Key file and stash file renewal information

Servers have associated key files and stash files. The following table describes the server key and stash files, including how they are created and refreshed.

Server Key and stash files How created How automatically updated How manually updated
SVA runtime package pd.kdb and pd.sth (does not contain a client-side certificate) runtime configuration pdadmin1 utility bassslcfg utility with the -chgpwd
Policy server ivmgrd.kdb and ivmgrd.sth server configuration pdmgrd1,2 mgrsslcfg with -chgpwd3 and -chgcert3
Proxy server pdmgrproxyd.kdb and pdmgrproxyd.sth server configuration pdmgrproxyd1 svrsslcfg with -chgpwd9 and -chgcert5
Authorization server [instance-]ivacld.kdb and [instance-]ivacld.sth
Each authorization server on a computer generate a set of .kdb and .sth files
server configuration pdacld1 svrsslcfg with -chgpwd4 and -chgcert5
Resource manager Key and stash file names are resource manager-dependent. The file name is configurable.6 svrsslcfg with -config Run an instance of the resource manager1 svrsslcfg utility with -chgpwd7 and -chgcert8


Notes

Parent topic: Certificate and password management