Strengthened EPM Agent Credential Protection
EPM Agent now uses AES-GCM to protect newly created direct credentials, including cloud passwords, database credentials, and OAuth 2.0 tokens. This authenticated encryption format helps detect altered or corrupted credential data, uses an EPM Agent-managed local key, and rejects invalid, unknown, or unsafe encryption formats without falling back to older algorithms.
Existing recognized legacy credentials remain readable with warnings during a six-month migration period. Administrators should re-encrypt direct credentials using encrypt password, refresh OAuth tokens as needed, and verify their affected jobs before the transition ends, when legacy readers are planned for removal.
Applies to: Account Reconciliation, Enterprise Profitability and Cost Management, Financial Consolidation and Close, Planning, Tax Reporting
Business Benefit: This enhancement provides stronger protection for sensitive credentials, reducing the risk of unauthorized access or service disruption caused by tampered, corrupted, or weakly encrypted data. The phased migration keeps existing customer configurations working while giving administrators time to move to the more secure standard without an immediate operational impact.
Key resources
- EPM Integration Agent in Administering Data Integration