ActivCERT

Update ActivCERT

Check compatibility before an update

Read the supplied release information and verify the approved package identity and license eligibility. Keep all runtime programs and CACERT from one package. Validate any replacement license before installing it.

The current datastore format is schema 2. A schema-1 datastore cannot be opened by the current programs and requires fresh initialization. There is no schema-1-to-schema-2 datastore migration procedure. Restoring old files does not convert their schema. Plan to recreate configuration and re-adopt or issue certificates using the documented procedures. Preserve the old complete datastore and installation under site-approved backup controls before an approved replacement. Do not initialize or delete an installation merely to test compatibility.

Prepare and verify the replacement installation

  1. Record the installed version, datastore location, monitor startup command, license location and relevant configuration. Arrange a maintenance window and a transactionally consistent backup of the complete datastore.

  2. Drain and stop CERTMON using the shutdown procedure. Confirm all processes using the datastore have stopped.

  3. Install the complete approved package into a new empty program subvolume using Install ActivCERT. Install and validate the eligible signed license separately. Retain the previous installation for the site-approved recovery plan.

  4. Validate the datastore with the new CERTCOM before starting CERTMON. For an incompatible schema, arrange an explicitly approved new datastore and recreate its configuration; follow datastore creation.

  5. Start the new CERTMON installation with the intended datastore and logging options. Confirm monitor, backup and scheduler state, and inspect tasks, certificates and targets. Resume scheduled processing only when ready.

  6. Verify a representative deployment and the consuming application before accepting the update. Keep backups until the site recovery policy permits their removal.

For recovery, stop all users of the datastore and follow the restore procedure. Use programs compatible with the restored datastore schema. Do not combine files from different datastores or program packages.