Notification
Risk classification
HIPER (High Impact and/or Pervasive)
Risk categories
Severe Performance Impact
Affected Domain
TS4500, TS4300, and TS2900 using 3592-EH7, LTO6 or LTO5 Tape Drives with Guardium Key Lifecycle Manager over SSL/TLS.
- TS4500: Enterprise TS1140 (3592-EH7), LTO-6 (3588-F6C), and LTO-5 (3588-F5C).
- TS4300: LTO-6 (Full High and Half High).
- TS2900: LTO-6 (3572-S6H) and LTO-5 (3572-S5H).
Abstract
IBM Tape Drive SHA1 CA certificates (ibmrootca and realsubcacert) stored in the Guardium Key Lifecycle Manager Truststore are expiring on 30 June 2026. Failure to renew these certificates before expiration will result in immediate communication failure between Guardium Key Lifecycle Manager and LTO/3592 Tape Drives using certificates signed by these CA authorities for SSL/TLS authentication.
Description
Impact of certificate expiration
CRITICAL: Once the certificates expire on 30 June 2026:
- Tape Drives currently communicating with Guardium Key Lifecycle Manager over SSL/TLS and using certificates signed by SHA1 based expiring CA certificates
ibmrootcaandrealsubcacertwill immediately stop communicating upon certificate expiration. - SSL/TLS handshake authentication will fail, preventing secure communication.
- Tape Drive operations requiring key management will be disrupted.
- Disruption happens automatically at expiration (No restart or external trigger is required for the disruption to occur).
No disruption will occur if you are:
- Using Guardium Key Lifecycle Manager version 5.1. As all the certificates already exist in Truststore, you do not need to import them again.
- Using storage and non-storage devices that are NOT LTO or 3592 tape libraries.
- NOT communicating with LTO and 3592 Tape Drives over SSL/TLS channel.
- Using your own custom certificates for LTO and 3592 Tape Drives (not IBM Tape Drive CA signed certificates).
- Using Tape Drive certificates that are not signed by SHA1 based expiring Truststore CA certificates
ibmrootcaandrealsubcacertfor communication.
Note:
- If you fall into any of the above categories, you may still want to complete the following steps:
- For Guardium Key Lifecycle Manager version 4.0.0, 4.1.0, 4.1.1: Step3 to remove the expiring/expired certificates.
- For Guardium Key Lifecycle Manager version 4.2.0, 4.2.1, and 5.0: Steps 3 and 4 to remove the expiring/expired certificates and reset notification settings to reduce certificate expiry alerts.
- For Guardium Key Lifecycle Manager version 5.1: Steps 1 and 2 to remove the expiring/expired certificates and reset notification settings to reduce certificate expiry alerts.
Recommended Action
Complete the following procedure as per the installed Guardium Key Lifecycle Manager version.
Prerequisites
- Administrative access to Guardium Key Lifecycle Manager UI.
Procedure for Guardium Key Lifecycle Manager version 4.0.0, 4.1.0, and 4.1.1
- Download the renewed certificates.
- Download ibmTapeDrive2048.zip.
Extract the archive to access:
-
ibmrootca.pem(renewed root CA certificate)-
realsubcacert.pem(renewed subordinate CA certificate)
- Import the renewed certificates.
- Login to Guardium Key Lifecycle Manager UI and complete the following steps for both the downloaded certificates.
- Go to Configuration > Truststore > Add.
Configure the import.
- Certificate Alias: Enter the certificate name.
- Click Browse to upload the certificates downloaded in
.pemformat in step 1.- Certificate type: Select DER.
Click Add certificate.
Remove the old certificates (After 1 July 2026).
Note: Complete this step in the first week of July 2026 (after the old certificates expire).
- Login to Guardium Key Lifecycle Manager UI.
- Go to Configuration > Truststore
Select the following expired certificates.
-
ibmrootca-
realsubcacert- Click Delete.
Procedure for Guardium Key Lifecycle Manager version 4.2.0 and 4.2.1
- Download the renewed certificates.
- Download ibmTapeDrive2048.zip.
Extract the archive to access:
-
ibmrootca.pem(renewed root CA certificate)-
realsubcacert.pem(renewed subordinate CA certificate)
- Import the renewed certificates.
- Login to Guardium Key Lifecycle Manager UI and complete the following steps for both the downloaded certificates.
- Go to Advanced Configuration > Client Device Certificates > Import.
Configure the import.
- Certificate name: Enter the certificate name for
ibmrootca.pemorrealsubcacert.pem. For example,ibmrootca2048.- Upload certificate downloaded in
.pemformat in step 1.- Device Group: Select the device group that is currently using certificates signed by the expiring Truststore CA certificates.
Do not leave this field blank.Note: - If there are multiple device groups of type LTO or 3592, you only need to import the certificates once, not for each device group.
- If you do not have, or do not use, device group of type LTO or 3592, you can skip this step.
- Check: Allow the server to trust this certificate with the associated client device.
Click Import.
Adjust the notification settings (optional but recommended)
Complete the following steps to reduce frequent notifications and emails about expiring certificates:
- Login to Guardium Key Lifecycle Manager UI.
- Go to Advanced Configuration > Notification configuration > Notification.
Set Certificate expiry service frequency to
168(hours).Note: This setting will affect notification frequency for all the expiring or expired certificates in Guardium Key Lifecycle Manager and not just tape drive certificates.
Remove the old certificates (After 1 July 2026).
Note: Complete this step in the first week of July 2026 (after the old certificates expire).
- Login to Guardium Key Lifecycle Manager UI.
- Go to Advanced Configuration > Client Device Certificates > Show preinstalled certificates.
Select the following expired certificates.
-
ibmrootca-
realsubcacert- Click Delete.
Reset the notification settings in step 3 back to original value (recommended 24hours).
Procedure for Guardium Key Lifecycle Manager version 5.0
Download the renewed certificates.
- Download ibmTapeDrive2048.zip.
Extract the archive to access:
-
ibmrootca.pem(renewed root CA certificate)-
realsubcacert.pem(renewed subordinate CA certificate)
- Import the renewed certificates.
- Login to Guardium Key Lifecycle Manager UI and complete the following steps for both the downloaded certificates.
- Go to Configuration > Encryption endpoint certificates > Import certificates.
Configure the import.
- Certificate name: Enter the certificate name for
ibmrootca.pemorrealsubcacert.pem. For example,ibmrootca2048.- Upload certificate downloaded in
.pemformat in step 1.- Endpoint: Select the endpoint that is currently using certificates signed by the expiring Truststore CA certificates.
Do not leave this field blank.Note: - If there are multiple endpoints of type LTO or 3592, you only need to import the certificates once, not for each endpoint.
- If you do not have, or do not use, endpoint of type LTO or 3592, you can skip this step.
- Check: Allow the server to trust this certificate with the associated endpoint.
Click Import.
Adjust the notification settings (optional but recommended).
Complete the following steps to reduce frequent notifications and emails about expiring certificates:
- Login to Guardium Key Lifecycle Manager UI.
- Go to Configuration > Notification settings > Notification.
Set Certificate expiry service frequency to
168(hours).Note: This setting will affect notification frequency for all the expiring or expired certificates in Guardium Key Lifecycle Manager and not just tape drive certificates.
Remove the old certificates (After 1 July 2026)
Note: Complete this step in the first week of July 2026 (after the old certificates expire).
- Login to Guardium Key Lifecycle Manager UI.
- Go to Configuration > Encryption endpoint certificates > Show preinstalled certificates.
- On the row of expiring certificate, click 3 dots for Options > Delete.
Delete the following expired certificates.
-
ibmrootca-
realsubcacertReset the notification settings in step 3 back to original value (recommended 24hours).
Procedure for Guardium Key Lifecycle Manager version 5.1
Guardium Key Lifecycle Manager version 5.1 is not affected, as all the required certificates are already present in Guardium Key Lifecycle Manager Truststore. Therefore, no additional action is needed to import certificates.
Proceed with the following steps to update the notification settings and remove the old or expired certificates.
Adjust the notification settings (optional but recommended).
Complete the following steps to reduce frequent notifications and emails about expiring certificates:
- Login to Guardium Key Lifecycle Manager UI.
- Go to Configuration > Notification settings > Notification.
Set Certificate expiry service frequency to
168(hours).Note: This setting will affect notification frequency for all the expiring or expired certificates in Guardium Key Lifecycle Manager and not just tape drive certificates.
Remove the old certificates (After 1 July 2026)
Note: Complete this step in the first week of July 2026 (after the old certificates expire).
- Login to Guardium Key Lifecycle Manager UI.
- Go to Configuration > Encryption endpoint certificates > Show preinstalled certificates.
- On the row of expiring certificate, click 3 dots for Options > Delete.
Delete the following expired certificates.
-
ibmrootca-
realsubcacertReset the notification settings in step 1 back to original value (recommended 24hours).
Frequently Asked Questions (FAQs)
1. How can I check if Tape drives or 3592 devices are communicating with Guardium Key Lifecycle Manager over SSL/TLS?
Answer: The following are the default ports used for SSL/TLS communication with Guardium Key Lifecycle Manager:
- Port 5696: Key Management Interoperability Protocol (KMIP) port
- Port 1441: IPP over SSL/TLS port
To determine whether SSL/TLS is being used, verify if the device is communicating with Guardium Key Lifecycle Manager over port 5696 or 1441. If either of these default ports is in use, then SSL/TLS communication is enabled.
2. What is the impact of not deleting the old certificates?
Answer. There is no functional impact. However, you may receive notifications. It is recommended to delete the old certificates after 1 July 2026.
3. What should I do if I am unsure whether my environment is impacted?
Answer: Export the device certificate and verify the details. If the issuer is 'IBM Tape Drive' and the algorithm is 'SHA-1', then update the certificate.
For steps to export LTO/3592 device certificates, refer to the LTO/3592 device documentation.
4. In a Master/Clone setup, do I need to update certificates on both systems?
Answer: No. You only need to import the certificate on the Master system. Then, trigger a full replication.
5. In a Multi-Master setup, where should the certificate be updated?
Answer: Update the certificate on the primary or any standby system. Ensure that HADR is up and the servers are connected.
6. Does this issue affect all LTO drives?
Answer: Not necessarily. Export the device certificate and check the details. If the issuer is 'IBM Tape Drive' and the algorithm is 'SHA-1', then update the certificate.
For steps to export LTO/3592 device certificates, refer to the LTO/3592 device documentation.
7. When will the new certificates be used, and how can I verify this?
Answer: The new certificates will be used automatically after import when the old certificates expire.
To verify the usage:
- Enable SSL tracking in Liberty by setting:
Djavax.net.debug=ssl:handshakeinjvm.options - Restart Liberty
- Run the KPD test
- Check the
console.logof Liberty
8. How can I confirm whether certificates are in use, or should I replace them anyway?
Answer: You can check by verifying the port (5696 or 1441 for SSL/TLS). If unsure, it is safe to replace the certificates, as they are part of the base product.
9. What happens if I delete old certificates before they expire?
Answer: If deleted before expiry, the certificates will reappear after Liberty restart. It is recommended to delete them only after they expire.
10. How can we verify whether the certificate is signed by IBM tape?
Answer: Tape drives that communicate with Guardium Key Lifecycle Manager over SSL/TLS using certificates signed by the SHA1-based expiring CA certificates (ibmrootca and realsubcacert) will stop communicating once those certificates expire. To verify, the device team should check whether the certificate in use is signed by ibmrootca or realsubcacert, since the certificate is owned and presented by the device during communication with Guardium Key Lifecycle Manager. They can export the device certificate and examine the CA authority. Typically, the issuer name and SUID will match the root certificate, confirming the signature.
11. What if the communication between the storage and Guardium Key Lifecycle Manager break even after following the suggested procedure?
Answer: As an immediate recovery step, set the TransportListener.ssl.clientauthentication= 0. Use REST interface or swagger UI to update this property in SKLMConfig.properties.
- Using REST interface:
- Open a REST client. For more information, see Using Swagger UI.
- Run the Update Config Property REST Service to update the TransportListener.ssl.clientauthentication.
For example, you can send the following HTTP request:
PUT https://localhost:<port>/GKLM/rest/v1/configProperties
{
"TransportListener.ssl.clientauthentication": "0"
}
This will disable client authentication. The communication between storage and Guardium Key Lifecycle Manager will be restored.
Please contact IBM support for further steps after device communication is restored.
Date first published
18 June 2026
Was this topic helpful?
Document Information
Modified date:
27 June 2026
UID
ibm17276562