PKI Hub supports the following version upgrades.

Upgrade from version

To version

Upgrading guide

Entrust Deployment Manager 2.0.2

Cryptographic Security Platform 1.0.0 - PKI Hub 1.1.0

https://api.managed.entrust.com/pki/1.0/Upgrading.html

Cryptographic Security Platform 1.0.0 - PKI Hub 1.1.0

Cryptographic Security Platform 1.1.0 - PKI Hub 1.2.0 

https://api.managed.entrust.com/pki/1.1/Upgrading.html

Cryptographic Security Platform 1.1.0 - PKI Hub 1.2.0

Cryptographic Security Platform 1.2.1 - PKI Hub 1.3.1

See sections below

Configuring the solutions

If the Validation Authority or Timestamp Authority solutions are already deployed in the upgraded installation, ensure that the value of the following parameter is at least 4096.

Solution

Parameter

Section

​Validation authority

​Max header bytes

OCSP Responder-Server

Timestamping Authority

Max header bytes

Tsa Server

Upgrade process

See below for how to run the upgrade process.

To upgrade to CSP 1.2.1 PKI Hub 1.3.1

  1. Follow the steps in Downloading the installation files to download the following file: 

     Cryptographic Security Platform 1.2.1 - PKI Hub 1.3.1 for VMware vSphere, Hyper-V, and Nutanix. ​

    You need this ISO image file to upgrade any installation, ISO-based or non-ISO-based. ​

  2. Back up the installation state as explained in the CSP 1.1.0 PKI Hub 1.2.0 guide:
    https://api.managed.entrust.com/pki/1.1/Backing-up-PKI-Hub.html

  3. Repeat the following steps sequentially on each PKI Hub node, ensuring they are not performed simultaneously on multiple nodes. 
    1. Using an SFTP client, upload the PKI Hub ISO image file to the /home/sysadmin folder. 
    2. Run the clusterctl upgrade command and wait for it to complete (around 2 hours) before proceeding to the next node.
  4. Reboot each node sequentially, allowing at least 15 minutes between reboots.
  5. Back up the installation state as explained in Backing up the PKI Hub state.