IBM Cognos TM1 ships with a digital certificate called an SSL (“secure Socket Layer”) certificate that is used to securely encrypt communication between the TM1 server and its web and non-web (TM1 Perspectives and TM1 Architect) clients. It’s basically a set of files that sit on the TM1 server. These certificates have expiration dates and it was recently realized that the one that ships with TM1 will expire on November 24, 2016 causing any TM1 server using the certificate to stop communicating with its clients. In other words: TM1 will STOP WORKING unless the certificate files are replaced.
This is an important issue that will affect ALL TM1 INSTALLATIONS AND VERSIONS.
Solution options are provided below. For more information on QueBit TM1 services see:
TM1 may stop working on November 24, 2016, unless you have already taken action
We believe that this will affect most QueBIT customers.
An issue has been discovered within the 1024-bit SSL Certificate used by TM1 for communication within the application (e.g. Admin Server) and to the client tools (e.g. Perspectives). This issue is that the SSL Certificate IBM shipped with the TM1 Software will expire at midnight on 11/24/2016 and IBM has not done a good enough job of communicating this critical issue to customers.
The issue lies in the default use of the 1024-bit SSL Certificate shipped with the IBM Cognos TM1 that is set to expire on 11/24/2016 and is one that every IBM Cognos TM1 customer will have to deal with as it is a software configuration issue rather than a software bug that could be fixed via a software patch.
The potential impact of the 1024-bit SSL Certificate expiring is that the TM1 Instance will stop work once the Default SSL Certificate has expired and may result in data loss.
There are solutions, and QueBIT is here to help if you need it!
If you took the step earlier of installing your own SSL certificates in order to secure your web communication with the TM1 server, you may be OK, but we would still recommend that you verify that the certificates in use for Perspectives client communication were also updated as part of that process.
If you are part of the majority of our customers who have not changed anything, and are still using the default set of 1024-bit SSL certificates that shipped with the product, you must take action in order for TM1 to continue to work after November 24, 2016:
Here are the options:
Note: Merely upgrading TM1 to v10.2.2 or installing a Fix Pack will not fix this issue as it is not an application code issue, but instead an application configuration issue.
More Information
Please do not hesitate to reach out to your friends at QueBIT at support@quebit.com for more information on this issue, and to make a plan to address it. If you have been thinking about upgrading TM1 for a while, there is still time to get it done, and QueBIT is available to help!
The following link to the IBM Knowledge Center will provide you all the information necessary to learn more about how TM1 can use/uses SSL and how to configure TM1 to use SSL were permitted.
Using SSL for data transmission security in TM1