Updating the encryption keystore
Your company IT policy might require that you periodically change the encryption key. Whenever the encryption key details change, you must update the encryption keystore in IBM OpenPages® with Watson™.
Note:
If field level encryption is already enabled, you do not need to disable the encryption keystore to update it.
Procedure
- Create a new keystore file. For more information, see Create the encryption keystore file and key pair.
- Create a keystore.properties file. See The keystore.properties file.
- Click
> Users and Security > Encryption
Keystore. - Click Edit.
- Enter the current encryption keystore password to access it.
- Update the details of the keystore.
For more information, see Setting up the encryption keystore.
- Click Update.
If you use field level encryption and it is enabled, the fields are re-encrypted using the new encryption key. Depending on the size of the repository, updating the encryption can take a long time. Field encryption runs in the background. You can view the progress by clicking Refresh.
- Update passwords in properties files.
- On each application server, change the passwords in properties files to plain text,
save the files, and then restart the application server. For more information, see Updating property files on application servers to use a custom key.
- On each reporting server, change the passwords in properties files to plain text, save
the files, and then restart the reporting server. For more information, see Updating property files on reporting servers to use a custom key.
- If you use global search, change the passwords in properties files to plain text, save
the files, and then restart the server. For more information, see Updating property files on the search server to use a custom key.
The passwords are encrypted with the updated encryption key when you restart the servers. - On each application server, change the passwords in properties files to plain text,
save the files, and then restart the application server.
- If you use IBM
OpenPages Loss Event Entry,
re-enter the password for each locale.
- Start the configuration tool. Go to http://<server_name>:<port>/openpages/app/jspview/lossevent#/editconfig
- Log in with a user account that is a member of the OPAdministrators group.
- Under the Locales section, expand each locale and enter the password.
- Close the configuration tool.
The passwords are encrypted with the updated encryption key. - If you use LDAP for user provisioning, do the following steps:
- Click
> Users and Security > User LDAP
Configuration. - Edit the LDAP configuration.
- In the Security credentials field, re-enter the password that is used to authenticate with the LDAP server.
- Click Save.
The security credentials are encrypted with the updated encryption key. - Click
- If you use natural language classifiers, do the following steps:
- Click
> Integrations > Mapping and Taxonomy
Suggestions. - Edit the classifier configuration.
- Natural Language Classifier: In the API Key field, re-enter the API key of the Natural Language Classifier instance.
- Watson Discovery Analyze API: Re-enter the password.
- Click Save.
- Repeat these steps for each classifier configuration.
The API keys are encrypted with the updated encryption key. - Click