IBM Support

How to verify when encryption keys (crypto keys) will expire

How To


By default the encryption keys in Cognos are set to expire every 730 days. Saving the configuration or restarting the services resets this clock, but it can be helpful to know when the keys will expire so you can update them beforehand.


Prevent outages by checking when encryption keys will expire so you can plan to renew them ahead of time


- All platforms


  1. Open ikeyman, located here on Windows installs: <cognos_install>\jre\bin\ikeyman.exe
  2. Once ikeyman opens select the "Open" icon and an open window will appear
  3. Under Key database type choose "PKCS12"
  4. Under file name, navigate to the CAMKeystore as follows: <cognos_install>\Configuration\certs\CAMKeystore
  5. If the default password has not been changed enter it "NoPassWordSet"
  6. Certificates will appear in the ikeyman window
  7. Select "encryption" and then select view/edit from the menu to the right of the window
  8. The certificate opens and you can see validity, which is the date range the certificate is valid for
  9. Close the certificate

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSTSF6","label":"IBM Cognos Analytics"},"Component":"Encryption keys","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF016","label":"Linux"},{"code":"PF033","label":"Windows"}],"Version":"Cognos Analytics - All versions","Edition":"","Line of Business":{"code":"LOB10","label":"Data and AI"}}]

Document Information

Modified date:
17 October 2018

