If your Cryptographic Security Platform Vault nodes are running version 10.4.3 or later, you can use the Cryptographic Security Platform Vault Management webGUI to upgrade any node in the cluster and Cryptographic Security Platform Vault will automatically upgrade the other nodes one at a time until all nodes have been upgraded. By doing sequential upgrades, Cryptographic Security Platform Vault ensures that at least one node in the cluster remains available during the entire upgrade process.
Important: If you are using HSM Root-of-Trust mode with password, you must enter the password on each node during upgrade.
You can use this procedure for all installations of Cryptographic Security Platform Vault, including AWS, Azure, and GCP.
Note: Any new features in the Cryptographic Security Platform Vault release will not be available until all nodes in the cluster have been upgraded.
Before You Begin
- Make sure that the Cryptographic Security Platform Vault nodes can communicate with one another on port
TCP/8443andTCP/5432. For details, see Network requirements. - Entrust recommends that you back up your Cryptographic Security Platform Vault cluster before you upgrade it. For details, see Backing Up CSP Vault Through the webGUI
- Please download your Admin Key and store it in a safe place before you upgrade. If Cryptographic Security Platform Vault prompts for an admin key to recover your Cryptographic Security Platform Vault system, you must provide this admin key to proceed. If you do not have your admin key, you may lose your data. For details, see Downloading Your Admin Key Part.
- We recommend that you enable the support login on all cluster nodes before you start the upgrade. For details, see Enabling or Disabling the Support Login .
- Make sure your internet connection to the Cryptographic Security Platform Vault node is as fast and as stable as possible. To begin the upgrade, you need to upload the upgrade ISO image to the Cryptographic Security Platform Vault node in one continuous session. If the upload times out or if connectivity to the Cryptographic Security Platform Vault node is lost during the upload, you will see error messages in Cryptographic Security Platform Vault and you must re-upload the file from scratch. Cryptographic Security Platform Vault cannot resume the upload from where it left off during a previous session.
Procedure
Sign on to the Cryptographic Security Platform Vault Management webGUI with Domain and Security Admin privileges.
In the top right, click the Appliance Management link.
- In the top menu bar, click Cluster and make sure the Status of the cluster is Healthy. If it is not, you must resolve those issues before you can upgrade the cluster.
- In the top menu bar, click Settings.
- In the System Settings section, click System Upgrade.
Click Browse, navigate to the Entrust ISO upgrade file, and click Open.
Important: Cryptographic Security Platform Vault now has separate ISO files for installation and upgrade. Please ensure that you use the ISO upgrade file.
Click Upload File. If the Upload File button is not active, make sure that you have selected an ISO file and that the cluster is healthy.
After Cryptographic Security Platform Vault uploads and validates the ISO file, Cryptographic Security Platform Vault begins the automatic upgrade process by copying the ISO file from the current node to all of the other Cryptographic Security Platform Vault nodes in the cluster. After the ISO file has been copied, Cryptographic Security Platform Vault displays a Success message. Click Close to continue with the upgrade.
Cryptographic Security Platform Vault displays a status message stating that the upgrade is in process along with a Cancel Upgrade button in case you want to stop the process.
During this time you can continue to use Cryptographic Security Platform Vault as normal, including changing all configuration options and adding or removing VMs. When Cryptographic Security Platform Vault is ready to upgrade all nodes in the cluster, it displays the Finish Upgrade button.
Click Finish Upgrade.
Note: Ensure you are still on the same node where you clicked Upgrade File.
Cryptographic Security Platform Vault displays a message stating that the cluster will be put into maintenance mode during this procedure and that all nodes will be rebooted. While in maintenance mode, Cryptographic Security Platform Vault can still service key requests from the registered VMs, but no Cryptographic Security Platform Vault configuration changes can be made and no new VMs can be added.
Click Proceed.
Cryptographic Security Platform Vault displays a status message stating that the cluster nodes are being rebooted. It may take a while for this process to run on all nodes except for the current node. When all of the other nodes have been upgraded and are back online, Cryptographic Security Platform Vault reboots the current node to finish the upgrade process on that node. At this point, you will be automatically logged out of the Cryptographic Security Platform Vault Management webGUI on that node. You can monitor the progress on the Cryptographic Security Platform Vault Management webGUI of the other nodes. This again may take a while to complete.
When any node is being upgraded, if you have access to the Cryptographic Security Platform Vault System Console, you can view the upgrade messages.
Note: When Cryptographic Security Platform Vault reboots the current node, you may see a message that the application cannot connect to the server, then browser page may display a "connection refused" message. Wait a few moments for the node to finish rebooting, then refresh your browser page. You should see the Cryptographic Security Platform Vault Login page.
Beginning with 10.2, Cryptographic Security Platform Vault has changed the login experience. You can now switch between the Cryptographic Security Platform Vault Management webGUI and the Cryptographic Security Platform Vault Appliance Management webGUI in the same browser with one login. When you log in, click the Switch to Appliance Management link at the top right side of the web page to switch.
To verify the upgrade, return to Settings > System Upgrade and verify the settings for Current Version and Previous Version.