11 Managing the Argus Insight Cryptography Key

This chapter describes how to update the cryptography key in Argus Insight after the key has been updated in Argus Safety.

11.1 Updating the Cryptography Key and Re-encrypt

After the cryptography key has been updated in Argus Safety, you must update the cryptography key in Argus Insight. This process will update all the required passwords in Argus Insight using the new key.

To update the cryptography key and regenerate passwords:

  1. Log in to the Argus Insight client.

  2. Click Start.

  3. Navigate to Programs > Oracle > Argus Insight, and then select Cryptography Key Management.

    The Argus Insight Key Management screen appears.

  4. Enter the following parameters and click Validate.

    1. DBA user name

    2. DBA user password

    3. Argus Insight database name

    After successful authentication, the Argus Insight Key Management - Options to re-crypt and change password are enabled.

  5. Select Re-Encrypt Existing Passwords.

  6. Select Apply New Secure Key check box.

  7. In the Enter Current Argus Secure Key field, enter the existing Argus Insight Secure Key.

  8. In the Enter New Argus Secure Key field, enter the new Argus Insight Secure Key from the Argus Safety Server.

    You may copy UserCryptoKey from the ArgusSecureKey.ini file, which is present on all Argus Safety Servers in C:\Windows folder. Make sure you use the exact key used by the corresponding Argus Safety Server.

  9. Enter justification.

  10. Click Execute to start the password regeneration process.

    When the password regeneration process completes, the status of the regeneration process (success or fail) appears.

  11. Click Reset to enable the Execute button again.

11.2 Updating the Cryptography Key and Change Password

To change all Argus Insight related passwords you can use Key Management Tool. You can change password with the existing cryptography key or use the new cryptography key. If the new cryptography key is used then the same key will be updated in ArgusSecureKey.ini.

To change the cryptography key and change passwords:

  1. Log in to the Argus Insight client.

  2. Click Start.

  3. Navigate to Programs > Oracle > Argus Insight, and then select Cryptography Key Management.

    Or, go to: C\Program Files (x86)\Oracle\ArgusInsight\Bin

    The Argus Insight Key Management screen appears.

  4. Enter the following parameters and click Validate.

    1. DBA user name

    2. DBA user password

    3. Argus Insight database name

    After successful authentication, the Argus Insight Key Management - Options to re-crypt and change password are enabled.

  5. Select Change Passwords.

  6. To change the cryptographic key, select Apply New Secure Key check box.

  7. In the Enter Current Argus Secure Key field, enter the existing Argus Insight Secure Key.

  8. In the Enter New Argus Secure Key field, enter the new Argus Insight Secure Key from the Argus Safety Server.

    You may copy UserCryptoKey from the ArgusSecureKey.ini file, which is present on all Argus Safety Servers in C:\Windows folder. Make sure you use the exact key used by the corresponding Argus Safety Server.

  9. Enter the Argus Insight Application User Password (deselect this options if you do not want to change password).

  10. Enter APR_USER password (deselect this option if you do not want to change password in the AI.INI).

  11. Enter the password for Argus Mart application users.

    If Argus Mart is not configured then this section will be disabled.

    • You can provide individual password for all enterprises.

    • To set same password for all the enterprises, select Set same Password for all enterprise.

    • Deselect the check box for which enterprise you do not want to change password.

    • Deselect all the check boxes if you do not want to change Argus Mart password.

  12. Enter justification.

  13. Click Execute to start the password change process.

    When the password change process completes, the status of the process (success or fail) appears.

  14. Click Reset to enable the Execute button again.

11.3 Copying Initialization Files to Other Servers

After you change the cryptography key using the Key Management tool, you must manually copy the AI.ini and Argus SecureKey.ini initialization files from the C:\Windows folder of the Argus Insight Web Server to the following folders:

  • C:\Windows of all Cognos Servers

  • C:\Windows of all Argus Insight Web Servers

You must copy the AI.ini and Argus SecureKey.ini files to keep the cryptography key and the APR_USER password in sync on all the servers. In case these files are not copied, the Cognos Server or any other Argus Insight Web Server will not function.

11.4 Restarting IIS and Running ETL

After you change the cryptography key, you must complete the following steps on the Argus Insight Web Server to reflect the changes:

  1. Restart the Internet Information Services (IIS).

  2. Run the incremental ETL.