System Administration > Encryption key management > Administering Teamcenter Key Manager
Manage secret keys
Learn how to manage secret keys using the Key Manager Administration application. Manage your site's keys on the Secret Key tab of the Teamcenter Key Manager Administration application. Click the Secret Key tab to view a list of current and expired keys in the key store organized by component. Components can be expanded and collapsed. Select a key to view its details. Click Filter to limit the types of keys listed: All Keys lists all keys in the secure store. Latest Keys lists only keys currently used for encryption and decryption for each component. Active Keys lists all keys that have not expired, including the most current keys and keys that may be used for decryption. Expired Keys lists keys that could be archived or deleted as they are no longer used for encryption or decryption. Creating a key You cannot manually create a key with the Key Manager Administration application. New keys are generated on demand according to policy settings. Keys can also be imported. Exporting a key Exchanging keys between Teamcenter sites is necessary when the sites exchange data. When exporting a key for use on a target key manager system, the key value is encrypted with a wrapping certificate created on that target system. This requires that a public certificate exists in the exporting key manager system's secure store. Before exporting a key from your system, export a wrapping certificate from the target system and import that certificate into your key store using the procedures in Managing certificates. Select the key to export and click Export Secret Key . Select a wrapping certificate created by the target system and save the exported key to an accessible directory. Importing a key Importing a key reads the definition of a key from a file exported by another key manager system and stores the key and attributes in the local secure store. To import a key exported from another system, you must first have provided the exporting system with a wrapping certificate in which the key is wrapped when exported. The imported key is decrypted using the private key corresponding to the certificate with which the key was wrapped and exported. With no key selected, click Import Secret Key . Use Choose File to locate and open the key on your file system and click Choose File to import the key into the key store. Deactivating (rolling over) a key A key rolls over with a new key being generated when the old key's key lifetime is reached. You can also manually roll over keys that have been compromised or for which you have another reason for wanting a new key. Select the key to be rolled over. Click Roll Over and confirm the key deactivation. The key is deactivated, a new key is generated, and the new key is used for future encrypting. The rolled over key is retained for future decrypting. Archiving keys Archiving a key removes it from the key store. Only expired keys can be archived. Archived keys can be reimported if needed at a later time. Select the key to be archived. Click Archive Secret Key . The key is removed from the key store and archived in the key manager server data directory: INSTALL_DIR\KeyManagerServer\data\AdminWeb\Archive\policy_name
Source: https://docs.sw.siemens.com/documentation/external/PL20251212545240207/en-US/tc_help/AWAdmin/fhs4814155880506/exc1737238558409/leu1737238559503/dqh1737238559821.html · retrieved Fri Jul 31 2026 00:00:00 GMT+0000 (Coordinated Universal Time)