If you set up your Cryptographic Coprocessor incorrectly, you can end up with an unusable configuration with which you cannot perform any cryptographic functions and cannot use any of the APIs to recover. For example, you can configure it such that you have no role authorized to set the master key and no role authorized to change or create new roles or profiles. You can call the hardware command for reinitializing the card by using the Cryptographic_Facility_Control (CSUACFC) SAPI.
However, in some cases, there may not be a role that is authorized to any hardware command. In this case, you must reload the Licensed Internal Code by using the function that is provided in Hardware Service Manager in System Service Tools.