Previous Topic: Maintain Session Stores for Single Sign-on in a Mixed Environment

Next Topic: Netegrity SNMP Agent Compatibility MIB Overview

Maintain Key Stores for Single Sign-on During Upgrade

You are not required to upgrade to a 6.x key store. 5.x key stores are compatible with 6.x Policy Servers, and you can configure the 6.x Policy Server to use a 5.x key store to maintain single sign-on as you upgrade to 6.x. As a result, you can either:

To maintain 5.x key stores for single sign-on during the upgrade

  1. Open the 6.x Policy Server Management Console.

    Important! If you are accessing this graphical user interface on Windows Server 2008, open the shortcut with Administrator permissions, even if you are logged into the system as an Administrator. For more information, see the release notes for your SiteMinder component.

  2. Select the Data tab of the Console and configure the 6.x Policy Server to use the 5.x key store.

    The 5.x key store referenced by the 6.x Policy Server can be located in the 5.x policy store or in a separate key store.

  3. Clear the Use Policy Store database check box so the 6.x Policy Server does not try to use its own policy store as the key store.
  4. Select the Keys tab and clear the Enable Agent Key Generation check box.

The following figure illustrates how to use 5.x key and policy stores with a 6.x Policy Server to maintain single sign-on.

5x key store for single sign on

Note: For more information about static and dynamic keys and configuring Policy Servers to use specific key stores, see the Policy Server Management guide.

To create a new 6.x static key store that contains the 5.x key data

  1. Export the 5.x key store using the smobjexport tool.

    The 5.x key store that you export can be located in the 5.x policy store or in a separate key store.

  2. Import the 5.x key store to a 6.x key store or enter the same key value for the 5.x and 6.x Policy Servers.

    Enter static keys using the Manage Keys option in the 6.x Policy Server User Interface.

  3. Open the 6.x Policy Server Management Console, select the Data tab, and configure the 6.x Policy Server to use the new 6.x key store.

    Important! If you are accessing this graphical user interface on Windows Server 2008, open the shortcut with Administrator permissions, even if you are logged into the system as an Administrator. For more information, see the release notes for your SiteMinder component.

    The 6.x key store can be an independent store or with the policy store.

The following figure illustrates how to upgrade static keys to maintain single sign-on.

SM--5x to 6x static key store for single sign on

To create a new 6.x dynamic key store that contains the 5.x key data

  1. Export the 5.x key store using the smobjexport tool.

    The 5.x key store that you export can be located in the 5.x policy store or in a separate key store.

  2. Import the 5.x key store to a 6.x key store or enter the same key value for the 5.x and 6.x Policy Servers.

    Enter dynamic keys using the Manage Keys option in the 6.x Policy Server User Interface.

  3. Open the 6.x Policy Server Management Console, select the Data tab, and configure the 6.x Policy Server to use the new 6.x key store.

    Important! If you are accessing this graphical user interface on Windows Server 2008, open the shortcut with Administrator permissions, even if you are logged into the system as an Administrator. For more information, see the release notes for your SiteMinder component.

    The 6.x key store can be an independent store or with the policy store.

The following figure illustrates how to upgrade dynamic keys to maintain single sign-on.

SM--5x to 6x key store upgrade for single sign on

Important! To maintain single sign–on in this type of environment, each time the 5.x keys are generated, manually import the 5.x keys into the 6.x key store or single sign–on fails.

Note: For more information about static and dynamic keys and configuring Policy Servers to use specific key stores, see the Policy Server Management guide.