nodetool createsystemkey

Synopsis

nodetool createsystemkey cipher_algorithm length filename
cipher_algorithm[/mode/padding]

HCD supports the following JCE cipher algorithms:

  • AES/CBC/PKCS5Padding (default with length 128): valid with length 128, 192, or 256

  • AES/ECB/PKCS5Padding: valid with length 128, 192, or 256

  • DES/CBC/PKCS5Padding: valid with length 56

  • DESede/CBC/PKCS5Padding: valid with length 112 or 168

  • Blowfish/CBC/PKCS5Padding: valid with length 32-448

  • RC2/CBC/PKCS5Padding: valid with length 40-128

-d directory, --directory directory

Key file output directory. Enables creating key files before HCD is installed. This option is typically used by IT automation tools like Ansible. When no directory is specified, keys are saved to the default system key directory.

length

Key length in bits. For example, 128, 192, 256. Required if cipher_algorithm is specified. Key length is not required for HMAC algorithms. Default value: 128 (with the default cipher algorithm AES/CBC/PKCS5Padding)

filename

Optional. The filename for the generated system key file. When no filename is specified, the default file name is system_key.

Example

To create a local key file

This creates a system key with the default filename system_key:

nodetool createsystemkey 'AES/ECB/PKCS5Padding' 128
To create a key file with a specific name

This creates a system key with the specified filename:

nodetool createsystemkey 'AES/ECB/PKCS5Padding' 128 my_key
To create a key file in a specific directory

This creates a system key with the specified filename in the specified directory:

nodetool createsystemkey 'AES/ECB/PKCS5Padding' 128 my_key -d /mydir

Was this helpful?

Give Feedback

How can we improve the documentation?

© Copyright IBM Corporation 2026 | Privacy policy | Terms of use |  Manage Privacy Choices

Apache, Apache Cassandra, Cassandra, Apache Tomcat, Tomcat, Apache Lucene, Apache Solr, Apache Hadoop, Hadoop, Apache Pulsar, Pulsar, Apache Spark, Spark, Apache TinkerPop, TinkerPop, Apache Kafka and Kafka are either registered trademarks or trademarks of the Apache Software Foundation or its subsidiaries in Canada, the United States and/or other countries. Kubernetes is the registered trademark of the Linux Foundation.

General Inquiries: Contact IBM