TeamcenterKnowledge

System Administration > Encryption key management

Install Teamcenter Key Manager

If your site is using Teamcenter Key Manager for cryptographic services, Teamcenter Key Manager and the local key manager satellite can be installed before or after Teamcenter foundation is installed using Deployment Center. A key manager satellite must be installed on every machine that will be using Teamcenter Key Manager. SSL certificates must also be established on each machine involved in the Teamcenter Key Manager system. Note Once a site is using Teamcenter Key Manager for cryptographic services, it cannot be reconfigured to use an alternate cryptographic system without reinstalling Teamcenter. Install the key manager server and satellites Teamcenter Key Manager is installed and deployed using Deployment Center. See the Teamcenter Compatibility Matrix to verify the version of Deployment Center required to install and deploy Teamcenter Key Manager. The following steps are specific to installing and deploying Key Manager using Deployment Center. For detailed information on using Deployment Center, see the most recent Deployment Center help collection available on Support Center. Procedure Download the Teamcenter Foundation software kit from Support Center and place it in the Deployment Center software repository. Log onto Deployment Center and click Software Repositories to view the Teamcenter Foundation software kit, verifying its availability in the software repository. Click Environments to display the environments scanned by Deployment Center. Select or add an environment in which to install Teamcenter Key Manager. On the Software tab, add the Teamcenter Foundation software kit to the Selected Software list. On the Options tab, select the options for your environment. Selecting Single Box allows you to install the key manager server and satellite on one machine. Selecting Distributed allows you to install the key manager server on one machine and satellites on one or more other machines. On the Applications tab, click to edit the selected applications. The list of available applications is displayed. Under Available Applications, check Key Manager. Remove the check from Teamcenter Foundation if Teamcenter has already been installed using Deployment Center. or you will install Teamcenter later using Deployment Center. Click Update Selected Applications. On the Components tab, one key manager server and one key manager satellite component are listed. If you have additional machines requiring satellites and selected Distributed on the Options tab, click to add a satellite for each additional machine. Satellites are required for each machine requiring cryptographic services, such as machines with two-tier rich clients and Dispatcher. If you plan to deploy a secondary key manager server, add a secondary server to the list. If you are installing Teamcenter and have the Server Manager component checked, ensure that a Key Manager satellite is installed on the server manager machine. Bring each component to a 100% complete status by supplying any remaining required settings for each. With a component selected, move your cursor over fields in the right pane for tips on entering setting values for that component and the machine on which it will be deployed. Values will all be verified during deployment of the component. Be aware of the following items: When setting a PKCS#11 Configuration Type value for the Key Manager Server, Default Network Security Services (NSS) is delivered with Teamcenter Key Manager. Selecting Customized Network Security Services (NSS) or Hardware Security Module (HSM) requires that those security systems are already installed at your site. Primary and secondary key manager servers must use the same PKCS#11 configuration type. The Key Manager Server Default Network Security Services (NSS) PIN can contain numbers, letters, and special characters. Record PINs, passwords, and other values for later reference. On the Deploy tab, generate the installation scripts. Review the Deploy Instructions information related to the generated installation scripts. Follow the steps in Run the deployment scripts in the Deployment Center help collection to run the deployment scripts for the primary server and satellites. Do not run the deployment script for a secondary key manager server until the primary key manager server and satellites are deployed and running. Deploying a secondary server requires that the primary server has already been deployed. See Installing a secondary Teamcenter Key Manager server for more details. If you selected Distributed on the Options tab and are deploying multiple satellites, deploy the Teamcenter Key Manager server before deploying satellites. Attempting to deploy satellites before deploying the server will fail. If you selected Single Box on the Options tab, the Teamcenter Key Manager server will automatically deploy before the satellite. Record the key manager and satellite installation directories for use during Teamcenter installations on each machine requiring Teamcenter Key Manager. If you are deploying Teamcenter Key Manager on Linux as a user without root privileges, log on as a user with root privileges and run the following scripts from the Teamcenter Key Manager installation directory ($INSTALL_DIR) for each server and satellite deployment: Teamcenter Key Manager server: $INSTALL_DIR/KeyManagerServer/root_post_tasks_key_manager_server.ksh $INSTALL_DIR/KeyManagerServer/root_post_tasks_key_manager_ca_server.ksh $INSTALL_DIR/KeyManagerServer/root_post_tasks_key_manager_admin.ksh Teamcenter Key Manager satellites: $INSTALL_DIR/KeyManagerSatellite/root_post_tasks_key_manager_satellite.ksh Teamcenter Key Manager servers and satellites run as services on Windows, and are started automatically. Ensure the services were successfully started as part of the deployments. If they are not running, start them using the steps in Start and stop Teamcenter Key Manager services. On Linux, Teamcenter Key Manager servers and satellites run as daemons that may need to be started manually if Java is not installed on the local machine. Ensure the following daemons are started. If necessary, start them as described in Start and stop Teamcenter Key Manager daemons. rc.key.manager.ca.server. rc.key.manager.admin rc.key.manager.satellite. rc.key.manager.server. Establish SSL certificates To provide keys and perform cryptography for programs running in the distributed Teamcenter environment, Teamcenter Key Manager is itself a separate distributed client-server system in which the client and the server trust each other using a PKI infrastructure. As part of the installation of the key manager server and key manager satellites, certificates were generated that can be trusted by Teamcenter Key Manager. Installing Teamcenter Key Manager for use with Multi-Site Collaboration To support Multi-Site Collaboration file transfers, keys must be available on both sites.

Source: https://docs.sw.siemens.com/documentation/external/PL20251212545240207/en-US/tc_help/AWAdmin/fhs4814155880506/exc1737238558409/xid1560806.html · retrieved Fri Jul 31 2026 00:00:00 GMT+0000 (Coordinated Universal Time)