What's new in this release

IBM® Security Key Lifecycle Manager provides a centralized and automated key management solution to protect keys that are used for encryption. With the new set of features and enhancements, IBM Security Key Lifecycle Manager version 4.0 offers improved key management capabilities for the key management infrastructure to protect data.

Installation, upgrade, migration enhancement
IBM Security Key Lifecycle Manager processes now run under a non-administrator or non-root user account even when you install the product under an administrator or root user account. For more information, see Validating services, ports, and processes.
New REST-based key management and serving
Cloud applications or clients that need to use keys and other cryptographic objects from IBM Security Key Lifecycle Manager can now use REST APIs to communicate with the IBM Security Key Lifecycle Manager server. For more information, see Using REST APIs to manage and serve keys, certificates, and other cryptographic objects.
Improved replication performance
IBM Security Key Lifecycle Manager now supports incremental replication.
When the frequency of cryptographic object generation is high, you can use incremental replication so that the clone servers contain almost up-to-date data. For more information, see Configuring replication.
Enhanced support for storage systems
Support for PEER-TO-PEER and DS8000® TCT storage systems is now enhanced. For more information, see Managing and serving keys, certificates, and other cryptographic objects.
Enhancements to the Multi-Master feature
Graphical user interface (GUI) enhancements
Enhanced administration
Support to archive served key data
You can now archive the transactional data of keys that are served to clients.

For more information, see Archiving transactional data of keys served to clients.

Simplified process to update the Db2® password in IBM Security Key Lifecycle Manager
The procedures to update the Db2 password for a stand-alone IBM Security Key Lifecycle Manager server and a Multi-Master cluster are now simplified.

For more information, see Updating Db2 password for a stand-alone IBM Security Key Lifecycle Manager server and Updating Db2 password for IBM Security Key Lifecycle Manager Multi-Master cluster.

Interactive and easy-to-use REST API console
Swagger UI is now integrated with IBM Security Key Lifecycle Manager, and you can use it to call any REST API.
For more information, see Using Swagger UI.
Enhanced support for KMIP profile
IBM Security Key Lifecycle Manager now includes enhanced support for Key Management Interoperability Protocol (KMIP) 2.0 profile.
For more information, see Using KMIP to manage and serve keys, certificates, and other cryptographic objects.