Hi Andrew,
I am not an expert on the DFSMShsm side of the process, but I'll make sure they are aware of the question and can get a more complete answer posted here.
With CDA, though, I often see similar things when credentials are saved on one system in the Sysplex, but they can't be accessed on a different LPAR. Often, the cause is that ICSF on the other system hasn't seen the updated entry in the ICSF Crypto Key Data Set (CKDS). To fix that, restarting the ICSF address space is needed. For a more permanent (and usable) solution, the ICSF parmlib member (CSFPRMxx) should have the SYSPLEXCKDS(YES) setting. That tells each ICSF address space that they are sharing the CKDS with other LPARs, and should be aware of changes done by other systems.
In your environment, was the DFSMShsm address space that issued the error on an LPAR different from where the CDA credentials utility was run/credentials saved?
Andrew Wilt
DFSMSdfp CDA Product Owner