This section explains how to perform the following upgrade.
Upgrade from version | To version |
|---|---|
Cryptographic Security Platform 1.2.0 - PKI Hub 1.3.0 | Cryptographic Security Platform 1.4.2 - PKI Hub 1.5.1 |
Follow the steps below in the indicated order.
Because of the EDM-22093 known issue, you must migrate any network configuration set with NetworkManager tools such as nmcli or nmtui. See Known issues in PKI Hub for Cryptographic Security Platform 1.4.0 for details.
Creating the cluster database
You need a cluster database. As explained in Starting up the database, you can alternatively:
- Use a third-party DBMS (Database Management System) that meets the PKI Hub third-party database requirements. Either a new one or an existing one that already hosts databases for deployed solutions, such as Certificate Authority or Certificate Hub.
Do not merge tables from different solutions or from tables required by the product during installation into a single database, as each solution component requires its own database.
- Download and install PKI DB Appliance.
Running the upgrade process
Upgrade to Cryptographic Security Platform 1.4.2 - PKI Hub 1.5.1 as explained below.
To upgrade to CSP 1.4.2 - PKI Hub 1.5.1
- Follow the steps in Downloading the installation files to download the following file:
Cryptographic Security Platform 1.4.2 - PKI Hub 1.5.1 for VMware vSphere, Hyper-V and Nutanix
You need this ISO image file to upgrade any installation, ISO-based or non-ISO-based.
- Back up the installation state as explained in the "Backing up PKI Hub" section of the PKI Hub Guide for the version you are upgrading from.
- Repeat the following steps sequentially on each PKI Hub node; do not perform them simultaneously on multiple nodes.
- Use an SFTP client to copy the PKI Hub ISO image file to the
/home/sysadminnode folder. - Run the clusterctl upgrade command and wait for it to complete (around 2 hours) before proceeding to the next node.
- Use an SFTP client to copy the PKI Hub ISO image file to the
- Reboot each node sequentially, allowing at least 15 minutes between reboots.
- Back up the installation state as explained in section Backing up PKI Hub of this guide.
Reviewing user role changes
After completing the upgrade, users who previously held the following discontinued roles are assigned the new IdpRole.
- Manage Users
- Manage Roles
- Manage Identity Providers