Pre-12.5 systems stored private key and certificate data in a key store called smkeydatabase. This data now resides in the certificate data store, which is colocated with the data store. The certificate data store is replacing the requirement that each federation system in the environment access a local smkeydatabase.
As part of the upgrade, the installer automatically backs up the local smkeydatabase and tries to migrate all content to the certificate data store. This process compares the smkeydatabase and CDS before starting the migration. The purpose of the comparison is to identify data inconsistencies, such as the same alias mapping to different certificates, that can prevent a successful migration.
In a cluster environment, there are multiple instances of the smkeydatabase. Before you upgrade or migrate to 12.52, synchronize all smkeydatabase instances so that the information is consistent. Synchronizing the databases helps ensure that no inconsistencies arise as each instance is migrated to the CDS.
Resolve all data inconsistencies between smkeydatabase instances from the Certs and Keys tab in the Administrative UI. Confirm that the following data is consistent across key database instances:
Important! After you resolve all data inconsistencies, do not make any further changes to the smkeydatabase instances until all migrations are complete
|
Copyright © 2013 CA.
All rights reserved.
|
|