TeamcenterKnowledge

System Administration > Encryption key management

Install a secondary Teamcenter Key Manager server

When using Teamcenter Key Manager for cryptographic services, you can optionally install a secondary key manager server for redundancy and failover purposes. The primary key manager server and satellites must be installed and running before the secondary server can be installed. The secondary key manager server must be installed on a different machine than that on which the primary key manager server is installed. Generate the secondary key manager server deployment script If you have already generated a deployment script for your secondary key manger server as described in Install Teamcenter Key Manager, proceed to Install the secondary key manager server. Otherwise, generate your secondary server script using the following steps. The secondary key manager server is installed and deployed using Deployment Center. See the Hardware and Software Certifications knowledge base article on Support Center to verify the version of Deployment Center required to install and deploy the secondary key manager server. Procedure Download the Teamcenter Foundation software kit from Support Center and place it in the Deployment Center software repository. Log onto Deployment Center and click Software Repositories to view the Teamcenter Foundation software kit, verifying its availability in the software repository. Click Environments to display the environments scanned by Deployment Center. Choose the environment in which the primary key manager server has been installed. On the Components tab, the key manager server and key manager satellite components are listed and shown to be 100% complete. Click , check Key Manager Secondary Server, and click Update Selected Components. Bring the secondary server component to a 100% complete status by supplying any remaining required settings. Values will all be verified during deployment of the component. Set the PKCS#11 Configuration Type value to be the same as that set for the primary key manager server. If your site is using hardware security modules (HSM), the secondary server must use a different HSM server than that used by the primary server. Alternately, one server can be configured to use an HSM server and the other server can be configured to use the default Network Security Services or customized Network Security Services. On the Deploy tab, generate the installation scripts. Review the Deploy Instructions information related to the generated installation scripts. Install the secondary key manager server Prerequisites These installation steps require the primary key manager server be disabled during the deployment of the secondary server installation script. Schedule the timing of this process to minimize impact at your site. Procedure On the machine running the primary key manager server: Stop the key manager server. Start the Teamcenter Key Manager root certificate authority server if it is not running. Start the Teamcenter Key Manager Administration application if it is not running. See Start and stop Teamcenter Key Manager services for instructions on starting and stopping servers and applications on Windows. See Start and stop Teamcenter Key Manager daemons for instructions on starting and stopping servers and applications on Linux. Follow the steps in Run the deployment scripts in the Deployment Center help collection to run the secondary server deployment script. The secondary key manager server runs as a service on Windows that is started automatically. Ensure the Teamcenter Key Manager Server service was successfully started as part of the deployment. If it is not running, start it using the steps in Start and stop Teamcenter Key Manager services. On Linux, the secondary key manager server runs as a daemon that may need to be started manually if Java is not installed on the local machine. Ensure the rc.key.manager.server daemon is started. If necessary, start it as described in Start and stop Teamcenter Key Manager daemons. Ensure the Teamcenter Key Manager Administration application remains running on the secondary server at all times. (As it is read-only, leaving it running does not create a security risk.) On the machine running the primary key manager server: Restart the key manager server. The secondary key manager server will automatically begin synchronizing with the primary server. Stop the Teamcenter Key Manager root certificate authority server. Stop the Teamcenter Key Manager Administration application. What to do next See Manage a secondary key manager server for more information on working with your secondary key manager server.

Source: https://docs.sw.siemens.com/documentation/external/PL20251212545240207/en-US/tc_help/AWAdmin/fhs4814155880506/exc1737238558409/xid1624222.html · retrieved Fri Jul 31 2026 00:00:00 GMT+0000 (Coordinated Universal Time)