Red_Hat_Certificate_System-8.1-Migration_Guide-en-US.pdf

(1028 KB) Pobierz
Red Hat Certificate System 8.1 Migration Guide
1
Red Hat Certificate System
8.1
Migration Guide
Migrating from 7.x to 8.1 and upgrading 8.0 to 8.1
Edition 1
Matthew Harmsen
Ade Lee
Edited by
Ella Deon Lackey
dlackey@redhat.com
2
Legal Notice
Legal Notice
Copyright © 2012 Red Hat, Inc..
T he text of and illustrations in this document are licensed by Red Hat under a Creative Commons
Attribution–Share Alike 3.0 Unported license ("CC-BY-SA"). An explanation of CC-BY-SA is available at
http://creativecommons.org/licenses/by-sa/3.0/.
In accordance with CC-BY-SA, if you distribute this
document or an adaptation of it, you must provide the URL for the original version.
Red Hat, as the licensor of this document, waives the right to enforce, and agrees not to assert, Section
4d of CC-BY-SA to the fullest extent permitted by applicable law.
Red Hat, Red Hat Enterprise Linux, the Shadowman logo, JBoss, MetaMatrix, Fedora, the Infinity Logo,
and RHCE are trademarks of Red Hat, Inc., registered in the United States and other countries.
Linux® is the registered trademark of Linus T orvalds in the United States and other countries.
Java® is a registered trademark of Oracle and/or its affiliates.
XFS® is a trademark of Silicon Graphics International Corp. or its subsidiaries in the United States
and/or other countries.
MySQL® is a registered trademark of MySQL AB in the United States, the European Union and other
countries.
All other trademarks are the property of their respective owners.
1801 Varsity Drive
Raleigh, NC 27606-2072 USA
Phone: +1 919 754 3700
Phone: 888 733 4281
Fax: +1 919 754 3701
January 31, 2012
Red Hat Certificate System 8.1 Migration Guide
3
Abstract
T his migration guide provides the procedure to perform an in-place upgrade of 8.0 subsystems to 8.1.
T his guide also provides in-depth procedures to migrate subsystems, user information, and certificate
and key materials from Red Hat Certificate System 7.1, 7.2, and 7.3 to Red Hat Certificate System 8.1.
4
Table of Contents
Table of Contents
About T his Guide
1. About Upgrade and Migration
2. Recommended Knowledge
3. Examples and Formatting
3.1. Formatting for Examples and Commands
3.2. T ool Locations
3.3. Guide Formatting
4. Additional Reading
5. Giving Feedback
6. Document History
1. Upgrading 8.0 Subsystems
1.1. Requirements for Upgrade
1.2. Preparing for Upgrade
1.3. Upgrading the Directory Server Contents
1.3.1. Upgrading the Directory Server Contents
1.3.2. Restoring the Configuration After an Upgrade Failure
1.4. Upgrading UI Files
1.5. Upgrading Configuration Files
1.6. Restarting the Instance
1.7. Replacing the Audit Certificate
1.8. Creating a Shared Secret (for T KS and T PS Upgrades Only)
2. Introduction to Red Hat Certificate System Migration
2.1. Certificate System Migration Overview
2.1.1. Migration Scripts
2.1.2. Certificate System Subsystems
2.2. Considerations Before Migration
3. Setting up Certificate System 8.1 Subsystems
3.1. Installing New Certificate System Subsystem Instances
3.2. Default File and Directory Locations for Certificate System Subsystems
3.2.1. CA Instance Information
3.2.2. RA Instance Information
3.2.3. DRM Instance Information
3.2.4. OCSP Instance Information
3.2.5. T KS Instance Information
3.2.6. T PS Instance Information
3.2.7. Shared Certificate System Subsystem File Locations
4. Migrating a CA Instance to Certificate System 8.1
4.1. Flush the Request Queue
4.2. Migrating the Security Databases
4.2.1. Option 1: Security Databases to Security Databases Migration
4.2.2. Option 2: Security Databases to HSM Migration
4.2.3. Option 3: HSM to Security Databases Migration
4.2.4. Option 4: HSM to HSM Migration
4.3. Migrating Subsystem Password Stores
4.3.1. Migrating Passwords from 7.1
4.3.2. Migrating Passwords from 7.2 and 7.3
4.3.3. Requiring System Password Prompts
4.4. Migrating the LDAP Database
4.5. Migrating Custom CS.cfg Settings and Other Data
4.6. Replacing the Audit Signing Certificate
Red Hat Certificate System 8.1 Migration Guide
5
4.7. Restarting the CA Instance
4.8. Setting Custom Configuration in the Console
4.9. Verifying the CA Migration
5. Migrating an RA to 8.1
5.1. Dumping the 7.3 Databases
5.2. Preparing 7.3 Security Databases
5.3. Importing the 7.3 SQL Database Information into the 8.1 SQL Database
5.4. Migrating the 7.3 Security Databases to the 8.1 RA
5.5. Migrating Passwords
5.6. Migrating Custom Configuration
5.7. Restarting the RA Instance
5.8. Verifying the RA Migration
6. Migrating a DRM Instance to Certificate System 8.1
6.1. Migrating the Security Databases
6.1.1. Option 1: Security Databases to Security Databases Migration
6.1.2. Option 2: Security Databases to HSM Migration
6.1.3. Option 3: HSM to Security Databases Migration
6.1.4. Option 4: HSM to HSM Migration
6.2. Migrating Subsystem Password Stores
6.2.1. Migrating Passwords from 7.1
6.2.2. Migrating Passwords from 7.2 and 7.3
6.2.3. Requiring System Password Prompts
6.3. Migrating the LDAP Database
6.4. Migrating Custom CS.cfg and Other Data Settings
6.5. Creating a Subsystem Certificate (7.1 Only)
6.6. Replacing the Audit Signing Certificate
6.7. Restarting the DRM Instance
6.8. Setting Custom Configuration in the Console
6.9. Verifying the DRM Migration
7. Migrating a OCSP Instance to Certificate System 8.1
7.1. Migrating the Security Databases
7.1.1. Option 1: Security Databases to Security Databases Migration
7.1.2. Option 2: Security Databases to HSM Migration
7.1.3. Option 3: HSM to Security Databases Migration
7.1.4. Option 4: HSM to HSM Migration
7.2. Migrating Subsystem Password Stores
7.2.1. Migrating Passwords from 7.1
7.2.2. Migrating Passwords from 7.2 and 7.3
7.2.3. Requiring System Password Prompts
7.3. Migrating the LDAP Database
7.4. Migrating Custom Data and Settings
7.5. Replacing the Audit Signing Certificate
7.6. Restarting the OCSP Instance
7.7. Setting Custom Configuration in the Console
7.8. Verifying the OCSP Migration
8. Migrating a T KS Instance to Certificate System 8.1
8.1. Migrating the Security Databases
8.1.1. Option 1: Security Databases to Security Databases Migration
8.1.2. Option 2: Security Databases to HSM Migration
8.1.3. Option 3: HSM to Security Databases Migration
8.1.4. Option 4: HSM to HSM Migration
8.2. Migrating Subsystem Password Stores
8.2.1. Migrating Passwords from 7.1
Zgłoś jeśli naruszono regulamin