311 - ANS1692E The certificate is not trusted.

1.1 Preliminary remark

A valid certificate is one of the requirements for a connection from the ISP node to the server.
Otherwise a connection cannot be established and you will receive an error message: 

ANS1692E The certificate is not trusted.
ANS8023E Unable to establish session with server.
ANS8002I Highest return code was -367.

One possible reason for this error message may be that the server certificate has been changed/renewed.
This new certificate must now be transferred to the node again.

A renewal is necessary, for example, if the ISP server is moved to a newer hardware.
Unfortunately, the certificate contains the IP address of the ISP server, which means that it is no longer valid for the new server with its new IP address.
Accordingly, the ISP node must then obtain a new certificate from the new ISP server in order to be able to trust the ISP server again.

If a node is used by several computers at the time of certificate renewal, the following steps must be carried out on each of these computers.

1.2 What needs to be done?

A. You are using one or more nodes on a system and at least one of these nodes is running a scheduler on this system.

In this case, you usually have to wait a day and do nothing. Just check that the scheduler is running on the system. It will automatically transfer the certificate.
One day later, access should work again. Please check whether the backup was successful.

In the unlikely event that access still does not work, please carry out steps B and C below.

B. You are using a simple configuration of one to three nodes without a scheduler on your system.

In this case, it is easiest to delete the distributed key database, consisting of the files dsmcert.kdb, dsmcert.sth and dsmcert.idx.

Procedure under Windows:
Directory: C:\Program Files\Tivoli\TSM\baclient

In Explorer, navigate to the directory C:\Program Files\Tivoli\TSM\baclient and delete the three files dsmcert.kdb, dsmcert.sth and dsmcert.idx.

Procedure under Linux:
Directory: /opt/tivoli/tsm/client/ba/bin/

cd  /opt/tivoli/tsm/client/ba/bin/; rm dsmcert.kdb dsmcert.sth dsmcert.idx

Procedure under Mac OS:
Directory: /Library/Application\ Support/tivoli/tsm/client/ba/bin/

cd /Library/Application\ Support/tivoli/tsm/client/ba/bin/; rm dsmcert.kdb dsmcert.sth dsmcert.idx 

Procedure under AIX:
Directory: /usr/tivoli/tsm/client/ba/bin/

cd   /usr/tivoli/tsm/client/ba/bin/; rm dsmcert.kdb dsmcert.sth dsmcert.idx

The client must then be started for each configured node and, if necessary, the password entered. 
This creates a new key database, which retrieves the new certificate from the new ISP server.

C. You are using a complex configuration with several nodes without a scheduler on a system or a TDP client.

In this case, the new certificate must unfortunately be downloaded manually. It can then be imported into the key database using the gsk8capicmd_64 -cert -add command.
The command gsk8capicmd_64 -cert -list -db <path to the certificate>/dsmcert.kdb -stashed lists the existing certificates. It can be used for checking before and after importing.
All client sessions must be terminated before executing gsk8capicmd_64 -cert -add command, otherwise you will continue to receive the "ANS1692E The certificate is not trusted" error message despite the correct certificate.

It is important that you download the correct certificate for your server. You will find a list of possible certificates in the table below.
Replace the entries <new certificate file> and <new label> with the corresponding values from the table below in the following commands!

Procedure under Linux:

gsk8capicmd_64 -cert -list -db /opt/tivoli/tsm/client/ba/bin/dsmcert.kdb -stashed
gsk8capicmd_64 -cert -add -db /opt/tivoli/tsm/client/ba/bin/dsmcert.kdb -file <new certificate file> -label "<new label>" -stashed
gsk8capicmd_64 -cert -list -db /opt/tivoli/tsm/client/ba/bin/dsmcert.kdb -stashed

Procedure under Mac OS:

/Library/ibm/gsk8/bin/gsk8capicmd -cert -list -db /Library/Application\ Support/tivoli/tsm/client/ba/bin/dsmcert.kdb -stashed
/Library/ibm/gsk8/bin/gsk8capicmd -cert -add -db  /Library/Application\ Support/tivoli/tsm/client/ba/bin/dsmcert.kdb -file  <new certificate file> -label "<new label>" -stashed
/Library/ibm/gsk8/bin/gsk8capicmd -cert -list -db /Library/Application\ Support/tivoli/tsm/client/ba/bin/dsmcert.kdb -stashed

Procedure under Windows:
Start cmd.exe and execute the following commands:

set PATH=C:\Program Files\ibm\gsk8\lib64;C:\Program Files\ibm\gsk8\bin;%PATH%

cd C:\Program Files\Tivoli\TSM\baclient
gsk8capicmd_64 -cert -list -db dsmcert.kdb -stashed
gsk8capicmd_64 -cert -add -db /opt/tivoli/tsm/client/ba/bin/dsmcert.kdb -file <new certificate file> -label "<new label>" -stashed
gsk8capicmd_64 -cert -list -db dsmcert.kdb -stashed
 server <new certificate file>

 <new label>

date of movenew IP-addressesport
T69I2Server_SelfSigned_T69I2.arm10.156.29.121:692003.06.202510.156.29.121, 2001:4ca0:0:117::a9c:1d796920
S65Server_SelfSigned_S65.arm10.156.29.121:215004.06.202510.156.29.121, 2001:4ca0:0:117::a9c:1d792150
S101Server_SelfSigned_S101.arm10.156.29.121:251011.06.202510.156.29.121, 2001:4ca0:0:117::a9c:1d792510
S100Server_SelfSigned_S100.arm10.156.29.121:250016.06.202510.156.29.121, 2001:4ca0:0:117::a9c:1d792500
S35Server_SelfSigned_S35.arm10.156.29.122:185024.06.202510.156.29.122, 2001:4ca0:0:117::a9c:1d7a1850
T68I110.156.29.122:681025.06.2025

10.156.29.122, 2001:4ca0:0:117::a9c:1d7a

6810

S4310.156.29.122:1930

26.06.2015

10.156.29.122, 2001:4ca0:0:117::a9c:1d7a

1930

S44

10.156.29.122:1940

30.06.2025

10.156.29.122, 2001:4ca0:0:117::a9c:1d7a

1940

T68I2

10.156.29.123:6820

01.07.2025

10.156.29.123, 2001:4ca0:0:117::a9c:1d7b

6810

S22

10.156.29.122:1720

02.07.2025

10.156.29.122, 2001:4ca0:0:117::a9c:1d7a

1720

S47

10.156.29.123:1970

03.07.2025

10.156.29.123, 2001:4ca0:0:117::a9c:1d7b

1970

S48

10.156.29.123:1980

0707.2023

10.156.29.123, 2001:4ca0:0:117::a9c:1d7b

1980

S52

10.156.29.123:2020

08.07.2023

10.156.29.123, 2001:4ca0:0:117::a9c:1d7b

2020

S68

10.156.29.124:2180

09.07.2025

10.156.29.124, 2001:4ca0:0:117::a9c:1d7c

2180

T68I3

10.156.29.124:6830

10.07.2025

10.156.29.124, 2001:4ca0:0:117::a9c:1d7c

6830

T68I4

10.156.29.124:6840

11.07.2025

10.156.29.125, 2001:4ca0:0:117::a9c:1d7d

6840

S60

10.156.29.124:2100

14.07.2025

10.156.29.124, 2001:4ca0:0:117::a9c:1d7c

2100

S41

10.156.29.124:1910

15.07.2025

10.156.29.124, 2001:4ca0:0:117::a9c:1d7c

1910

S39

10.156.29.125:1890

15.07.2025

10.156.29.125, 2001:4ca0:0:117::a9c:1d7d

1890

S40

10.156.29.125:1900

16.07.2025

10.156.29.125, 2001:4ca0:0:117::a9c:1d7d

1900

S42

10.156.29.125:1920

17.07.2025

10.156.29.125, 2001:4ca0:0:117::a9c:1d7d

1920

T69I1

10.156.29.126:6910

18.07.2025

10.156.29.126,2001:4ca0:0:117::a9c:1d7e

6910

S67

10.156.29.126:2170

21.07.2025

10.156.29.126,2001:4ca0:0:117::a9c:1d7e

2170

S53

10.156.29.126:2030

22.07.2025

10.156.29.126,2001:4ca0:0:117::a9c:1d7e

2030

S54

10.156.29.127:2040

23.07.2025

10.156.29.127,2001:4ca0:0:117::a9c:1d7f

2040

S49

10.156.29.126:1990

23.07.2025

10.156.29.126,2001:4ca0:0:117::a9c:1d7e

1990

T69I3

10.156.29.127:6930

25.07.2025

10.156.29.126,2001:4ca0:0:117::a9c:1d7e

6930

S19

10.156.29.127:1690

25.07.2025

10.156.29.126,2001:4ca0:0:117::a9c:1d7e

1690

S62

10.156.29.127:2120

28.07.2025

10.156.29.127,2001:4ca0:0:117::a9c:1d7f

2120

T67I1

10.156.29.128:6710

29.07.2025

10.156.29.128, 2001:4ca0:0:117::a9c:1d80

6710

S51

10.156.29.128:2010

29.07.2025

10.156.29.128, 2001:4ca0:0:117::a9c:1d80

2010

S25

10.156.29.129:1750

30.07.2025

10.156.29.129, 2001:4ca0:0:117::a9c:1d81

1750

S45

10.156.29.128:1950

31.07.2025

10.156.29.128, 2001:4ca0:0:117::a9c:1d80

1950

T69I4

10.156.29.128:6940

01.08.2025

10.156.29.128, 2001:4ca0:0:117::a9c:1d80

6940

S381

10.156.29.129:5310

04.08.2025

10.156.29.129, 2001:4ca0:0:117::a9c:1d81

5310

S382

10.156.29.129:5320

05.08.2025

10.156.29.129, 2001:4ca0:0:117::a9c:1d81

5320

S29

10.156.29.130:1790

05.08.2025

10.156.29.130, 2001:4ca0:0:117::a9c:1d82

1790

S24Server_SelfSigned_S24.arm

10.156.29.130:1740

07.08.2025

10.156.29.130, 2001:4ca0:0:117::a9c:1d82

1740

S403

10.156.29.129:5530

07.08.2025

10.156.29.129, 2001:4ca0:0:117::a9c:1d81

5530

S18

10.156.29.130:1680

11.08.2025

10.156.29.130, 2001:4ca0:0:117::a9c:1d82

1680

S30

10.156.29.130:1800

12.08.2025

10.156.29.130, 2001:4ca0:0:117::a9c:1d82

1800

S23

10.156.29.131:1730

13.08.2025

10.156.29.131, 2001:4ca0:0:117::a9c:1d83

1730

S12

10.156.29.131:1620

16.09.2025

10.156.29.131, 2001:4ca0:0:117::a9c:1d83

1620

S14

10.156.29.131:1640

17.09.2025

10.156.29.131, 2001:4ca0:0:117::a9c:1d83

1640

S16

10.156.29.131:1660

18.09.2025

10.156.29.131, 2001:4ca0:0:117::a9c:1d83

1660

S15

10.156.29.132:1650

22.09.2025

10.156.29.132, 2001:4ca0:0:117::a9c:1d84

1650

S17

10.156.29.132:1670

25.09.2025

10.156.29.132, 2001:4ca0:0:117::a9c:1d84

1670

S21

10.156.29.132:1710

29.09.2025

10.156.29.132, 2001:4ca0:0:117::a9c:1d84

1710

S28

10.156.29.132:1780

30.09.2025

10.156.29.132, 2001:4ca0:0:117::a9c:1d84

1780