See below for how to upgrade your installation to Cryptographic Security Platform 1.1.0. 

Upgrade requirements

Upgrading to Cryptographic Security Platform 1.1.0 requires the following installation. 

Version

Installation mode

Cryptographic Security Platform 1.0.0

prod_mode

If you have a previous version, upgrade it to Cryptographic Security Platform 1.0.0 as explained in section Upgrading of the Cryptographic Security Platform 1.0.0 guide.

If the Validation Authority or Timestamp Authority solutions are already deployed in the upgraded installation, ensure the value of the following parameter equals or exceeds 4096.

Solution

Parameter

Section

​Validation authority

​Max header bytes

OCSP Responder-Server

Timestamping Authority

Max header bytes

Tsa Server

Upgrade process

See below for how to run the upgrade process.

To upgrade Cryptographic Security Platform 1.0.0 to 1.1.0

  1. Follow the steps in Downloading the installation files to download the PKI Hub 1.2.0 for VMWare vSphere, Hyper-V and Nutanix file. You need this ISO image file to upgrade any installation, ISO-based or non-ISO-based. ​
  2. Backup the installation state as explained in section Backing up of the Cryptographic Security Platform 1.0.0 guide.

  3. Repeat the following steps on each Cryptographic Security Platform node. 
    1. Use an SFTP client to copy the Cryptographic Security Platform ISO image file to the /home/sysadmin node folder. 
    2. Run the clusterctl upgrade command and wait until completion (around 2 hours).
  4. Reboot each node sequentially, with at least 15 minutes before each reboot.
  5. Back up the installation state as explained in section Backing up of this guide.

Supported commands during the upgrade

During the upgrade process or while fixing a failed upgrade, you can only run the following commands (or equivalent Management Console operations)