Changes to configuration properties or database values

Changes to some configuration properties in the SKLMConfig.properties file or in the IBM Security Key Lifecycle Manager database can occur dynamically.

Changes to other properties or database entries require that you restart the IBM Security Key Lifecycle Manager server before the change takes effect.

Depending on the change you intend to make, you might use the graphical user interface, command-line interface, or the REST interface. Not all properties in the SKLMConfig.properties file or in the IBM Security Key Lifecycle Manager database can be changed by using all the interfaces.

Table 1. Changes to configuration properties or database entries
Property Installation sets default Changes occur dynamically Change requires server restart Change available only in command-line interface or REST interface
Audit.event.outcome
check mark symbol
 
check mark symbol
 
Audit.eventQueue.max
check mark symbol
 
check mark symbol
 
Audit.event.types
check mark symbol
check mark symbol
   
Audit.handler.file.multithreads    
check mark symbol
check mark symbol
Audit.handler.file.name
check mark symbol
 
check mark symbol
 
Audit.handler.file.size
check mark symbol
 
check mark symbol
 
Audit.handler.file.threadlifespan    
check mark symbol
check mark symbol
Audit.isSyslog  
check mark symbol
   
Audit.syslog.server.host  
check mark symbol
   
Audit.syslog.server.port  
check mark symbol
   
Audit.syslog.isSSL  
check mark symbol
   
autoRestartAfterRestore  
check mark symbol
   
backup.keycert.before.serving
check mark symbol
check mark symbol
 
check mark symbol
browse.root.dir    
check mark symbol
 
cert.valiDATE  
check mark symbol
   
config.keystore.name
check mark symbol
 
check mark symbol
You cannot modify this property by using the command-line or REST interface.
config.keystore.batchUpdateSize
check mark symbol
 
check mark symbol
 
config.keystore.batchUpdateTimer
check mark symbol
 
check mark symbol
 
config.keystore.ssl.certalias *  
check mark symbol
check mark symbol
 
data.synchronizing.backup.password  
check mark symbol
check mark symbol
(if changed manually)
 
data.synchronizing.svc.interval  
check mark symbol
check mark symbol
 
data.synchronizing.svc.MaxBackupNum  
check mark symbol
check mark symbol
 
debug  
check mark symbol
check mark symbol
(if changed manually)
 
drive.acceptUnknownDrives (replaced by device group attribute device.AutoPendingAutoDiscovery in the IBM Security Key Lifecycle Manager database)  
drive.default.alias1 (replaced by a device group attribute in the IBM Security Key Lifecycle Manager database)  
drive.default.alias2 (replaced by a device group attribute in the IBM Security Key Lifecycle Manager database)  
ds8k.acceptUnknownDrives (replaced by device group attribute device.AutoPendingAutoDiscovery in the IBM Security Key Lifecycle Manager database)  
enableClientCertPush
check mark symbol
check mark symbol
check mark symbol
(if changed manually)
 
enableHighScaleBackup  
check mark symbol
check mark symbol
(if changed manually)
check mark symbol
enableKeyRelease  
check mark symbol
check mark symbol
(if changed manually)
 
enablePBEInHSM    
check mark symbol
(if changed manually)
check mark symbol
fips
check mark symbol
 
check mark symbol
(if changed manually)
check mark symbol
kmip.request.processing.hostNameLookup    
check mark symbol
(if changed manually)
check mark symbol
KMIPListener.ssl.port *
check mark symbol
check mark symbol
check mark symbol
 
lock.timeout  
check mark symbol
 
check mark symbol
maximum.keycert.expiration.period.in.years
check mark symbol
     
maxPendingClientCerts  
check mark symbol
check mark symbol
(if changed manually)
 
pcache.refresh.interval This property is optional in the configuration file. By default, its value is not set and IBM Security Key Lifecycle Manager uses the default time interval of 15 minutes.
check mark symbol
 
check mark symbol
pkcs11.pin    
check mark symbol
(if changed manually)
check mark symbol
pkcs11.pin.obfuscated    
check mark symbol
(if changed manually)
check mark symbol
pkcs11.pin.obfuscated    
check mark symbol
(if changed manually)
check mark symbol
requireSHA2Signatures      
check mark symbol
rest.user.inactive_time    
check mark symbol
(if changed manually)
check mark symbol
stopRoundRobinKeyGrps    
check mark symbol
(if changed manually)
check mark symbol
suiteB    
check mark symbol
check mark symbol
symmetricKeySet (an attribute in the IBM Security Key Lifecycle Manager database)  
tklm.backup.db2.dir       You cannot modify this property by using the command-line or REST interface.
tklm.backup.dir Running a backup adds this property to the configuration file.  
check mark symbol
You cannot modify this property by using the command-line interface or REST interface.
tklm.encryption.keysize
check mark symbol
 
check mark symbol
(if changed manually)
check mark symbol
tklm.encryption.password This is an internally used property. Do not change its value. You cannot modify this property by using the command-line or REST interface.
tklm.encryption.pbe.algorithm    
check mark symbol
(if changed manually)
check mark symbol
tklm.lockout.attempts
check mark symbol
 
check mark symbol
check mark symbol
tklm.lockout.enable
check mark symbol
 
check mark symbol
check mark symbol
TransportListener.tcp.port
check mark symbol
 
check mark symbol
 
TransportListener.tcp.timeout    
check mark symbol
 
TransportListener.ssl.ciphersuites    
check mark symbol
check mark symbol
TransportListener.ssl.clientauthentication      
check mark symbol
TransportListener.ssl.port *
check mark symbol
check mark symbol
check mark symbol
 
TransportListener.ssl.protocols
check mark symbol
 
check mark symbol
 
TransportListener.ssl.timeout    
check mark symbol
 
Transport.ssl.vulnerableciphers.patterns
check mark symbol
 
check mark symbol
check mark symbol
Transport.ssl.vulnerableciphers    
check mark symbol
check mark symbol
useSKIDefaultLabels  
check mark symbol
   
zOSCompatibility  
check mark symbol
   

* If you set this value for the first time, restart is not required. If you later modify the value, restart is required.