RSA KMS upgrade overview

Prior to beginning the upgrade, you must determine the maintenance period in which you will perform the upgrade and verify the source RSA KMS system is currently working.

Definitions

Source and target system refers to a specific RSA KMS system.

System

Description

Source

RSA KMS version 2.7.1

Or

RSA KMS version 3.2.1

Target

RSA KMS version 3.5.2

The upgrade process supports RSA KMS systems with the SQL Server database on and off the servers hosting the RSA KMS application.

Changing Authentication mode

The authentication mode can be changed as part of the upgrade procedure. See Related topics for a link to the steps.

RSA KMS clients

The KMS clients are not impacted by the upgrade. You do not need to upgrade the RSA KMS clients.

RSA KMS port and Secured gateway

  • The RSA KMS ports are not changed as a result of the upgrade.

  • The RSA KMS does not utilize the Secured gateway.

Downtime

You must complete the entire upgrade in a single downtime. During the downtime, you must reboot the RSA KMS.

Order in which to upgrade data center servers

The RSA KMS software must be upgraded to the target RSA KMS version before the other data center servers are upgraded to a higher version.

RSA KMS running version 2.0.1

If the RSA KMS is currently running version 2.0.1, you must first migrate your RSA KMS to version 2.7.1, and then upgrade to the target version.

Upgrade and migration overview

Update KMC certificates on the upgraded RSA KMS

Workflow: Configure mixed mode authentication