admintask.noRealm.SECJ7725E=SECJ7725E: The user registry has no realm name defined.
  </MsgText>
  <Explanation>
    Unable to make this user registry the active user registry because it does not have realm name defined.
  </Explanation>
  <UserResponse>
    Ensure the user registry has a realm name.
  </UserResponse>
</Message>
<Message ID="SECJ7335E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.ExceptionGettingWizardSettings" varFormat="Java">
    security.admintask.ExceptionGettingWizardSettings=SECJ7335E: Exception raised while getting wizard security settings
  </MsgText>
  <Explanation>
    Caught exception while getting wizard security settings
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0301W" severity="W" prefix="yes">
  <MsgText pgmKey="security.policy.parser.malformedurlexception" varFormat="Java">
    security.policy.parser.malformedurlexception=SECJ0301W: Failed to convert a file path {0} to CodeSource. The exception is {1}
  </MsgText>
  <Explanation>
    MalformedURLException occurred when trying to convert the specified path to URL.
  </Explanation>
  <UserResponse>
    Verify that the policy files, xml files(resource.xml) to confirm the class path specified in them are correct.
  </UserResponse>
</Message>
<Message ID="SECJ7775E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.oldResource.SECJ7775E" varFormat="Java">
    security.admintask.oldResource.SECJ7775E=SECJ7775E: Resource {0} cannot be part of any security domain becuase, its product version is not 7.0 or greater. Check the corresponding node&apos;&apos;s product version.
  </MsgText>
  <Explanation>
    The server must be running a 7.0 or greater version to be mapped to a domain.
  </Explanation>
  <UserResponse>
    Ensure that servers are at the correct level.
  </UserResponse>
</Message>
<Message ID="SECJ7103I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.No.Moderator.Role.User" varFormat="Java">
    security.configrpt.No.Moderator.Role.User=SECJ7103I: No Moderator user or group
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0256E" severity="E" prefix="yes">
  <MsgText pgmKey="security.bind.server.error" varFormat="Java">
    security.bind.server.error=SECJ0256E: Error binding SecurityServer to naming. The exception is {0}.
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7385E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.InvalidEmailFormat" varFormat="Java">
    security.admintask.InvalidEmailFormat=SECJ7385E: Non valid email format specified.
  </MsgText>
  <Explanation>
    Must either specify &quot;html&quot; or &quot;text&quot;.
  </Explanation>
  <UserResponse>
    Supply a valid email format
  </UserResponse>
</Message>
<Message ID="SECJ7064I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.sessionGCInterval" varFormat="Java">
    security.configrpt.core.sessionGCInterval=SECJ7064I: Session GC Interval
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7392E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.NotBinaryImpl" varFormat="Java">
    security.admintask.NotBinaryImpl=SECJ7392E: The audit service provider referenced is not an IBM Binary service provider implementation.
  </MsgText>
  <Explanation>
    The referenced service provider is not the default IBM Binary service provider implementation.
  </Explanation>
  <UserResponse>
    Enter a valid reference to a IBM Binary service provider implementation
  </UserResponse>
</Message>
<Message ID="SECJ0361E" severity="E" prefix="yes">
  <MsgText pgmKey="security.authn.failed.nouser" varFormat="Java">
    security.authn.failed.nouser=SECJ0361E: Authentication failed for {0} because user is not found in the registry.
  </MsgText>
  <Explanation>
    Authentication failed because the user does not exist.
  </Explanation>
  <UserResponse>
    Make sure that the user is valid in the registry. Also, when using LDAP, make sure that the user is searchable. The admin id in some LDAP servers might not be searchable.
  </UserResponse>
</Message>
<Message ID="SECJ0122I" severity="I" prefix="yes">
  <MsgText pgmKey="security.web.ta.intsig" varFormat="Java">
    security.web.ta.intsig=SECJ0122I: Trust Association Init Interceptor signature: {0}
  </MsgText>
  <Explanation>
    Reports the signature of the Trust Association interceptor.
  </Explanation>
  <UserResponse>
    None, informational only.
  </UserResponse>
</Message>
<Message ID="SECJ7772E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.missingParameter.krb5Config.SECJ7772E" varFormat="Java">
    security.admintask.missingParameter.krb5Config.SECJ7772E=SECJ7772E: The {0} is missing in the Kerberos configuration file {1}.
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7104I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.Configurator.Role.User" varFormat="Java">
    security.configrpt.Configurator.Role.User=SECJ7104I: Configurator User
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ6101I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.service.no.context.audit" varFormat="Java">
    security.audit.service.no.context.audit=SECJ6101I: Web access security context not found.
  </MsgText>
  <Explanation>
    A web request is rejected because no web access security context is configured.
  </Explanation>
  <UserResponse>
    The cause might be a simple user error or an indication of potential threat where malicious users explore the weakness of web applications. You might perform a correlation analysis of security auditing events.
  </UserResponse>
</Message>
<Message ID="SECJ0266E" severity="E" prefix="yes">
  <MsgText pgmKey="security.web.form.createWebAttr" varFormat="Java">
    security.web.form.createWebAttr=SECJ0266E: Failed to create a new web attribute.
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ6048E" severity="E" prefix="yes">
  <MsgText pgmKey="security.audit.send.mail.error" varFormat="Java">
    security.audit.send.mail.error=SECJ6048E: Failure sending audit notification.
  </MsgText>
  <Explanation>
    An error occurred while sending an audit notification.
  </Explanation>
  <UserResponse>
    Examine the error logs for the cause of the problem.
  </UserResponse>
</Message>
<Message ID="SECJ7774E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.noLoginModulNamed.SECJ7774E" varFormat="Java">
    security.admintask.noLoginModulNamed.SECJ7774E=SECJ7774E: Login module cannot be created using the name of the login module proxy class {0}.
  </MsgText>
  <Explanation>
    The login module proxy class name cannot be used when creating a new login module.
  </Explanation>
  <UserResponse>
    Ensure the login module proxy class is not used when creating a login module.
  </UserResponse>
</Message>
<Message ID="SECJ0048E" severity="E" prefix="yes">
  <MsgText pgmKey="security.sas.futureconfigurl.error" varFormat="Java">
    security.sas.futureconfigurl.error=SECJ0048E: Error updating or loading future security configuration URL specified by property {0}
  </MsgText>
  <Explanation>
    The path or file specified in the property might be not valid or there could be a file permission problem.
  </Explanation>
  <UserResponse>
    Verify that the path and file specified by the property is valid and the file has read permission.
  </UserResponse>
</Message>
<Message ID="SECJ7281I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.sso.ssl.required" varFormat="Java">
    security.configrpt.core.sso.ssl.required=SECJ7281I: Single signon requires SSL
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ4065W" severity="W" prefix="yes">
  <MsgText pgmKey="security.jaas.IdentityAssertion.context" varFormat="Java">
    security.jaas.IdentityAssertion.context=SECJ4065W: Principal and X509Certificate provided in the trust information, using the principal.
  </MsgText>
  <Explanation>
    Both a principal and X509Certificate are provided in the trust information, the principal has priority and will be used for the login.
  </Explanation>
  <UserResponse>
    If login with the X509Certificate is desired then the principal should not be passed in the trust information.
  </UserResponse>
</Message>
<Message ID="SECJ7379E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.MissingDeleteParms" varFormat="Java">
    security.admintask.MissingDeleteParms=SECJ7379E: No attributes specified on the delete command.
  </MsgText>
  <Explanation>
    No attributes were specified on the delete command.
  </Explanation>
  <UserResponse>
    Supply attribute(s) to delete the specified object
  </UserResponse>
</Message>
<Message ID="SECJ7743E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.noIdentity.SECJ7743E" varFormat="Java">
    security.admintask.noIdentity.SECJ7743E=SECJ7743E: When useServerIdentity is false then a trusted identity should be provided.
  </MsgText>
  <Explanation>
    When a user specifies useServerIdentity is false then a trusted identity should be provided.
  </Explanation>
  <UserResponse>
    Run the command specifying a trusted id.
  </UserResponse>
</Message>
<Message ID="SECJ7209I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.daysBeforeNotification" varFormat="Java">
    security.configrpt.core.daysBeforeNotification=SECJ7209I: Expiration notification threshold
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7710E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.mechanismNotValid.SECJ7710E" varFormat="Java">
    security.admintask.mechanismNotValid.SECJ7710E=SECJ7710E: Authentication mechanism is not valid.
  </MsgText>
  <Explanation>
    Valid authentication mechanisms are: KRB5, LTPA, Custom, BasicAuth.
  </Explanation>
  <UserResponse>
    Ensure that the authentication mechanisms is valid.
  </UserResponse>
</Message>
<Message ID="SECJ0202I" severity="I" prefix="yes">
  <MsgText pgmKey="security.init.adminapp" varFormat="Java">
    security.init.adminapp=SECJ0202I: Admin application initialized successfully
  </MsgText>
  <Explanation>
    The Admin application initialized successfully
  </Explanation>
  <UserResponse>
    None. Informational only.
  </UserResponse>
</Message>
<Message ID="SECJ0132I" severity="I" prefix="yes">
  <MsgText pgmKey="security.jsecman.installed" varFormat="Java">
    security.jsecman.installed=SECJ0132I: Java 2 Security is enabled
  </MsgText>
  <Explanation>
    Java 2 Security Manager is installed.
  </Explanation>
  <UserResponse>
    None, informational only.
  </UserResponse>
</Message>
<Message ID="SECJ0187E" severity="E" prefix="yes">
  <MsgText pgmKey="security.policy.sysext.parserexception" varFormat="Java">
    security.policy.sysext.parserexception=SECJ0187E: Caught ParserException while creating template for System Extension Policy of type {1} The exception is.{0}
  </MsgText>
  <Explanation>
    ParserException occurred when creating the system extension template in the hashmap of all the templates.
  </Explanation>
  <UserResponse>
    Check the ParserException data. Check the specified policy file.
  </UserResponse>
</Message>
<Message ID="SECJ0295E" severity="E" prefix="yes">
  <MsgText pgmKey="security.sa.get.props" varFormat="Java">
    security.sa.get.props=SECJ0295E: Error getting properties to file ({0}). The exception is {1}.
  </MsgText>
  <Explanation>
    An IOException occurred when getting properties from the specified file.
  </Explanation>
  <UserResponse>
    Verify that the property file exists, and that it has read permission.
  </UserResponse>
</Message>
<Message ID="SECJ0270E" severity="E" prefix="yes">
  <MsgText pgmKey="security.SecurityContext.getActualCreds" varFormat="Java">
    security.SecurityContext.getActualCreds=SECJ0270E: Failed to get actual credentials. The exception is {0}.
  </MsgText>
  <Explanation>
    Unexpected exception occurred when trying to run getActualCredential() method.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ0382I" severity="I" prefix="yes">
  <MsgText pgmKey="security.merge.notadded" varFormat="Java">
    security.merge.notadded=SECJ0382I: The alias {0} from the server level security has not been updated to the cell.
  </MsgText>
  <Explanation>
    Informational.
  </Explanation>
  <UserResponse>
    During the server and the cell security object merging, if a same alias name exists in both, the alias is not copied to the cell configuration. This is as designed. Normally, this should not happen since the alias names are unique. However, if a removeNode operation has been performed prior to the addNode operation, you might see this message since the removeNode does not remove the existing aliases. Also, if the alias names in the security.xml file were manually changed, then this message appears if the aliases match.
  </UserResponse>
</Message>
<Message ID="SECJ7720E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.noActiveUserRegistsry.SECJ7720E" varFormat="Java">
    security.admintask.noActiveUserRegistsry.SECJ7720E=SECJ7720E: Unable to enable security when there is no active user registry.
  </MsgText>
  <Explanation>
    There is an attempt to enable global security when there is no active user registry defined.
  </Explanation>
  <UserResponse>
    Ensure an user registry is defined when enabling global security.
  </UserResponse>
</Message>
<Message ID="SECJ6237E" severity="E" prefix="yes">
  <MsgText pgmKey="security.zos.saf.authz.allFailed" varFormat="Java">
    security.zos.saf.authz.allFailed=SECJ6237E: Authorization failed. The SAF user {0} does not have {1} access to any of the following SAF profiles in the EJBROLE class:  {2}.
  </MsgText>
  <Explanation>
    Authorization failed for the user.
  </Explanation>
  <UserResponse>
    Consult with the SAF administrator for granting the necessary access in the SAF database.
  </UserResponse>
</Message>
<Message ID="SECJ4056E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaas.get.initCtx" varFormat="Java">
    security.jaas.get.initCtx=SECJ4056E: Error getting initial context. The exception is {0}.
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7718E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.scopeNotValid.SECJ7718E" varFormat="Java">
    security.admintask.scopeNotValid.SECJ7718E=SECJ7718E: {0} is not a valid resource name.
  </MsgText>
  <Explanation>
    The resource name provided is not valid.
  </Explanation>
  <UserResponse>
    Ensure a valid resource name is provided.
  </UserResponse>
</Message>
<Message ID="SECJ0093E" severity="E" prefix="yes">
  <MsgText pgmKey="security.authtbl.relhome" varFormat="Java">
    security.authtbl.relhome=SECJ0093E: Relation home not found
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7406E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.NoCertKeyFilePathValue" varFormat="Java">
    security.admintask.NoCertKeyFilePathValue=SECJ7406E: No value was specified for the key file path for the certificate to import
  </MsgText>
  <Explanation>
    When selecting to import an existing certificate, a key file path for the certificate must be entered.
  </Explanation>
  <UserResponse>
    Supply a key file path for the certificate to import
  </UserResponse>
</Message>
<Message ID="SECJ7091I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.Security.property.name" varFormat="Java">
    security.configrpt.core.Security.property.name=SECJ7091I: Name
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7222I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.reuseConnection" varFormat="Java">
    security.configrpt.core.reuseConnection=SECJ7222I: Reuse connection
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7750E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.certNotInKS.SECJ7750E" varFormat="Java">
    security.admintask.certNotInKS.SECJ7750E=SECJ7750E: Certificate {0} is not in key store {1}.
  </MsgText>
  <Explanation>
    The certificate alias provided is not in the key store.
  </Explanation>
  <UserResponse>
    Run the command providing a certificate alias that is in the key store.
  </UserResponse>
</Message>
<Message ID="SECJ6226W" severity="W" prefix="yes">
  <MsgText pgmKey="security.zos.saf.threadid.sync.ipt.warning" varFormat="Java">
    security.zos.saf.threadid.sync.ipt.warning=SECJ6226W: Thread identity synchronization of user &quot;{0}&quot; is not allowed on the &quot;initial pthread task.&quot;
  </MsgText>
  <Explanation>
    The BPX1TLS service does cannot be called from the initial pthread task (IPT).  If this service is called on the IPT, future calls to perform connection management or application thread identity synchronization will fail.
  </Explanation>
  <UserResponse>
    No action is required.
  </UserResponse>
</Message>
<Message ID="SECJ7439E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.CannotDeleteCertAlias" varFormat="Java">
    security.admintask.CannotDeleteCertAlias=SECJ7439E: Empty value specified for the certAlias. Cannot delete the certificate alias when audit encryption is enabled or is being enabled.
  </MsgText>
  <Explanation>
    Audit encryption is enabled or is being enabled.  The certificate alias is in use and cannot be deleted.
  </Explanation>
  <UserResponse>
    Disable audit encryption before deleteing the certificate alias.
  </UserResponse>
</Message>
<Message ID="SECJ6209I" severity="I" prefix="yes">
  <MsgText pgmKey="security.zos.threadid.app.enabled" varFormat="Java">
    security.zos.threadid.app.enabled=SECJ6209I: Application thread identity synchronization is enabled.
  </MsgText>
  <Explanation>
    The server has been configured to perform J2EE and operating system thread identity synchronization for applications that request it.
  </Explanation>
  <UserResponse>
    No user action is required.
  </UserResponse>
</Message>
<Message ID="SECJ7186I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.keyManagerClass" varFormat="Java">
    security.configrpt.core.keyManagerClass=SECJ7186I: Class name
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0257E" severity="E" prefix="yes">
  <MsgText pgmKey="security.find.server.error" varFormat="Java">
    security.find.server.error=SECJ0257E: Failed to find security server in name space. The exception is {0}.
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7798E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.spnego.errorDeleteLastFilter.SECJ7798E" varFormat="Java">
    security.admintask.spnego.errorDeleteLastFilter.SECJ7798E=SECJ7798E: Can not delete the last SPNEGO filter because SPNEGO Web authentication is enabled.
  </MsgText>
  <Explanation>
    The SPNEGO Web authentication is enabled, it requires at least one SPNEGO filter.
  </Explanation>
  <UserResponse>
    Disable SPNEGO Web authentication before delete the last SPNEGO filter.
  </UserResponse>
</Message>
<Message ID="SECJ7199I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.keyReference" varFormat="Java">
    security.configrpt.core.keyReference=SECJ7199I: Key reference
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ5004W" severity="W" prefix="yes">
  <MsgText pgmKey="security.sap.warning.propagation.token.exists" varFormat="Java">
    security.sap.warning.propagation.token.exists=SECJ5004W: Trying to add propagation token name {0} and version {1} that already exists on the thread. The existing PropagationToken is returned and will not be overwritten.
  </MsgText>
  <Explanation>
    Cannot overwrite an existing PropagationToken.  The existing one is returned, so use it to set new attributes given the proper permission.
  </Explanation>
  <UserResponse>
    Check the addPropagationToken SPI for the value returned.  A null value indicates this is the first time the token is added.  A non-null value indicates you are setting the token again which is not allowed.  Use the returned value to add new attributes.
  </UserResponse>
</Message>
<Message ID="SECJ7305E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.FoundOtherWIMFlavors" varFormat="Java">
    security.admintask.FoundOtherWIMFlavors=SECJ7305E: Found other virtual member manager repository configurations. Only the built-in virtual member manager file-based repository is supported through the wizard
  </MsgText>
  <Explanation>
    Found other virtual member manager repository configurations but only file-based is supported in the wizard
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ6051E" severity="E" prefix="yes">
  <MsgText pgmKey="security.audit.auditorId.change.error" varFormat="Java">
    security.audit.auditorId.change.error=SECJ6051E: User name specified as the auditor ID does not have auditor privileges.
  </MsgText>
  <Explanation>
    Cannot assign a user who does not have the auditor role as the primary auditor.
  </Explanation>
  <UserResponse>
    Ensure the user specified is given the auditor role or select a user who already has the auditor role.
  </UserResponse>
</Message>
<Message ID="SECJ4014E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaas.callBackHandlerException" varFormat="Java">
    security.jaas.callBackHandlerException=SECJ4014E: Login Module {0} detected unsupported {1}  callback in CallbackHandler {2}
  </MsgText>
  <Explanation>
    Unsupported Exception occurred while processing callbacks
  </Explanation>
  <UserResponse>
    Check the application. Contact your service representative with exception stack trace information present in the error log if the problem persists.
  </UserResponse>
</Message>
<Message ID="SECJ0176E" severity="E" prefix="yes">
  <MsgText pgmKey="security.policy.sysext.param" varFormat="Java">
    security.policy.sysext.param=SECJ0176E: An exception was caught while getting the policy template of type {1}. The exception is {0}.
  </MsgText>
  <Explanation>
    Could not retrieve the policy template of the above type.
  </Explanation>
  <UserResponse>
    This is an internal error. However, it could be caused by an incorrect xml file. Enable security trace with com.ibm.ws.security.policy.* to get more detailed information.
  </UserResponse>
</Message>
<Message ID="SECJ7143I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.SingleSignon" varFormat="Java">
    security.configrpt.core.SingleSignon=SECJ7143I: Single signon (SSO)
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0299E" severity="E" prefix="yes">
  <MsgText pgmKey="security.policy.parser.decodeexception" varFormat="Java">
    security.policy.parser.decodeexception=SECJ0299E: An exception was caught while decoding the file path: {0}. The exception is {1}.
  </MsgText>
  <Explanation>
    Failed to decode the specified file. The details is shown in the exception.
  </Explanation>
  <UserResponse>
    Verify that the policy files, xml files(resource.xml) to confirm the class path specified in them are correct.
  </UserResponse>
</Message>
<Message ID="SECJ4032E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaasconfig.helper.baddata" varFormat="Java">
    security.jaasconfig.helper.baddata=SECJ4032E: Method {0} detected missing or malformed data when trying to perform conversion. The data item name is {1} and value is {2}.
  </MsgText>
  <Explanation>
    Internal problem related to malformed or corrupted data storage.
  </Explanation>
  <UserResponse>
    Contact your service representative with exception stack trace information present in the error log.
  </UserResponse>
</Message>
<Message ID="SECJ0212I" severity="I" prefix="yes">
  <MsgText pgmKey="security.init.wccmjaas.init" varFormat="Java">
    security.init.wccmjaas.init=SECJ0212I: WCCM JAAS configuration information successfully pushed to login provider class.
  </MsgText>
  <Explanation>
    The WCCM JAAS login configuration information was pushed to the JAAS configuration object.
  </Explanation>
  <UserResponse>
    None. Informational only.
  </UserResponse>
</Message>
<Message ID="SECJ6206W" severity="W" prefix="yes">
  <MsgText pgmKey="security.zOS.SecurityManager.PermissionFailure2.warning" varFormat="Java">
    security.zOS.SecurityManager.PermissionFailure2.warning=SECJ6206W: The current Java 2 Security policy report a potential violation of a Java 2 Security Permission.  Stack Trace:{0}
  </MsgText>
  <Explanation>
    The Java Security Manager checkPermission() threw a SecurityException. A caller on the call stack does not have the required permission.
  </Explanation>
  <UserResponse>
    Verify that the attempted operation is permitted by examining all Java 2 security files and application code. Additional permissions might be required.
  </UserResponse>
</Message>
<Message ID="SECJ7450E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.InvalidSequenceSet" varFormat="Java">
    security.admintask.InvalidSequenceSet=SECJ7450E: Non valid sequence set specified.  Either a single sequence record number can be specified or a group of sequence records may be specified as begin:end.
  </MsgText>
  <Explanation>
    A non valid value was specified for the sequence set of audit records to report
  </Explanation>
  <UserResponse>
    Specify a non-empty or valid value for the sequence set.
  </UserResponse>
</Message>
<Message ID="SECJ4000E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaas.LoginException" varFormat="Java">
    security.jaas.LoginException=SECJ4000E: JAAS Login Exception occurred at {0}.
  </MsgText>
  <Explanation>
    JAAS Login exception occurred while refreshing the credential.
  </Explanation>
  <UserResponse>
    Confirm user id, password and realm information are correct. If you still see the problem, contact your service representative with exception stack trace information present in the error log.
  </UserResponse>
</Message>
<Message ID="SECJ4034I" severity="I" prefix="yes">
  <MsgText pgmKey="security.jaas.tokenloginvaldationfailure" varFormat="Java">
    security.jaas.tokenloginvaldationfailure=SECJ4034I: Token Login failed.    If the failure is due to an expiring token, verify the system date and time of the WebSphere nodes are synchronized or consider increasing the token timeout value. Authentication mechanism {0} and exception is  {1}
  </MsgText>
  <Explanation>
    Token Authentication failure might be caused by an expired token, token that is not valid, or a date or time synchronization problem between WebSphere nodes.  Web browsers often cache WebSphere SSO cookies which contain the token to validate.  These tokens do expire.
  </Explanation>
  <UserResponse>
    Token validation failures are not always unexpected given that tokens can expire.  might consider increasing timeout value or verifying that the system date and time between WebSphere nodes is synchronized.
  </UserResponse>
</Message>
<Message ID="SECJ0407E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jacc.tools.appname.error" varFormat="Java">
    security.jacc.tools.appname.error=SECJ0407E: Cannot obtain the application name for propagating the security constraints to the provider.
  </MsgText>
  <Explanation>
    The appname is required to propagate the security policy information to the provider.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ6139I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.csi.session.authztoken.audit" varFormat="Java">
    security.audit.csi.session.authztoken.audit=SECJ6139I: The authorization token is invalid.
  </MsgText>
  <Explanation>
    Parsing the client authorization token failed.
  </Explanation>
  <UserResponse>
    Need to determine if this is caused by programming error.
  </UserResponse>
</Message>
<Message ID="SECJ0429W" severity="W" prefix="yes">
  <MsgText pgmKey="security.disabled.during.login" varFormat="Java">
    security.disabled.during.login=SECJ0429W: A login has occurred while admin security is disabled.  An UNAUTHENTICATED Subject will be returned since most security subsystems are unavailable.
  </MsgText>
  <Explanation>
    When admin security is disabled we do not initialize user registry or other services needed to properly authenticate.  Therfore, we will return an UNAUTHENTICATED Subject to ensure the runtime continues to operate.
  </Explanation>
  <UserResponse>
    If an authenticated JAAS Subject is desired, you must enable at least administrative security in the security configuration.
  </UserResponse>
</Message>
<Message ID="SECJ7153I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.webAuthAttrs" varFormat="Java">
    security.configrpt.core.webAuthAttrs=SECJ7153I: Web Authentication
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ6216I" severity="I" prefix="yes">
  <MsgText pgmKey="security.zos.saf.delegation.enabled" varFormat="Java">
    security.zos.saf.delegation.enabled=SECJ6216I: SAF delegation is enabled.
  </MsgText>
  <Explanation>
    The APPLDATA associated with the profile representing the J2EE role will be used to determine the id of a user that is in the role.  An invocation Subject will be built with a credential for that user.
  </Explanation>
  <UserResponse>
    No user action is required.
  </UserResponse>
</Message>
<Message ID="SECJ8009E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.jaspi.provider.exists.SECJ8009E" varFormat="Java">
    security.admintask.jaspi.provider.exists.SECJ8009E=SECJ8009E: Authentication provider {0} is already defined in domain {1}.
  </MsgText>
  <Explanation>
    The name of each authentication provider must be unique.
  </Explanation>
  <UserResponse>
    Specify a unique name for the authentication provider.
  </UserResponse>
</Message>
<Message ID="SECJ0054E" severity="E" prefix="yes">
  <MsgText pgmKey="security.authz.noowncreds" varFormat="Java">
    security.authz.noowncreds=SECJ0054E: No own credentials
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ6111I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.sso.exception.audit" varFormat="Java">
    security.audit.sso.exception.audit=SECJ6111I: SSO token {0} failed validation with an Exception.
  </MsgText>
  <Explanation>
    Authentication failed due to internal failure.
  </Explanation>
  <UserResponse>
    Examine the cause of the exception and correct the problem. If the problem persists, contact your service representative.
  </UserResponse>
</Message>
<Message ID="SECJ8022E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.authCacheTimeout.SECJ8022E" varFormat="Java">
    security.admintask.authCacheTimeout.SECJ8022E=SECJ8022E: Authentication cache timoue value invalid. Timeout must be less than or equal to the LTPA token timeout value.
  </MsgText>
  <Explanation>
    The authentication cache timeout value must be less than or equal to the LTPA token timeout value.
  </Explanation>
  <UserResponse>
    Specify a timeout value that is less than or equal to the LTPA token timeout value.
  </UserResponse>
</Message>
<Message ID="SECJ7409E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.NoCertAliasToImport" varFormat="Java">
    security.admintask.NoCertAliasToImport=SECJ7409E: No name was specified for the certificate alias to import
  </MsgText>
  <Explanation>
    When selecting to import an existing certificate, a certificate aliase for the certificate must be entered.
  </Explanation>
  <UserResponse>
    Supply a certificate alias name for the certificate to import
  </UserResponse>
</Message>
<Message ID="SECJ7269I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.useNativeAuthorization" varFormat="Java">
    security.configrpt.core.useNativeAuthorization=SECJ7269I: Use native authorization
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7127I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.Naming" varFormat="Java">
    security.configrpt.Naming=SECJ7127I: Naming
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ6229E" severity="E" prefix="yes">
  <MsgText pgmKey="security.zos.saf.idprop.distributedRealm.null" varFormat="Java">
    security.zos.saf.idprop.distributedRealm.null=SECJ6229E: The distributed realm name is null.
  </MsgText>
  <Explanation>
    The distributed realm name is null and will not be mapped not a SAF user.
  </Explanation>
  <UserResponse>
    Specify a valid distributed realm name.
  </UserResponse>
</Message>
<Message ID="SECJ0127E" severity="E" prefix="yes">
  <MsgText pgmKey="security.web.ta.userex" varFormat="Java">
    security.web.ta.userex=SECJ0127E: Unable to find a valid user for Trust Association
  </MsgText>
  <Explanation>
    When the WebAuthenticator invoked an interceptor to return the authenticate user name, no such user name was returned.
  </Explanation>
  <UserResponse>
    Verify that the reverse proxy server is inserting the correct user name in the HTTP request before it sends the request to WebSphere.
  </UserResponse>
</Message>
<Message ID="SECJ7469E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.UserNotInRole" varFormat="Java">
    security.admintask.UserNotInRole=SECJ7469E: The user has not been included in the required role of &quot;{0}&quot;.
  </MsgText>
  <Explanation>
    The user must be included in all the required roles needed to run the task.
  </Explanation>
  <UserResponse>
    Ensure the acting user has been given the proper role(s).
  </UserResponse>
</Message>
<Message ID="SECJ0137E" severity="E" prefix="yes">
  <MsgText pgmKey="security.adminApp.installation" varFormat="Java">
    security.adminApp.installation=SECJ0137E: Could not get EnterpriseAppHome
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ0271E" severity="E" prefix="yes">
  <MsgText pgmKey="security.SecurityContext.restoreCreds" varFormat="Java">
    security.SecurityContext.restoreCreds=SECJ0271E: Error restoring original credentials.
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7704E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.registryDoesNotExist.SECJ7704E" varFormat="Java">
    security.admintask.registryDoesNotExist.SECJ7704E=SECJ7704E: User registry does not exist in the security configuration.
  </MsgText>
  <Explanation>
    The user registry specified does not exist in the configuration.
  </Explanation>
  <UserResponse>
    Rerun the command using a user registry that exist in the configuration.
  </UserResponse>
</Message>
<Message ID="SECJ0114W" severity="W" prefix="yes">
  <MsgText pgmKey="security.web.cred.getAttrFail" varFormat="Java">
    security.web.cred.getAttrFail=SECJ0114W: Unable to extract the security attributes from the credential
  </MsgText>
  <Explanation>
    The credential might be malformed or corrupted.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7263I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.domain.application.jaas" varFormat="Java">
    security.configrpt.domain.application.jaas=SECJ7263I: JAAS Application Logins
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0372E" severity="E" prefix="yes">
  <MsgText pgmKey="security.ltpa.validate.verifytoken.failed" varFormat="Java">
    security.ltpa.validate.verifytoken.failed=SECJ0372E: Validation of the inbound LTPA token failed.  The configured LTPA keys are probably not the ones that generated the token signature.
  </MsgText>
  <Explanation>
    The LTPA keys might not be the correct ones needed to verify the signature of the token.
  </Explanation>
  <UserResponse>
    This error occurs if the keys used to encrypt the token are not the same as the keys used to decrypt. If a new set of keys has been generated, this is an expected error. Any tokens signed using the old keys will no longer work. Contact your service representative if the problem persists.
  </UserResponse>
</Message>
<Message ID="SECJ7012I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.useDomainQualifiedUserNames" varFormat="Java">
    security.configrpt.core.useDomainQualifiedUserNames=SECJ7012I: Use realm-qualified user names
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ4045E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaas.call.convertMapToString2" varFormat="Java">
    security.jaas.call.convertMapToString2=SECJ4045E: {0} : Error: An exception occurred when trying to reflect on or invoke convertMapToString(). The exception is {1}
  </MsgText>
  <Explanation>
    Exception occurred trying to reflect on or invoke convertMapToString().
  </Explanation>
  <UserResponse>
    Investigate the exception. Check class path.
  </UserResponse>
</Message>
<Message ID="SECJ7387E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.NotificationInUse" varFormat="Java">
    security.admintask.NotificationInUse=SECJ7387E: Audit notification is in use.
  </MsgText>
  <Explanation>
    Audit notification is in use and cannot be deleted.
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0263E" severity="E" prefix="yes">
  <MsgText pgmKey="security.swam.remove.cred.ex" varFormat="Java">
    security.swam.remove.cred.ex=SECJ0263E: Exception occurred when removing WSCredential during cleanup. The exception is {0}
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7059I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.integrity" varFormat="Java">
    security.configrpt.core.integrity=SECJ7059I: Integrity
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7446I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.report.Outcome.name" varFormat="Java">
    security.audit.report.Outcome.name=SECJ7446I: Outcome
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7174I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.registryClassName" varFormat="Java">
    security.configrpt.core.registryClassName=SECJ7174I: Custom registry class name
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ6127I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.basic.exception.audit" varFormat="Java">
    security.audit.basic.exception.audit=SECJ6127I: Basic authentication failed due to internal error.
  </MsgText>
  <Explanation>
    Basic Authentication failed and a runtime exception was caught.
  </Explanation>
  <UserResponse>
    Report this problem to IBM.
  </UserResponse>
</Message>
<Message ID="SECJ7030I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.serverPassword" varFormat="Java">
    security.configrpt.core.serverPassword=SECJ7030I: Server user password
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0221E" severity="E" prefix="yes">
  <MsgText pgmKey="security.ejb.beanperm.matchmetherr" varFormat="Java">
    security.ejb.beanperm.matchmetherr=SECJ0221E: An unexpected exception occurred in findMatchingMethod for method {0} and bean {1}, the exception is {2}
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7168I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.type" varFormat="Java">
    security.configrpt.core.type=SECJ7168I: Type
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7782E" severity="E" prefix="yes">
  <MsgText pgmKey="security.domain.app.deploy.error.SECJ7782E" varFormat="Java">
    security.domain.app.deploy.error.SECJ7782E=SECJ7782E: You cannot install an application across multiple security domains. Make sure that all the deployment targets belong to the same security domain.
  </MsgText>
  <Explanation>
    Application cannot be installed accross multiple security domains.
  </Explanation>
  <UserResponse>
    Verify that user is not installing this application accorss multiple security domains.
  </UserResponse>
</Message>
<Message ID="SECJ7541W" severity="W" prefix="yes">
  <MsgText pgmKey="security.scanner.risk.admin.role.every.all.improve" varFormat="Java">
    security.scanner.risk.admin.role.every.all.improve=SECJ7541W: Special subject &quot;{0}&quot; is configured for the Administrator role.  It is not recommended to have Everyone and AllAuthenticatedUsers specified for the Administrator role.
  </MsgText>
  <Explanation>
    A special subject is configured for the Administrator role.  It is not recommended to have Everyone and AllAuthenticatedUsers specified for the Administrator role.
  </Explanation>
  <UserResponse>
    refer to the infoCenter to determine if a more secure configuration is more suitable.
  </UserResponse>
</Message>
<Message ID="SECJ7235I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.allowLTPAFallback" varFormat="Java">
    security.configrpt.core.allowLTPAFallback=SECJ7235I: Allow fallback to LTPA
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7797E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.notServerType.SECJ7797E" varFormat="Java">
    security.admintask.notServerType.SECJ7797E=SECJ7797E: The resource must be a single server resource in order for it to be converted to a security domain.
  </MsgText>
  <Explanation>
    The resource provided is not a single server resource.
  </Explanation>
  <UserResponse>
    Ensure the resource provided is a single server resource.
  </UserResponse>
</Message>
<Message ID="SECJ0376E" severity="E" prefix="yes">
  <MsgText pgmKey="security.ltpa.importkeys" varFormat="Java">
    security.ltpa.importkeys=SECJ0376E: Error importing LTPA keys. The exception is {0}.
  </MsgText>
  <Explanation>
    Cannot import LTPA keys.
  </Explanation>
  <UserResponse>
    This error occurs when the password used to import the keys does not match the password that encrypted the keys. Make sure that the password is the same. If the problem persists, contact your service representative.
  </UserResponse>
</Message>
<Message ID="SECJ7808I" severity="I" prefix="yes">
  <MsgText pgmKey="security.admintask.createDummyDomain.SECJ7808I" varFormat="Java">
    security.admintask.createDummyDomain.SECJ7808I=SECJ7808I: The domain {0} has been created because a cell wide domain exists in a mixed version setup.
  </MsgText>
  <Explanation>
    This special domain is created to associate previous version servers, clusters and SIBuses to this domain.
  </Explanation>
  <UserResponse>
    If any of the old servers, clusters and SIBuses need to use the cell wide domain instead of the special domain, they need to be removed from this special domain. This might impact the security configuration of the resources deployed in these processes based on the cell wide domain security configuration.
  </UserResponse>
</Message>
<Message ID="SECJ7210I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.deleteOld" varFormat="Java">
    security.configrpt.core.deleteOld=SECJ7210I: Delete old certificate after replacement
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7229I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.Deployer.Role.Group" varFormat="Java">
    security.configrpt.Deployer.Role.Group=SECJ7229I: Moderator Group
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0159E" severity="E" prefix="yes">
  <MsgText pgmKey="security.wsaccessmanager.classnotfound" varFormat="Java">
    security.wsaccessmanager.classnotfound=SECJ0159E: Cannot find class {0}
  </MsgText>
  <Explanation>
    The Vendor specified Authorization Table class could not be found in the CLASSPATH.
  </Explanation>
  <UserResponse>
    Make sure that the vendor&apos;s implementation of Authorization Table as specified in the sas.server.props file is in the CLASSPATH.
  </UserResponse>
</Message>
<Message ID="SECJ0165W" severity="W" prefix="yes">
  <MsgText pgmKey="security.policy.appparser.expandperm" varFormat="Java">
    security.policy.appparser.expandperm=SECJ0165W: Expand exception occurred. Skip the permission entry in app.policy file. The exception is {0}.
  </MsgText>
  <Explanation>
    An expand exception occurred while expanding the permission in the application policy file.
  </Explanation>
  <UserResponse>
    Check the permission entry syntax in the application policy file (app.policy or was.policy). To identify which policy file has a problem, enable security trace for the component com.ibm.ws.security.policy.*. The trace.log file will contain the policy name.
  </UserResponse>
</Message>
<Message ID="SECJ6225E" severity="E" prefix="yes">
  <MsgText pgmKey="security.zos.saf.role.mapper.exception" varFormat="Java">
    security.zos.saf.role.mapper.exception=SECJ6225E: Unable to load the custom SAF role to profile mapper &quot;{0}&quot; due to the following exception: {1}
  </MsgText>
  <Explanation>
    WebSphere was unable to load and and instantiate the configured class.  This is generally due to an incorrect class name.
  </Explanation>
  <UserResponse>
    Verify that the specified class name is correct and that it can be loaded by the WebSphere class loader.
  </UserResponse>
</Message>
<Message ID="SECJ0167W" severity="W" prefix="yes">
  <MsgText pgmKey="security.policy.filterparser.expandperm" varFormat="Java">
    security.policy.filterparser.expandperm=SECJ0167W: Expand exception occurred. Skip the permission entry in filter.policy file. The exception is {0}.
  </MsgText>
  <Explanation>
    While expanding the permission entry in filter.policy file, caught an expand exception
  </Explanation>
  <UserResponse>
    Check the permission entry syntax in filter policy file.
  </UserResponse>
</Message>
<Message ID="SECJ0383I" severity="I" prefix="yes">
  <MsgText pgmKey="security.merge.proceeding" varFormat="Java">
    security.merge.proceeding=SECJ0383I: Proceeding with merging the server&apos;s security configuration with the cell&apos;s for this Application Server.
  </MsgText>
  <Explanation>
    Informational.
  </Explanation>
  <UserResponse>
    This message appears when the Application Server contains its own security configuration that must be merged with cell level configuration.
  </UserResponse>
</Message>
<Message ID="SECJ7769E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.null.krbRealm.SECJ7769E" varFormat="Java">
    security.admintask.null.krbRealm.SECJ7769E=SECJ7769E: The Kerberos realm name is null.
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ0050E" severity="E" prefix="yes">
  <MsgText pgmKey="security.sasconfig.shutdown.error" varFormat="Java">
    security.sasconfig.shutdown.error=SECJ0050E: Error encountered while shutting down the server
  </MsgText>
  <Explanation>
    An unexpected RemoteException, OpException or IOException occurred during server shutdown. There could be problems with loading or writing of security configuration URL property files.
  </Explanation>
  <UserResponse>
    Verify that the file associated with security configuration URL property file (typically sas.server.props) has read permission and is writable.
  </UserResponse>
</Message>
<Message ID="SECJ8000E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.jaspi.provider.exists.SECJ8000E" varFormat="Java">
    security.admintask.jaspi.provider.exists.SECJ8000E=SECJ8000E: Authentication provider {0} is already defined in the cell.
  </MsgText>
  <Explanation>
    The name of each authentication provider must be unique.
  </Explanation>
  <UserResponse>
    Specify a unique name for the authentication provider.
  </UserResponse>
</Message>
<Message ID="SECJ7783W" severity="W" prefix="yes">
  <MsgText pgmKey="security.domain.app.deploy.warning.SECJ7783W" varFormat="Java">
    security.domain.app.deploy.warning.SECJ7783W=SECJ7783W: The application is being installed across deployment targets that use different security domains. Depending on the security attributes defined in the security domains this can cause security problems.
  </MsgText>
  <Explanation>
    The application is being installed across deployment targets that use different security domains. Depending on the security attributes defined in the security domains this can cause security problems.
  </Explanation>
  <UserResponse>
    Refer to the information center documentation for more information before you proceed with this installation to make sure that you would not run into any security related issues.
  </UserResponse>
</Message>
<Message ID="SECJ0417I" severity="I" prefix="yes">
  <MsgText pgmKey="security.fips.enabled" varFormat="Java">
    security.fips.enabled=SECJ0417I: FIPS is enabled.
  </MsgText>
  <Explanation>
    The server is running in FIPS mode, using the IBMJCEFIPS provider.
  </Explanation>
  <UserResponse>
    No user action is required.
  </UserResponse>
</Message>
<Message ID="SECJ7201I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.version" varFormat="Java">
    security.configrpt.core.version=SECJ7201I: Version
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ4019E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaas.NoUtil" varFormat="Java">
    security.jaas.NoUtil=SECJ4019E: Not supposed to construct Util object
  </MsgText>
  <Explanation>
    Util object instance should not be constructed.
  </Explanation>
  <UserResponse>
    Check the user application. Util should not be directly constructed.
  </UserResponse>
</Message>
<Message ID="SECJ7359E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.InvalidAuditorPwd" varFormat="Java">
    security.admintask.InvalidAuditorPwd=SECJ7359E: Non valid or no value specified for auditor password.
  </MsgText>
  <Explanation>
    The auditor password is a required field.
  </Explanation>
  <UserResponse>
    Verify that a value has been specified for the auditor password
  </UserResponse>
</Message>
<Message ID="SECJ0219E" severity="E" prefix="yes">
  <MsgText pgmKey="security.roleauthz.appnoload" varFormat="Java">
    security.roleauthz.appnoload=SECJ0219E: Unable to obtain or use a role-based authorizer because application {0} has not been loaded.
  </MsgText>
  <Explanation>
    The application must be loaded for the role base authorizer can be used to enforce authorization.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ0255E" severity="E" prefix="yes">
  <MsgText pgmKey="security.create.remote.server.error" varFormat="Java">
    security.create.remote.server.error=SECJ0255E: Error creating security server/ The exception is {0}.
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7070I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.enableCryptoHardwareSupport" varFormat="Java">
    security.configrpt.core.enableCryptoHardwareSupport=SECJ7070I: Cryptographic token
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7121I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.Naming.None" varFormat="Java">
    security.configrpt.Naming.None=SECJ7121I: No roles defined
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7105I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.No.Configurator.Role.User" varFormat="Java">
    security.configrpt.No.Configurator.Role.User=SECJ7105I: No Configurator user or group
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0356E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.nullrealm" varFormat="Java">
    security.registry.nullrealm=SECJ0356E: Could not get the realm for the registry in windows.
  </MsgText>
  <Explanation>
    Not able to get the host name of the Windows machine or the domain controller.
  </Explanation>
  <UserResponse>
    Make sure that the user who is running WebSphere Application Server has administrative and &quot;act as part of operating system&quot; privileges on the Windows machine and is also an administrator in the domain machine. Contact your service representative if the problem persists.
  </UserResponse>
</Message>
<Message ID="SECJ6148I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.csi.authn.success.audit" varFormat="Java">
    security.audit.csi.authn.success.audit=SECJ6148I: Authentication succeeded.
  </MsgText>
  <Explanation>
    The authentication was successful.
  </Explanation>
  <UserResponse>
    No action is required.
  </UserResponse>
</Message>
<Message ID="SECJ0354E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.usersecurityname.error" varFormat="Java">
    security.registry.usersecurityname.error=SECJ0354E: Could not get the name of the user whose uniqueId is {0} because of the following exception {1}.
  </MsgText>
  <Explanation>
    Internal Error.
  </Explanation>
  <UserResponse>
    Make sure that the user is valid. Contact your service representative if the problem persists.
  </UserResponse>
</Message>
<Message ID="SECJ0166W" severity="W" prefix="yes">
  <MsgText pgmKey="security.policy.appparser.expandgrant" varFormat="Java">
    security.policy.appparser.expandgrant=SECJ0166W: Expand exception occurred. Skip the grant entry in app.policy file. The exception is {0}.
  </MsgText>
  <Explanation>
    An expand exception occurred while expanding the grant entry in the pplication policy file.
  </Explanation>
  <UserResponse>
    Check the grant entry syntax in your application policy file (app.policy or was.policy). To identify which policy file has a problem, enable security trace for the component com.ibm.ws.security.policy.*. The trace.log file will contain the policy name.
  </UserResponse>
</Message>
<Message ID="SECJ7115I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.Naming.Console.Path" varFormat="Java">
    security.configrpt.Naming.Console.Path=SECJ7115I: CORBA Naming Console Path
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ6152I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.logout.success.audit" varFormat="Java">
    security.audit.logout.success.audit=SECJ6152I: Form Logout.
  </MsgText>
  <Explanation>
    The HTTP session is cleaned up after form logout.
  </Explanation>
  <UserResponse>
    No action is required.
  </UserResponse>
</Message>
<Message ID="SECJ0414W" severity="W" prefix="yes">
  <MsgText pgmKey="security.checkProviderList.warning" varFormat="Java">
    security.checkProviderList.warning=SECJ0414W: FIPS is enabled but the IBMJCEFIPS provider is not active in the java.security file.  To ensure FIPS algorithms usage for all WebSphere Application Server process types, uncomment the IBMJCEFIPS provider in the java.security file, ahead of the IBMJCE, and renumber the provider list in sequential order.
  </MsgText>
  <Explanation>
    When the server is running in FIPS mode the IBMJCEFIPS provider should be in the java.security file.
  </Explanation>
  <UserResponse>
    The java.security file needs to be changed to include the IBMJCEFIPS provider in the provider list before the IBMJCE provider.
  </UserResponse>
</Message>
<Message ID="SECJ6124I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.basic.missing.audit" varFormat="Java">
    security.audit.basic.missing.audit=SECJ6124I: Basic authentication data is missing.  Send out 401 challenge.
  </MsgText>
  <Explanation>
    The authentication failed because there is no user id and password information in the HTTP header. WebSphere Application Server will send a 401 challenge to the web client.
  </Explanation>
  <UserResponse>
    No action is required.
  </UserResponse>
</Message>
<Message ID="SECJ0300W" severity="W" prefix="yes">
  <MsgText pgmKey="security.policy.parser.filenotexist" varFormat="Java">
    security.policy.parser.filenotexist=SECJ0300W: The file or directory ( {0} ) does not exist.
  </MsgText>
  <Explanation>
    The specified file or directory does not exist.
  </Explanation>
  <UserResponse>
    Verify that the policy files, xml files(resource.xml) to confirm the class path specified in them are correct.
  </UserResponse>
</Message>
<Message ID="SECJ6137I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.csi.session.nocred.audit" varFormat="Java">
    security.audit.csi.session.nocred.audit=SECJ6137I: ASSOC_ACCEPT message is illegal at the target.  The client might not be using correct configuration.
  </MsgText>
  <Explanation>
    The message type ASSOC_ACCEPT should not be received at the target server.  This might occur due to an exception that occurred on the client which caused a mixup.
  </Explanation>
  <UserResponse>
    Check the client configuration to ensure that there&apos;s nothing out of the ordinary that might be causing an exception to occur.
  </UserResponse>
</Message>
<Message ID="SECJ0309I" severity="I" prefix="yes">
  <MsgText pgmKey="security.manager.disabled" varFormat="Java">
    security.manager.disabled=SECJ0309I: Java 2 Security is disabled.
  </MsgText>
  <Explanation>
    Java 2 Security Manager is NOT installed.
  </Explanation>
  <UserResponse>
    None, informational only.
  </UserResponse>
</Message>
<Message ID="SECJ4028E" severity="E" prefix="yes">
  <MsgText pgmKey="security.j2c.unexpectedExceptionNewURL" varFormat="Java">
    security.j2c.unexpectedExceptionNewURL=SECJ4028E: Unexpected Exception caught in new URL {0} : Exception is {1}
  </MsgText>
  <Explanation>
    Unexpected exception occurred while creating a new URL.
  </Explanation>
  <UserResponse>
    Check the specified URL. Contact your service representative with exception stack trace information present in the error log.
  </UserResponse>
</Message>
<Message ID="SECJ7101I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.No.Operator.Role.User" varFormat="Java">
    security.configrpt.No.Operator.Role.User=SECJ7101I: No Operator user or group
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7825E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.checkHostPort.SECJ7825E" varFormat="Java">
    security.admintask.checkHostPort.SECJ7825E=SECJ7825E: The number of LDAP hosts in the ldapHost parameter needs to equal the number of port numbers in the ldapPort parameter.
  </MsgText>
  <Explanation>
    When configuring multiple LDAP hosts there needs to be a port number provided for each hostname in the list of LDAP hosts.
  </Explanation>
  <UserResponse>
    Ensure there is a port for each LDAP host in the list of LDAP hosts.
  </UserResponse>
</Message>
<Message ID="SECJ0290W" severity="W" prefix="yes">
  <MsgText pgmKey="security.servcomp.remove.DenyAllRole" varFormat="Java">
    security.servcomp.remove.DenyAllRole=SECJ0290W: All subjects assigned to Special role DenyAllRole for application {0} are removed.
  </MsgText>
  <Explanation>
    All subjects assigned to Special role DenyAllRole for the specified application are removed.
  </Explanation>
  <UserResponse>
    None. This is a warning.
  </UserResponse>
</Message>
<Message ID="SECJ7430E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.CannotConfigEncryption" varFormat="Java">
    security.admintask.CannotConfigEncryption=SECJ7430E: Cannot configure encryption when enable value is false.
  </MsgText>
  <Explanation>
    Encryption for audit cannot be configured when the enable value is false.  Either use true for enable or, if the intention is to disable/delete encryption, use the appropriate disable/delete tasks.
  </Explanation>
  <UserResponse>
    Specify true as the enable value if the intention is to configure encryption for audit.
  </UserResponse>
</Message>
<Message ID="SECJ7455I" severity="I" prefix="yes">
  <MsgText pgmKey="security.admintask.LogNotEncrypted" varFormat="Java">
    security.admintask.LogNotEncrypted=SECJ7455I: The Binary Audit Log specified is not encrypted.
  </MsgText>
  <Explanation>
    The Binary Audit Log specified has not been encrypted.
  </Explanation>
  <UserResponse>
    none
  </UserResponse>
</Message>
<Message ID="SECJ7355E" severity="E" prefix="yes">
  <MsgText pgmKey="security.profiletask.FailedAddAdminId" varFormat="Java">
    security.profiletask.FailedAddAdminId=SECJ7355E: Failed to add the adminID to the user registry object
  </MsgText>
  <Explanation>
    Failed to add the adminID to the user registry object
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ6140I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.csi.gss.format.audit" varFormat="Java">
    security.audit.csi.gss.format.audit=SECJ6140I: Invalid GSS security token format.
  </MsgText>
  <Explanation>
    GSS security context token contains OID number that is not valid or authentication mechanism that is not valid.
  </Explanation>
  <UserResponse>
    No action required.
  </UserResponse>
</Message>
<Message ID="SECJ7712E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.identitySpecified.SECJ7712E" varFormat="Java">
    security.admintask.identitySpecified.SECJ7712E=SECJ7712E: Either use the server identity or specify a trusted identity not both.
  </MsgText>
  <Explanation>
    If user server identity is enabled a trusted identity and password should not be specified.
  </Explanation>
  <UserResponse>
    Specify either a trusted identity or enable user server identity.
  </UserResponse>
</Message>
<Message ID="SECJ6037E" severity="E" prefix="yes">
  <MsgText pgmKey="security.audit.event.factory.config.error" varFormat="Java">
    security.audit.event.factory.config.error=SECJ6037E: Configuration error: no audit event factories are defined.
  </MsgText>
  <Explanation>
    No Audit Event Factory implementations are found in the configuration.
  </Explanation>
  <UserResponse>
    Ensure that there is at least one audit event factory configured.
  </UserResponse>
</Message>
<Message ID="SECJ6049E" severity="E" prefix="yes">
  <MsgText pgmKey="security.audit.notify.config.error" varFormat="Java">
    security.audit.notify.config.error=SECJ6049E: Error in the audit notification configuration.
  </MsgText>
  <Explanation>
    Audit system failure policy set to WARN or FATAL, but notification configuration is not properly configured.
  </Explanation>
  <UserResponse>
    Ensure audit notification is configured.
  </UserResponse>
</Message>
<Message ID="SECJ7393E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.FilterNotConfigured" varFormat="Java">
    security.admintask.FilterNotConfigured=SECJ7393E: Audit specification not configured.
  </MsgText>
  <Explanation>
    The referenced audit specification does not exist in the audit.xml.
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7361E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.InvalidUniqueName" varFormat="Java">
    security.admintask.InvalidUniqueName=SECJ7361E: Non valid or no reference specified to uniquely identify this implementation.
  </MsgText>
  <Explanation>
    The uniqueName reference is a required field.
  </Explanation>
  <UserResponse>
    Verify that a valid reference has been specified for the uniqueName
  </UserResponse>
</Message>
<Message ID="SECJ0296E" severity="E" prefix="yes">
  <MsgText pgmKey="security.sa.chk.password" varFormat="Java">
    security.sa.chk.password=SECJ0296E: Error checking password for user :{0}. The exception is {1}.
  </MsgText>
  <Explanation>
    com.ibm.websphere.security.PasswordCheckFailedException occurred when checking the password for specified user.
  </Explanation>
  <UserResponse>
    Verify that the password for the specified user.
  </UserResponse>
</Message>
<Message ID="SECJ7152I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.CertExpMonitor" varFormat="Java">
    security.configrpt.core.CertExpMonitor=SECJ7152I: Manage certificate expiration
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7787I" severity="I" prefix="yes">
  <MsgText pgmKey="security.admintask.multidomain.globalSecurity.SECJ7787I" varFormat="Java">
    security.admintask.multidomain.globalSecurity.SECJ7787I=SECJ7787I: The {0} member is being associated with the global security configuration.
  </MsgText>
  <Explanation>
    This message is for informational purposes only.
  </Explanation>
  <UserResponse>
    No action is required.
  </UserResponse>
</Message>
<Message ID="SECJ7096I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.Console.Role.Name" varFormat="Java">
    security.configrpt.Console.Role.Name=SECJ7096I: Administrative Role Name
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ4010E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaas.missingToken" varFormat="Java">
    security.jaas.missingToken=SECJ4010E: Credential Token is null or empty array
  </MsgText>
  <Explanation>
    Credential token is missing.
  </Explanation>
  <UserResponse>
    Confirm that the necessary authentication data is passed.
  </UserResponse>
</Message>
<Message ID="SECJ7546E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.invalid.serviceName" varFormat="Java">
    security.admintask.invalid.serviceName=SECJ7546E: The service name {0} is not valid. It contains a slash character (/).
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    The service name contains the slash character. The service name is the first component of the Kerberos service principal name.
  </UserResponse>
</Message>
<Message ID="SECJ7356E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.InvalidActionType" varFormat="Java">
    security.admintask.InvalidActionType=SECJ7356E: Unsupported audit system failure action type
  </MsgText>
  <Explanation>
    The audit system failure action type provided is not supported.  Supported types are: WARN, NOWARN, and FATAL
  </Explanation>
  <UserResponse>
    Verify the audit system failure action type is correctly specified
  </UserResponse>
</Message>
<Message ID="SECJ7436E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.CannotRemoveAuditorPwd" varFormat="Java">
    security.admintask.CannotRemoveAuditorPwd=SECJ7436E: Empty value specified for auditorPwd. Cannot delete the auditorPwd when auditing is enabled.
  </MsgText>
  <Explanation>
    Auditing is enabled and requires an auditorId and auditorPwd.
  </Explanation>
  <UserResponse>
    Disable auditing before deleting the auditorPwd
  </UserResponse>
</Message>
<Message ID="SECJ0195E" severity="E" prefix="yes">
  <MsgText pgmKey="security.policy.filter.parserexception" varFormat="Java">
    security.policy.filter.parserexception=SECJ0195E: Caught ParserException while adding permission to the set of filtered permissions. The exception is {0}.
  </MsgText>
  <Explanation>
    ParserException occurred when adding permission to the set of filtered permissions.
  </Explanation>
  <UserResponse>
    Check the ParserException data.
  </UserResponse>
</Message>
<Message ID="SECJ7371E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.InvalidEventFactory" varFormat="Java">
    security.admintask.InvalidEventFactory=SECJ7371E: Non valid or no reference specified for the audit event factory implementation.
  </MsgText>
  <Explanation>
    The eventFactory field is required.
  </Explanation>
  <UserResponse>
    Verify that a valid reference has been specified for the audit event factory implementation
  </UserResponse>
</Message>
<Message ID="SECJ0197E" severity="E" prefix="yes">
  <MsgText pgmKey="security.policy.perminstance.targetexception" varFormat="Java">
    security.policy.perminstance.targetexception=SECJ0197E: Caught Invocation TargetException while constructing the permission object. This exception might be due to syntax error in the policy file. The exception is {0}.
  </MsgText>
  <Explanation>
    Invocation TargetException occurred while constructing the permission object.
  </Explanation>
  <UserResponse>
    Check the exception.
  </UserResponse>
</Message>
<Message ID="SECJ0117E" severity="E" prefix="yes">
  <MsgText pgmKey="security.web.loginFail" varFormat="Java">
    security.web.loginFail=SECJ0117E: Form login failed for user {0}
  </MsgText>
  <Explanation>
    The user could not be authenticated by the FormLogin Servlet.  The user id or password might have been entered incorrectly.  The user might not exist in the user registry that WebSphere is configured to authenticate to.
  </Explanation>
  <UserResponse>
    Verify that the user id and password are entered correctly. Consult with the administrator of the user registry if the problem persists.
  </UserResponse>
</Message>
<Message ID="SECJ6234I" severity="I" prefix="yes">
  <MsgText pgmKey="security.zos.saf.idprop.enabled.info" varFormat="Java">
    security.zos.saf.idprop.enabled.info=SECJ6234I: The SAF feature for distributed identity mapping is in effect.
  </MsgText>
  <Explanation>
    The SAF feature for distributed identity mapping is in effect. Distributed users will be mapped to SAF users using the filters defined in the SAF RACMAP profiles.
  </Explanation>
  <UserResponse>
    No user action is required.
  </UserResponse>
</Message>
<Message ID="SECJ7022I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.interceptors" varFormat="Java">
    security.configrpt.core.interceptors=SECJ7022I: Interceptors
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ4005E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaas.noCORBAToken" varFormat="Java">
    security.jaas.noCORBAToken=SECJ4005E: No CORBA Credentials for credential token
  </MsgText>
  <Explanation>
    JAAS Login returned null credential while invoking login() with token. There is no CORBA Credential.
  </Explanation>
  <UserResponse>
    login returned null Credential. Check the user application how it authenticate. Enabling security debug trace will provide the details.(com.ibm.ws.security.auth.* )
  </UserResponse>
</Message>
<Message ID="SECJ0216E" severity="E" prefix="yes">
  <MsgText pgmKey="security.init.wccmjaas.setcfgerror" varFormat="Java">
    security.init.wccmjaas.setcfgerror=SECJ0216E: An exception occurred when setting JAAS login provider configuration class to {0}. The exception is {1}.
  </MsgText>
  <Explanation>
    WebSphere provides an implementation of the javax.security.auth.login.Configuration class.  This class could not be set at server startup.
  </Explanation>
  <UserResponse>
    Configuration.class might not be present.  This is an internal error.
  </UserResponse>
</Message>
<Message ID="SECJ6012I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.service.optional.audit" varFormat="Java">
    security.audit.service.optional.audit=SECJ6012I: Security Auditing is optional.
  </MsgText>
  <Explanation>
    This audit message indicates that security auditing records are optional.
  </Explanation>
  <UserResponse>
    No action is required if this is the desired setting.  Note that the intention of this auditing policy is not to suspend a business transaction when security auditing records cannot be saved.
  </UserResponse>
</Message>
<Message ID="SECJ0174W" severity="W" prefix="yes">
  <MsgText pgmKey="security.policy.sysextparser.ignoreperm" varFormat="Java">
    security.policy.sysextparser.ignoreperm=SECJ0174W: Permission entry {0} is being ignored
  </MsgText>
  <Explanation>
    In the system extension policy files, the permission entries with signatures are not supported in the current version.
  </Explanation>
  <UserResponse>
    Remove the signature values from the permission entry in the system extension policy file. (spi.policy or library.policy)
  </UserResponse>
</Message>
<Message ID="SECJ4029E" severity="E" prefix="yes">
  <MsgText pgmKey="security.j2c.unexpectedExceptionOpenURL" varFormat="Java">
    security.j2c.unexpectedExceptionOpenURL=SECJ4029E: Unexpected Exception caught in openStream URL {0} : Exception is {1}
  </MsgText>
  <Explanation>
    Unexpected Exception occurred while opening an URL.
  </Explanation>
  <UserResponse>
    Check the specified URL. Contact your service representative with exception stack trace information present in the error log.
  </UserResponse>
</Message>
<Message ID="SECJ0272E" severity="E" prefix="yes">
  <MsgText pgmKey="security.SecurityContext.setCreds" varFormat="Java">
    security.SecurityContext.setCreds=SECJ0272E: Error setting to system credentials.
  </MsgText>
  <Explanation>
    An unexpected exception occurred while restoring the original credentials.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7002I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.Security.Settings" varFormat="Java">
    security.configrpt.core.Security.Settings=SECJ7002I: Security Settings
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ4001E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaas.LoginFailure" varFormat="Java">
    security.jaas.LoginFailure=SECJ4001E: Login failed for {0}/{1} {2}
  </MsgText>
  <Explanation>
    Authentication can fail for many reasons.  The user or password might not have been entered correctly, misspelled for instance. The user account might not exist, might have expired, or be disabled. The password might have expired or require a change at first logon.  If WebSphere security is configured to use LDAP as the user registry, the WebSphere security LDAP user and group search filter configuration might not match what the LDAP directory expects.
  </Explanation>
  <UserResponse>
    Confirm that the user information (realm name, user name, password) is valid. Try authenticating the user directly to the configured user registry outside of WebSphere authentication to verify that the user and password are valid in the user registry.  The WebSphere information center documents additional user account requirements for specific user registries.
  </UserResponse>
</Message>
<Message ID="SECJ6001I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.service.required.audit" varFormat="Java">
    security.audit.service.required.audit=SECJ6001I: Security Auditing is required.
  </MsgText>
  <Explanation>
    This audit message indicates that security auditing records are required.
  </Explanation>
  <UserResponse>
    No action is required if this is the desired setting.  Note that the intention of this auditing policy is not to commit a business transaction unless the required security auditing records can be saved.
  </UserResponse>
</Message>
<Message ID="SECJ0128E" severity="E" prefix="yes">
  <MsgText pgmKey="security.web.ta.genexc" varFormat="Java">
    security.web.ta.genexc=SECJ0128E: An unexpected exception occurred during Trust Association. The exception is {0}.
  </MsgText>
  <Explanation>
    This refers to all other exceptions that can be possibly created by an interceptor, when validating trust with the reverse proxy server and when getting the authenticated user name,  aside from  WebTrustAssociationFailedException and WebTrustAssociationUserException.
  </Explanation>
  <UserResponse>
    Debug the problem from the stack trace that is printed together with this error message. You can also turn on the debug trace to get more information about the nature of the  exception.
  </UserResponse>
</Message>
<Message ID="SECJ7136I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.AuthMechanism.Expiration" varFormat="Java">
    security.configrpt.core.AuthMechanism.Expiration=SECJ7136I: Authentication expiration
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0087E" severity="E" prefix="yes">
  <MsgText pgmKey="security.web.internalservererror" varFormat="Java">
    security.web.internalservererror=SECJ0087E: Internal Server Error
  </MsgText>
  <Explanation>
    The HttpServletResponse indicates an Internal Server Error has occurred.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7340E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.ExceptionLDAPConnect" varFormat="Java">
    security.admintask.ExceptionLDAPConnect=SECJ7340E: Exception raised trying to connect to LDAP server
  </MsgText>
  <Explanation>
    Exception raised connecting to the LDAP server
  </Explanation>
  <UserResponse>
    Verify input parameters are correct
  </UserResponse>
</Message>
<Message ID="SECJ7026I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.requiresSSL" varFormat="Java">
    security.configrpt.core.requiresSSL=SECJ7026I: Requires SSL
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ6100I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.service.bad.uri.denied.audit" varFormat="Java">
    security.audit.service.bad.uri.denied.audit=SECJ6100I: Invalid URI.
  </MsgText>
  <Explanation>
    A web request is rejected because it contains a URI name that is not valid.
  </Explanation>
  <UserResponse>
    Incorrect URI might be a simple user error or an indication of potential threat where malicious users explore the weakness of web applications. You might perform a correlation analysis of security auditing events.
  </UserResponse>
</Message>
<Message ID="SECJ7133I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.Certificate.Management" varFormat="Java">
    security.configrpt.Certificate.Management=SECJ7133I: Certificate Management
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7711E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.sslConfigNotValid.SECJ7711E" varFormat="Java">
    security.admintask.sslConfigNotValid.SECJ7711E=SECJ7711E: SSL configuration is not valid.
  </MsgText>
  <Explanation>
    Valid ssl configuration not supplied.
  </Explanation>
  <UserResponse>
    Ensure that the ssl configuration is exists.
  </UserResponse>
</Message>
<Message ID="SECJ0052E" severity="E" prefix="yes">
  <MsgText pgmKey="security.authz.failed.invalidcreds" varFormat="Java">
    security.authz.failed.invalidcreds=SECJ0052E: Authorization failed while invoking ({0}){1} {2} - invalid credentials
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7182I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.hoverHelpKey" varFormat="Java">
    security.configrpt.core.hoverHelpKey=SECJ7182I: Hover help key
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0252E" severity="E" prefix="yes">
  <MsgText pgmKey="security.getting.remote.server.error" varFormat="Java">
    security.getting.remote.server.error=SECJ0252E: Error getting remote security server. The exception is {0}.
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ4060W" severity="W" prefix="yes">
  <MsgText pgmKey="security.j2c.missingParameter" varFormat="Java">
    security.j2c.missingParameter=SECJ4060W: Cannot find parameter {0} that might be needed by Mapping LoginModules.
  </MsgText>
  <Explanation>
    Either the custom properties HashMap or the authentication data alias was not defined.
  </Explanation>
  <UserResponse>
    This might not be a problem depending on the particilar mapping LoginModules.
  </UserResponse>
</Message>
<Message ID="SECJ6136I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.csi.session.expired.audit" varFormat="Java">
    security.audit.csi.session.expired.audit=SECJ6136I: Session or token expired.
  </MsgText>
  <Explanation>
    The security token in the security context has expired.
  </Explanation>
  <UserResponse>
    Typically token has a finite expiration time and this condition might be normal.
  </UserResponse>
</Message>
<Message ID="SECJ6032E" severity="E" prefix="yes">
  <MsgText pgmKey="security.audit.emitter.binary.log.error" varFormat="Java">
    security.audit.emitter.binary.log.error=SECJ6032E: Failure writing audit record out to the binary log.  Exception = {0}.
  </MsgText>
  <Explanation>
    IO error writing the audit record to the binary log.
  </Explanation>
  <UserResponse>
    Verify the log exists.   Examine the exception for the cause of the problem.
  </UserResponse>
</Message>
<Message ID="SECJ7829E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.globalfedoption.globalnonfedappset.SECJ7829E" varFormat="Java">
    security.admintask.globalfedoption.globalnonfedappset.SECJ7829E=SECJ7829E: Cannot set the user registry of an application security domain to use the federated repository when the global federated repository option is enabled and the global security domain is not using the federated repository.
  </MsgText>
  <Explanation>
    The global federated repository option has been enabled in the application security domain.  The global security domain must be configured with a federated repository as the active user registry in order to make the federated repository the active repository of the application security domain.
  </Explanation>
  <UserResponse>
    Either the global security domain should be configured with a federated repository as the active user registry or the application security domain should elect not to use the global federated repository option.  This should be done before attempting to set the active user registry to use the federated repository in the application security domain.
  </UserResponse>
</Message>
<Message ID="SECJ0329E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.unsupportedclass" varFormat="Java">
    security.registry.unsupportedclass=SECJ0329E: The registry implementation file {0} is not a instance of the supported user registries.
  </MsgText>
  <Explanation>
    This can happen when using custom registries and if they are not instances of UserRegistry or CustomRegistry.
  </Explanation>
  <UserResponse>
    Make sure you implement the UserRegistry interface for your custom registry.
  </UserResponse>
</Message>
<Message ID="SECJ0196W" severity="W" prefix="yes">
  <MsgText pgmKey="security.policy.wccm.custom.permission" varFormat="Java">
    security.policy.wccm.custom.permission=SECJ0196W: Custom permission {0} is being used in an application policy file {1}
  </MsgText>
  <Explanation>
    Custom permission is being used in an application policy file.
  </Explanation>
  <UserResponse>
    Make sure that it is all right to use a custom permission in an application policy file.
  </UserResponse>
</Message>
<Message ID="SECJ0160E" severity="E" prefix="yes">
  <MsgText pgmKey="security.wsaccessmanager.instantiationerror" varFormat="Java">
    security.wsaccessmanager.instantiationerror=SECJ0160E: Can not instantiate class {0}
  </MsgText>
  <Explanation>
    The vendor specified Authorization Table class could not be instantiated.
  </Explanation>
  <UserResponse>
    Make sure that the vendor&apos;s implementation of Authorization Table as specified in the sas.server.props file could be loaded and instantiated.
  </UserResponse>
</Message>
<Message ID="SECJ0206E" severity="E" prefix="yes">
  <MsgText pgmKey="security.init.mbeanerror" varFormat="Java">
    security.init.mbeanerror=SECJ0206E: Error creating or registering {0} mBean. The exception is {1}
  </MsgText>
  <Explanation>
    An unexpected exception occurred when trying to create or register an mBean.
  </Explanation>
  <UserResponse>
    There might be a problem with the configuration.  The exception might include details.
  </UserResponse>
</Message>
<Message ID="SECJ7809E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.cannotRemoveDomain.SECJ7809E" varFormat="Java">
    security.admintask.cannotRemoveDomain.SECJ7809E=SECJ7809E: The {0} domain can not be delete because a the cell is a mixed version setup.
  </MsgText>
  <Explanation>
    The cell is in mixed version setup.  The special security domain can not be removed.
  </Explanation>
  <UserResponse>
    This operation can not be performed in the current configuration.
  </UserResponse>
</Message>
<Message ID="SECJ7171I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.minutes" varFormat="Java">
    security.configrpt.minutes=SECJ7171I: minutes
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ6015I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.service.event.default.audit" varFormat="Java">
    security.audit.service.event.default.audit=SECJ6015I: AuditEvent = {0}, AuditEventFactory Name = {1}.
  </MsgText>
  <Explanation>
    This message is intended to be used by the defaultAuditServiceProviderImpl sendEvent method only.
  </Explanation>
  <UserResponse>
    No action required.
  </UserResponse>
</Message>
<Message ID="SECJ6143I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.csi.idassertion.failure.audit" varFormat="Java">
    security.audit.csi.idassertion.failure.audit=SECJ6143I: Authentication failed.
  </MsgText>
  <Explanation>
    Could not validate Client Authentication Token or Client Certificates during Identity Assertion.
  </Explanation>
  <UserResponse>
    No action is required.
  </UserResponse>
</Message>
<Message ID="SECJ7275I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.Cookie.Protection" varFormat="Java">
    security.configrpt.core.Cookie.Protection=SECJ7275I: Cookie Protection
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0125E" severity="E" prefix="yes">
  <MsgText pgmKey="security.web.ta.loadclasserr" varFormat="Java">
    security.web.ta.loadclasserr=SECJ0125E: Trust Association Init Unable to load Trust Association class {0}.
  </MsgText>
  <Explanation>
    A ClassNotFoundException occurred when trying to load the subject class.
  </Explanation>
  <UserResponse>
    Verify that the appropriate Trust Association classes are installed and the class path is correct.
  </UserResponse>
</Message>
<Message ID="SECJ6027E" severity="E" prefix="yes">
  <MsgText pgmKey="security.audit.retrieve.signer.error" varFormat="Java">
    security.audit.retrieve.signer.error=SECJ6027E: Exception while retrieving the signer information from the audit signer certificate. Exception = {0}.
  </MsgText>
  <Explanation>
    A failure occurred while retrieving the audit signer certificate.
  </Explanation>
  <UserResponse>
    Examine the exception for the cause of the problem.  Ensure that the signer certificate exists.
  </UserResponse>
</Message>
<Message ID="SECJ7244I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.nonceCacheTimeout" varFormat="Java">
    security.configrpt.core.nonceCacheTimeout=SECJ7244I: Nonce cache timeout
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0379E" severity="E" prefix="yes">
  <MsgText pgmKey="security.sambean.noltpaserver" varFormat="Java">
    security.sambean.noltpaserver=SECJ0379E: Cannot get LTPAServer in the security MBean.
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ6028E" severity="E" prefix="yes">
  <MsgText pgmKey="security.audit.cert.encode.error" varFormat="Java">
    security.audit.cert.encode.error=SECJ6028E: Exception retrieving a certificates&apos;&apos;s encoded bytes UTF-8 format.  Exception = {0}.
  </MsgText>
  <Explanation>
    Certificate encoding error.
  </Explanation>
  <UserResponse>
    Examine the exception for the cause of the problem.
  </UserResponse>
</Message>
<Message ID="SECJ7727E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.unsetActiveUserRegistry.SECJ7727E" varFormat="Java">
    security.admintask.unsetActiveUserRegistry.SECJ7727E=SECJ7727E: Unable to unset the activeUserRegistry attribute when global security is enabled.
  </MsgText>
  <Explanation>
    The activeUserRegistry attribute must point to a user registry object when global security is enabled.
  </Explanation>
  <UserResponse>
    Ensure global security is not enables when changing unsetting the activeUserRegistry.
  </UserResponse>
</Message>
<Message ID="SECJ6135I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.csi.session.conflict.audit" varFormat="Java">
    security.audit.csi.session.conflict.audit=SECJ6135I: Session does not exist on server.
  </MsgText>
  <Explanation>
    The client context id is inconsistent with session state.
  </Explanation>
  <UserResponse>
    This problem should be analyzed to determine whether it was due to program or operational error or due to spoofing attempt.
  </UserResponse>
</Message>
<Message ID="SECJ0066E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.impl.stopped" varFormat="Java">
    security.registry.impl.stopped=SECJ0066E: registry impl object has been stopped
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7407E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.NoCertKeyFileTypeValue" varFormat="Java">
    security.admintask.NoCertKeyFileTypeValue=SECJ7407E: No value was specified for the key file type for the certificate to import
  </MsgText>
  <Explanation>
    When selecting to import an existing certificate, a key file type for the certificate must be entered.
  </Explanation>
  <UserResponse>
    Supply a key file type for the certificate to import
  </UserResponse>
</Message>
<Message ID="SECJ0330E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.loadclass" varFormat="Java">
    security.registry.loadclass=SECJ0330E: The registry implementation file {0} cannot be loaded because of the following exception {1}
  </MsgText>
  <Explanation>
    This can happen when the specified custom registry cannot be loaded.
  </Explanation>
  <UserResponse>
    The custom registry implementation file should be in the class path as mentioned in the custom user registry section in the information center documentation. If this happens for WebSphere Application Server provided registries contact your service representative if the problem persists.
  </UserResponse>
</Message>
<Message ID="SECJ0274E" severity="E" prefix="yes">
  <MsgText pgmKey="security.get.initCtx" varFormat="Java">
    security.get.initCtx=SECJ0274E: Error getting Initial Naming Context. The exception is {0}.
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7125I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.Naming.Delete.Name" varFormat="Java">
    security.configrpt.Naming.Delete.Name=SECJ7125I: Delete
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7739E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.SPNEGOFilterExists" varFormat="Java">
    security.admintask.SPNEGOFilterExists=SECJ7739E: Filter object already exists.
  </MsgText>
  <Explanation>
    The specified object already exists. Unable to create another one.
  </Explanation>
  <UserResponse>
    Create the object with a unique name.
  </UserResponse>
</Message>
<Message ID="SECJ0312W" severity="W" prefix="yes">
  <MsgText pgmKey="security.policy.was.key" varFormat="Java">
    security.policy.was.key=SECJ0312W: {$Application} phrase should not include ${was.module.path} keyword.
  </MsgText>
  <Explanation>
    Syntax error in the policy file. ${Application} phrase should not include ${was.module.path} keyword. This entry is ignored.
  </Explanation>
  <UserResponse>
    Check the application policy file.
  </UserResponse>
</Message>
<Message ID="SECJ7148I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.keySetGroup" varFormat="Java">
    security.configrpt.core.keySetGroup=SECJ7148I: Key set groups
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ5000E" severity="E" prefix="yes">
  <MsgText pgmKey="security.sap.error.creating.opaque.token" varFormat="Java">
    security.sap.error.creating.opaque.token=SECJ5000E: The following exception occurred while creating the attribute propagation token: {0}
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ0410E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jacc.updated.task" varFormat="Java">
    security.jacc.updated.task=SECJ0410E: An exception occurred when updating the security policy information for application {0} to the JACC provider. The exception is {1}.
  </MsgText>
  <Explanation>
    Because of an exception, the security policy information might not have been updated to the provider during the application update.
  </Explanation>
  <UserResponse>
    Make sure that the provider is up and running and the JACC configuration is correct. Once the problem is fixed, one can also use the wsadmin tool to manually propagate the security policy information to the provider instead of reinstalling the application. See the information center documentation for more details on running this tool. If problem persists, contact your service representative.
  </UserResponse>
</Message>
<Message ID="SECJ6228E" severity="E" prefix="yes">
  <MsgText pgmKey="security.zos.saf.idprop.distributedUser.null" varFormat="Java">
    security.zos.saf.idprop.distributedUser.null=SECJ6228E: The distributed user name is null and will not be mapped not a SAF user.
  </MsgText>
  <Explanation>
    The distributed user name is null and will not be mapped not a SAF user.
  </Explanation>
  <UserResponse>
    Specify a valid distributed user name.
  </UserResponse>
</Message>
<Message ID="SECJ7028I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.realm" varFormat="Java">
    security.configrpt.core.realm=SECJ7028I: Realm
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7110I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.Moderator.Role.Group" varFormat="Java">
    security.configrpt.Moderator.Role.Group=SECJ7110I: Moderator Group
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ6230E" severity="E" prefix="yes">
  <MsgText pgmKey="security.zos.saf.idprop.distributedUser.tooLong" varFormat="Java">
    security.zos.saf.idprop.distributedUser.tooLong=SECJ6230E: The distributed user name exceeds the maximum length of {1}. The distributed user, {0}, will not be mapped to a SAF user.
  </MsgText>
  <Explanation>
    The distributed user name exceeds the maximum allowable length.
  </Explanation>
  <UserResponse>
    Specify a valid distributed user name.
  </UserResponse>
</Message>
<Message ID="SECJ0327E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.loadproperr" varFormat="Java">
    security.registry.loadproperr=SECJ0327E: Problem loading the registry properties file. The exception is {0}.
  </MsgText>
  <Explanation>
    Unexpected exception occurred when loading registry properties file.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7129I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.Certificate.Console.Name" varFormat="Java">
    security.configrpt.Certificate.Console.Name=SECJ7129I: Console Name for Certificate Management
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7781E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.spnego.noFilter.SECJ7781E" varFormat="Java">
    security.admintask.spnego.noFilter.SECJ7781E=SECJ7781E: Cannot enable SPNEGO Web authentication without defining any SPNEGO Web authentication filters.
  </MsgText>
  <Explanation>
    Cannot enable SPNEGO Web authentication without defined any SPNEGO Web authentication filter.
  </Explanation>
  <UserResponse>
    Create at least one SPNEGO Web authentication filter before enabled the SPENGO Web Authentication.
  </UserResponse>
</Message>
<Message ID="SECJ7740E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.SPNEGOFilterInvalidURL" varFormat="Java">
    security.admintask.SPNEGOFilterInvalidURL=SECJ7740E: The URLs specified is malformed.
  </MsgText>
  <Explanation>
    A MalformedURLException was encountered parsing one of the specified URLs.
  </Explanation>
  <UserResponse>
    Verify the URL syntax is correct.
  </UserResponse>
</Message>
<Message ID="SECJ7058I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.enableProtection" varFormat="Java">
    security.configrpt.core.enableProtection=SECJ7058I: Enable Protection
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7107I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.Console.Group" varFormat="Java">
    security.configrpt.Console.Group=SECJ7107I: Administrative Group Roles
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7228I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.No.Deployer.Role.User" varFormat="Java">
    security.configrpt.No.Deployer.Role.User=SECJ7228I: No Deployer user or group
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0075E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.unsupported.entrytype" varFormat="Java">
    security.registry.unsupported.entrytype=SECJ0075E: Unsupported entry type {0}
  </MsgText>
  <Explanation>
    This is an internal error.  A registry of the specified type could not be looked up.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ8044E" severity="E" prefix="yes">
  <MsgText pgmKey="security.saml.tai.notexist.SECJ8044E" varFormat="Java">
    security.saml.tai.notexist.SECJ8044E=SECJ8044E: SAML TAI configuration is not found.
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7761E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.dupType.SECJ7761E" varFormat="Java">
    security.admintask.dupType.SECJ7761E=SECJ7761E: Only specify one parameter, securityDomainName, resourceName, or securityRealmName.
  </MsgText>
  <Explanation>
    Only one parameter can be used at time either securityDomainName, resourceName, or securityRealmName.
  </Explanation>
  <UserResponse>
    Run the command and specify either securityDomainName, resourceName, or securityRealmName,
  </UserResponse>
</Message>
<Message ID="SECJ7071I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.keyFileFormat" varFormat="Java">
    security.configrpt.core.keyFileFormat=SECJ7071I: Key file format
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0355E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.isvalidgroup.error" varFormat="Java">
    security.registry.isvalidgroup.error=SECJ0355E: Validating the group {0} throws the following exception {1}.
  </MsgText>
  <Explanation>
    Internal Error.
  </Explanation>
  <UserResponse>
    Make sure that the group is valid. Contact your service representative if the problem persists.
  </UserResponse>
</Message>
<Message ID="SECJ0145E" severity="E" prefix="yes">
  <MsgText pgmKey="security.ssl.decode.error" varFormat="Java">
    security.ssl.decode.error=SECJ0145E: An unexpected exception occurred when decoding password in initial_ssl.properties
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ8053E" severity="E" prefix="yes">
  <MsgText pgmKey="security.saml.unsupport.version.SECJ8053E" varFormat="Java">
    security.saml.unsupport.version.SECJ8053E=SECJ8053E: The SAML TAI version in the IdP partner metadata file is not supported. It supports SAML version 2.0 only.
  </MsgText>
  <Explanation>
    The SAML TAI version in the IdP partner metadata file is not supported.
  </Explanation>
  <UserResponse>
    Use SAML version 2.0 in the IdP partner metadata file.
  </UserResponse>
</Message>
<Message ID="SECJ7118I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.Naming.Server" varFormat="Java">
    security.configrpt.Naming.Server=SECJ7118I: ServerId
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7137I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.appEnabled" varFormat="Java">
    security.configrpt.core.appEnabled=SECJ7137I: Application security
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0297E" severity="E" prefix="yes">
  <MsgText pgmKey="security.sa.chk.password.custom" varFormat="Java">
    security.sa.chk.password.custom=SECJ0297E: Error checking password for user :{0}. The exception is {1}.
  </MsgText>
  <Explanation>
    com.ibm.websphere.security.CustomRegitryException exception occurred when checking the password for specified user.
  </Explanation>
  <UserResponse>
    Verify that the password for the specified user.
  </UserResponse>
</Message>
<Message ID="SECJ7818I" severity="I" prefix="yes">
  <MsgText pgmKey="security.admintask.resourceRemovedFromSecurityDomain.SECJ7818I" varFormat="Java">
    security.admintask.resourceRemovedFromSecurityDomain.SECJ7818I=SECJ7818I: The resource {0} has been removed from the security domain {1} since the resource no longer exists.
  </MsgText>
  <Explanation>
    Once a resource is removed from the system, its association with any domain will also be removed.
  </Explanation>
  <UserResponse>
    No action is required.
  </UserResponse>
</Message>
<Message ID="SECJ7706E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.strategyTypeNotValid.SECJ7706E" varFormat="Java">
    security.admintask.strategyTypeNotValid.SECJ7706E=SECJ7706E: Authentication strategy type is not valid.
  </MsgText>
  <Explanation>
    Valid authentication strategy types are: REQUIRED, REQUISITE, SUFFICIENT, OTPIONAL.
  </Explanation>
  <UserResponse>
    Ensure that the authentication strategy type is a valid type.
  </UserResponse>
</Message>
<Message ID="SECJ7526I" severity="I" prefix="yes">
  <MsgText pgmKey="security.scanner.risk.app.security.ok" varFormat="Java">
    security.scanner.risk.app.security.ok=SECJ7526I: Application security is enabled. Application security enables security for the applications in your environment. This type of security provides application isolation and requirements for authenticating application users.
  </MsgText>
  <Explanation>
    Application security is enabled. Application security enables security for the applications in your environment. This type of security provides application isolation and requirements for authenticating application users.
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0302W" severity="W" prefix="yes">
  <MsgText pgmKey="security.wccmjaas.no.alias" varFormat="Java">
    security.wccmjaas.no.alias=SECJ0302W: No alias name for {0}.
  </MsgText>
  <Explanation>
    This configuration does not have any alias name.
  </Explanation>
  <UserResponse>
    No action is required. This is a warning message.
  </UserResponse>
</Message>
<Message ID="SECJ7373E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.InvalidBinaryRef" varFormat="Java">
    security.admintask.InvalidBinaryRef=SECJ7373E: Non valid reference to Binary File audit service provider implementation.
  </MsgText>
  <Explanation>
    Reference must be to a Binary File audit service provider implementation.
  </Explanation>
  <UserResponse>
    Verify that a valid reference has been specified to a Binary File implementation
  </UserResponse>
</Message>
<Message ID="SECJ0360E" severity="E" prefix="yes">
  <MsgText pgmKey="security.authn.failed.multiusers" varFormat="Java">
    security.authn.failed.multiusers=SECJ0360E: Authentication failed for {0} because multiple users matched the user.
  </MsgText>
  <Explanation>
    Authentication failed because multiple users were found in the registry with the same name.
  </Explanation>
  <UserResponse>
    When using LDAP, make sure that the user shortname is unique. For example, if &quot;uid&quot; is used as the shortname, make sure that the uid is unique in the registry.
  </UserResponse>
</Message>
<Message ID="SECJ0063E" severity="E" prefix="yes">
  <MsgText pgmKey="security.ltpa.credmap.failed.nullaccessid" varFormat="Java">
    security.ltpa.credmap.failed.nullaccessid=SECJ0063E: Credential mapping failed due to invalid access ID
  </MsgText>
  <Explanation>
    This is an internal error. Cannot get accessID from credential.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ6116I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.tai.mapping.audit" varFormat="Java">
    security.audit.tai.mapping.audit=SECJ6116I: Authentication failed becasue Trust Accosication Interceptor user name cannot be mapped to WebSphere Application Server user.
  </MsgText>
  <Explanation>
    The authentication via the specified Trust Association Interceptor failed because the asserted user name cannot be mapped to a valid WebSphere Application Server user.
  </Explanation>
  <UserResponse>
    If this problem persists, the mapping problem is likely to be caused either by incorrect TAI configuration or by TAI implementation.
  </UserResponse>
</Message>
<Message ID="SECJ7208I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.autoReplace" varFormat="Java">
    security.configrpt.core.autoReplace=SECJ7208I: Automatically replace expiring self-signed certificates
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ5014E" severity="E" prefix="yes">
  <MsgText pgmKey="security.ltpa.factory.init.error" varFormat="Java">
    security.ltpa.factory.init.error=SECJ5014E: Could not find the factory class {0} specified for this token.  The exception is {1}.
  </MsgText>
  <Explanation>
    The LTPA TokenFactory implementation is likely not present in the class path.
  </Explanation>
  <UserResponse>
    Ensure that the LTPA TokenFactory implementation is located in the WebSphere class path. Typically these implementations are put in the ${WAS_INSTALL_ROOT}/classes directory.
  </UserResponse>
</Message>
<Message ID="SECJ7534I" severity="I" prefix="yes">
  <MsgText pgmKey="security.scanner.risk.java2.ok" varFormat="Java">
    security.scanner.risk.java2.ok=SECJ7534I: Java 2 security is enabled. Java 2 security provides a policy-based, fine-grain access control mechanism that increases overall system integrity by checking for permissions before allowing access to certain protected system resources. Java 2 security guards access to system resources such as file I/O, sockets, and properties.
  </MsgText>
  <Explanation>
    Java 2 security is enabled. Java 2 security provides a policy-based, fine-grain access control mechanism that increases overall system integrity by checking for permissions before allowing access to certain protected system resources. Java 2 security guards access to system resources such as file I/O, sockets, and properties.
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0276E" severity="E" prefix="yes">
  <MsgText pgmKey="security.secsrv.basic.destroy" varFormat="Java">
    security.secsrv.basic.destroy=SECJ0276E: BasicAuthData credential is already destroyed. The exception is {0}.
  </MsgText>
  <Explanation>
    CredentialDestroyedException occurred while trying to get BasicAuthData. The credential was already destroyed.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ0099E" severity="E" prefix="yes">
  <MsgText pgmKey="security.mg.finderr.key" varFormat="Java">
    security.mg.finderr.key=SECJ0099E: Error finding method group for id {0}
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ0218E" severity="E" prefix="yes">
  <MsgText pgmKey="security.init.roleauthz.geterr" varFormat="Java">
    security.init.roleauthz.geterr=SECJ0218E: An exception was caught retrieving RoleBasedAuthorizer.  The exception is {0}.
  </MsgText>
  <Explanation>
    The Rolebased authorizer could not be retrieved due to an exception.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ0304E" severity="E" prefix="yes">
  <MsgText pgmKey="security.wsaccessmanage.get.reg" varFormat="Java">
    security.wsaccessmanage.get.reg=SECJ0304E: Cannot get user registry. The exception is {0}.
  </MsgText>
  <Explanation>
    Unexpected exception occurred when getting user registry.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7003I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.activeAuthMechanism" varFormat="Java">
    security.configrpt.core.activeAuthMechanism=SECJ7003I: Active authentication mechanism
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0108E" severity="E" prefix="yes">
  <MsgText pgmKey="security.sasconfig.registryattrs" varFormat="Java">
    security.sasconfig.registryattrs=SECJ0108E: Unexpected exception occurred when getting user registry or registry attributes.
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    Verify that the user registry has been configured in WebSphere properly.
  </UserResponse>
</Message>
<Message ID="SECJ7404E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.NoCertAliasValue" varFormat="Java">
    security.admintask.NoCertAliasValue=SECJ7404E: Missing value for new certificate alias name.
  </MsgText>
  <Explanation>
    No value was specified for the new certificate alias name.
  </Explanation>
  <UserResponse>
    Supply a value for the certificate alias name.
  </UserResponse>
</Message>
<Message ID="SECJ7452E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.SequenceSetOutOfOrder" varFormat="Java">
    security.admintask.SequenceSetOutOfOrder=SECJ7452E: Non valid sequence set specified: the beginning sequence number is greater than the ending sequence number.
  </MsgText>
  <Explanation>
    A non valid value was specified for the sequence set of audit records to report
  </Explanation>
  <UserResponse>
    Make sure that the starting sequence number is less than the ending sequence number.
  </UserResponse>
</Message>
<Message ID="SECJ0348E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.userdisplayname.notfound" varFormat="Java">
    security.registry.userdisplayname.notfound=SECJ0348E: Could not get the display name of the user {0}.
  </MsgText>
  <Explanation>
    Internal Error.
  </Explanation>
  <UserResponse>
    Make sure that the user is valid and has a display name. Contact your service representative if the problem persists.
  </UserResponse>
</Message>
<Message ID="SECJ0323E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.ldap.invalidID" varFormat="Java">
    security.registry.ldap.invalidID=SECJ0323E: Invalid LDAP user/group ID
  </MsgText>
  <Explanation>
    Using invalid user/group ID or the user/group ID is not a directory entry. The directory administration ID (root DN) is not a directory entry on most LDAP servers.
  </Explanation>
  <UserResponse>
    Verify that the user/group ID is a valid directory entry.
  </UserResponse>
</Message>
<Message ID="SECJ6147I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.csi.authn.failure.audit" varFormat="Java">
    security.audit.csi.authn.failure.audit=SECJ6147I: Authentication failed.
  </MsgText>
  <Explanation>
    Examine the exception for reason of failure.
  </Explanation>
  <UserResponse>
    No action is required.
  </UserResponse>
</Message>
<Message ID="SECJ0418I" severity="I" prefix="yes">
  <MsgText pgmKey="security.registry.ldap.connect.audit" varFormat="Java">
    security.registry.ldap.connect.audit=SECJ0418I: Cannot connect to the LDAP server {0}.
  </MsgText>
  <Explanation>
    Security is unable to connect to some target Lightweight Directory Access Protocol (LDAP) servers, which  might prevent future failover.
  </Explanation>
  <UserResponse>
    If you need to bring up additional servers for failover, verify that the required LDAP server is running.
  </UserResponse>
</Message>
<Message ID="SECJ7709E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.authLevelNotValid.SECJ7709E" varFormat="Java">
    security.admintask.authLevelNotValid.SECJ7709E=SECJ7709E: Authentication level is not valid.
  </MsgText>
  <Explanation>
    Valid authentication levels are: Never, Supported, Required.
  </Explanation>
  <UserResponse>
    Ensure that the authentication level is valid.
  </UserResponse>
</Message>
<Message ID="SECJ7021I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.enableTrust" varFormat="Java">
    security.configrpt.core.enableTrust=SECJ7021I: Enable trust association
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0120I" severity="I" prefix="yes">
  <MsgText pgmKey="security.web.ta.loadint" varFormat="Java">
    security.web.ta.loadint=SECJ0120I: Trust Association Init loaded {0} interceptor(s)
  </MsgText>
  <Explanation>
    Reports the number of Trust Association interceptors that have been added.
  </Explanation>
  <UserResponse>
    None, informational only.
  </UserResponse>
</Message>
<Message ID="SECJ0268E" severity="E" prefix="yes">
  <MsgText pgmKey="security.wsaccessmanager.classloading" varFormat="Java">
    security.wsaccessmanager.classloading=SECJ0268E: Problem loading class {0}, using default authorization table provided by WebSphere
  </MsgText>
  <Explanation>
    The Vendor specified Authorization Table could not be loaded successfully. Therefore, using WebSphere provided authorization table.
  </Explanation>
  <UserResponse>
    Check to make sure that the Vendor&apos;s implementation of Authorization Table is in the CLASSPATH and could be loaded.
  </UserResponse>
</Message>
<Message ID="SECJ0123E" severity="E" prefix="yes">
  <MsgText pgmKey="security.web.ta.classloaderr" varFormat="Java">
    security.web.ta.classloaderr=SECJ0123E: Trust Association Init Error retrieving class loader. Trust Association cannot be enabled.
  </MsgText>
  <Explanation>
    getClassLoader() operation returned null.
  </Explanation>
  <UserResponse>
    Verify that the appropriate Trust Association classes are installed and the class path is correct.
  </UserResponse>
</Message>
<Message ID="SECJ7521W" severity="W" prefix="yes">
  <MsgText pgmKey="security.scanner.risk.adminid.improve" varFormat="Java">
    security.scanner.risk.adminid.improve=SECJ7521W: Multiple Administrative user IDs are not configured. When WebSphere Application Server security is enabled, a single security ID the Administrator role is initially configured as the Security Server ID. Configuring multiple administrative user ids as Administrator can protect this server ID and enable more effective audit logging
  </MsgText>
  <Explanation>
    Multiple Administrative user IDs are not configured. When WebSphere Application Server security is enabled, a single security ID the Administrator role is initially configured as the Security Server ID. Configuring multiple administrative user ids as Administrator can protect this server ID and enable more effective audit logging
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ4062W" severity="W" prefix="yes">
  <MsgText pgmKey="security.j2c.mappingUnsuccessful" varFormat="Java">
    security.j2c.mappingUnsuccessful=SECJ4062W: Cannot find the credential information.
  </MsgText>
  <Explanation>
    WebSphere default principal/credential mapping function could not find the specified credential information.
  </Explanation>
  <UserResponse>
    This is most likely caused by incorrect authentication data configuration.
  </UserResponse>
</Message>
<Message ID="SECJ0283E" severity="E" prefix="yes">
  <MsgText pgmKey="security.secsrv.bind.registry" varFormat="Java">
    security.secsrv.bind.registry=SECJ0283E: Error binding User Registry. The exception is {0}.
  </MsgText>
  <Explanation>
    javax.naming.NamingException occurred while rebinding the user registry.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7146I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.keyManager" varFormat="Java">
    security.configrpt.core.keyManager=SECJ7146I: Key managers
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ6102I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.service.no.webattrs.audit" varFormat="Java">
    security.audit.service.no.webattrs.audit=SECJ6102I: Access to a web resource is allowed because no access control is required.
  </MsgText>
  <Explanation>
    Access to a web resource does not require access control because there is no servlet mapping.
  </Explanation>
  <UserResponse>
    The URI is not protected.  No action is required is this is the desired configuration.  Otherwise, proper security constraint should be added to the web application.
  </UserResponse>
</Message>
<Message ID="SECJ0041E" severity="E" prefix="yes">
  <MsgText pgmKey="security.NullLTPAConfig" varFormat="Java">
    security.NullLTPAConfig=SECJ0041E: Can&apos;t set Authentication Mechanism to LTPA when LTPAConfig is null
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7525W" severity="W" prefix="yes">
  <MsgText pgmKey="security.scanner.risk.admin.security.improve" varFormat="Java">
    security.scanner.risk.admin.security.improve=SECJ7525W: Administrative Security is disabled. Only users with specific rights can use the WebSphere Application Server administrative tools to perform any administrative operation. Note that other important security features listed might be reported as enabled, but they will not take effect until administrative security is activated. The settings include the authentication of users, the use of Secure Sockets Layer (SSL), and the choice of user account repository. In particular, application security, including authentication and role-based authorization, is not enforced unless administrative security is active.
  </MsgText>
  <Explanation>
    Administrative Security is disabled.  Note that other important security features listed might be reported as enabled, but they will not take effect until administrative security is activated. The settings include the authentication of users, the use of Secure Sockets Layer (SSL), and the choice of user account repository. In particular, application security, including authentication and role-based authorization, is not enforced unless administrative security is active.
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7055I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.establishTrustInClient" varFormat="Java">
    security.configrpt.core.establishTrustInClient=SECJ7055I: Establish trust in client
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7073I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.keyFilePassword" varFormat="Java">
    security.configrpt.core.keyFilePassword=SECJ7073I: Key file password
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7079I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.libraryFile" varFormat="Java">
    security.configrpt.core.libraryFile=SECJ7079I: Library file
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7390E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.EmitterExists" varFormat="Java">
    security.admintask.EmitterExists=SECJ7390E: An audit service provider implementation with this unique name is already configured.
  </MsgText>
  <Explanation>
    Cannot configure an audit service provider implementation with the same unique name as one that is already configured.
  </Explanation>
  <UserResponse>
    Specify a unique name for the new audit service provider implementation
  </UserResponse>
</Message>
<Message ID="SECJ7056I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.requiredQOP" varFormat="Java">
    security.configrpt.core.requiredQOP=SECJ7056I: Required Quality of protection (QoP) settings
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7024I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.singleSignon" varFormat="Java">
    security.configrpt.core.singleSignon=SECJ7024I: Single signon (SSO)
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7029I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.serverId" varFormat="Java">
    security.configrpt.core.serverId=SECJ7029I: Server user ID
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0367W" severity="W" prefix="yes">
  <MsgText pgmKey="security.init.ltpawithoutsso" varFormat="Java">
    security.init.ltpawithoutsso=SECJ0367W: Warning, LTPA is configured as the authentication mechanism but SSO is disabled. Web applications that use FormBased Login, including the WebSphere web based admin console, might not work correctly.
  </MsgText>
  <Explanation>
    SSO is required for FormBased logon to work in Web applications when LTPA is the authentication mechanism.
  </Explanation>
  <UserResponse>
    If this is the intended configuration then ignore this warning.  If this is not the intended configuration, then the enabled attribute of Single Sign-on element in the security.xml must be set to the true value.
  </UserResponse>
</Message>
<Message ID="SECJ4015E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaas.LoginModuleCommitError" varFormat="Java">
    security.jaas.LoginModuleCommitError=SECJ4015E: An unexpected exception occurred during the JAAS login commit action in Login Module {0}. The exception is {1}.
  </MsgText>
  <Explanation>
    Exception occurred while committing LoginModule
  </Explanation>
  <UserResponse>
    Check the application. Contact your service representative with exception stack trace information present in the error log if the problem persists.
  </UserResponse>
</Message>
<Message ID="SECJ0203I" severity="I" prefix="yes">
  <MsgText pgmKey="security.init.namingapp" varFormat="Java">
    security.init.namingapp=SECJ0203I: Naming application initialized successfully
  </MsgText>
  <Explanation>
    The Naming application initialized successfully
  </Explanation>
  <UserResponse>
    None. Informational only.
  </UserResponse>
</Message>
<Message ID="SECJ7010I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.enforceJava2Security" varFormat="Java">
    security.configrpt.core.enforceJava2Security=SECJ7010I: Java 2 security
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7238I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.krb5Realm" varFormat="Java">
    security.configrpt.core.krb5Realm=SECJ7238I: Kerberos realm name
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7166I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.location" varFormat="Java">
    security.configrpt.core.location=SECJ7166I: Path
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7019I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.simpleAuthConfig" varFormat="Java">
    security.configrpt.core.simpleAuthConfig=SECJ7019I: Simple authentication config
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ4049E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaas.create.credential" varFormat="Java">
    security.jaas.create.credential=SECJ4049E: Error creating credential from registry object. The exception is {0}.
  </MsgText>
  <Explanation>
    Unexpected exception occurred while creating and initializing the user registry.
  </Explanation>
  <UserResponse>
    Check the application and the registry set up. Contact your service representative if the problem persist.
  </UserResponse>
</Message>
<Message ID="SECJ7162I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.sslProtocol" varFormat="Java">
    security.configrpt.core.sslProtocol=SECJ7162I: SSL Protocol
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0258E" severity="E" prefix="yes">
  <MsgText pgmKey="security.swam.find.registry" varFormat="Java">
    security.swam.find.registry=SECJ0258E: Cannot find user registry. The exception is {0}
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ6125I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.basic.error.audit" varFormat="Java">
    security.audit.basic.error.audit=SECJ6125I: Basic authentication failed due to incorrect user id and/or password Will send a 401 challenge.
  </MsgText>
  <Explanation>
    The authentication failed because there the user id and password information in the HTTP header was incorrect. WebSphere Application Server will send a 401 challenge to the web client.
  </Explanation>
  <UserResponse>
    No action is required.
  </UserResponse>
</Message>
<Message ID="SECJ7249I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.enabledGssCredDelegate" varFormat="Java">
    security.configrpt.core.enabledGssCredDelegate=SECJ7249I: Enable delegation of Kerberos credentials
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ6217E" severity="E" prefix="yes">
  <MsgText pgmKey="security.zos.saf.delegation.service.error" varFormat="Java">
    security.zos.saf.delegation.service.error=SECJ6217E: Unable to create a SAF delegation credential for the SAF profile named &quot;{0}&quot; in application &quot;{1}&quot;.  The native service results information are: {2}.
  </MsgText>
  <Explanation>
    The security service was unable to create a delegation credential.  This failure is usually due to incorrect or missing APPLDATA associated with the EJBROLE profile associated with the application role.
  </Explanation>
  <UserResponse>
    Verify that the EJBROLE profile exists and is defined correctly.  If the profile is correct, use the information about the SAF service, and SAF service return codes to determine the cause of the failure.  If the problem persists, contact the IBM support center.
  </UserResponse>
</Message>
<Message ID="SECJ7037I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.policyConfigurationFactoryImplClassName" varFormat="Java">
    security.configrpt.core.policyConfigurationFactoryImplClassName=SECJ7037I: Policy configuration factory class name
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0251E" severity="E" prefix="yes">
  <MsgText pgmKey="security.getting.namingctx.error" varFormat="Java">
    security.getting.namingctx.error=SECJ0251E: Error getting Initial Naming Context. The exception is {0}.
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7539I" severity="I" prefix="yes">
  <MsgText pgmKey="security.scanner.risk.samples.ok" varFormat="Java">
    security.scanner.risk.samples.ok=SECJ7539I: WebSphere Application Server Sample Applications are not installed. WebSphere Application Server ships with examples to demonstrate various parts of WebSphere Application Server. These samples might be installed by default and are not intended for use in a production environment. Some of these samples can provide an intruder with information about your system.
  </MsgText>
  <Explanation>
    WebSphere Application Server Sample Applications are not installed. WebSphere Application Server ships with examples to demonstrate various parts of WebSphere Application Server. These samples might be installed by default and are not intended for use in a production environment. Some of these samples can provide an intruder with information about your system.
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0416I" severity="I" prefix="yes">
  <MsgText pgmKey="security.jacc.secpolicy.removed" varFormat="Java">
    security.jacc.secpolicy.removed=SECJ0416I: The security policy for application {0} is successfully removed from the JACC provider.
  </MsgText>
  <Explanation>
    This message is provided for information purposes only.
  </Explanation>
  <UserResponse>
    No user action is required.
  </UserResponse>
</Message>
<Message ID="SECJ8057W" severity="W" prefix="yes">
  <MsgText pgmKey="security.saml.at.global.security.SECJ8057W" varFormat="Java">
    security.saml.at.global.security.SECJ8057W=SECJ8057W: SAML TAI should be configured at the security domain level instead of global security.
  </MsgText>
  <Explanation>
    There is a security domain, but SAML TAI is configured at the global level.
  </Explanation>
  <UserResponse>
    Configure the SAML TAI at the domain level.
  </UserResponse>
</Message>
<Message ID="SECJ0404E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jacc.tools.object.null" varFormat="Java">
    security.jacc.tools.object.null=SECJ0404E: The {0} object is null.
  </MsgText>
  <Explanation>
    Could not get the object required for security policy propagation.
  </Explanation>
  <UserResponse>
    Make sure that the JACC provider properties are set correctly in the JACC configuration. Also make sure that all the provider classes are in the class path of all the servers.
  </UserResponse>
</Message>
<Message ID="SECJ7039I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.roleConfigurationFactoryImplClassName" varFormat="Java">
    security.configrpt.core.roleConfigurationFactoryImplClassName=SECJ7039I: Role configuration factory class name
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ4016E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaas.removePrinException" varFormat="Java">
    security.jaas.removePrinException=SECJ4016E: An unexpected exception occurred in Login Module {0} when removing principal {1} during cleanup. The exception is {2}
  </MsgText>
  <Explanation>
    Exception occurred while removing the principal.
  </Explanation>
  <UserResponse>
    Contact your service representative with exception stack trace information present in the error log.
  </UserResponse>
</Message>
<Message ID="SECJ6227W" severity="W" prefix="yes">
  <MsgText pgmKey="security.zos.saf.authen.kerb.map.failed.warning" varFormat="Java">
    security.zos.saf.authen.kerb.map.failed.warning=SECJ6227W: Authentication failed for kerberos principal {0}.  The native service results related to the authentication failure are: {1}.
  </MsgText>
  <Explanation>
    WebSphere was unable to map the kerberos prinicpal that was presented to a valid RACF user.
  </Explanation>
  <UserResponse>
    Verify that the kerberos principal is set to the KERBNAME value in the KERB segment of a valid RACF user.
  </UserResponse>
</Message>
<Message ID="SECJ0346E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.groupsecurityname.error" varFormat="Java">
    security.registry.groupsecurityname.error=SECJ0346E: Could not get the name of the group whose uniqueId is {0} because of the following exception {1}.
  </MsgText>
  <Explanation>
    Internal Error.
  </Explanation>
  <UserResponse>
    Make sure that the group is valid. Contact your service representative if the problem persists.
  </UserResponse>
</Message>
<Message ID="SECJ0209E" severity="E" prefix="yes">
  <MsgText pgmKey="security.init.wccmjaas.error" varFormat="Java">
    security.init.wccmjaas.error=SECJ0209E: An unexpected exception occurred when attempting to update the JAAS login configuration with WCCM JAAS configuration information. The exception is {0}
  </MsgText>
  <Explanation>
    The WCCM JAAS login configuration information could not be pushed to the JAAS configuration object.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7001I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.Value" varFormat="Java">
    security.configrpt.core.Value=SECJ7001I: Value
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7817I" severity="I" prefix="yes">
  <MsgText pgmKey="security.admintask.doesNotMatchGlobalValues.SECJ7817I" varFormat="Java">
    security.admintask.doesNotMatchGlobalValues.SECJ7817I=SECJ7817I: The parameter values entered do not match the values at the global security configuration (security.xml) for this registry. These values have been ignored and replaced with the values {0}, {1}, {2} from the global security configuration (security.xml) for this registry.
  </MsgText>
  <Explanation>
    Since the registry configuration should be consistent across all security configurations the values from the global security configuration are copied to the configuration.
  </Explanation>
  <UserResponse>
    No action is required.
  </UserResponse>
</Message>
<Message ID="SECJ7816I" severity="I" prefix="yes">
  <MsgText pgmKey="security.admintask.doesNotMatchGlobalValues.SECJ7816I" varFormat="Java">
    security.admintask.doesNotMatchGlobalValues.SECJ7816I=SECJ7816I: The parameter values entered do not match the values at the global security configuration (security.xml) for this registry. These values have been ignored and replaced with the values from the global security configuration (security.xml) for this registry.
  </MsgText>
  <Explanation>
    Since the registry configuration should be consistent across all security configurations the values from the global security configuration are copied to the configuration.
  </Explanation>
  <UserResponse>
    No action is required.
  </UserResponse>
</Message>
<Message ID="SECJ6029E" severity="E" prefix="yes">
  <MsgText pgmKey="security.audit.unsupported.encode.error" varFormat="Java">
    security.audit.unsupported.encode.error=SECJ6029E: Unsupported encoding exception raised.  Exception = {0}.
  </MsgText>
  <Explanation>
    Encoding error.
  </Explanation>
  <UserResponse>
    Examine the exception for the cause of the problem.
  </UserResponse>
</Message>
<Message ID="SECJ7447E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.IOErrorBinaryLog" varFormat="Java">
    security.admintask.IOErrorBinaryLog=SECJ7447E: Failure while reading the specified Binary Audit Log.  Either a pathname that is not valid was specified or the file is corrupted.
  </MsgText>
  <Explanation>
    Could not open or read the Binary Audit Log.
  </Explanation>
  <UserResponse>
    Check the pathname specified for the location of the Binary Audit Log.
  </UserResponse>
</Message>
<Message ID="SECJ7088I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.Security" varFormat="Java">
    security.configrpt.core.Security=SECJ7088I: Security
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0337E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.mapcertificate.notsupported" varFormat="Java">
    security.registry.mapcertificate.notsupported=SECJ0337E: The mapCertificate method is not supported.
  </MsgText>
  <Explanation>
    Internal Error.
  </Explanation>
  <UserResponse>
    Information purposes only.
  </UserResponse>
</Message>
<Message ID="SECJ6009E" severity="E" prefix="yes">
  <MsgText pgmKey="security.audit.service.factory.error" varFormat="Java">
    security.audit.service.factory.error=SECJ6009E: AuditEventFactory number {0} getActive() malfunction, Provider Exception = {1}.
  </MsgText>
  <Explanation>
    The getActive method in the spcified AuditEventFactory implementation failed.
  </Explanation>
  <UserResponse>
    Examine the exception for the cause of the problem.  If the problem was not related to incorrect configuration, then you need to consult with the vendor of the AuditEventFactory implementation.
  </UserResponse>
</Message>
<Message ID="SECJ7191I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.autoGenerate" varFormat="Java">
    security.configrpt.core.autoGenerate=SECJ7191I: Automatically generate keys
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7543W" severity="W" prefix="yes">
  <MsgText pgmKey="security.scanner.risk.other.role.all.improve" varFormat="Java">
    security.scanner.risk.other.role.all.improve=SECJ7543W: Special subject &quot;{0}&quot; is configured for one of the administrative roles.  It is not recommended to have AllAuthenticatedUsers specified for any of the administrative user roles.
  </MsgText>
  <Explanation>
    A special subject is configured for one of the administrative roles.  It is not recommended to have AllAuthenticatedUsers specified for any of the administrative user roles.
  </Explanation>
  <UserResponse>
    Remove the AllAuthenticatedUsers subject from any of the administrative user roles if applicable.
  </UserResponse>
</Message>
<Message ID="SECJ7270I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.useClaim" varFormat="Java">
    security.configrpt.core.useClaim=SECJ7270I: Use claim
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7815E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.doesNotMatchGlobalValues.SECJ7815E" varFormat="Java">
    security.admintask.doesNotMatchGlobalValues.SECJ7815E=SECJ7815E: The parameter values entered do not match the values at the global security configuration (security.xml) for this registry. Make sure the values match since this registry configuration should be consistent in all security configurations in the cell.
  </MsgText>
  <Explanation>
    The Federated Repository registry configuration should be consistent across all the security domains and should match the values at the global security configuration (security.xml).
  </Explanation>
  <UserResponse>
    Make sure that the parameter values for this task match the values at the global security configuration for this registry.
  </UserResponse>
</Message>
<Message ID="SECJ0397W" severity="W" prefix="yes">
  <MsgText pgmKey="security.jacc.uninstall.task.warning" varFormat="Java">
    security.jacc.uninstall.task.warning=SECJ0397W: Error removing information from the JACC provider for application {0}. The exception is {1}.
  </MsgText>
  <Explanation>
    Cannot delete the security policy information from the JACC provider because of the exception. This problem creates redundant information in the JACC provider.
  </Explanation>
  <UserResponse>
    Make sure that the JACC provider is properly configured and can be accessed. The JACC provider might have tools to remove this information.
  </UserResponse>
</Message>
<Message ID="SECJ7391E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.InvalidCustomProperty" varFormat="Java">
    security.admintask.InvalidCustomProperty=SECJ7391E: The custom properties have been invalidly specified.
  </MsgText>
  <Explanation>
    Custom properties must be specified as name-value pairs, separated by a comma, semicolon or space.
  </Explanation>
  <UserResponse>
    Enter a valid syntax for the custom properties
  </UserResponse>
</Message>
<Message ID="SECJ7799E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.spnego.errorDeleteAllFiters.SECJ7799E" varFormat="Java">
    security.admintask.spnego.errorDeleteAllFiters.SECJ7799E=SECJ7799E: Can not delete all SPNEGO filters because SPNEGO Web authentication is enabled.
  </MsgText>
  <Explanation>
    The SPNEGO Web authentication is enabled, it requires at least one SPNEGO filter.
  </Explanation>
  <UserResponse>
    Disable SPNEGO Web authentication before delete all SPNEGO filters.
  </UserResponse>
</Message>
<Message ID="SECJ4004E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaas.invalidToken" varFormat="Java">
    security.jaas.invalidToken=SECJ4004E: Login failed for credential token {0}
  </MsgText>
  <Explanation>
    JAAS Login failure occurred while invoking login() with token.
  </Explanation>
  <UserResponse>
    Check the user authenticate data is correct. Enabling security debug trace will provide the details.(com.ibm.ws.security.auth.* )
  </UserResponse>
</Message>
<Message ID="SECJ7378E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.MissingModifyParms" varFormat="Java">
    security.admintask.MissingModifyParms=SECJ7378E: No attributes specified on the modify command.
  </MsgText>
  <Explanation>
    No attributes were specified on the modify command.
  </Explanation>
  <UserResponse>
    Supply attribute(s) to modify on the audit object
  </UserResponse>
</Message>
<Message ID="SECJ7449E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.InvalidReportMode" varFormat="Java">
    security.admintask.InvalidReportMode=SECJ7449E: Non valid or empty value specified for the report mode.  Valid values are basic, complete or custom.  The default mode is basic.
  </MsgText>
  <Explanation>
    A non valid value was specified for the report mode.
  </Explanation>
  <UserResponse>
    Specify a non-empty or valid value for the report mode.
  </UserResponse>
</Message>
<Message ID="SECJ6118I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.cert.success.audit" varFormat="Java">
    security.audit.cert.success.audit=SECJ6118I: Authentication failed becasue Trust the client certificate cannot be mapped to WebSphere Application Server user.
  </MsgText>
  <Explanation>
    The authentication based on the X509 client certificate failed because the certificate user name cannot be mapped to a valid WebSphere Application Server user.
  </Explanation>
  <UserResponse>
    No action is required.
  </UserResponse>
</Message>
<Message ID="SECJ0375E" severity="E" prefix="yes">
  <MsgText pgmKey="security.ltpa.realm_mismatch" varFormat="Java">
    security.ltpa.realm_mismatch=SECJ0375E: Mismatch of realms during token validation.
  </MsgText>
  <Explanation>
    The realm in the token does not match the current realm.
  </Explanation>
  <UserResponse>
    This error can occur when a token is passed between one cell and another cell, and the realms do not match in these cells. If you are using LDAP, make sure that both cells use the same host name and port number.
  </UserResponse>
</Message>
<Message ID="SECJ7717E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.scopeMapped.SECJ7717E" varFormat="Java">
    security.admintask.scopeMapped.SECJ7717E=SECJ7717E: One or more resources are still mapped to the security configuration.  Not able to delete the security configuration at this time.
  </MsgText>
  <Explanation>
    At least one resource is still mapped to the security configuration.  The security configuration cannot be removed until there are no scopes mapped to it.
  </Explanation>
  <UserResponse>
    Ensure that there no now scopes mapped to the security configuration before deleting it.
  </UserResponse>
</Message>
<Message ID="SECJ7046I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.moduleClassName" varFormat="Java">
    security.configrpt.core.moduleClassName=SECJ7046I: Module class name
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0069E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.nosecurityname" varFormat="Java">
    security.registry.nosecurityname=SECJ0069E: Problem getting Security Name for privilege id: {0}. The exception is {1}.
  </MsgText>
  <Explanation>
    Cannot find a name for the specified SID in the Windows user registry.This can occur if a network time-out prevents the function from finding the name. It also occurs for SIDs that have no corresponding account name, such as a logon SID that identifies a logon session
  </Explanation>
  <UserResponse>
    WebSphere might still have a reference to the user in the authorization table but, that user might have been removed from the Windows user registry.  If you know the user, remove it from any resource protection permissions in WebSphere.  If the user is still valid, then it needs to be recreated in the Windows user registry and then reassigned to proper resource permissions in WebSphere.
  </UserResponse>
</Message>
<Message ID="SECJ8048E" severity="E" prefix="yes">
  <MsgText pgmKey="security.saml.sso.is.null.SECJ8048E" varFormat="Java">
    security.saml.sso.is.null.SECJ8048E=SECJ8048E: More than one SSO entry. You must specify the ssoId parameter.
  </MsgText>
  <Explanation>
    You must specify the ssoId because the SAML TAI attributes have more than one SSO entry.
  </Explanation>
  <UserResponse>
    Specify a ssoId number that exists.
  </UserResponse>
</Message>
<Message ID="SECJ6141I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.csi.failure.audit" varFormat="Java">
    security.audit.csi.failure.audit=SECJ6141I: Authentication failed due to internal error.
  </MsgText>
  <Explanation>
    Authentication failed due to internal error.
  </Explanation>
  <UserResponse>
    No action required.
  </UserResponse>
</Message>
<Message ID="SECJ7116I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.Naming.Read.Name" varFormat="Java">
    security.configrpt.Naming.Read.Name=SECJ7116I: Read
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0358E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.isvaliduser.error" varFormat="Java">
    security.registry.isvaliduser.error=SECJ0358E: Validating the user {0} throws the following exception {1}.
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7785E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.missingParameter.krb5ConfigAndSecurity.SECJ7785E" varFormat="Java">
    security.admintask.missingParameter.krb5ConfigAndSecurity.SECJ7785E=SECJ7785E: The {0} is missing in the Kerberos configuration file {1} and the Kerberos authentication mechanism object.
  </MsgText>
  <Explanation>
    The entry is not found in the Kerberos configuration file and the Kerberos authentication object.
  </Explanation>
  <UserResponse>
    Add the entry in the Kerberos configuration file or specify this entry.
  </UserResponse>
</Message>
<Message ID="SECJ0156E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registryimpl.initerr" varFormat="Java">
    security.registryimpl.initerr=SECJ0156E: Unable to initialize user registry class {0} for type {1} due to exception: {2}
  </MsgText>
  <Explanation>
    The WebSphere security code couldn&apos;t find, load, or had problems loading the user registry class.
  </Explanation>
  <UserResponse>
    The exception mentioned in the message should provide additional clues including the class or file that could not be found or loaded.  Verify that the mentioned file exists in the correct directory and PATH.
  </UserResponse>
</Message>
<Message ID="SECJ4021E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaas.duplicateCORBAAttribute" varFormat="Java">
    security.jaas.duplicateCORBAAttribute=SECJ4021E: CORBA: Duplicate Attribute Type: {0} {1}
  </MsgText>
  <Explanation>
    CORBA credential has duplicate attributes.
  </Explanation>
  <UserResponse>
    Contact your service representative with exception stack trace information present in the error log.
  </UserResponse>
</Message>
<Message ID="SECJ7221I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.bindPassword" varFormat="Java">
    security.configrpt.core.bindPassword=SECJ7221I: Bind password
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0313I" severity="I" prefix="yes">
  <MsgText pgmKey="security.jsecman.debugflagmsg" varFormat="Java">
    security.jsecman.debugflagmsg=SECJ0313I: Java 2 Security Manager debug message flags are initialized: TrDebug: {0}, Access: {1}, Stack: {2}, Failure: {3}, Rethrow {4}
  </MsgText>
  <Explanation>
    This message provides the current value of the java.security.debug property which is used to enable various debug information related to Java 2 Security.
  </Explanation>
  <UserResponse>
    None, this is informational only.
  </UserResponse>
</Message>
<Message ID="SECJ0305I" severity="I" prefix="yes">
  <MsgText pgmKey="security.rolebauthz.authzfail" varFormat="Java">
    security.rolebauthz.authzfail=SECJ0305I: The role-based authorization check failed for {0} operation {1}:{2}.  The user {3} (unique ID: {4}) was not granted any of the following required roles: {5}.
  </MsgText>
  <Explanation>
    The caller does not have the necessary permission, this problem can occur because no credential is found on the thread, the caller is not authenticated, or the accessId might be null.
  </Explanation>
  <UserResponse>
    If the failure is unexpected, verify that the caller has been granted the required role.
  </UserResponse>
</Message>
<Message ID="SECJ6112I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.sso.expired.audit" varFormat="Java">
    security.audit.sso.expired.audit=SECJ6112I: SSO token {0} is expired and failed validation.
  </MsgText>
  <Explanation>
    Authentication failed because the SSO token has expired.
  </Explanation>
  <UserResponse>
    No action is required.
  </UserResponse>
</Message>
<Message ID="SECJ7170I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.seconds" varFormat="Java">
    security.configrpt.seconds=SECJ7170I: seconds
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7175I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.clientKeyAlias" varFormat="Java">
    security.configrpt.core.clientKeyAlias=SECJ7175I: Default client certificate alias
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7167I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.provider" varFormat="Java">
    security.configrpt.core.provider=SECJ7167I: Provider
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7014I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.Authentication.Mechanisms" varFormat="Java">
    security.configrpt.core.Authentication.Mechanisms=SECJ7014I: Authentication mechanisms and expiration
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0278E" severity="E" prefix="yes">
  <MsgText pgmKey="security.secsrv.token.destroy" varFormat="Java">
    security.secsrv.token.destroy=SECJ0278E: TokenData credential is already destroyed.  The exception is {0}.
  </MsgText>
  <Explanation>
    CredentialDestroyedException occurred while trying to get credential token. The credential was already destroyed.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ0328E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.noclassname" varFormat="Java">
    security.registry.noclassname=SECJ0328E: Registry implementation file is missing.
  </MsgText>
  <Explanation>
    Cannot locate the registry implementation file.
  </Explanation>
  <UserResponse>
    If you are using a Custom Registry make sure that your provide the registry implementation file in the GUI or in the scripting (whichever is being used). If you are using WebSphere Application Server supplied registries contact your service representative if the problem persists.
  </UserResponse>
</Message>
<Message ID="SECJ0210I" severity="I" prefix="yes">
  <MsgText pgmKey="security.init.secstatus" varFormat="Java">
    security.init.secstatus=SECJ0210I: Security enabled {0}
  </MsgText>
  <Explanation>
    Reports current security enabled or disabled status.
  </Explanation>
  <UserResponse>
    None. Informational only
  </UserResponse>
</Message>
<Message ID="SECJ7027I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.User.Registry" varFormat="Java">
    security.configrpt.core.User.Registry=SECJ7027I: User Registry
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7154I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.internalServerId" varFormat="Java">
    security.configrpt.core.internalServerId=SECJ7154I: Internal server ID
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0164E" severity="E" prefix="yes">
  <MsgText pgmKey="security.native.error" varFormat="Java">
    security.native.error=SECJ0164E: Error number {0} while calling the operating system API {1}
  </MsgText>
  <Explanation>
    An error was returned by the operating system API
  </Explanation>
  <UserResponse>
    Depending on the API being called, check the operating system specific documentation
  </UserResponse>
</Message>
<Message ID="SECJ0083E" severity="E" prefix="yes">
  <MsgText pgmKey="security.web.cache.initerror" varFormat="Java">
    security.web.cache.initerror=SECJ0083E: Error initializing web cache on admin server
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ0247I" severity="I" prefix="yes">
  <MsgText pgmKey="security.sas.orbssl.config.error" varFormat="Java">
    security.sas.orbssl.config.error=SECJ0247I: ORB SSL Key File or Passwords settings were missing in server-cfg.xml
  </MsgText>
  <Explanation>
    ORB SSL Key File or Passwords settings were missing in server-cfg.xml
  </Explanation>
  <UserResponse>
    Verify that the server-cfg.xml file.
  </UserResponse>
</Message>
<Message ID="SECJ6236E" severity="E" prefix="yes">
  <MsgText pgmKey="security.zos.saf.authz.failed" varFormat="Java">
    security.zos.saf.authz.failed=SECJ6236E: Authorization failed; the exception is {0}.
  </MsgText>
  <Explanation>
    Authorization failed for the user. The exception has information on why the authorization failed.
  </Explanation>
  <UserResponse>
    Examine the message in the exception for more information.
  </UserResponse>
</Message>
<Message ID="SECJ6146I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.csi.message.failure.audit" varFormat="Java">
    security.audit.csi.message.failure.audit=SECJ6146I: Message type was not supported.
  </MsgText>
  <Explanation>
    Message type is not EstablishContext and stateful=false.
  </Explanation>
  <UserResponse>
    No action is required.
  </UserResponse>
</Message>
<Message ID="SECJ7205I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.nextStartDate" varFormat="Java">
    security.configrpt.core.nextStartDate=SECJ7205I: Next start date
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0386I" severity="I" prefix="yes">
  <MsgText pgmKey="security.registry.TAM.initialize" varFormat="Java">
    security.registry.TAM.initialize=SECJ0386I: Initializing registry to use Tivoli Access Manager for authentication.
  </MsgText>
  <Explanation>
    Authenticaton will be perfomed using Tivoli Access Manager. This requires that WebSphere is configured to use an external Tivoli Access Manager server.
  </Explanation>
  <UserResponse>
    None, informational only.
  </UserResponse>
</Message>
<Message ID="SECJ0321E" severity="E" prefix="yes">
  <MsgText pgmKey="security.rolebauthz.iscallerinrolefail" varFormat="Java">
    security.rolebauthz.iscallerinrolefail=SECJ0321E: Role based authorization is caller in role failed for security name {0}, accessId {1}, and role name {2}.
  </MsgText>
  <Explanation>
    The caller does not have the necessary permission, there was no credential on the thread, the caller is not authenticated, or the accessId could be null.
  </Explanation>
  <UserResponse>
    If the failure is unexpected, verify the caller has been granted the required role.
  </UserResponse>
</Message>
<Message ID="SECJ0368E" severity="E" prefix="yes">
  <MsgText pgmKey="security.ltpa.noalgorithm" varFormat="Java">
    security.ltpa.noalgorithm=SECJ0368E: No such LTPA Algorithm. The exception is {0}.
  </MsgText>
  <Explanation>
    This is an internal error. A NoSuchAlgorithmException occurred when the LTPAServer tried to sign the token.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7536I" severity="I" prefix="yes">
  <MsgText pgmKey="security.scanner.risk.ldaplink.ok.used" varFormat="Java">
    security.scanner.risk.ldaplink.ok.used=SECJ7536I: User Registry is LDAP. SSL between WebSphere Application Server and LDAP is enabled. This ensures that the communication between WebSphere Application Server and LDAP is encrypted
  </MsgText>
  <Explanation>
    User Registry is LDAP. SSL between WebSphere Application Server and LDAP is enabled. This ensures that the communication between WebSphere Application Server and LDAP is encrypted
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ6231E" severity="E" prefix="yes">
  <MsgText pgmKey="security.zos.saf.idprop.distributedRealm.tooLong" varFormat="Java">
    security.zos.saf.idprop.distributedRealm.tooLong=SECJ6231E: The distributed realm name exceeds the maximum length of {1}. The distributed realm name is {0}. The distributed user will not be mapped to a SAF user.
  </MsgText>
  <Explanation>
    The distributed realm name exceeds the maximum allowable length.
  </Explanation>
  <UserResponse>
    Specify a valid distributed realm name.
  </UserResponse>
</Message>
<Message ID="SECJ6036E" severity="E" prefix="yes">
  <MsgText pgmKey="security.audit.service.init.error" varFormat="Java">
    security.audit.service.init.error=SECJ6036E: AuditService not initialized.
  </MsgText>
  <Explanation>
    Audit service was not initialized, which occurred most likely due to incorrect class definition, incorrect class path, or missing class files.
  </Explanation>
  <UserResponse>
    Examine the exception for the cause of the problem.
  </UserResponse>
</Message>
<Message ID="SECJ0430W" severity="W" prefix="yes">
  <MsgText pgmKey="security.authn.cache.maxsize.reached" varFormat="Java">
    security.authn.cache.maxsize.reached=SECJ0430W: The authentication cache currently has {0} entries which has exceeded the maximum size of {1}.  The cache cleanup algorithm will remove some entries.  Consider increasing the maximum cache size.
  </MsgText>
  <Explanation>
    When the authentication cache maximum size is reached, some entries from the cache are evicted.  This will cause some users to go back through the login modules which is a slower process.
  </Explanation>
  <UserResponse>
    To increase the max cache size for the authentication cache, set the following System property (com.ibm.websphere.security.util.authCacheMaxSize) for each process that needs it.  The property default is 25000 entries.
  </UserResponse>
</Message>
<Message ID="SECJ7226I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.secure.communications.fips" varFormat="Java">
    security.configrpt.secure.communications.fips=SECJ7226I: Use the United States Federal Information Processing Standard (FIPS) algorithms
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7397E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.FilePathException" varFormat="Java">
    security.admintask.FilePathException=SECJ7397E: Exception validating existance of audit log filepath.
  </MsgText>
  <Explanation>
    An exception occurred validating or creating the file path location for the audit logs.
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0046I" severity="I" prefix="yes">
  <MsgText pgmKey="security.sas.prop.updated" varFormat="Java">
    security.sas.prop.updated=SECJ0046I: SAS Property:{0} has been updated
  </MsgText>
  <Explanation>
    Informational.
  </Explanation>
  <UserResponse>
    A security configuration change has caused a SAS Property to be updated.
  </UserResponse>
</Message>
<Message ID="SECJ7771E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.missingParameter.krb5Auth.SECJ7771E" varFormat="Java">
    security.admintask.missingParameter.krb5Auth.SECJ7771E=SECJ7771E: The {0} is missing in the Kerberos authentication mechanism object.
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7100I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.Operator.Role.User" varFormat="Java">
    security.configrpt.Operator.Role.User=SECJ7100I: Operator User
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0183W" severity="W" prefix="yes">
  <MsgText pgmKey="security.policy.fileToURL" varFormat="Java">
    security.policy.fileToURL=SECJ0183W: An exception was caught while trying to convert the filepath {1} to URL. The exception is {0}.
  </MsgText>
  <Explanation>
    Could not convert the specified filepath to URL.
  </Explanation>
  <UserResponse>
    Check the specified filepath. It could be caused by incorrect data in xml file. Enable security trace with com.ibm.ws.security.policy.* to get more detailed information.
  </UserResponse>
</Message>
<Message ID="SECJ7342E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.FailedCheckPassword" varFormat="Java">
    security.admintask.FailedCheckPassword=SECJ7342E: Failed to validate user/password
  </MsgText>
  <Explanation>
    Failed to validate user password in federated respositories
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7428E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.CertNotInKeyStore" varFormat="Java">
    security.admintask.CertNotInKeyStore=SECJ7428E: Could not find certificate alias in the referenced keystore.
  </MsgText>
  <Explanation>
    Certificate alias does not exist in the referenced keystore.
  </Explanation>
  <UserResponse>
    Make sure to specify a certificate alias that does exist in the referenced keystore.
  </UserResponse>
</Message>
<Message ID="SECJ6218W" severity="W" prefix="yes">
  <MsgText pgmKey="security.zos.saf.delegation.using.caller.warning" varFormat="Java">
    security.zos.saf.delegation.using.caller.warning=SECJ6218W: The SAF delegation implementation was unable to create a subject in the role named &quot;{0}&quot; in application &quot;{1}&quot; for role delegation.  The current subject will be used.
  </MsgText>
  <Explanation>
    An earlier error prevented WebSphere from creating a subject that was in the required role.  The target method will be dispatched without a change the current security environment.  This might result in authorization errors as the caller might not be in the required role.
  </Explanation>
  <UserResponse>
    Examine the previous messages to determine the initial cause of th error.
  </UserResponse>
</Message>
<Message ID="SECJ8028E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaspi.configuration.factory.invalid.SECJ8028E" varFormat="Java">
    security.jaspi.configuration.factory.invalid.SECJ8028E=SECJ8028E: AuthConfigFactory is null, JASPI bindings cannot be registered.
  </MsgText>
  <Explanation>
    JASPI bindings cannot be registered because a JASPI factory implementation is not defined.
  </Explanation>
  <UserResponse>
    Verify the fully qualified class name of the default JASPI factory implementation class is defined using the property authconfigprovider.factory in java.security.
  </UserResponse>
</Message>
<Message ID="SECJ0277E" severity="E" prefix="yes">
  <MsgText pgmKey="security.secsrv.basic.expired" varFormat="Java">
    security.secsrv.basic.expired=SECJ0277E: BasicAuthData credential is already expired. The exception is {0}.
  </MsgText>
  <Explanation>
    javax.security.auth.login.CredentialExpiredException occurred while trying to get BasicAuthData.
  </Explanation>
  <UserResponse>
    refresh the credential.
  </UserResponse>
</Message>
<Message ID="SECJ7234I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.allowBasicAuth" varFormat="Java">
    security.configrpt.core.allowBasicAuth=SECJ7234I: Allow basic authentication
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0387E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jacc.tools.pcf" varFormat="Java">
    security.jacc.tools.pcf=SECJ0387E: Error getting the PolicyConfiguration object for the contextID {0}. The exception is {1}.
  </MsgText>
  <Explanation>
    Could not get the JACC provider PolicyConfiguration object. This object is required to propagate the security constraints information to the provider.
  </Explanation>
  <UserResponse>
    Make sure that the JACC provider property javax.security.jacc.PolicyConfigurationFactory.provider is set correctly to the PolicyConfigurationFactory implementation class. The preferred way to set this property is to use the JACC configuration properties panel or wsadmin tool. Also make sure that the provider classes are in the class path of all the servers.
  </UserResponse>
</Message>
<Message ID="SECJ7256I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.usage" varFormat="Java">
    security.configrpt.core.usage=SECJ7256I: Usage
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0201I" severity="I" prefix="yes">
  <MsgText pgmKey="security.native.audit" varFormat="Java">
    security.native.audit=SECJ0201I: Error number {0} while calling the operating system API {1}
  </MsgText>
  <Explanation>
    The above error number was returned by the above API.
  </Explanation>
  <UserResponse>
    Depending on the API being called, check the operating system documentation for the API.
  </UserResponse>
</Message>
<Message ID="SECJ7214I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.days" varFormat="Java">
    security.configrpt.days=SECJ7214I: days
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7068I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.setting" varFormat="Java">
    security.configrpt.core.setting=SECJ7068I: SSL settings
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0390E" severity="E" prefix="yes">
  <MsgText pgmKey="security.iscallerinrole.error" varFormat="Java">
    security.iscallerinrole.error=SECJ0390E: Error when caling isCallerInRole for role {0}. The exception is {1}.
  </MsgText>
  <Explanation>
    Cannot determine the isCallerInRole because of the exception. Default is to return false. Make sure that the security role-ref information is correct.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7041I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.Application.Login.Config" varFormat="Java">
    security.configrpt.core.Application.Login.Config=SECJ7041I: Application login configuration
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7074I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.securityLevel" varFormat="Java">
    security.configrpt.core.securityLevel=SECJ7074I: Security level
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0408E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jacc.tools.uninstall" varFormat="Java">
    security.jacc.tools.uninstall=SECJ0408E: An exception occurred when removing the security policy information from the provider for application {0} during uninstall. The exception is {1}.
  </MsgText>
  <Explanation>
    Because of an exception, the security policy information might not have been removed completely from the provider during the application uninstallation.
  </Explanation>
  <UserResponse>
    Make sure that the provider is up and running and the JACC configuration is correct. One can use the tools provided by the provider to remove the security policy information manully from the provider&apos;s repository.
  </UserResponse>
</Message>
<Message ID="SECJ7123I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.Naming.Write.Name" varFormat="Java">
    security.configrpt.Naming.Write.Name=SECJ7123I: Write
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7400E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.CheckKeyStore" varFormat="Java">
    security.admintask.CheckKeyStore=SECJ7400E: Key store file did not verify, make sure the file exists, check key store type and password.
  </MsgText>
  <Explanation>
    When creating a key store object with an existing key store file the file must exist and a valid password and key store type must be supplied.
  </Explanation>
  <UserResponse>
    Make sure the key store file exists with a valid password and key store type.  Then rerun the command.
  </UserResponse>
</Message>
<Message ID="SECJ0338E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.groupdisplayname.error" varFormat="Java">
    security.registry.groupdisplayname.error=SECJ0338E: The following error occurs when getting the display name of the group {0}, {1}.
  </MsgText>
  <Explanation>
    Error getting display name of a group.
  </Explanation>
  <UserResponse>
    Make sure that the group is valid and has a display name.
  </UserResponse>
</Message>
<Message ID="SECJ6129I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.authz.disabled.audit" varFormat="Java">
    security.audit.authz.disabled.audit=SECJ6129I: Access is allowed because security is disabled.
  </MsgText>
  <Explanation>
    Access to the resource is allowed because WebSphere Application Server global security eas not enabled.
  </Explanation>
  <UserResponse>
    No action required if this is the configured behavior.
  </UserResponse>
</Message>
<Message ID="SECJ7034I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.initializeJACCProviderClassName" varFormat="Java">
    security.configrpt.core.initializeJACCProviderClassName=SECJ7034I: Provider initialization class name
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7425E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.EncryptionNotEnabled" varFormat="Java">
    security.admintask.EncryptionNotEnabled=SECJ7425E: Cannot specify keystore for encryption: encryption not enabled.
  </MsgText>
  <Explanation>
    When encryption is not enabled, cannot configure the encryption keystore.
  </Explanation>
  <UserResponse>
    Enable encryption before setting the encryption keystore.
  </UserResponse>
</Message>
<Message ID="SECJ7456E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.InvalidTimeStampRange" varFormat="Java">
    security.admintask.InvalidTimeStampRange=SECJ7456E: Non valid timestamp range specified.  Either a single timestamp can be specified or a group of timestamp records may be specified as begin:end.
  </MsgText>
  <Explanation>
    A non valid value was specified for the timestamp set of audit records to report
  </Explanation>
  <UserResponse>
    Specify a non-empty or valid value for the timestap  set.
  </UserResponse>
</Message>
<Message ID="SECJ0369E" severity="E" prefix="yes">
  <MsgText pgmKey="security.ltpa.authenticate" varFormat="Java">
    security.ltpa.authenticate=SECJ0369E: Authentication failed when using LTPA. The exception is {0}.
  </MsgText>
  <Explanation>
    Authentication has failed when using LTPA.
  </Explanation>
  <UserResponse>
    There could be multiple reasons why this might have occurred. Most of the time this should have preceeded with other exceptions that will indicate what the exact problem is. This might occur if the userName, password or both are incorrect, if the setup of the registry is not valid. If problems persist contact your service representative.
  </UserResponse>
</Message>
<Message ID="SECJ7252I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.hostName" varFormat="Java">
    security.configrpt.core.hostName=SECJ7252I: Host name
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7080I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.tokenType" varFormat="Java">
    security.configrpt.core.tokenType=SECJ7080I: Token Type
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7819E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.unknown.hostname.SECJ7819E" varFormat="Java">
    security.admintask.unknown.hostname.SECJ7819E=SECJ7819E: Unknown host name {0}
  </MsgText>
  <Explanation>
    The host name is unknown.
  </Explanation>
  <UserResponse>
    Ensure that a valid host name is specified.
  </UserResponse>
</Message>
<Message ID="SECJ6211I" severity="I" prefix="yes">
  <MsgText pgmKey="security.zos.threadid.connmgmt.enabled" varFormat="Java">
    security.zos.threadid.connmgmt.enabled=SECJ6211I: Connection management thread identity synchronization is enabled.
  </MsgText>
  <Explanation>
    The server has been configured to perform J2EE and operating system thread identity synchronization for connectors that are able to exploit it.
  </Explanation>
  <UserResponse>
    No user action is required.
  </UserResponse>
</Message>
<Message ID="SECJ7408E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.NoCertKeyFilePasswordValue" varFormat="Java">
    security.admintask.NoCertKeyFilePasswordValue=SECJ7408E: No value was specified for the key file password for the certificate to import
  </MsgText>
  <Explanation>
    When selecting to import an existing certificate, a key file password for the certificate must be entered.
  </Explanation>
  <UserResponse>
    Supply a key file password for the certificate to import
  </UserResponse>
</Message>
<Message ID="SECJ5003W" severity="W" prefix="yes">
  <MsgText pgmKey="security.sap.warning.deserializing.custom.objects.from.subject" varFormat="Java">
    security.sap.warning.deserializing.custom.objects.from.subject=SECJ5003W: An error occurred while de-serializing a custom object from the inbound authorization token.  This does not cause the request to fail but this custom object will not get restored in the inbound Subject.
  </MsgText>
  <Explanation>
    The object failed to de-serialize at the target server.  The likely cause is the implementation class is not present on the target server or the Java class version between the sending server and target server is different.
  </Explanation>
  <UserResponse>
    Ensure that the correct java class exists at the target server.
  </UserResponse>
</Message>
<Message ID="SECJ7140I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.webAuth" varFormat="Java">
    security.configrpt.core.webAuth=SECJ7140I: Web security
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7189I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.scopeName" varFormat="Java">
    security.configrpt.core.scopeName=SECJ7189I: Scope Name
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0423I" severity="I" prefix="yes">
  <MsgText pgmKey="security.merge.cell.signer.not.exchanged" varFormat="Java">
    security.merge.cell.signer.not.exchanged=SECJ0423I: During addNode from node &quot;{0}&quot; the default cell certificate did not exchange its signer with the node default truststore.  This might cause a handshake failure when the node agent starts up.  Manual signer exchange might need to occur.
  </MsgText>
  <Explanation>
    It&apos;s likely the TrustStore named NodeDefaultTrustStore or KeyStore named CellDefaultKeyStore does not exist in the configuration.
  </Explanation>
  <UserResponse>
    The cell&apos;s signer certificates need to be added to the node&apos;s truststores.
  </UserResponse>
</Message>
<Message ID="SECJ7007I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.defaultSSLSettings" varFormat="Java">
    security.configrpt.core.defaultSSLSettings=SECJ7007I: Default SSL settings
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7531I" severity="I" prefix="yes">
  <MsgText pgmKey="security.scanner.risk.drs.ok.used" varFormat="Java">
    security.scanner.risk.drs.ok.used=SECJ7531I: Encryption is enabled on Distributed Replication Service(DRS). This ensures that the data shared among WebSphere Application servers is encrypted.
  </MsgText>
  <Explanation>
    Encryption is enabled on Distributed Replication Service(DRS). This ensures that the data shared among WebSphere Application servers is encrypted.
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7708E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.loginModuleDoesNotExist.SECJ7708E" varFormat="Java">
    security.admintask.loginModuleDoesNotExist.SECJ7708E=SECJ7708E: The {0} does not exist.
  </MsgText>
  <Explanation>
    The login module specified does not exist.
  </Explanation>
  <UserResponse>
    Ensure that the login module exists.
  </UserResponse>
</Message>
<Message ID="SECJ5001E" severity="E" prefix="yes">
  <MsgText pgmKey="security.sap.error.creating.token.holder.list" varFormat="Java">
    security.sap.error.creating.token.holder.list=SECJ5001E: The following exception occurred while creating the attribute propagation token holder list from the authorization token: {0}
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ0244I" severity="I" prefix="yes">
  <MsgText pgmKey="security.init.svcstartfail" varFormat="Java">
    security.init.svcstartfail=SECJ0244I: Security service failed to start successfully
  </MsgText>
  <Explanation>
    Security service  started.
  </Explanation>
  <UserResponse>
    None. Informational only
  </UserResponse>
</Message>
<Message ID="SECJ7374E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.NotificationMonitorConfigured" varFormat="Java">
    security.admintask.NotificationMonitorConfigured=SECJ7374E: Audit Notification Monitor already configured.
  </MsgText>
  <Explanation>
    Audit Notification Monitor has already been configured.
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0246E" severity="E" prefix="yes">
  <MsgText pgmKey="security.sas.orbssl.setting.exception" varFormat="Java">
    security.sas.orbssl.setting.exception=SECJ0246E: Caught unexpected exception in retrieving ORB SSL settings {0}
  </MsgText>
  <Explanation>
    An unexpected exception occurred retrieving the ORB SSL settings.
  </Explanation>
  <UserResponse>
    Verify that the property file, usually sas.server.props contents. Contact your service representative if the problem persists.
  </UserResponse>
</Message>
<Message ID="SECJ0085E" severity="E" prefix="yes">
  <MsgText pgmKey="security.web.adminwebcache.initerror" varFormat="Java">
    security.web.adminwebcache.initerror=SECJ0085E: Error initializing admin web cache
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ0053E" severity="E" prefix="yes">
  <MsgText pgmKey="security.authz.failed.foruser" varFormat="Java">
    security.authz.failed.foruser=SECJ0053E: Authorization failed for {0} while invoking ({1}){2} {3} {4}
  </MsgText>
  <Explanation>
    The user does not have the necessary permission to access the resource. This failure might be expected if the user should not be granted access. If this error is unexpected, then there are several possible causes. The user has not been mapped to one the roles protecting the resource if the user requires access to the protected resource. The user is not a member of one of the groups that might have been mapped to one of the roles. If WebSphere security is configured to use LDAP as the user registry, the WebSphere security LDAP user and group search filter configuration might not match what the LDAP directory expects.
  </Explanation>
  <UserResponse>
    If the authorization failure is unexpected, verify the user, or a group that the user is a member of, is mapped to the role protecting the resource.  Verify that the WebSphere security LDAP user and group filters configuration match what the LDAP directory expects.
  </UserResponse>
</Message>
<Message ID="SECJ7250I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.filterClass" varFormat="Java">
    security.configrpt.core.filterClass=SECJ7250I: SPNEGO Filter class
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7108I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.Admin.Role.Group" varFormat="Java">
    security.configrpt.Admin.Role.Group=SECJ7108I: Administrator Group
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ8041E" severity="E" prefix="yes">
  <MsgText pgmKey="security.saml.element.id.notexistent.SECJ8041E" varFormat="Java">
    security.saml.element.id.notexistent.SECJ8041E=SECJ8041E: {0} {1} is not defined in the SAML TAI configuration.
  </MsgText>
  <Explanation>
    The given parameter value is not defined in the SAML TAI configuration.
  </Explanation>
  <UserResponse>
    Verify the SAML TAI properties and specify a value that exists.
  </UserResponse>
</Message>
<Message ID="SECJ7172I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.dynamicallyUpdateSSLConfig" varFormat="Java">
    security.configrpt.core.dynamicallyUpdateSSLConfig=SECJ7172I: Dynamically update run time when SSL configuration changes occur
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7139I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.SecureEndpoint" varFormat="Java">
    security.configrpt.core.SecureEndpoint=SECJ7139I: Manage endpoint security configurations
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0224E" severity="E" prefix="yes">
  <MsgText pgmKey="security.webatts.exception" varFormat="Java">
    security.webatts.exception=SECJ0224E: An unexpected exception occurred when trying to configure the security related web attributes for web applications {0}.  The exception is {1}.
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7542W" severity="W" prefix="yes">
  <MsgText pgmKey="security.scanner.risk.other.role.every.improve" varFormat="Java">
    security.scanner.risk.other.role.every.improve=SECJ7542W: Special subject &quot;{0}&quot; is configured for one of the administrative roles.  It is not recommended to have Everyone specified for any of the administrative user roles.
  </MsgText>
  <Explanation>
    A special subject is configured for one of the administrative roles.  It is not recommended to have Everyone specified for any of the administrative user roles.
  </Explanation>
  <UserResponse>
    Remove the Everyone subject from any of the administrative user roles if applicable.
  </UserResponse>
</Message>
<Message ID="SECJ0074E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.createerror" varFormat="Java">
    security.registry.createerror=SECJ0074E: Error creation user registry.  The exception is {0}
  </MsgText>
  <Explanation>
    An unexpected exception occurred when trying to load or create the user registry.
  </Explanation>
  <UserResponse>
    Verify that the CLASSPATH used to start WebSphere is correct and that the jar files have at least the read permission and exist.
  </UserResponse>
</Message>
<Message ID="SECJ8023E" severity="E" prefix="yes">
  <MsgText pgmKey="security.adminapp.cmd.error.SECJ8023E" varFormat="Java">
    security.adminapp.cmd.error.SECJ8023E=SECJ8023E: An unexpected exception occurred processing Jaspi bindings during application deployment. Failed command: {0}, exception: {1}
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7357E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.ConfigurationError" varFormat="Java">
    security.admintask.ConfigurationError=SECJ7357E: Configuration error detected in the audit configuration
  </MsgText>
  <Explanation>
    Error detected in the audit configuration
  </Explanation>
  <UserResponse>
    Verify that the audit configuration is correctly specified in the audit.xml
  </UserResponse>
</Message>
<Message ID="SECJ0413I" severity="I" prefix="yes">
  <MsgText pgmKey="security.jacc.initialized" varFormat="Java">
    security.jacc.initialized=SECJ0413I: The JACC provider is successfully initialized with the following setup. The policy class name is {0}. The PolicyConfigurationFactory class name is {1}. The optional RoleConfigurationFactory call name is {2}. The optional initialization class name is {3}.
  </MsgText>
  <Explanation>
    This message is provided for information purposes only.
  </Explanation>
  <UserResponse>
    No user action is required.
  </UserResponse>
</Message>
<Message ID="SECJ7742E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.Kerb.cannotUseInternalServerId" varFormat="Java">
    security.admintask.Kerb.cannotUseInternalServerId=SECJ7742E: InternalServerId cannot be used with Kerberos authentication mechanism. Modify the dmgr security configuration to use the serverID/passwd before configure Kerberos authentication mechanism.
  </MsgText>
  <Explanation>
    Modify the dmgr security configuration to use the serverID/password with Kerberos authentication mechanism.
  </Explanation>
  <UserResponse>
    The Kerberos authentication cannot be configured with InternalServerId.
  </UserResponse>
</Message>
<Message ID="SECJ7157I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.trustedPassword" varFormat="Java">
    security.configrpt.core.trustedPassword=SECJ7157I: Password
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7180I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.displayNameKey" varFormat="Java">
    security.configrpt.core.displayNameKey=SECJ7180I: Key file name
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ6205W" severity="W" prefix="yes">
  <MsgText pgmKey="security.zOS.SecurityManager.PermissionFailure1.warning" varFormat="Java">
    security.zOS.SecurityManager.PermissionFailure1.warning=SECJ6205W: The current Java 2 Security policy reported a potential violation of a Java 2 Security Permission. Refer to the InfoCenter for further information.{0}Permission:{1}Code:{2}Code Base Location:{3}
  </MsgText>
  <Explanation>
    The Java Security Manager checkPermission() threw a SecurityException on the subject Permission. A caller on the call stack does not have the required permission.  This might not be a problem if the caller properly handles this exception.
  </Explanation>
  <UserResponse>
    Verify that the attempted operation is permitted by examining all Java 2 security policy files and application code. Additional permissions might be required, an AccessController.doPrivileged call might be needed in some code on the call stack, or the Security Manager has properly prevented access to a resource that a caller does not have permission to access.
  </UserResponse>
</Message>
<Message ID="SECJ0229E" severity="E" prefix="yes">
  <MsgText pgmKey="security.policy.parser.methodisnull" varFormat="Java">
    security.policy.parser.methodisnull=SECJ0229E: Method {0} of object of {1} type is null.
  </MsgText>
  <Explanation>
    Method returned by reflection is null.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ0241I" severity="I" prefix="yes">
  <MsgText pgmKey="security.init.startfail" varFormat="Java">
    security.init.startfail=SECJ0241I: Security service initialization completed successfully
  </MsgText>
  <Explanation>
    Security service initialization started.
  </Explanation>
  <UserResponse>
    None. Informational only
  </UserResponse>
</Message>
<Message ID="SECJ7827E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.globalfedoption.noglobalfed.SECJ7827E" varFormat="Java">
    security.admintask.globalfedoption.noglobalfed.SECJ7827E=SECJ7827E: Cannot configure an application security domain to use the global federated repository option when the global security domain does not have a federated repository as the active user registry.
  </MsgText>
  <Explanation>
    The global security domain must be configured with a federated repository as the active user registry in order for any application security domain to be configured with the global federated repository option.
  </Explanation>
  <UserResponse>
    Either the global security domain should be configured with a federated repository as the active user registry or the application security domain should elect not to use the global federated repository option.
  </UserResponse>
</Message>
<Message ID="SECJ7278I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.Servers" varFormat="Java">
    security.configrpt.core.Servers=SECJ7278I: Servers
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ4038E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaas.create.URL" varFormat="Java">
    security.jaas.create.URL=SECJ4038E: {0} :ERROR: Could not create URL: {1}. The exception is {2}
  </MsgText>
  <Explanation>
    IOException occurred trying to connect the specified URL.
  </Explanation>
  <UserResponse>
    Investigate the exception. Check the specified URL.
  </UserResponse>
</Message>
<Message ID="SECJ8008E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.jaspi.classname.invalid.SECJ8008E" varFormat="Java">
    security.admintask.jaspi.classname.invalid.SECJ8008E=SECJ8008E: The {0} class name is not valid: {1}. Specify a valid class name.
  </MsgText>
  <Explanation>
    The class name of an authentication provider or module must not be empty.
  </Explanation>
  <UserResponse>
    Specify a non-empty class name for the authentication provider or module.
  </UserResponse>
</Message>
<Message ID="SECJ7778I" severity="I" prefix="yes">
  <MsgText pgmKey="security.admintask.authFailed.SECJ7778I" varFormat="Java">
    security.admintask.authFailed.SECJ7778I=SECJ7778I: Password check for {0} in {1} failed.
  </MsgText>
  <Explanation>
    A test to check the users password on a particular realm was failed.
  </Explanation>
  <UserResponse>
    none.
  </UserResponse>
</Message>
<Message ID="SECJ0228E" severity="E" prefix="yes">
  <MsgText pgmKey="security.policy.parser.objectisnull" varFormat="Java">
    security.policy.parser.objectisnull=SECJ0228E: Object of type {0} is null.
  </MsgText>
  <Explanation>
    Object created by reflection is null.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ6113I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.sso.invalid.audit" varFormat="Java">
    security.audit.sso.invalid.audit=SECJ6113I: SSO token {0} is invalid and failed validation.
  </MsgText>
  <Explanation>
    Authentication failed because the SSO token was not valid.
  </Explanation>
  <UserResponse>
    No action is required.
  </UserResponse>
</Message>
<Message ID="SECJ0155E" severity="E" prefix="yes">
  <MsgText pgmKey="security.roleref.configerror" varFormat="Java">
    security.roleref.configerror=SECJ0155E: Deployment descriptor configuration error.  security-role-ref {0} in ejb-jar.xml is not mapped to any security role in bean {1}, module {2}, application {3}.
  </MsgText>
  <Explanation>
    A security role reference in the specified EJB&apos;s ejb-jar.xml file has not been mapped to a security role.  This is a configuration error.
  </Explanation>
  <UserResponse>
    The security-role-ref in the EJB&apos;s ejb-jar.xml deployment descriptor should be mapped to a security role.
  </UserResponse>
</Message>
<Message ID="SECJ5008W" severity="W" prefix="yes">
  <MsgText pgmKey="security.sap.warning.realm.does.not.match.current.realm" varFormat="Java">
    security.sap.warning.realm.does.not.match.current.realm=SECJ5008W: The realm specified in com.ibm.wsspi.security.cred.realm ({0}) does not match the current realm ({1}). This could cause problems when trying to make a downstream request.
  </MsgText>
  <Explanation>
    The realm specified does not match the current security realm of this server.  This could cause problems when trying to go downstream to another server on the same current realm.
  </Explanation>
  <UserResponse>
    If a different realm is desired, set the supportedTargetRealms field to include the new realm you are specifying in order to go outbound to servers in the current realm.
  </UserResponse>
</Message>
<Message ID="SECJ8045W" severity="W" prefix="yes">
  <MsgText pgmKey="security.saml.idp.missing.element.SECJ8045W" varFormat="Java">
    security.saml.idp.missing.element.SECJ8045W=SECJ8045W: {0} is missing from IdP metadata file {1}.
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ6138I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.csi.session.success.audit" varFormat="Java">
    security.audit.csi.session.success.audit=SECJ6138I: Security context setup successfully.
  </MsgText>
  <Explanation>
    The client security context was re-established successfully using the client session context identifier. The message type ASSOC_ACCEPT should not be received at the target server.
  </Explanation>
  <UserResponse>
    No action is required.
  </UserResponse>
</Message>
<Message ID="SECJ0388E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jacc.provider.inservice" varFormat="Java">
    security.jacc.provider.inservice=SECJ0388E: Problem getting the PolicyConfiguration inService status. The exception is {1}.
  </MsgText>
  <Explanation>
    The policy configuration object status could not be determined. Access will not be granted to this module.
  </Explanation>
  <UserResponse>
    The module in question might be in the process of being deleted. If the problem persists, contact your service representative.
  </UserResponse>
</Message>
<Message ID="SECJ7092I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.Security.jaasAuth" varFormat="Java">
    security.configrpt.core.Security.jaasAuth=SECJ7092I: Java Authentication and Authorization Service
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ6038E" severity="E" prefix="yes">
  <MsgText pgmKey="security.audit.keystore.not.found.error" varFormat="Java">
    security.audit.keystore.not.found.error=SECJ6038E: Audit keystore not found.
  </MsgText>
  <Explanation>
    Cannot find keystore created by the Auditor.
  </Explanation>
  <UserResponse>
    Ensure that the keystore has been created containing the certificate generated by the Auditor.
  </UserResponse>
</Message>
<Message ID="SECJ8051W" severity="W" prefix="yes">
  <MsgText pgmKey="security.saml.can.not.delete.certificate.SECJ8051W" varFormat="Java">
    security.saml.can.not.delete.certificate.SECJ8051W=SECJ8051W: You cannot remove the certificate from the trust store because more than one IdP or SP reference this certificate in the SAML TAI.
  </MsgText>
  <Explanation>
    The certificate is used by other IdP or SP.
  </Explanation>
  <UserResponse>
    Verify the certificate is not used by any other IdP or SP.
  </UserResponse>
</Message>
<Message ID="SECJ7241I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.trimUserName" varFormat="Java">
    security.configrpt.core.trimUserName=SECJ7241I: Trim Kerberos realm from principal name
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0350E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.uniqueusrid.notfound" varFormat="Java">
    security.registry.uniqueusrid.notfound=SECJ0350E: Could not get the uniqueId of the user {0}.
  </MsgText>
  <Explanation>
    Internal Error.
  </Explanation>
  <UserResponse>
    Make sure that the user is valid. Contact your service representative if the problem persists.
  </UserResponse>
</Message>
<Message ID="SECJ7227I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.Deployer.Role.User" varFormat="Java">
    security.configrpt.Deployer.Role.User=SECJ7227I: Deployer User
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7403E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.MustSpecifyCertGenMethod" varFormat="Java">
    security.admintask.MustSpecifyCertGenMethod=SECJ7403E: Must specify only one option for either autogenerating or importing a certificate.
  </MsgText>
  <Explanation>
    The values for auto-generating a certificate and importing a certificate matched.  Must specify true for one or the other.
  </Explanation>
  <UserResponse>
    Specify either auto-generating a certificate or importing a certificate.
  </UserResponse>
</Message>
<Message ID="SECJ0260E" severity="E" prefix="yes">
  <MsgText pgmKey="security.swam.unsupport.callback" varFormat="Java">
    security.swam.unsupport.callback=SECJ0260E: Unsupported {0}  callback in CallbackHandler. The exception is {1}
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ0190E" severity="E" prefix="yes">
  <MsgText pgmKey="security.policy.was.ioexception" varFormat="Java">
    security.policy.was.ioexception=SECJ0190E: Caught IOException while creating template for was.policy {0}. The exception is {1}.
  </MsgText>
  <Explanation>
    IOException occurred when putting the was.policy template in the hashmap of all the templates.
  </Explanation>
  <UserResponse>
    Check the specified was.policy file.
  </UserResponse>
</Message>
<Message ID="SECJ7042I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.entries" varFormat="Java">
    security.configrpt.core.entries=SECJ7042I: Entries
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0208E" severity="E" prefix="yes">
  <MsgText pgmKey="security.init.secidautherror" varFormat="Java">
    security.init.secidautherror=SECJ0208E: An unexpected exception occurred when attempting to authenticate the server&apos;&apos;s id during security initialization. The exception is {0}.
  </MsgText>
  <Explanation>
    The userId and password specified for the server&apos;s identity when configuring global security could not be used to authenticate the server.
  </Explanation>
  <UserResponse>
    Verify that the userId and password are valid and meet the requirements for the user registry or authentication mechanism.
  </UserResponse>
</Message>
<Message ID="SECJ0279E" severity="E" prefix="yes">
  <MsgText pgmKey="security.secsrv.token.expired" varFormat="Java">
    security.secsrv.token.expired=SECJ0279E: TokenData credential is already expired. The exception is {0}.
  </MsgText>
  <Explanation>
    javax.security.auth.login.CredentialExpiredException occurred while trying to get token.
  </Explanation>
  <UserResponse>
    refresh the credential.
  </UserResponse>
</Message>
<Message ID="SECJ8026W" severity="W" prefix="yes">
  <MsgText pgmKey="security.admintask.jaspi.version.warning.SECJ8026W" varFormat="Java">
    security.admintask.jaspi.version.warning.SECJ8026W=SECJ8026W: JASPI authentication can only be enabled on version 8 and higher nodes.
  </MsgText>
  <Explanation>
    JASPI authentication only functions on version 8 and higher nodes.
  </Explanation>
  <UserResponse>
    Only use JASPI authentication on version 8 and higher nodes.
  </UserResponse>
</Message>
<Message ID="SECJ6021I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.service.logout.default.audit" varFormat="Java">
    security.audit.service.logout.default.audit=SECJ6021I: AuditEventType = {0}, AuditOutcome = {1}, AuditOutcomeReason = {2}, unique Event ID = {3}, Cell Name = {4}, Node Name = {5}, Server Name = {6}, Component Name = {7}, App Name = {8}, Session ID = {9}, Realm = {10}, User Name = {11}, Provider Name = {12}, Provider Successful = {13}, Subject = {14}, Caller List = {15}, Remote Addr = {16}, Remote Host = {17}, Remote Port = {18}, Exception = {19}.
  </MsgText>
  <Explanation>
    This message is intended to be used by the defaultAuditEventFactoryImpl sendLogoutAuditEvent method only.
  </Explanation>
  <UserResponse>
    No action required.
  </UserResponse>
</Message>
<Message ID="SECJ6046E" severity="E" prefix="yes">
  <MsgText pgmKey="security.audit.decryption.data.error" varFormat="Java">
    security.audit.decryption.data.error=SECJ6046E: Data that is not valid was passed into the decryption algorithm.
  </MsgText>
  <Explanation>
    A data stream that is not valid was passed into the decryption algorithm.
  </Explanation>
  <UserResponse>
    Verify that a non-null byte stream of data is being passed in.
  </UserResponse>
</Message>
<Message ID="SECJ7384E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.MissingEmailList" varFormat="Java">
    security.admintask.MissingEmailList=SECJ7384E: Must enter an email list when send email is true.
  </MsgText>
  <Explanation>
    Must enter an email list when send email is true.
  </Explanation>
  <UserResponse>
    Supply an email list
  </UserResponse>
</Message>
<Message ID="SECJ0129E" severity="E" prefix="yes">
  <MsgText pgmKey="security.web.authz.failed.foruser" varFormat="Java">
    security.web.authz.failed.foruser=SECJ0129E: Authorization failed for user {0} while invoking {1} on {2}, {3}
  </MsgText>
  <Explanation>
    The user does not have the necessary permission to access the resource.
  </Explanation>
  <UserResponse>
    Contact your WebSphere security administrator if this is unexpected. Your user must be mapped to one the roles protecting the resource if access to the protected resource is required.
  </UserResponse>
</Message>
<Message ID="SECJ7254I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.spnegoNotSupportedPage" varFormat="Java">
    security.configrpt.core.spnegoNotSupportedPage=SECJ7254I: SPNEGO not supported page URL
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7077I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.trustFilePassword" varFormat="Java">
    security.configrpt.core.trustFilePassword=SECJ7077I: Trust file password
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7748E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.RSATrustStore.SECJ7748E" varFormat="Java">
    security.admintask.RSATrustStore.SECJ7748E=SECJ7748E: {0} is not a RSA token trust store.
  </MsgText>
  <Explanation>
    A RSA trust store must be used on a RSA authorization mechanism.
  </Explanation>
  <UserResponse>
    Run the command specifying a RSA trust store.
  </UserResponse>
</Message>
<Message ID="SECJ0373E" severity="E" prefix="yes">
  <MsgText pgmKey="security.ltpa.validate.createcredential.failed" varFormat="Java">
    security.ltpa.validate.createcredential.failed=SECJ0373E: Cannot create credential for the user {0} due to failed validation of the LTPA token. The exception is {1}.
  </MsgText>
  <Explanation>
    This is an internal Error. Cannot create a credential after the token is validated.
  </Explanation>
  <UserResponse>
    This error usually occurs due to an expired token or a token created with different LTPA keys.If the token is expired, you might need to increase the LTPA timeout. If the keys are not the same, make sure that one set of LTPA keys are used.
  </UserResponse>
</Message>
<Message ID="SECJ8047E" severity="E" prefix="yes">
  <MsgText pgmKey="security.saml.parameter.is.null.SECJ8047E" varFormat="Java">
    security.saml.parameter.is.null.SECJ8047E=SECJ8047E: {0} is null.
  </MsgText>
  <Explanation>
    Specify the given parameter.
  </Explanation>
  <UserResponse>
    Specify a valid parameter value.
  </UserResponse>
</Message>
<Message ID="SECJ7086I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.AdminSecurity" varFormat="Java">
    security.configrpt.core.AdminSecurity=SECJ7086I: Global security
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7243I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.adminCertificateTrustStore" varFormat="Java">
    security.configrpt.core.adminCertificateTrustStore=SECJ7243I: Trusted signers keystore
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ8061W" severity="W" prefix="yes">
  <MsgText pgmKey="security.saml.idp.entity.id.notexistent.SECJ8061W" varFormat="Java">
    security.saml.idp.entity.id.notexistent.SECJ8061W=SECJ8061W: There is no entityID in the IdP metadata file {0}.
  </MsgText>
  <Explanation>
    The entityID is missing from the IdP metadata file.
  </Explanation>
  <UserResponse>
    Verify the IdP metadata file.
  </UserResponse>
</Message>
<Message ID="SECJ7454E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.DataPointsContainsSpecial" varFormat="Java">
    security.admintask.DataPointsContainsSpecial=SECJ7454E: The specified data points for the custom report contain one or more of the following: event type, sequence number or outcome type.  These cannot be specified as values for this parameter.  They will always be provided by default.
  </MsgText>
  <Explanation>
    Event type, sequence number, and outcome may not be specified under the -dataPoints parameter.  All three of these pieces of data will always be reported.
  </Explanation>
  <UserResponse>
    Do not specify event type, sequence number and outcome as values for the -dataPoints parameter.
  </UserResponse>
</Message>
<Message ID="SECJ0243I" severity="I" prefix="yes">
  <MsgText pgmKey="security.init.svcstartcomplete" varFormat="Java">
    security.init.svcstartcomplete=SECJ0243I: Security service started successfully
  </MsgText>
  <Explanation>
    Security service  started.
  </Explanation>
  <UserResponse>
    None. Informational only
  </UserResponse>
</Message>
<Message ID="SECJ7418E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.ImportCertFailure" varFormat="Java">
    security.admintask.ImportCertFailure=SECJ7418E: Failure importing the self signed certificate for audit encryption
  </MsgText>
  <Explanation>
    Failed to import the self signed certificate for audit encryption
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ6132I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.authz.denied.verbose.audit" varFormat="Java">
    security.audit.authz.denied.verbose.audit=SECJ6132I: Access is denied, Reason: {0}.
  </MsgText>
  <Explanation>
    Access to the resource is denied because the user or the groups the user is in does not have any of the required security role.
  </Explanation>
  <UserResponse>
    No action required if this is the desired behavior.
  </UserResponse>
</Message>
<Message ID="SECJ7119I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.Naming.AllAuthenticated" varFormat="Java">
    security.configrpt.Naming.AllAuthenticated=SECJ7119I: All Authenticated Users and Groups
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0079E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.usertype.notsupp" varFormat="Java">
    security.registry.usertype.notsupp=SECJ0079E: User type not supported in the user registry
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ8021E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.jaspi.module.exists.SECJ8021E" varFormat="Java">
    security.admintask.jaspi.module.exists.SECJ8021E=SECJ8021E: Security domain {0} is not defined. The existing domains include:  {1}.
  </MsgText>
  <Explanation>
    A security domain with the specified name does not exist.
  </Explanation>
  <UserResponse>
    Specify the name of an existing security domain.
  </UserResponse>
</Message>
<Message ID="SECJ6018I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.service.authz.default.audit" varFormat="Java">
    security.audit.service.authz.default.audit=SECJ6018I: AuditEventType = {0}, AuditOutcome = {1}, AuditOutcomeReason = {2}, unique Event ID = {3}, Cell Name = {4}, Node Name = {5}, Server Name = {6}, Component Name = {7}, App Name = {8}, Session ID = {9}, Resource Name = {10}, Resource Type = {11}, Method Name = {12}, Provider Name = {13}, Provider Successful = {14}, Subject = {15}, Exception = {16}.
  </MsgText>
  <Explanation>
    This message is intended to be used by the defaultAuditEventFactoryImpl sendAuthzAuditEvent method only.
  </Explanation>
  <UserResponse>
    No action required.
  </UserResponse>
</Message>
<Message ID="SECJ0285E" severity="E" prefix="yes">
  <MsgText pgmKey="security.secsrv.get.RoleBasedAuthorizer" varFormat="Java">
    security.secsrv.get.RoleBasedAuthorizer=SECJ0285E: Failed to retrieve RoleBasedAuthorizer. The exception is {0}.
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7120I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.Naming.UserId" varFormat="Java">
    security.configrpt.Naming.UserId=SECJ7120I: Specific User Ids
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7535W" severity="W" prefix="yes">
  <MsgText pgmKey="security.scanner.risk.java2.improve" varFormat="Java">
    security.scanner.risk.java2.improve=SECJ7535W: Java 2 security is disabled. Java 2 security provides a policy-based, fine-grain access control mechanism that increases overall system integrity by checking for permissions before allowing access to certain protected system resources. Java 2 security guards access to system resources such as file I/O, sockets, and properties.
  </MsgText>
  <Explanation>
    Java 2 security is disabled. Java 2 security provides a policy-based, fine-grain access control mechanism that increases overall system integrity by checking for permissions before allowing access to certain protected system resources. Java 2 security guards access to system resources such as file I/O, sockets, and properties.
  </Explanation>
  <UserResponse>
    Enable  Java 2 security if applicable.
  </UserResponse>
</Message>
<Message ID="SECJ7530W" severity="W" prefix="yes">
  <MsgText pgmKey="security.scanner.risk.corba.improve.everyone" varFormat="Java">
    security.scanner.risk.corba.improve.everyone=SECJ7530W: The CORBA Namespace can be modified by Everyone. Anyone can alter the JNDI namespace. The default naming security policy is to grant all users read access to the CosNaming space and to grant any authenticated user the privilege to modify the contents of the CosNaming space. You can restrict user access to the CosNaming space.
  </MsgText>
  <Explanation>
    The CORBA Namespace can be modified by Everyone. Anyone can alter the JNDI namespace. The default naming security policy is to grant all users read access to the CosNaming space and to grant any authenticated user the privilege to modify the contents of the CosNaming space. You can restrict user access to the CosNaming space.
  </Explanation>
  <UserResponse>
    Restrict user access to the CosNaming space if applicable.
  </UserResponse>
</Message>
<Message ID="SECJ7062I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.performs" varFormat="Java">
    security.configrpt.core.performs=SECJ7062I: performs
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ6107I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.service.unsupported.auth.mechanism.audit" varFormat="Java">
    security.audit.service.unsupported.auth.mechanism.audit=SECJ6107I: The request is denied because the {0} login method was not supported.
  </MsgText>
  <Explanation>
    WebSphee Application Server does not support the configured login method.
  </Explanation>
  <UserResponse>
    Modify the deployment descriptor to choose a supported login method. You might explore the Trust Association Interface and the UserRegistry interface and plug in your custom implementation to support the DIGEST login method.
  </UserResponse>
</Message>
<Message ID="SECJ7081I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.properties" varFormat="Java">
    security.configrpt.core.properties=SECJ7081I: Custom properties
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0240I" severity="I" prefix="yes">
  <MsgText pgmKey="security.init.startcomplete" varFormat="Java">
    security.init.startcomplete=SECJ0240I: Security service initialization completed successfully
  </MsgText>
  <Explanation>
    Security service initialization started.
  </Explanation>
  <UserResponse>
    None. Informational only
  </UserResponse>
</Message>
<Message ID="SECJ7220I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.bindDN" varFormat="Java">
    security.configrpt.core.bindDN=SECJ7220I: Bind distinguished name
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7206I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.emailList" varFormat="Java">
    security.configrpt.core.emailList=SECJ7206I: List of e-mail addresses
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ8056E" severity="E" prefix="yes">
  <MsgText pgmKey="security.saml.no.sp.SECJ8056E" varFormat="Java">
    security.saml.no.sp.SECJ8056E=SECJ8056E: No service provider (SP) custom properties found for {0}.
  </MsgText>
  <Explanation>
    There are no SP custom properties found for the given SSO in the SAML TAI.
  </Explanation>
  <UserResponse>
    Configure the SP custom properties for the given SAML TAI SSO before you export it.
  </UserResponse>
</Message>
<Message ID="SECJ7255I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.description" varFormat="Java">
    security.configrpt.core.description=SECJ7255I: Description
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7084I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.security.enablePluggableAuthentication" varFormat="Java">
    security.configrpt.core.security.enablePluggableAuthentication=SECJ7084I: Enable pluggable authentication
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7763E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.noUserReg.SECJ7763E" varFormat="Java">
    security.admintask.noUserReg.SECJ7763E=SECJ7763E: A filter must be specified when certificateMapMode is set to CERTIFICATE_FILTER.
  </MsgText>
  <Explanation>
    When the certificateMapMode is set to CERTIFICATE_FILTER a filter must be provided.
  </Explanation>
  <UserResponse>
    Ensure a filter is provided when certificateMapMode is set to CERTIFICATE_FILTER.
  </UserResponse>
</Message>
<Message ID="SECJ7188I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.direction" varFormat="Java">
    security.configrpt.core.direction=SECJ7188I: Direction
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7396E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.InvalidMaxSizeValue" varFormat="Java">
    security.admintask.InvalidMaxSizeValue=SECJ7396E: Non valid value for maximum size of each audit log was specified.
  </MsgText>
  <Explanation>
    The maximum size of and audit log needs to a value greater than 0.
  </Explanation>
  <UserResponse>
    Supply a valid value for maximum number of audit logs
  </UserResponse>
</Message>
<Message ID="SECJ0118E" severity="E" prefix="yes">
  <MsgText pgmKey="security.authn.error.foruser" varFormat="Java">
    security.authn.error.foruser=SECJ0118E: Authentication error during authentication for user {0}
  </MsgText>
  <Explanation>
    An authentication error occurred during authentication.  This could be due to a user name and password that is not valid.
  </Explanation>
  <UserResponse>
    Verify that the user name and password specified are valid.
  </UserResponse>
</Message>
<Message ID="SECJ7061I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.sslConfig" varFormat="Java">
    security.configrpt.core.sslConfig=SECJ7061I: SSL configurations
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7033I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.authorizationProviders" varFormat="Java">
    security.configrpt.core.authorizationProviders=SECJ7033I: Authorization providers
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7762E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.noUserReg.SECJ7762E" varFormat="Java">
    security.admintask.noUserReg.SECJ7762E=SECJ7762E: Unable to find the registry object.
  </MsgText>
  <Explanation>
    The registry object matching the domain, resource, or realm provide does not exist.
  </Explanation>
  <UserResponse>
    Run the command with a domain, resource, or realm that has a user registry associated with it.
  </UserResponse>
</Message>
<Message ID="SECJ7233I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.adminPreferredAuthMech" varFormat="Java">
    security.configrpt.core.adminPreferredAuthMech=SECJ7233I: Primary Authentication Method for Administrative Actions
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7203I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.frequency" varFormat="Java">
    security.configrpt.core.frequency=SECJ7203I: Frequency
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7049I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.CSI" varFormat="Java">
    security.configrpt.core.CSI=SECJ7049I: CSI
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ6034E" severity="E" prefix="yes">
  <MsgText pgmKey="security.audit.logger.init.error" varFormat="Java">
    security.audit.logger.init.error=SECJ6034E: Exception raised trying to create the Audit log.  Exception = {0}.
  </MsgText>
  <Explanation>
    Failed to create the output Audit log.
  </Explanation>
  <UserResponse>
    Examine the exception for the cause of the problem.
  </UserResponse>
</Message>
<Message ID="SECJ8049E" severity="E" prefix="yes">
  <MsgText pgmKey="security.saml.sso.with.no.sp.SECJ8049E" varFormat="Java">
    security.saml.sso.with.no.sp.SECJ8049E=SECJ8049E: You must configure a service provider (SP) for {0} before adding an IdP partner.
  </MsgText>
  <Explanation>
    The SSO entry has no SP information.
  </Explanation>
  <UserResponse>
    Configure a service provider for this SSO before adding an IdP partner.
  </UserResponse>
</Message>
<Message ID="SECJ0211E" severity="E" prefix="yes">
  <MsgText pgmKey="security.secsvr.nameerror" varFormat="Java">
    security.secsvr.nameerror=SECJ0211E: Failed to lookup or rebind security server with name {0}.  The exception is {1}.
  </MsgText>
  <Explanation>
    An unexpected error occurred.  It could be that the Cell Manager or Node Agent are not started.
  </Explanation>
  <UserResponse>
    If a remote security server was specified when enabling global security, verify that the Node Agent and Cell Manager are running.
  </UserResponse>
</Message>
<Message ID="SECJ7722E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.noAuthMechanismObj.SECJ7722E" varFormat="Java">
    security.admintask.noAuthMechanismObj.SECJ7722E=SECJ7722E: The authentication mechanism is not configured.
  </MsgText>
  <Explanation>
    Unable to find the authentication mechanism in the user registry.
  </Explanation>
  <UserResponse>
    Ensure a authentication mechanism is configured.
  </UserResponse>
</Message>
<Message ID="SECJ6222I" severity="I" prefix="yes">
  <MsgText pgmKey="security.zos.saf.threadid.sync.not.allowed.info" varFormat="Java">
    security.zos.saf.threadid.sync.not.allowed.info=SECJ6222I: Thread identity synchronization of user &quot;{0}&quot; was not authorized by the z/OS security product.
  </MsgText>
  <Explanation>
    The z/OS security product did not authorize the creation of a security environment for the specified user.  The security environment associated with the current address space will be used.
  </Explanation>
  <UserResponse>
    Contact your security product administrator to authorize the creation of a security environment for the specified user if required by your application.
  </UserResponse>
</Message>
<Message ID="SECJ6114I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.tai.challenge.invalid.audit" varFormat="Java">
    security.audit.tai.challenge.invalid.audit=SECJ6114I: Trust Accosication Interceptor challenges the web client for authentication information. Status code = {0}.
  </MsgText>
  <Explanation>
    A Trust Association Interceptor engages in the authentication protocol and needs authentication information from the web client.
  </Explanation>
  <UserResponse>
    No action is required.
  </UserResponse>
</Message>
<Message ID="SECJ6131I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.authz.denied.audit" varFormat="Java">
    security.audit.authz.denied.audit=SECJ6131I: Access is denied.
  </MsgText>
  <Explanation>
    Access to the resource is denied because the user or the groups the user is in does not have any of the required security role.
  </Explanation>
  <UserResponse>
    No action required if this is the desired behavior.
  </UserResponse>
</Message>
<Message ID="SECJ0398E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jacc.modify.task.error" varFormat="Java">
    security.jacc.modify.task.error=SECJ0398E: Error updating information to the JACC provider for application {0}. The exception is {1}.
  </MsgText>
  <Explanation>
    Cannot provide the security policy information to the JACC provider because of the exception. Without this information, the authorization decisions cannot be made correctly when security is enabled.
  </Explanation>
  <UserResponse>
    Make sure that the JACC provider is properly configured and can be accessed. After the problem is fixed, one can either re-install the application or run the propagatePolicyToJACCProvider tool to propagate the policy information to the JACC provider. For more information about this tool, search for propagatePolicyToJaccProvider in the information center documentation. If the modification involved removing any modules, you can delete the information in the JACC provider to avoid redundant data.
  </UserResponse>
</Message>
<Message ID="SECJ4037E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaas.open.URL" varFormat="Java">
    security.jaas.open.URL=SECJ4037E: {0} :ERROR: Could not open URL: {1}. The exception is {2}
  </MsgText>
  <Explanation>
    MalformedURLException occurred trying to connect the specified URL.
  </Explanation>
  <UserResponse>
    Investigate the exception. Check the specified URL.
  </UserResponse>
</Message>
<Message ID="SECJ0096E" severity="E" prefix="yes">
  <MsgText pgmKey="security.mg.createexcp" varFormat="Java">
    security.mg.createexcp=SECJ0096E: Error creating method group {0}
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7529W" severity="W" prefix="yes">
  <MsgText pgmKey="security.scanner.risk.corba.improve.all.auth" varFormat="Java">
    security.scanner.risk.corba.improve.all.auth=SECJ7529W: The CORBA Namespace can be modified by All Authenticated users. Any authenticated user can alter the JNDI namespace. The default naming security policy is to grant all users read access to the CosNaming space and to grant any authenticated user the privilege to modify the contents of the CosNaming space. You can restrict user access to the CosNaming space.
  </MsgText>
  <Explanation>
    The CORBA Namespace can be modified by All Authenticated users. Any authenticated user can alter the JNDI namespace. The default naming security policy is to grant all users read access to the CosNaming space and to grant any authenticated user the privilege to modify the contents of the CosNaming space. You can restrict user access to the CosNaming space.
  </Explanation>
  <UserResponse>
    Restrict user access to the CosNaming space if applicable.
  </UserResponse>
</Message>
<Message ID="SECJ7794I" severity="I" prefix="yes">
  <MsgText pgmKey="security.multidomain.runtime.SECJ7794I" varFormat="Java">
    security.multidomain.runtime.SECJ7794I=SECJ7794I: No User registry is defined at the domain level of the server. The global security  registry will be used.
  </MsgText>
  <Explanation>
    This message is for informational purposes only.
  </Explanation>
  <UserResponse>
    No action is required.
  </UserResponse>
</Message>
<Message ID="SECJ0056E" severity="E" prefix="yes">
  <MsgText pgmKey="security.authn.failed" varFormat="Java">
    security.authn.failed=SECJ0056E: Authentication failed for reason {0}
  </MsgText>
  <Explanation>
    Authentication failed with the specified reason.
  </Explanation>
  <UserResponse>
    Verify that the user id and password are entered correctly. Consult with the administrator of the user registry if the problem persist.
  </UserResponse>
</Message>
<Message ID="SECJ7264I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.domain.system.jaas" varFormat="Java">
    security.configrpt.domain.system.jaas=SECJ7264I: JAAS System Logins
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0153E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.ldap.invalidUserID" varFormat="Java">
    security.registry.ldap.invalidUserID=SECJ0153E: Invalid LDAP user ID
  </MsgText>
  <Explanation>
    Using user ID that is not valid or the user ID is not a directory entry. The directory administration ID (root DN) is not a directory entry on most LDAP servers.
  </Explanation>
  <UserResponse>
    Verify that the user ID is a valid directory entry.
  </UserResponse>
</Message>
<Message ID="SECJ7793I" severity="I" prefix="yes">
  <MsgText pgmKey="security.multidomain.runtime.SECJ7793I" varFormat="Java">
    security.multidomain.runtime.SECJ7793I=SECJ7793I: A User registry of type {0} is defined at the domain level for the server. This will override use of the global security registry.
  </MsgText>
  <Explanation>
    This message is for informational purposes only.
  </Explanation>
  <UserResponse>
    No action is required.
  </UserResponse>
</Message>
<Message ID="SECJ7005I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.activeUserRegistry" varFormat="Java">
    security.configrpt.core.activeUserRegistry=SECJ7005I: User account repository
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7729E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.noLTPAAuthMechanism.SECJ7729E" varFormat="Java">
    security.admintask.noLTPAAuthMechanism.SECJ7729E=SECJ7729E: No LTPA auth mechanism was found.
  </MsgText>
  <Explanation>
    An LTPA auth mechanism must be defined.
  </Explanation>
  <UserResponse>
    Ensure that an LTPA auth mechanism is defined.
  </UserResponse>
</Message>
<Message ID="SECJ0173W" severity="W" prefix="yes">
  <MsgText pgmKey="security.policy.sysextparser.ignoregrant" varFormat="Java">
    security.policy.sysextparser.ignoregrant=SECJ0173W: Grant entry with codebase {0} and signedby {1} is being ignored
  </MsgText>
  <Explanation>
    In the system extension policy files, the grant entries should not specify codebase and signedby values
  </Explanation>
  <UserResponse>
    Remove the codebase and signedby values from the grant entry in the system extension policy file. (spi.policy or library.policy)
  </UserResponse>
</Message>
<Message ID="SECJ7149I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.keySets" varFormat="Java">
    security.configrpt.core.keySets=SECJ7149I: Key sets
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7792I" severity="I" prefix="yes">
  <MsgText pgmKey="security.multidomain.runtime.SECJ7792I" varFormat="Java">
    security.multidomain.runtime.SECJ7792I=SECJ7792I: Outbound trusted foreign realms are defined. The following is a the list of such realms {0}.
  </MsgText>
  <Explanation>
    This message is for informational purposes only.
  </Explanation>
  <UserResponse>
    No action is required.
  </UserResponse>
</Message>
<Message ID="SECJ4033E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaas.nosubect" varFormat="Java">
    security.jaas.nosubect=SECJ4033E: The LoginContext does not contain a Subject after authenticating user {0} with LoginModule alias {1}.
  </MsgText>
  <Explanation>
    The LoginModule did not create a Subject.  There is a problem with the LoginModule
  </Explanation>
  <UserResponse>
    This problem could be due to a configuration error in security.xml or an internal error.
  </UserResponse>
</Message>
<Message ID="SECJ6045E" severity="E" prefix="yes">
  <MsgText pgmKey="security.audit.invalid.shared.key.error" varFormat="Java">
    security.audit.invalid.shared.key.error=SECJ6045E: Shared key that is not valid has been encountered.
  </MsgText>
  <Explanation>
    A shared key that is not valid was detected.
  </Explanation>
  <UserResponse>
    Verify that a valid key is being used.  Check the error logs for further information.
  </UserResponse>
</Message>
<Message ID="SECJ0362E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.createcredential.nouser" varFormat="Java">
    security.registry.createcredential.nouser=SECJ0362E: Cannot create credential for the user {0}.
  </MsgText>
  <Explanation>
    A user cannot be found to create the credential.
  </Explanation>
  <UserResponse>
    Make sure that the user is valid in the registry. Contact your service representative if the problem persists.
  </UserResponse>
</Message>
<Message ID="SECJ0233E" severity="E" prefix="yes">
  <MsgText pgmKey="security.sambean.getusrerr" varFormat="Java">
    security.sambean.getusrerr=SECJ0233E: An unexpected exception occurred when trying to get users from the User Registry with pattern {0} and limit {1}. The exception is {2}.
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7466E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.NoSuchAlgorithmException" varFormat="Java">
    security.admintask.NoSuchAlgorithmException=SECJ7466E: Exception was raised while loading the keystore.  A particular crypto algorithm was requested by is not available.
  </MsgText>
  <Explanation>
    The crypto algorithm associated with this keystore is not available.
  </Explanation>
  <UserResponse>
    Ensure the crypto algorithm is available.
  </UserResponse>
</Message>
<Message ID="SECJ7731E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.noInterceptor.SECJ7731E" varFormat="Java">
    security.admintask.noInterceptor.SECJ7731E=SECJ7731E: The specified interceptor does not exist.
  </MsgText>
  <Explanation>
    The specified interceptor does not exist.
  </Explanation>
  <UserResponse>
    Either create the interceptor, or specify a different interceptor class name.
  </UserResponse>
</Message>
<Message ID="SECJ0401E" severity="E" prefix="yes">
  <MsgText pgmKey="security.web.compmetadata.error" varFormat="Java">
    security.web.compmetadata.error=SECJ0401E: Error getting the WebModuleMetaData or missing metadata for context root {0}. The exception is {1}.
  </MsgText>
  <Explanation>
    This is an internal error. Without the meta data, the moduleName and applicationName cannot be obtained for access decisions.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7459E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.InvalidSequenceNumber" varFormat="Java">
    security.admintask.InvalidSequenceNumber=SECJ7459E: Non valid sequence number specified.  Sequence numbers begin at 0 and have integer values.
  </MsgText>
  <Explanation>
    A non valid value was specified for the sequence number associated with an audit records to report
  </Explanation>
  <UserResponse>
    Specify a non-empty or valid value for the sequence number.
  </UserResponse>
</Message>
<Message ID="SECJ7791I" severity="I" prefix="yes">
  <MsgText pgmKey="security.multidomain.runtime.SECJ7791I" varFormat="Java">
    security.multidomain.runtime.SECJ7791I=SECJ7791I: Inbound trusted foreign realms are defined. The following is the list of such realms {0}.
  </MsgText>
  <Explanation>
    This message is for informational purposes only.
  </Explanation>
  <UserResponse>
    No action is required.
  </UserResponse>
</Message>
<Message ID="SECJ7151I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.WSNotification" varFormat="Java">
    security.configrpt.core.WSNotification=SECJ7151I: Notifications
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7169I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.milliseconds" varFormat="Java">
    security.configrpt.milliseconds=SECJ7169I: milliseconds
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0058E" severity="E" prefix="yes">
  <MsgText pgmKey="security.ltpaserver.notexist" varFormat="Java">
    security.ltpaserver.notexist=SECJ0058E: LTPAServer does not exist
  </MsgText>
  <Explanation>
    This is an internal error probably due to LTPAServer initialization problems.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7248I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.filters" varFormat="Java">
    security.configrpt.core.filters=SECJ7248I: SPNEGO Filters
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0131E" severity="E" prefix="yes">
  <MsgText pgmKey="security.authn.error.owncred" varFormat="Java">
    security.authn.error.owncred=SECJ0131E: Authentication failed. Unable to get the mapped credential for SecOwnCredentials.
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7197I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.keyGenerationClass" varFormat="Java">
    security.configrpt.core.keyGenerationClass=SECJ7197I: Key generation class
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0186E" severity="E" prefix="yes">
  <MsgText pgmKey="security.policy.sysext.ioexception" varFormat="Java">
    security.policy.sysext.ioexception=SECJ0186E: Caught IOException while creating template for System Extension Policy of type {1} The exception is {0}
  </MsgText>
  <Explanation>
    IOException occurred when creating the system extension template in the hashmap of all the templates.
  </Explanation>
  <UserResponse>
    Check the IOException to see the cause for not being able to create the system extension template in the hashmap.
  </UserResponse>
</Message>
<Message ID="SECJ7211I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.isEnabled" varFormat="Java">
    security.configrpt.core.isEnabled=SECJ7211I: Enable checking
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ4048E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaas.app.parse" varFormat="Java">
    security.jaas.app.parse=SECJ4048E: ParserException occurred during parsing jaas application configuration. The exception is {0}
  </MsgText>
  <Explanation>
    ParserException occurred during parsing jaas application configuration.
  </Explanation>
  <UserResponse>
    Investigate the exception. It has the information of syntax error in the configuration file.
  </UserResponse>
</Message>
<Message ID="SECJ0291E" severity="E" prefix="yes">
  <MsgText pgmKey="security.servcomp.get.resource" varFormat="Java">
    security.servcomp.get.resource=SECJ0291E: Failed to retrieve the information of Resource Adapter for provider ( {0} ) to call setupPolicy().
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ4047E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaas.app.parseIO" varFormat="Java">
    security.jaas.app.parseIO=SECJ4047E: IOException occurred during parsing jaas application configuration. The exception is {0}
  </MsgText>
  <Explanation>
    IOException occurred during parsing jaas application configuration.
  </Explanation>
  <UserResponse>
    Check the configuration file. Investigate the exception.
  </UserResponse>
</Message>
<Message ID="SECJ0378E" severity="E" prefix="yes">
  <MsgText pgmKey="security.sambean.nullsecserver" varFormat="Java">
    security.sambean.nullsecserver=SECJ0378E: Cannot get SecurityServer in the security MBean.
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7538W" severity="W" prefix="yes">
  <MsgText pgmKey="security.scanner.risk.ldaplink.improve" varFormat="Java">
    security.scanner.risk.ldaplink.improve=SECJ7538W: User Registry is LDAP. SSL between WebSphere Application Server and LDAP is disabled. The communication between WebSphere Application Server and LDAP is not encrypted
  </MsgText>
  <Explanation>
    User Registry is LDAP. SSL between WebSphere Application Server and LDAP server is disabled. The communication between WebSphere Application Server and LDAP is not encrypted
  </Explanation>
  <UserResponse>
    Enable SSL between the WebSphere Application Server and LDAP server if needed.
  </UserResponse>
</Message>
<Message ID="SECJ7790I" severity="I" prefix="yes">
  <MsgText pgmKey="security.multidomain.runtime.SECJ7790I" varFormat="Java">
    security.multidomain.runtime.SECJ7790I=SECJ7790I: In addition to global security, this server process is associated with a domain security configuration. The domain name of this server is:  {0}.
  </MsgText>
  <Explanation>
    This message is for informational purposes only.
  </Explanation>
  <UserResponse>
    No action is required.
  </UserResponse>
</Message>
<Message ID="SECJ7420E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.AliasNotPersonalCert" varFormat="Java">
    security.admintask.AliasNotPersonalCert=SECJ7420E: Alias is not a personal certificate in key store.
  </MsgText>
  <Explanation>
    The alias is either not in the key store or it is not a personal certificate in the key store.
  </Explanation>
  <UserResponse>
    Rerun the command with a personal certificate that is located in the key store.
  </UserResponse>
</Message>
<Message ID="SECJ4022E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaas.NoCredentialsHelper" varFormat="Java">
    security.jaas.NoCredentialsHelper=SECJ4022E: CORBA: Not suppose to construct CredentialsHelper object
  </MsgText>
  <Explanation>
    CredentialsHelper object instance should not be constructed.
  </Explanation>
  <UserResponse>
    Check the user application. CredentialsHelper should not be directly constructed.
  </UserResponse>
</Message>
<Message ID="SECJ7360E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.InvalidKeystoreRef" varFormat="Java">
    security.admintask.InvalidKeystoreRef=SECJ7360E: Non valid or no reference specified for the keystore.
  </MsgText>
  <Explanation>
    The keystore reference is a required field.
  </Explanation>
  <UserResponse>
    Verify that a valid reference has been specified for the keystore
  </UserResponse>
</Message>
<Message ID="SECJ7160I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.jsseProvider" varFormat="Java">
    security.configrpt.core.jsseProvider=SECJ7160I: JSSE Provider
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ5009E" severity="E" prefix="yes">
  <MsgText pgmKey="security.sap.error.credential.not.mapped" varFormat="Java">
    security.sap.error.credential.not.mapped=SECJ5009E: Could not create a WSCredential given the information provided during a propagation login.  The following exception occurred: {0}
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7187I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.certificateAlias" varFormat="Java">
    security.configrpt.core.certificateAlias=SECJ7187I: Certificate alias
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0077E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registryimpl.notfound" varFormat="Java">
    security.registryimpl.notfound=SECJ0077E: Registry impl class {0} not found for type {1}
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7183I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.inclusive" varFormat="Java">
    security.configrpt.core.inclusive=SECJ7183I: Inclusive
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7017I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.authValidationConfig" varFormat="Java">
    security.configrpt.core.authValidationConfig=SECJ7017I: Authentication validation config
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ5011E" severity="E" prefix="yes">
  <MsgText pgmKey="security.sap.error.authorization.token.not.mapped" varFormat="Java">
    security.sap.error.authorization.token.not.mapped=SECJ5011E: Could not create default AuthorizationToken during propagation login.  The following exception occurred: {0}
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7714E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.noServerID.SECJ7714E" varFormat="Java">
    security.admintask.noServerID.SECJ7714E=SECJ7714E: When automatic generation of the server identity is enabled then server id and password should not be specified.
  </MsgText>
  <Explanation>
    When automatic generation of the server id is enable then no server id and password should be provided.
  </Explanation>
  <UserResponse>
    Ensure no server id and password is provided when automatic generation of server id is enabled.
  </UserResponse>
</Message>
<Message ID="SECJ7260I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.domain.AuthMechanism" varFormat="Java">
    security.configrpt.domain.AuthMechanism=SECJ7260I: LTPA Timeout
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7752E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.invalidCommoType.SECJ7752E" varFormat="Java">
    security.admintask.invalidCommoType.SECJ7752E=SECJ7752E: Communication type is not valid, specify inbound or outbound.
  </MsgText>
  <Explanation>
    The communication type specified is not valid.  Either inbound or outbound needs to be specified.
  </Explanation>
  <UserResponse>
    Run the command specifying the correct communication type.
  </UserResponse>
</Message>
<Message ID="SECJ4009E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaas.missingUserRealmOrPwd" varFormat="Java">
    security.jaas.missingUserRealmOrPwd=SECJ4009E: Either user name, realm or password data is missing.
  </MsgText>
  <Explanation>
    User name, realm name or password is missing.
  </Explanation>
  <UserResponse>
    Confirm that the necessary authentication data is passed. Enabling security debug trace for component com.ibm.ws.security.auth.* might yield additional information.
  </UserResponse>
</Message>
<Message ID="SECJ7434E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.NotThirdPartyImpl" varFormat="Java">
    security.admintask.NotThirdPartyImpl=SECJ7434E: The audit service provider referenced is not a third party provider implementation.
  </MsgText>
  <Explanation>
    The referenced service provider is not a third party service provider implementation.
  </Explanation>
  <UserResponse>
    Enter a valid reference to a third party service provider implementation
  </UserResponse>
</Message>
<Message ID="SECJ0162E" severity="E" prefix="yes">
  <MsgText pgmKey="security.wsaccessmanager.VendorAuthTableSpecificError" varFormat="Java">
    security.wsaccessmanager.VendorAuthTableSpecificError=SECJ0162E: Vendor&apos;&apos;s specific exception. The exception is {0} .
  </MsgText>
  <Explanation>
    This indicates the vendor&apos;s specific error. Example:- Server not started, Network failure, Server failed.
  </Explanation>
  <UserResponse>
    Depends on the error.
  </UserResponse>
</Message>
<Message ID="SECJ0135W" severity="W" prefix="yes">
  <MsgText pgmKey="security.jsecman.illexit" varFormat="Java">
    security.jsecman.illexit=SECJ0135W: Illegal System.exit() attempted
  </MsgText>
  <Explanation>
    Only the main thread is allowed to exit the Java VM
  </Explanation>
  <UserResponse>
    Verify that the code attempting the system exit is not trying to subvert the WebSphere security manager.
  </UserResponse>
</Message>
<Message ID="SECJ5013E" severity="E" prefix="yes">
  <MsgText pgmKey="security.sap.error.propagation.token.not.mapped" varFormat="Java">
    security.sap.error.propagation.token.not.mapped=SECJ5013E: Could not create default SingleSignonToken during propagation login.  The following exception occurred: {0}
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ6033E" severity="E" prefix="yes">
  <MsgText pgmKey="security.audit.encryption.init.error" varFormat="Java">
    security.audit.encryption.init.error=SECJ6033E: Failure to initialize Audit encryption algorithm.  Exception = {0}.
  </MsgText>
  <Explanation>
    Initialization failure of encryption algorithm.
  </Explanation>
  <UserResponse>
    Examine the exception for the cause of the problem.
  </UserResponse>
</Message>
<Message ID="SECJ0425I" severity="I" prefix="yes">
  <MsgText pgmKey="security.merge.custom.property.notadded" varFormat="Java">
    security.merge.custom.property.notadded=SECJ0425I: The custom property {0} from the Node security.xml already exists in the Cell security.xml and will not overwrite the Cell value.
  </MsgText>
  <Explanation>
    Informational.
  </Explanation>
  <UserResponse>
    No user action is required. During the server and the cell security object merging, if a custom property with the same name exists in both, the property will not be copied to the cell configuration. It is normal for the cell to have custom properties that match the server.
  </UserResponse>
</Message>
<Message ID="SECJ4054E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaas.invalidType2.cred.exception" varFormat="Java">
    security.jaas.invalidType2.cred.exception=SECJ4054E: InvalidCredentialType exception is caught while serialized Subject is being restored. The exception is {0}.
  </MsgText>
  <Explanation>
    InvalidCredentialType exception occurred while restoring the credential.
  </Explanation>
  <UserResponse>
    Investigate the SAS problem. Contact your service representative if the problem persist.
  </UserResponse>
</Message>
<Message ID="SECJ7047I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.options" varFormat="Java">
    security.configrpt.core.options=SECJ7047I: Custom properties
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7130I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.Certificate.Console.Path" varFormat="Java">
    security.configrpt.Certificate.Console.Path=SECJ7130I: Console Path for Certificate Management
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7468E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.ErrorLoadingKeystore" varFormat="Java">
    security.admintask.ErrorLoadingKeystore=SECJ7468E: Error loading the keystore. The password may have been incorrectly specified.
  </MsgText>
  <Explanation>
    Could not open the keystore.
  </Explanation>
  <UserResponse>
    Verify that the password was correctly specified and verify the keystore exists.
  </UserResponse>
</Message>
<Message ID="SECJ7262I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.domain.Auth.Config" varFormat="Java">
    security.configrpt.domain.Auth.Config=SECJ7262I: Authorization Provider
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7300E" severity="E" prefix="yes">
  <MsgText pgmKey="security.profiletask.failAddingAdminToWim" varFormat="Java">
    security.profiletask.failAddingAdminToWim=SECJ7300E: Failed in attempt to add administrative user to virtual member manager
  </MsgText>
  <Explanation>
    Admin user id could not be added to virtual member manager file-based registry
  </Explanation>
  <UserResponse>
    Validate virtual member manager has been configured
  </UserResponse>
</Message>
<Message ID="SECJ7440E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.CannotDeleteSigningKeyStore" varFormat="Java">
    security.admintask.CannotDeleteSigningKeyStore=SECJ7440E: Empty value specified for keystore.  Cannot delete the signing keystore when signing is enabled or being enabled.
  </MsgText>
  <Explanation>
    Signing is enabled or is being enabled. The signing keystore is in use and cannot be deleted
  </Explanation>
  <UserResponse>
    Disable encryption before deleting the signing keystore.
  </UserResponse>
</Message>
<Message ID="SECJ6004I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.service.disabled.audit" varFormat="Java">
    security.audit.service.disabled.audit=SECJ6004I: Security Auditing is disabled.
  </MsgText>
  <Explanation>
    This audit message indicates that the WebSphere Application Server Security Auditing service is disabled.
  </Explanation>
  <UserResponse>
    No action is required if this is the desired setting.
  </UserResponse>
</Message>
<Message ID="SECJ7728E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.noSingleSignon.SECJ7728E" varFormat="Java">
    security.admintask.noSingleSignon.SECJ7728E=SECJ7728E: No singleSignon attribute was found.
  </MsgText>
  <Explanation>
    The LTPA authMechanism must contain a singleSignon attribute.
  </Explanation>
  <UserResponse>
    Ensure that the security.xml file contains an LTPA authMechanism with a singleSignon attribute.
  </UserResponse>
</Message>
<Message ID="SECJ0097E" severity="E" prefix="yes">
  <MsgText pgmKey="security.mg.finderr" varFormat="Java">
    security.mg.finderr=SECJ0097E: Error finding method groups
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7190I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.scopeType" varFormat="Java">
    security.configrpt.core.scopeType=SECJ7190I: Scope Type
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7451E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.InvalidOutputLocation" varFormat="Java">
    security.admintask.InvalidOutputLocation=SECJ7451E: Non valid or no value specified for the fully qualified path for the location of the output html report.
  </MsgText>
  <Explanation>
    The expected fully qualified file location for the output html report was specified incorrectly.
  </Explanation>
  <UserResponse>
    Specify a non-empty valid name for the file location of the output html report.
  </UserResponse>
</Message>
<Message ID="SECJ4050E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaas.restore.exception" varFormat="Java">
    security.jaas.restore.exception=SECJ4050E: An unexpected exception is caught: {0}.
  </MsgText>
  <Explanation>
    Unexpected exception occurred while restoring the credential.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7128I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.secure.communications" varFormat="Java">
    security.configrpt.secure.communications=SECJ7128I: SSL certificate and key management
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ4030E" severity="E" prefix="yes">
  <MsgText pgmKey="security.j2c.unrecognizedCallbackIndex" varFormat="Java">
    security.j2c.unrecognizedCallbackIndex=SECJ4030E: Unrecognizable Callback index = {0} {1}
  </MsgText>
  <Explanation>
    Unrecognizable Callback is passed.
  </Explanation>
  <UserResponse>
    Contact your service representative with information present in the error log.
  </UserResponse>
</Message>
<Message ID="SECJ6122I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.cert.default.audit" varFormat="Java">
    security.audit.cert.default.audit=SECJ6122I: Client certificate Authentication failed due to internal error.  Will try Basec authentication which is permitted by the web application configuration.
  </MsgText>
  <Explanation>
    The authentication failed due to an unexpected runtime exception.  The web application configuration allows authentication using user id and password. Will try to see if there is user id and password information in the HTTP header.
  </Explanation>
  <UserResponse>
    No action is required.
  </UserResponse>
</Message>
<Message ID="SECJ0332E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.checkpass.failed" varFormat="Java">
    security.registry.checkpass.failed=SECJ0332E: The checkPassword method failed for user {0}.
  </MsgText>
  <Explanation>
    The checkPassword method failed to return a user.
  </Explanation>
  <UserResponse>
    If you are using WebSphere Application Server provided registries, this problem should have been preceeded by other authentication related exception(s). Refere to those exceptions to fix the actual authentication problem. If a custom registry is used, make sure to return a valid userId after authentication is successful.
  </UserResponse>
</Message>
<Message ID="SECJ7780E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.mismatch.krbKeytab.SECJ7780E" varFormat="Java">
    security.admintask.mismatch.krbKeytab.SECJ7780E=SECJ7780E: Mismatch Kerberos keytab file. The keytab file for Kerberos authentication mechanism is {0} but the keytab file for SPNEGO Web authentication is {1}
  </MsgText>
  <Explanation>
    The Kerberos keytab for Kerberos authentication mechanism is not the same with the SPNEGO Web authentication.
  </Explanation>
  <UserResponse>
    Verify the Kerberos keytab file for Kerberos authentication and SPNEGO Web authentication are the same one.
  </UserResponse>
</Message>
<Message ID="SECJ6030E" severity="E" prefix="yes">
  <MsgText pgmKey="security.audit.encryption.error" varFormat="Java">
    security.audit.encryption.error=SECJ6030E: Failure to encrypt the audit record.  Exception = {0}.
  </MsgText>
  <Explanation>
    Encryption error generated while trying to encrypt the audit record.
  </Explanation>
  <UserResponse>
    Examine the exception for the cause of the problem.
  </UserResponse>
</Message>
<Message ID="SECJ0261E" severity="E" prefix="yes">
  <MsgText pgmKey="security.swam.commit.ex" varFormat="Java">
    security.swam.commit.ex=SECJ0261E: Something wrong during LoginModule commit. The exception is {0}
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7048I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.value" varFormat="Java">
    security.configrpt.core.value=SECJ7048I: Value
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ6042E" severity="E" prefix="yes">
  <MsgText pgmKey="security.audit.signing.data.error" varFormat="Java">
    security.audit.signing.data.error=SECJ6042E: Data that is not valid was passed into the signing algorithm.
  </MsgText>
  <Explanation>
    A data stream that was not valid was passed in to the signing algorithm.
  </Explanation>
  <UserResponse>
    Verify that a non-null byte stream of data is being passed in.
  </UserResponse>
</Message>
<Message ID="SECJ0111W" severity="W" prefix="yes">
  <MsgText pgmKey="security.core.norunasmap" varFormat="Java">
    security.core.norunasmap=SECJ0111W: RunAsMap Not defined properly for Application {0}
  </MsgText>
  <Explanation>
    The run-as-bindings size is zero for this application.
  </Explanation>
  <UserResponse>
    Verify that the run-as bindings are specified for the application if necessary.
  </UserResponse>
</Message>
<Message ID="SECJ4013E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaas.callBackHandlerIOException" varFormat="Java">
    security.jaas.callBackHandlerIOException=SECJ4013E: An unexpected IOexception occurred in Login Module {0} CallbackHandler. The exception is {1}
  </MsgText>
  <Explanation>
    Exception occurred while processing callbacks
  </Explanation>
  <UserResponse>
    Contact your service representative with exception stack trace information present in the error log.
  </UserResponse>
</Message>
<Message ID="SECJ7533W" severity="W" prefix="yes">
  <MsgText pgmKey="security.scanner.risk.drs.improve" varFormat="Java">
    security.scanner.risk.drs.improve=SECJ7533W: Encryption is disabled on Distributed Replication Service(DRS). The data shared among WebSphere Application servers is not encrypted.
  </MsgText>
  <Explanation>
    Encryption is disabled on Distributed Replication Service(DRS). The data shared among WebSphere Application servers is not encrypted.
  </Explanation>
  <UserResponse>
    Enable Distributed Replication Service encryption if needed.
  </UserResponse>
</Message>
<Message ID="SECJ6224I" severity="I" prefix="yes">
  <MsgText pgmKey="security.zos.saf.role.mapper.loaded" varFormat="Java">
    security.zos.saf.role.mapper.loaded=SECJ6224I: The custom SAF role to profile mapper &quot;{0}&quot; has been initialized.
  </MsgText>
  <Explanation>
    A custom SAF role to profile mapper has been configured, loaded, and initialized.
  </Explanation>
  <UserResponse>
    No user action is required.
  </UserResponse>
</Message>
<Message ID="SECJ6022E" severity="E" prefix="yes">
  <MsgText pgmKey="security.audit.service.provider.error" varFormat="Java">
    security.audit.service.provider.error=SECJ6022E: AuditServiceProvider malfunction when security auditing is required, Provider Exception = {0}.
  </MsgText>
  <Explanation>
    The configured AuditServiceProvider did not run the method in a reasonable time period while security auditing function is required.
  </Explanation>
  <UserResponse>
    Examine the exception for the cause of the problem.  Typically the business transactions should have been aborted because no security auditing record can be logged.
  </UserResponse>
</Message>
<Message ID="SECJ6145I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.csi.unauthn.cred.audit" varFormat="Java">
    security.audit.csi.unauthn.cred.audit=SECJ6145I: Authenticate to unauthenticated credentials.
  </MsgText>
  <Explanation>
    Setting the credentials to unauthenticated because there is no valid identity token.
  </Explanation>
  <UserResponse>
    No action is required.
  </UserResponse>
</Message>
<Message ID="SECJ7377E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.UnsupportedFilterOp" varFormat="Java">
    security.admintask.UnsupportedFilterOp=SECJ7377E: Unsupported operation: cannot delete a subset of a multi-set defined filter.
  </MsgText>
  <Explanation>
    Admin task does not support deletion of a subset of a multi-set defined filter.
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7242I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.adminCertificate" varFormat="Java">
    security.configrpt.core.adminCertificate=SECJ7242I: Personal certificate for encryption
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ6005E" severity="E" prefix="yes">
  <MsgText pgmKey="security.audit.service.invalid.error" varFormat="Java">
    security.audit.service.invalid.error=SECJ6005E: Invalid configuration {0} = name {1} and class name {2}.
  </MsgText>
  <Explanation>
    The provider configuration in global security custom properties was incorrect.
  </Explanation>
  <UserResponse>
    Check the specified properties and in particular the first missing parameter in the error message.
  </UserResponse>
</Message>
<Message ID="SECJ0226E" severity="E" prefix="yes">
  <MsgText pgmKey="security.init.secidequalsrealm" varFormat="Java">
    security.init.secidequalsrealm=SECJ0226E: The LocalOS server ID ({0}) should not be the same value as the LocalOS realm ({1}) in the security.xml.
  </MsgText>
  <Explanation>
    When the LocalOS server ID is equal to the LocalOS realm, the access ID returned by the operating system is the machine ID not the server ID.
  </Explanation>
  <UserResponse>
    Make sure that the server ID is different from the machine ID.
  </UserResponse>
</Message>
<Message ID="SECJ0384E" severity="E" prefix="yes">
  <MsgText pgmKey="security.web.ta.initerr" varFormat="Java">
    security.web.ta.initerr=SECJ0384E: Trust Association Init Error. The Trust Association interceptor implementation {0} initialization failed. The error status/exception is {1}. If you receive this error message in association with a trust association interceptor that you are not using, you can ignore this message.
  </MsgText>
  <Explanation>
    The initialization of this Trust Association implementation failed.
  </Explanation>
  <UserResponse>
    Verify that the appropriate Trust Association properties required for the initialization are set up correctly. If you are using your own implementation, check your initilization method for any problems. If a single Trust Association implementation is used, this indicates that the Trust Association is not in effect. However, if multiple TrustAssociation implementations are used, Trust Association can be in effect if one of the implementations is successful. If you receive this error message in association with a trust association interceptor that you are not using, you can ignore this message.
  </UserResponse>
</Message>
<Message ID="SECJ0316W" severity="W" prefix="yes">
  <MsgText pgmKey="security.policy.invalid.filter.permission" varFormat="Java">
    security.policy.invalid.filter.permission=SECJ0316W: The permission {0} specified in the filter policy file(filter.policy) does not exist.
  </MsgText>
  <Explanation>
    The permission class specified in the filter policy file does not exist.
  </Explanation>
  <UserResponse>
    Fix the filter policy file.
  </UserResponse>
</Message>
<Message ID="SECJ7457E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.TimeStampRangeOutOfOrder" varFormat="Java">
    security.admintask.TimeStampRangeOutOfOrder=SECJ7457E: Non valid timestamp range specified: the beginning timestamp is greater than the ending timestamp.
  </MsgText>
  <Explanation>
    A non valid value was specified for the timestamps of audit records to report
  </Explanation>
  <UserResponse>
    Make sure that the starting timestamp is less than the ending timestamp.
  </UserResponse>
</Message>
<Message ID="SECJ7777I" severity="I" prefix="yes">
  <MsgText pgmKey="security.admintask.authPassed.SECJ7777I" varFormat="Java">
    security.admintask.authPassed.SECJ7777I=SECJ7777I: Password check for {0} in {1} succeeded.
  </MsgText>
  <Explanation>
    A test to check the users password on a particular realm was sucessful.
  </Explanation>
  <UserResponse>
    none.
  </UserResponse>
</Message>
<Message ID="SECJ7173I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.ignoreCase" varFormat="Java">
    security.configrpt.core.ignoreCase=SECJ7173I: Ignore case for authorization
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0363E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.createcredential.error" varFormat="Java">
    security.registry.createcredential.error=SECJ0363E: Cannot create credential for the user {0} because of the following exception {1}.
  </MsgText>
  <Explanation>
    Cannot create credential.
  </Explanation>
  <UserResponse>
    Make sure that the user is valid in the registry. If this error is preceeded by other exceptions, check those also. Contact your service representative if the problem persists.
  </UserResponse>
</Message>
<Message ID="SECJ0347E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.groupsecurityname.notfound" varFormat="Java">
    security.registry.groupsecurityname.notfound=SECJ0347E: Could not get the name of the group whose uniqueId is {0}.
  </MsgText>
  <Explanation>
    Internal Error.
  </Explanation>
  <UserResponse>
    Make sure that the group is valid. Contact your service representative if the problem persists.
  </UserResponse>
</Message>
<Message ID="SECJ8059E" severity="E" prefix="yes">
  <MsgText pgmKey="security.saml.tai.no.custom.property.SECJ8059E" varFormat="Java">
    security.saml.tai.no.custom.property.SECJ8059E=SECJ8059E: There is no {0} custom property.
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ6142I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.csi.ittprincipal.audit" varFormat="Java">
    security.audit.csi.ittprincipal.audit=SECJ6142I: Cannot obtain the identity of the ITTPrincipalName.
  </MsgText>
  <Explanation>
    The Identity token is not valid.
  </Explanation>
  <UserResponse>
    No action is required.
  </UserResponse>
</Message>
<Message ID="SECJ7532I" severity="I" prefix="yes">
  <MsgText pgmKey="security.scanner.risk.drs.ok.unused" varFormat="Java">
    security.scanner.risk.drs.ok.unused=SECJ7532I: Data Replication Service(DRS) is not being used to exchange data among WebSphere Application servers
  </MsgText>
  <Explanation>
    Data Replication Service(DRS) is not being used to exchange data among WebSphere Application servers
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7367E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.InvalidEventType" varFormat="Java">
    security.admintask.InvalidEventType=SECJ7367E: Non valid or no reference specified for the event type.
  </MsgText>
  <Explanation>
    The eventType field is required.
  </Explanation>
  <UserResponse>
    Verify that a valid reference has been specified for the event type
  </UserResponse>
</Message>
<Message ID="SECJ6024E" severity="E" prefix="yes">
  <MsgText pgmKey="security.audit.service.sendevent.error" varFormat="Java">
    security.audit.service.sendevent.error=SECJ6024E: AuditServiceProvider failure logging audit event, Exception = {0}.
  </MsgText>
  <Explanation>
    A failure occurred in the auditing subsystem, preventing the event from being processed/logged.
  </Explanation>
  <UserResponse>
    Examine the exception for the cause of the problem.
  </UserResponse>
</Message>
<Message ID="SECJ7090I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.Security.Console.Path.Name" varFormat="Java">
    security.configrpt.core.Security.Console.Path.Name=SECJ7090I: Console Path Name
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ5007E" severity="E" prefix="yes">
  <MsgText pgmKey="security.sap.error.longsecurityname.not.found.in.hashtable" varFormat="Java">
    security.sap.error.longsecurityname.not.found.in.hashtable=SECJ5007E: Cannot create WSCredential without a valid com.ibm.wsspi.security.cred.longSecurityName property value.
  </MsgText>
  <Explanation>
    The com.ibm.wsspi.security.cred.longSecurityName property has not been found during a properties login attempt.
  </Explanation>
  <UserResponse>
    Ensure that the java.util.Hashtable used for a properties login contains a valid property value for com.ibm.wsspi.security.cred.longSecurityName.
  </UserResponse>
</Message>
<Message ID="SECJ7094I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.Security.applicationLogin" varFormat="Java">
    security.configrpt.core.Security.applicationLogin=SECJ7094I: Application logins
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7365E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.InvalidAuditFilters" varFormat="Java">
    security.admintask.InvalidAuditFilters=SECJ7365E: Non valid or no reference specified for the audit filters.
  </MsgText>
  <Explanation>
    The auditFilters reference is a required field.
  </Explanation>
  <UserResponse>
    Verify that a valid reference has been specified for the auditFilters
  </UserResponse>
</Message>
<Message ID="SECJ0109W" severity="W" prefix="yes">
  <MsgText pgmKey="security.sasconfig.recoverurl" varFormat="Java">
    security.sasconfig.recoverurl=SECJ0109W: Recovering ({0}) from ({1})
  </MsgText>
  <Explanation>
    The security configuration URL is being recovered from the future version. This might happen if the security configuration URL is missing or has been deleted.
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ6053E" severity="E" prefix="yes">
  <MsgText pgmKey="security.audit.enforcing.nowrap.error" varFormat="Java">
    security.audit.enforcing.nowrap.error=SECJ6053E: The audit log wrapping behavior is set to NOWRAP and the maximum number of audit logs has been reached.  Quiescing the server.
  </MsgText>
  <Explanation>
    The server is in a quiesced state.  The maximum number of audit logs has been reached and the wrapping behavior is set to not wrap the oldest log.
  </Explanation>
  <UserResponse>
    Determine whether the maximum number of audit logs needs to be increased.  To get the audit service and server running again, archive all the audit logs to a safe repository, and restart the server.
  </UserResponse>
</Message>
<Message ID="SECJ4024W" severity="W" prefix="yes">
  <MsgText pgmKey="security.jaas.noConfig" varFormat="Java">
    security.jaas.noConfig=SECJ4024W: {0} :Warning: getAppConfigurationEntry() was called with no configuration name.
  </MsgText>
  <Explanation>
    getAppConfigurationEntry() was called with null string.
  </Explanation>
  <UserResponse>
    Check the parameter if it is called from user application. If not, Contact your service representative.
  </UserResponse>
</Message>
<Message ID="SECJ0148E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.ldap.mapcredentialAmbiguous" varFormat="Java">
    security.registry.ldap.mapcredentialAmbiguous=SECJ0148E: Cannot create a credential map given credential token certificate subject DN {0} with filter {1} into LDAP because multiple entries match the filter.  This ambiguous condition is not supported.
  </MsgText>
  <Explanation>
    More than one user entry in LDAP matched the certificate mapping filter specified in the global security settings.  It is not possible to map a subjectDN in a certificate to more than one user in an LDAP user registry.  The mapping filter results in an ambiguous condition that cannot be supported.
  </Explanation>
  <UserResponse>
    Specify a certificate mapping filter in the LDAP Advanced properties in the Security Center.
  </UserResponse>
</Message>
<Message ID="SECJ6154I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.form.login.success.audit" varFormat="Java">
    security.audit.form.login.success.audit=SECJ6154I: Form based authentication was successful.
  </MsgText>
  <Explanation>
    Form based authentication was successful.
  </Explanation>
  <UserResponse>
    No action is required.
  </UserResponse>
</Message>
<Message ID="SECJ0076E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registryentry.createerror" varFormat="Java">
    security.registryentry.createerror=SECJ0076E: Error creating registry entry home
  </MsgText>
  <Explanation>
    This is an internal error. Unable to create the home for the registry.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ0340E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.uniquegrpid.notfound" varFormat="Java">
    security.registry.uniquegrpid.notfound=SECJ0340E: Could not get the uniqueId for the group {0}.
  </MsgText>
  <Explanation>
    Problem getting uniqueId of a group.
  </Explanation>
  <UserResponse>
    Make sure that the group is valid in the registry and if it is a custom registry make sure it also has an uniqueId.
  </UserResponse>
</Message>
<Message ID="SECJ7339E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.ExceptionValidAdminName" varFormat="Java">
    security.admintask.ExceptionValidAdminName=SECJ7339E: Exception raised while validating admin name
  </MsgText>
  <Explanation>
    Caught exception while validating admin name
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7311E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.FailAddUsertoAdminAuthz" varFormat="Java">
    security.admintask.FailAddUsertoAdminAuthz=SECJ7311E: Failed to add user to admin-authz.xml
  </MsgText>
  <Explanation>
    Error occurred updating the admin-authz.xml file with the new admin user
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7738E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.CSIDoesNotExist.SECJ7738E" varFormat="Java">
    security.admintask.CSIDoesNotExist.SECJ7738E=SECJ7738E: The CSI object does not exist.
  </MsgText>
  <Explanation>
    The CSI object does not exist in the configuration.
  </Explanation>
  <UserResponse>
    Ensure that the CSI object exists.
  </UserResponse>
</Message>
<Message ID="SECJ4026W" severity="W" prefix="yes">
  <MsgText pgmKey="security.j2c.invalidWSDefaultPrincipalMapping" varFormat="Java">
    security.j2c.invalidWSDefaultPrincipalMapping=SECJ4026W: WSDefaultPrincipalMapping() should not be invoked.
  </MsgText>
  <Explanation>
    WSDefaultPrincipalMapping() should not be invoked.
  </Explanation>
  <UserResponse>
    This is warning. Check the user application. WSDefaultPrincipalMappingshould not be directly constructed.
  </UserResponse>
</Message>
<Message ID="SECJ7040I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.supportsDynamicModuleUpdates" varFormat="Java">
    security.configrpt.core.supportsDynamicModuleUpdates=SECJ7040I: Supports dynamic module updates
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ6214I" severity="I" prefix="yes">
  <MsgText pgmKey="security.zos.saf.authz.enabled" varFormat="Java">
    security.zos.saf.authz.enabled=SECJ6214I: SAF authorization is enabled.
  </MsgText>
  <Explanation>
    WebSphere for z/OS has been configured to use the z/OS security product for authorization.  The authorization policies for WebSphere must be defined in the EJBROLE class of the z/OS security product.  Authorization policies embedded in the applications will be ignored.
  </Explanation>
  <UserResponse>
    No user action is required.
  </UserResponse>
</Message>
<Message ID="SECJ7813E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.duplicateAuthDataEntry.SECJ7813E" varFormat="Java">
    security.admintask.duplicateAuthDataEntry.SECJ7813E=SECJ7813E: A duplicate alias name exists. You must use a unique alias name.
  </MsgText>
  <Explanation>
    A duplicate alias name in the format alias or nodeName/alias already exists.
  </Explanation>
  <UserResponse>
    Input a unique alias name
  </UserResponse>
</Message>
<Message ID="SECJ8010E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.jaspi.provider.undefined.SECJ8010E" varFormat="Java">
    security.admintask.jaspi.provider.undefined.SECJ8010E=SECJ8010E: Authentication provider {0} is not defined in domain {1}.
  </MsgText>
  <Explanation>
    An authentication provider with the specified name does not exist in the security configuration.
  </Explanation>
  <UserResponse>
    Specify the name of an existing authentication provider. Use the displayJaspiProviderNames command to list the names of defined authentication providers.
  </UserResponse>
</Message>
<Message ID="SECJ7421E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.ReuseCertError" varFormat="Java">
    security.admintask.ReuseCertError=SECJ7421E: Options to select certificate to use for signing are mutually exclusive.
  </MsgText>
  <Explanation>
    Cannot select reusing encryption certificate for signing with autogenerating or importing. Options are mutually exclusive.
  </Explanation>
  <UserResponse>
    Select only one option: to reuse the certificate used for encrypting audit records, autogenerating a certificate to use to sign the audit records, or import a certificate.
  </UserResponse>
</Message>
<Message ID="SECJ0217W" severity="W" prefix="yes">
  <MsgText pgmKey="security.init.wccmjaas.dupentry" varFormat="Java">
    security.init.wccmjaas.dupentry=SECJ0217W: Detected a duplicate JAAS LoginModule alias name {0} when processing JAAS configuration information.
  </MsgText>
  <Explanation>
    A duplicate JAAS LoginModule alias name exist either in a JAAS login URL or in the security.xml file. The duplicate will be replaced with the last one  processed.
  </Explanation>
  <UserResponse>
    Verify no duplicate JAAS LoginModule aliases exist in the login URLs or in the security.xml file.
  </UserResponse>
</Message>
<Message ID="SECJ7545W" severity="W" prefix="yes">
  <MsgText pgmKey="security.admintask.fileNotExist" varFormat="Java">
    security.admintask.fileNotExist=SECJ7545W: The {0} file does not exist
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    Check the file permissions for the file to ensure that they are readable.  If the file is missing, create or restore it.
  </UserResponse>
</Message>
<Message ID="SECJ6235I" severity="I" prefix="yes">
  <MsgText pgmKey="security.zos.saf.idprop.disabled.info" varFormat="Java">
    security.zos.saf.idprop.disabled.info=SECJ6235I: The SAF feature for distributed identity mapping is not in effect.
  </MsgText>
  <Explanation>
    The SAF feature for distributed identity mapping is not in effect.
  </Explanation>
  <UserResponse>
    No user action is required.
  </UserResponse>
</Message>
<Message ID="SECJ7102I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.Moderator.Role.User" varFormat="Java">
    security.configrpt.Moderator.Role.User=SECJ7102I: Moderator User
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7341E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.ExceptionUseRegistryServerId" varFormat="Java">
    security.admintask.ExceptionUseRegistryServerId=SECJ7341E: Exception raised while setting useRegistryServerId
  </MsgText>
  <Explanation>
    Exception raised while setting useRegistryServerId in the user registry object
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ4027W" severity="W" prefix="yes">
  <MsgText pgmKey="security.j2c.fileNotFound" varFormat="Java">
    security.j2c.fileNotFound=SECJ4027W: {0} does not exist, use {1} wsj2cdpm.properties
  </MsgText>
  <Explanation>
    Specified file did not exist. Use the default file.
  </Explanation>
  <UserResponse>
    This is a warning. Check the specified file name.
  </UserResponse>
</Message>
<Message ID="SECJ8033I" severity="I" prefix="yes">
  <MsgText pgmKey="security.jaspi.configuration.factory.notdefault.SECJ8033I" varFormat="Java">
    security.jaspi.configuration.factory.notdefault.SECJ8033I=SECJ8033I: The AuthConfigFactory instance is {0}.
  </MsgText>
  <Explanation>
    The JASPI factory implementation defined is not the default JASPI factory implementation provided by WebSphere Application Server.
  </Explanation>
  <UserResponse>
    none.
  </UserResponse>
</Message>
<Message ID="SECJ7821E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.config.object.does.not.exist.SECJ7821E" varFormat="Java">
    security.admintask.config.object.does.not.exist.SECJ7821E=SECJ7821E: The object {0} does not exist in the security.xml file.
  </MsgText>
  <Explanation>
    The security configuration does not have this object.
  </Explanation>
  <UserResponse>
    Run the command with a pre-existing security configuration.
  </UserResponse>
</Message>
<Message ID="SECJ0072E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.findererror.type" varFormat="Java">
    security.registry.findererror.type=SECJ0072E: Error finding registry for type {0}
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ0334E" severity="E" prefix="yes">
  <MsgText pgmKey="security.registry.nulluser" varFormat="Java">
    security.registry.nulluser=SECJ0334E: Cannot create credential for null user.
  </MsgText>
  <Explanation>
    Internal Error. The user name provided to create the credential is null.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7716E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.badAdminID.SECJ7716E" varFormat="Java">
    security.admintask.badAdminID.SECJ7716E=SECJ7716E: Primary administrative user Id does not exist in the registry.
  </MsgText>
  <Explanation>
    The primary administrative id specified was not found the user registry.
  </Explanation>
  <UserResponse>
    Ensure a primary administrative id is provided.
  </UserResponse>
</Message>
<Message ID="SECJ7502E" severity="E" prefix="yes">
  <MsgText pgmKey="security.scanner.error.parse.xml" varFormat="Java">
    security.scanner.error.parse.xml=SECJ7502E: An exception occured while parsing the XML file &quot;{0}&quot;.  Detailed message: {1}
  </MsgText>
  <Explanation>
    An exception occured while parsing a configuration document.
  </Explanation>
  <UserResponse>
    Check the error logs for more information into the failure.
  </UserResponse>
</Message>
<Message ID="SECJ6008E" severity="E" prefix="yes">
  <MsgText pgmKey="security.audit.service.exception.error" varFormat="Java">
    security.audit.service.exception.error=SECJ6008E: Exception caught in AuditService initialization, Exception = {0}.
  </MsgText>
  <Explanation>
    Runtime exception occured most likely due to incorrect class definition, incorrect class path, or missing class files.
  </Explanation>
  <UserResponse>
    Examine the exception for the cause of the problem.
  </UserResponse>
</Message>
<Message ID="SECJ7054I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.enable" varFormat="Java">
    security.configrpt.core.enable=SECJ7054I: Enable
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ6121I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.cert.exception.audit" varFormat="Java">
    security.audit.cert.exception.audit=SECJ6121I: Client certificate Authentication failed due to internal error.
  </MsgText>
  <Explanation>
    The authentication failed due to an unexpected runtime exception.
  </Explanation>
  <UserResponse>
    Report the problem to IBM.
  </UserResponse>
</Message>
<Message ID="SECJ7272I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.enableOutOfSequenceDetection" varFormat="Java">
    security.configrpt.core.enableOutOfSequenceDetection=SECJ7272I: Enable out of sequence detection
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7453E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.CustomReportNoDataPoints" varFormat="Java">
    security.admintask.CustomReportNoDataPoints=SECJ7453E: The report mode chosen is custom but no data points were specified.
  </MsgText>
  <Explanation>
    When specifying a report mode of custom, one or more data points must be specified.
  </Explanation>
  <UserResponse>
    Specify one or more data points when electing to generate a custom report.
  </UserResponse>
</Message>
<Message ID="SECJ7279I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.App.Servers" varFormat="Java">
    security.configrpt.core.App.Servers=SECJ7279I: Application servers
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7202I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.dayOfWeek" varFormat="Java">
    security.configrpt.core.dayOfWeek=SECJ7202I: Day of week
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ6233I" severity="I" prefix="yes">
  <MsgText pgmKey="security.zos.saf.idprop.versionNumber.info" varFormat="Java">
    security.zos.saf.idprop.versionNumber.info=SECJ6233I: The version number of the SAF product is: {0}.
  </MsgText>
  <Explanation>
    The version of the SAF product is displayed.
  </Explanation>
  <UserResponse>
    No user action is required.
  </UserResponse>
</Message>
<Message ID="SECJ7435E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.CannotRemoveAuditorId" varFormat="Java">
    security.admintask.CannotRemoveAuditorId=SECJ7435E: Empty value specified for auditorId.  Cannot delete the auditorId when auditing is enabled.
  </MsgText>
  <Explanation>
    Auditing is enabled and requires an auditorId and auditorPwd.
  </Explanation>
  <UserResponse>
    Disable auditing before deleting the auditorId
  </UserResponse>
</Message>
<Message ID="SECJ6103I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.service.no.security.audit" varFormat="Java">
    security.audit.service.no.security.audit=SECJ6103I: Access to a web resource is allowed because no access control is required.
  </MsgText>
  <Explanation>
    Access to a web resource does not require access control because there is no security constraint.
  </Explanation>
  <UserResponse>
    The URI is not protected.  No action is required is this is the desired configuration.  Otherwise, proper security constraint should be added to the web application.
  </UserResponse>
</Message>
<Message ID="SECJ7253I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.ntlmTokenReceivedPage" varFormat="Java">
    security.configrpt.core.ntlmTokenReceivedPage=SECJ7253I: NTLM token received page URL
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0307E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jsecman.exception.codebase" varFormat="Java">
    security.jsecman.exception.codebase=SECJ0307E: Unexpected exception is caught when trying to determine the code base location. Exception: {0}
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ6115I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.tai.success.audit" varFormat="Java">
    security.audit.tai.success.audit=SECJ6115I: Authentication successful with Trust Accosication Interceptor.
  </MsgText>
  <Explanation>
    The authentication via the specified Trust Association Interceptor was successful.
  </Explanation>
  <UserResponse>
    No action is required.
  </UserResponse>
</Message>
<Message ID="SECJ0415I" severity="I" prefix="yes">
  <MsgText pgmKey="security.jacc.secpolicy.propagated" varFormat="Java">
    security.jacc.secpolicy.propagated=SECJ0415I: The security policy for application {0} is successfully propagated to the JACC provider.
  </MsgText>
  <Explanation>
    This message is provided for information purposes only.
  </Explanation>
  <UserResponse>
    No user action is required.
  </UserResponse>
</Message>
<Message ID="SECJ0205I" severity="I" prefix="yes">
  <MsgText pgmKey="security.init.sambean" varFormat="Java">
    security.init.sambean=SECJ0205I: Security Admin mBean registered successfully
  </MsgText>
  <Explanation>
    The Security Admin mBean registered successfully
  </Explanation>
  <UserResponse>
    None. Informational only.
  </UserResponse>
</Message>
<Message ID="SECJ5010E" severity="E" prefix="yes">
  <MsgText pgmKey="security.sap.error.authentication.token.not.mapped" varFormat="Java">
    security.sap.error.authentication.token.not.mapped=SECJ5010E: Could not create default AuthenticationToken during propagation login.  The following exception occurred: {0}
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ6011W" severity="W" prefix="yes">
  <MsgText pgmKey="security.audit.service.missing.warning" varFormat="Java">
    security.audit.service.missing.warning=SECJ6011W: Custom property {0} was not defined.
  </MsgText>
  <Explanation>
    The specified audit service provider was not defined in the global security custom properties.
  </Explanation>
  <UserResponse>
    Define the specified properties if security auditing service is required in your business environment.
  </UserResponse>
</Message>
<Message ID="SECJ4017E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaas.removeCredException" varFormat="Java">
    security.jaas.removeCredException=SECJ4017E: An unexpected exception occurred in Login Module {0} when removing WSCredential during cleanup {1}
  </MsgText>
  <Explanation>
    Exception occurred while removing the credential.
  </Explanation>
  <UserResponse>
    Contact your service representative with exception stack trace information present in the error log.
  </UserResponse>
</Message>
<Message ID="SECJ0310E" severity="E" prefix="yes">
  <MsgText pgmKey="security.policy.template.parser" varFormat="Java">
    security.policy.template.parser=SECJ0310E: Caught a ParserException while adding the grant entry to the policy template {1}. The exception is {0}
  </MsgText>
  <Explanation>
    A ParserException occurred while adding the grant entry to the policy template.
  </Explanation>
  <UserResponse>
    Check the ParserException data. Check the specified  policy file.
  </UserResponse>
</Message>
<Message ID="SECJ0428E" severity="E" prefix="yes">
  <MsgText pgmKey="security.web.httpsPort.notFound" varFormat="Java">
    security.web.httpsPort.notFound=SECJ0428E: The product cannot locate the HTTPS port value in the list of virtual hosts. Confirm that the port exists in the virtualhosts.xml file for the cell.
  </MsgText>
  <Explanation>
    The product cannot locate the HTTPS port value that is specified in the URL. The port value is not found in the list of virtual hosts.
  </Explanation>
  <UserResponse>
    Check that the HTTPS port value that is specified is in the virtualhosts.xml file for the cell. The virtualhosts.xml file is located in the profile_root/config/cells/cell_name directory.
  </UserResponse>
</Message>
<Message ID="SECJ0245E" severity="E" prefix="yes">
  <MsgText pgmKey="security.secvrfactory.createrr" varFormat="Java">
    security.secvrfactory.createrr=SECJ0245E: An unexpected exception occurred when the SecurityServerFactory tried to create the SecurityServer. The exception is {0}.
  </MsgText>
  <Explanation>
    An error occurred that prevented the SecurityServer from being created.
  </Explanation>
  <UserResponse>
    The log should contain additional errors that might indicate the cause of the problem.
  </UserResponse>
</Message>
<Message ID="SECJ7376E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.InvalidNotificationRef" varFormat="Java">
    security.admintask.InvalidNotificationRef=SECJ7376E: Non valid reference for Audit Notification.
  </MsgText>
  <Explanation>
    Non valid reference for audit notification specified.
  </Explanation>
  <UserResponse>
    Verify that a valid reference has been specified for the audit notification
  </UserResponse>
</Message>
<Message ID="SECJ0059E" severity="E" prefix="yes">
  <MsgText pgmKey="security.ltpa.nopasswd.nocreate" varFormat="Java">
    security.ltpa.nopasswd.nocreate=SECJ0059E: Cannot create LTPAServer without a password
  </MsgText>
  <Explanation>
    The wrong constructor was used when trying to create an instance of LTPAServerBean.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ8031I" severity="I" prefix="yes">
  <MsgText pgmKey="security.jaspi.provider.registered.SECJ8031I" varFormat="Java">
    security.jaspi.provider.registered.SECJ8031I=SECJ8031I: JASPI binding has been registered: Application={0}, Web Module={1}, Registration ID={2}[{3}], Provider Class={4}.
  </MsgText>
  <Explanation>
    The named JASPI provider will perform authentication of web requests for the named application and web module.
  </Explanation>
  <UserResponse>
    none.
  </UserResponse>
</Message>
<Message ID="SECJ8029E" severity="E" prefix="yes">
  <MsgText pgmKey="security.jaspi.configuration.provider.invalid.SECJ8029E" varFormat="Java">
    security.jaspi.configuration.provider.invalid.SECJ8029E=SECJ8029E: The provider name in the application&apos;s or web module&apos;s bindings is null or is empty.
  </MsgText>
  <Explanation>
    The web module&apos;s JASPI binding cannot be registered in AuthConfigFactory because the provider name is null.
  </Explanation>
  <UserResponse>
    Verify the provider name in the application&apos;s or web module&apos;s bindings is defined in the security configuration.
  </UserResponse>
</Message>
<Message ID="SECJ6013E" severity="E" prefix="yes">
  <MsgText pgmKey="security.audit.service.bad.factory.error" varFormat="Java">
    security.audit.service.bad.factory.error=SECJ6013E: The configured J2EE AuditEventFactory implementation did not implement the J2EEAuditEventFactory interface.
  </MsgText>
  <Explanation>
    As a convention, an AuditEventFactory implementation that is configured under the J2EE name must implement the J2EEAuditEventFactory interface.
  </Explanation>
  <UserResponse>
    Examine the com.ibm.websphere.security.audit.AuditEventFactory properties in global security custom properties.
  </UserResponse>
</Message>
<Message ID="SECJ7193I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.minute" varFormat="Java">
    security.configrpt.core.minute=SECJ7193I: Minute
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0393E" severity="E" prefix="yes">
  <MsgText pgmKey="security.web.authz.isuserinrole.failed" varFormat="Java">
    security.web.authz.isuserinrole.failed=SECJ0393E: Error when checking the isUserInRole requirement for the contextID {0}. The exception is {1}.
  </MsgText>
  <Explanation>
    Could not determine the isUserInRole requirements for this resource. The default value false will be returned
  </Explanation>
  <UserResponse>
    Make sure that the RoleRef information is correctly configured in the deployment descriptor.
  </UserResponse>
</Message>
<Message ID="SECJ7358E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.InvalidAuditorId" varFormat="Java">
    security.admintask.InvalidAuditorId=SECJ7358E: Non valid or no value specified for auditor identity.
  </MsgText>
  <Explanation>
    The auditor identity is a required field.
  </Explanation>
  <UserResponse>
    Verify that a value has been specified for the auditor identity
  </UserResponse>
</Message>
<Message ID="SECJ0101E" severity="E" prefix="yes">
  <MsgText pgmKey="security.mg.removeerr" varFormat="Java">
    security.mg.removeerr=SECJ0101E: Error removing method group
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ0057E" severity="E" prefix="yes">
  <MsgText pgmKey="security.authn.invalid.data" varFormat="Java">
    security.authn.invalid.data=SECJ0057E: Invalid authentication data
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7422E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.NoEncryptionKeyStore" varFormat="Java">
    security.admintask.NoEncryptionKeyStore=SECJ7422E: Cannot use the encryption certificate as the signer certificate: No encryption keystore found.
  </MsgText>
  <Explanation>
    No encryption keystore found: unable to reuse the same certificate for signing audit records.
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ8024E" severity="E" prefix="yes">
  <MsgText pgmKey="security.adminapp.other.error.SECJ8024E" varFormat="Java">
    security.adminapp.other.error.SECJ8024E=SECJ8024E: An error occurred processing Jaspi bindings during application deployment. {0}
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7736E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.loginAliasDoesNotExist.SECJ7736E" varFormat="Java">
    security.admintask.loginAliasDoesNotExist.SECJ7736E=SECJ7736E: The JAAS login entry {0} does not exist.
  </MsgText>
  <Explanation>
    The JAAS login entry does not exist in the configuration.
  </Explanation>
  <UserResponse>
    Ensure that the JAAS login entry exists.
  </UserResponse>
</Message>
<Message ID="SECJ0163E" severity="E" prefix="yes">
  <MsgText pgmKey="security.wsaccessmanager.VendorAuthTableGenericError" varFormat="Java">
    security.wsaccessmanager.VendorAuthTableGenericError=SECJ0163E: Generic Error from Vendor AuthorizationTable
  </MsgText>
  <Explanation>
    Unknown error from Vendor&apos;s authorization table
  </Explanation>
  <UserResponse>
    Contact your service representative with exception stack trace information present in the error log.
  </UserResponse>
</Message>
<Message ID="SECJ6104I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.service.login.audit" varFormat="Java">
    security.audit.service.login.audit=SECJ6104I: Access to a web resource is allowed because the URI is either login page, error page or form login page.
  </MsgText>
  <Explanation>
    Access to login page, error page, and form login page does not require access control.
  </Explanation>
  <UserResponse>
    The URI is not protected.  No action is required.
  </UserResponse>
</Message>
<Message ID="SECJ0199E" severity="E" prefix="yes">
  <MsgText pgmKey="security.policy.ratemplate.io" varFormat="Java">
    security.policy.ratemplate.io=SECJ0199E: Caught an IOException while adding the grant entry to the policy template of the resource adaptor {1} . The exception is {0}.
  </MsgText>
  <Explanation>
    An IOException occurred while adding the grant entry to the policy template of the resource adaptor.
  </Explanation>
  <UserResponse>
    Check the specified ra.xml file.
  </UserResponse>
</Message>
<Message ID="SECJ0086E" severity="E" prefix="yes">
  <MsgText pgmKey="security.web.config.error" varFormat="Java">
    security.web.config.error=SECJ0086E: Configuration error
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7464E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.MalformedURLException" varFormat="Java">
    security.admintask.MalformedURLException=SECJ7464E: Exception was raised while trying to open the keystore.  The keystore location is malformed.
  </MsgText>
  <Explanation>
    The keystore location url is malformed.
  </Explanation>
  <UserResponse>
    Verify that the keystore location is valid and that the keystore does exist.
  </UserResponse>
</Message>
<Message ID="SECJ6014I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.service.access.default.audit" varFormat="Java">
    security.audit.service.access.default.audit=SECJ6014I: AuditEventType = {0}, AuditOutcome = {1}, AuditOutcomeReason = {2}, unique Event ID = {3}, Cell Name = {4}, Node Name = {5}, Server Name = {6}, Component Name = {7}, App Name = {8}, Session ID = {9}, Resource Name = {10}, Resource Type = {11}, Method Name = {12}, Provider Name = {13}, Provider Successful = {14}, Exception = {15}.
  </MsgText>
  <Explanation>
    This message is intended to be used by the defaultAuditEventFactoryImpl sendAccessAuditEvent method only.
  </Explanation>
  <UserResponse>
    No action required.
  </UserResponse>
</Message>
<Message ID="SECJ7814E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.localModeNotSupported.SECJ7814E" varFormat="Java">
    security.admintask.localModeNotSupported.SECJ7814E=SECJ7814E: This command is not supported in local mode
  </MsgText>
  <Explanation>
    This command is not supported in local mode
  </Explanation>
  <UserResponse>
    This command is not supported in local mode
  </UserResponse>
</Message>
<Message ID="SECJ0281E" severity="E" prefix="yes">
  <MsgText pgmKey="security.secsrv.create.registry" varFormat="Java">
    security.secsrv.create.registry=SECJ0281E: Error creating user registry object. The exception is {0}.
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7035I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.j2eePolicyImplClassName" varFormat="Java">
    security.configrpt.core.j2eePolicyImplClassName=SECJ7035I: J2EE Policy implementation class name
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0045E" severity="E" prefix="yes">
  <MsgText pgmKey="security.sas.initerror" varFormat="Java">
    security.sas.initerror=SECJ0045E: Error initializing security/SAS
  </MsgText>
  <Explanation>
    An error occurred while initializing the Secure Association Service, which is part of the ORB security.
  </Explanation>
  <UserResponse>
    Verify that the property file, usually sas.server.props, is present and has read permission.
  </UserResponse>
</Message>
<Message ID="SECJ0419I" severity="I" prefix="yes">
  <MsgText pgmKey="security.registry.ldap.connected.audit" varFormat="Java">
    security.registry.ldap.connected.audit=SECJ0419I: The user registry is currently connected to the LDAP server {0}.
  </MsgText>
  <Explanation>
    This name refers to the LDAP host name that is currently used by the WebSphere Application Server security registry.
  </Explanation>
  <UserResponse>
    No user action is required.
  </UserResponse>
</Message>
<Message ID="SECJ7161I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.trustStore" varFormat="Java">
    security.configrpt.core.trustStore=SECJ7161I: Trust store
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7082I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.systemLoginConfig" varFormat="Java">
    security.configrpt.core.systemLoginConfig=SECJ7082I: System login configuration
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0098E" severity="E" prefix="yes">
  <MsgText pgmKey="security.mg.finderr.one" varFormat="Java">
    security.mg.finderr.one=SECJ0098E: Error finding method group {0}
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7076I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.trustFileName" varFormat="Java">
    security.configrpt.core.trustFileName=SECJ7076I: Trust file name
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0106E" severity="E" prefix="yes">
  <MsgText pgmKey="security.sas.encode.error" varFormat="Java">
    security.sas.encode.error=SECJ0106E: An unexpected exception occurred when encoding the value [{0}] for password [{1}] in the security configured URL
  </MsgText>
  <Explanation>
    The password cannot be encoded because it is missing or malformed.
  </Explanation>
  <UserResponse>
    Verify that the passwords in the security configuration URL are not corrupted or missing. Reset the affected password through the WebSphere Admin console if possible.  If all else fails, reset the password to its plain text value in the security configuration URL (which is usually sas.server.props).
  </UserResponse>
</Message>
<Message ID="SECJ0113E" severity="E" prefix="yes">
  <MsgText pgmKey="security.ejb.getreqrole.exception" varFormat="Java">
    security.ejb.getreqrole.exception=SECJ0113E: An unexpected exception occurred in getRequiredRoles for method {0} and resource {1}. The exception is {2}
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ0110E" severity="E" prefix="yes">
  <MsgText pgmKey="security.sasconfig.propload" varFormat="Java">
    security.sasconfig.propload=SECJ0110E: I/O Error occurred when loading property URL {0}
  </MsgText>
  <Explanation>
    A loadProperties() operation probably failed.
  </Explanation>
  <UserResponse>
    Verify that the file permissions associated with security configuration URL property file (typically sas.server.props) are read and writable.
  </UserResponse>
</Message>
<Message ID="SECJ6144I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.csi.cert.failure.audit" varFormat="Java">
    security.audit.csi.cert.failure.audit=SECJ6144I: Authentication failed.
  </MsgText>
  <Explanation>
    Failed to convert the client certificate.
  </Explanation>
  <UserResponse>
    No action is required.
  </UserResponse>
</Message>
<Message ID="SECJ7066I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.IBM" varFormat="Java">
    security.configrpt.core.IBM=SECJ7066I: SAS
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7213I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.wsNotification" varFormat="Java">
    security.configrpt.core.wsNotification=SECJ7213I: Notifications
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7726E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.noUnconfigure.SECJ7726E" varFormat="Java">
    security.admintask.noUnconfigure.SECJ7726E=SECJ7726E: {0} is the active user registry unable to unconfigure.
  </MsgText>
  <Explanation>
    A user registy cannot be unconfigured if it is the active user registry.
  </Explanation>
  <UserResponse>
    Change the active user registry in the global security setting then unconfigure the user registry.
  </UserResponse>
</Message>
<Message ID="SECJ6000I" severity="I" prefix="yes">
  <MsgText pgmKey="security.audit.service.enabled.audit" varFormat="Java">
    security.audit.service.enabled.audit=SECJ6000I: Security Auditing is enabled.
  </MsgText>
  <Explanation>
    This audit message indicates that the WebSphere Application Server Security Auditing service is enabled.
  </Explanation>
  <UserResponse>
    No action is required is this is the desired setting.
  </UserResponse>
</Message>
<Message ID="SECJ7067I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.repertoire" varFormat="Java">
    security.configrpt.core.repertoire=SECJ7067I: SSL configuration repertoires
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0427E" severity="E" prefix="yes">
  <MsgText pgmKey="security.merge.node.missing.server.password" varFormat="Java">
    security.merge.node.missing.server.password=SECJ0427E: The server password is null or missing in the dmgr configuration.  Cannot add an older version node unless the server password is entered.
  </MsgText>
  <Explanation>
    An earlier leveled node cannot be added to a dmgr whose configuration is missing the server password
  </Explanation>
  <UserResponse>
    The dmgr configuration needs to be modified to specify the server password
  </UserResponse>
</Message>
<Message ID="SECJ6002E" severity="E" prefix="yes">
  <MsgText pgmKey="security.audit.service.loading.error" varFormat="Java">
    security.audit.service.loading.error=SECJ6002E: Failed to load {0} name {1} and class name {2}.
  </MsgText>
  <Explanation>
    Failed to load the specified class which was defined in the global security custom properties.
  </Explanation>
  <UserResponse>
    Verify that the class name, class path, and class file are configured properly.
  </UserResponse>
</Message>
<Message ID="SECJ7402E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.KeyStoreObjectExists" varFormat="Java">
    security.admintask.KeyStoreObjectExists=SECJ7402E: Encryption key file object already exists.
  </MsgText>
  <Explanation>
    The specified object already exists.  Unable to create another one.
  </Explanation>
  <UserResponse>
    Create the object with a unique name
  </UserResponse>
</Message>
<Message ID="SECJ7312E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.FailAccesstoSecWS" varFormat="Java">
    security.admintask.FailAccesstoSecWS=SECJ7312E: Failed to get to Security workspace
  </MsgText>
  <Explanation>
    Exception raised when accessing the Security object in the workspace
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ4031E" severity="E" prefix="yes">
  <MsgText pgmKey="security.j2c.unexpectedIOException" varFormat="Java">
    security.j2c.unexpectedIOException=SECJ4031E: Unexpected IOException caught {0}
  </MsgText>
  <Explanation>
    Unexpected IOException was caught while processing callbacks.
  </Explanation>
  <UserResponse>
    Contact your service representative with exception stack trace information present in the error log.
  </UserResponse>
</Message>
<Message ID="SECJ7381E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.NotificationMonitorNotConfigured" varFormat="Java">
    security.admintask.NotificationMonitorNotConfigured=SECJ7381E: Audit Notification Monitor is not configured.
  </MsgText>
  <Explanation>
    Audit Notification Monitor is not configured.
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0319I" severity="I" prefix="yes">
  <MsgText pgmKey="security.policy.all.permission" varFormat="Java">
    security.policy.all.permission=SECJ0319I: java.security.AllPermission was found in the application policy file {0}.
  </MsgText>
  <Explanation>
    java.securityAllPermission was found in the application.
  </Explanation>
  <UserResponse>
    none. This is an informational message.
  </UserResponse>
</Message>
<Message ID="SECJ7150I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.WSSchedule" varFormat="Java">
    security.configrpt.core.WSSchedule=SECJ7150I: Schedules
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ7159I" severity="I" prefix="yes">
  <MsgText pgmKey="security.configrpt.core.enabledCiphers" varFormat="Java">
    security.configrpt.core.enabledCiphers=SECJ7159I: Enabled Ciphers
  </MsgText>
  <Explanation>
    None
  </Explanation>
  <UserResponse>
    None
  </UserResponse>
</Message>
<Message ID="SECJ0289E" severity="E" prefix="yes">
  <MsgText pgmKey="security.servcomp.removePolicy" varFormat="Java">
    security.servcomp.removePolicy=SECJ0289E: Failed to call removePolicy for {0}.
  </MsgText>
  <Explanation>
    A unexpected exception occurred when trying to call the removePolicy() method for the specified type.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ0179E" severity="E" prefix="yes">
  <MsgText pgmKey="security.policy.rar.path" varFormat="Java">
    security.policy.rar.path=SECJ0179E: An exception was caught while trying to get the Resource adaptor&apos;&apos;s absolute file path. The exception is {0}.
  </MsgText>
  <Explanation>
    Could not get the absolute filepath of the resource adaptor policy file.
  </Explanation>
  <UserResponse>
    Check the filepath specified in resource.xml file. Enable security trace with com.ibm.ws.security.policy.* to get more detailed information.
  </UserResponse>
</Message>
<Message ID="SECJ7389E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.EventFactoryExists" varFormat="Java">
    security.admintask.EventFactoryExists=SECJ7389E: An audit event factory implementation with this unique name is already configured.
  </MsgText>
  <Explanation>
    Cannot configure an audit event factory with the same unique name as one that is already configured.
  </Explanation>
  <UserResponse>
    Specify a unique name for the new audit event factory
  </UserResponse>
</Message>
<Message ID="SECJ0102E" severity="E" prefix="yes">
  <MsgText pgmKey="security.mg.createerr" varFormat="Java">
    security.mg.createerr=SECJ0102E: Error creating method group
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ0116W" severity="W" prefix="yes">
  <MsgText pgmKey="security.web.cred.getTokFail" varFormat="Java">
    security.web.cred.getTokFail=SECJ0116W: Unable to extract the credential token from the credential
  </MsgText>
  <Explanation>
    The credential is possibly malformed or corrupted.
  </Explanation>
  <UserResponse>
    If the problem persists, additional information might be available if you search for the message ID on the following Web sites: WebSphere Application Server Support page: http://www.ibm.com/software/webservers/appserv/was/support/ WebSphere Application Server for z/OS Support page: http://www.ibm.com/software/webservers/appserv/zos_os390/support/ .
  </UserResponse>
</Message>
<Message ID="SECJ7753E" severity="E" prefix="yes">
  <MsgText pgmKey="security.admintask.noRealms.SECJ7753E" varFormat="Java">
    security.admintask.noRealms.SECJ7753E=SECJ7753E: No realms provided to add to the trusted realm list.
  </MsgText>
  <Explanation>
    No realm name were provided to add the the trusted realm list.
  </Explanation>
  <UserResponse>
    Ensure a realm or realm list is provided when the command is run.
  </UserResponse>
</Message>
<!-- END MESSAGES -->
</TMSSource>
