
USArmy49180 (Customer) asked a question.
RSA Community,
I am trying to figure out what the best method of standing up two new instances of RSA Security Console (x1 Primary & x1 Replica) and replace our current setup (x1 Primary & x1 Replica). Is it better to create a back up of the old current database and configs, then restore it on to the newly built instance? Or is it better to add the newly built instance to the existing group, then promote it as the primary and from there create another replica, then tear down the old 2 instances?
@USArmy49180 (Customer) ,
There are several things to consider when standing up new servers and promoting one to primary.
At what version of software did your current Authentication Manager deployment start?
I ask because if your servers started at Authentication Manager 8.5 or earlier, we recommend replacing those servers. We also need to know if you have a base license, allowing a primary and one replica or an enterprise license allowing up to 15 replicas. You can find this information in the Security Console by navigating to Setup > License > Manage Existing, clicking on the View Installed Licenses button and then clicking on the context arrow for one of the LID number that you see.
A quick overview of the upgrade process (not all steps may apply):
NOTES:
Are the current servers hardware appliances or running on a virtual platform?
We have seen an issue where if you try to apply Authentication Manager 8.7 SP1 to a hardware appliance that started before Authentication Manager 8.7 SP1 that you could run into a GRUB issue from which you cannot recover the server. In this case, we recommend using virtual servers to upgrade. If your installation requires the use of hardware appliances you can then factory reset the hardware appliance as a replica server running 8.7 SP1 or 8.7 SP2 then attach it to your primary.
If you have additional questions, please post here or open a support case to have a TSE assist with any further questions.
@EricaChalfin (RSA)
Thank you for your response. We are currently on 8.7 SP 1. I've also check our license and it seems to be a base license (Authentication Manager Base). I guess this means that I am tied down to a max of 1 primary and 1 replica. Would getting rid of our existing replica and creating a replica of new instance work out? This will ensure that we stay within the threshold of 2 instances.