IBM Support

How to Regenerate Cryptographic Keys as of Cognos 10.2.2?

Technote (FAQ)


How can the Cryptographic Keys be regenerated in Cognos 10.2.2?


There are several instances when the Cryptographic Keys may need to be regenerated. Beginning with Cognos 10.2.2, the traditional method to regenerate the cryptographic keys is no longer valid and the below steps would need to be followed instead.


1. Stop the Cognos services.

2. On the Content Manager computer, launch " Cognos Configuration".

  • Click "File - Export As"
  • Choose "yes" (at the prompt) and save the file (for example as "backup.xml" in the c10_location/configuration folder
  • Close Cognos Configuration

3. On the Content Manager computer, create a backup of the following files and directories then MOVE these files and folders to this different location that is secure.

During the crypto keys regeneration process these files and folders will be re-created

The files are:
  • c10_location/configuration/cogstartup.xml
  • c10_location/configuration/caSerial
  • c10_location/configuration/certs/CAMCrypto.status
  • c10_location/configuration/certs/CAMKeystore
  • c10_location/configuration/certs/CAMKeystore.lock
  • c10_location/temp/cam/freshness

The directory is
  • c10_location/configuration/csk

4. In the c10_location/configuration folder, rename backup.xml to cogstartup.xml.

5. Open Cognos Configuration, save the configuration and start the services. On Gateway installation, restart the Web Server.

6. Repeat steps 1 to 5 on all computers that have Cognos Business Intelligence BI Server components installed.

Document information

More support for: Cognos Business Intelligence
Install and Config

Software version: 10.2.2

Operating system(s): AIX, HP-UX, Linux, Solaris, Windows

Software edition: All Editions

Reference #: 1694322

Modified date: 25 February 2015