Trusted credentials

Trusted credentials are used for users who must perform a task or process, but do not have sufficient access permissions for entries that contain sensitive data, such as database signons and group memberships. Users with more extensive access permissions, who own the entries, can authorize a trusted user to use their credentials to access the entries.

Trusted credentials are also used to run scheduled requests when users are not logged on to IBM® Cognos® software, for example, overnight. When the request runs, a user session is created. The trusted credential is used to log on to IBM Cognos software as the user the trusted credential represents and the user's access permissions are used to run the report or the job.

Trusted credentials can consist of one or more credential pairings (user ID and password). The number of trusted credentials depends on the number of namespaces you log in to during your session, when you create or renew your credentials. The account that the trusted credentials is applied to is the first namespace you log into for that session, also known as the primary namespace.

Trusted credentials are stored as part of the account object in the namespace.

By default, trusted credentials are automatically renewed once a day. An administrator can change the default renewal frequency by specifying the expiryRenewedTC property in IBM Cognos Configuration, under Security > Authentication > Advanced properties. Only integers, which represent number of days, can be used as values for this property. The minimum value is 1.

If you change your password during the day after your credentials are automatically renewed in a Cognos Analytics session, you must renew them manually to prevent any schedules that are using the credentials from failing later in the day. For example, you log in to Cognos Analytics in the morning. The automatic renewal happens. In the afternoon, you change your password and log into Cognos Analytics again. The automatic renewal already took place in that 24 hour period, so it will not happen again until the next renewal period. In this case you must renew manually to ensure any schedules later that day do not fail.