Ce contenu n'est pas disponible dans la langue sélectionnée.
Chapter 21. Upgrading the Database
21.1. Upgrading the Database from 9.0 to 9.1 Copier lienLien copié sur presse-papiers!
Copier lienLien copié sur presse-papiers!
After you upgraded the packages and configuration files, you must manually upgrade the database schema and subsystem databases for every Certificate System instance.
21.1.1. Upgrading the Database Schema Copier lienLien copié sur presse-papiers!
Copier lienLien copié sur presse-papiers!
To upgrade the Certificate System database schema in Directory Server:
21.1.2. Upgrading the CA Database Copier lienLien copié sur presse-papiers!
Copier lienLien copié sur presse-papiers!
To upgrade the certificate authority (CA) database:
- Upgrade the container entries:
Copy to Clipboard Copied! Toggle word wrap Toggle overflow - Upgrade the access control list (ACL) entries:
Copy to Clipboard Copied! Toggle word wrap Toggle overflow - Upgrade the database indexes:
Copy to Clipboard Copied! Toggle word wrap Toggle overflow - Add the
realmattribute:Copy to Clipboard Copied! Toggle word wrap Toggle overflow - Remove the certificate validity delay:
- In the
/var/lib/pki/instance_name/ca/profiles/ca/caDualCert.cfgfile, set:policyset.signingCertSet.2.default.params.startTime=0
policyset.signingCertSet.2.default.params.startTime=0Copy to Clipboard Copied! Toggle word wrap Toggle overflow - In the
/var/lib/pki/instance_name/ca/profiles/ca/caECDualCert.cfgfile, set:policyset.signingCertSet.2.default.params.startTime=0
policyset.signingCertSet.2.default.params.startTime=0Copy to Clipboard Copied! Toggle word wrap Toggle overflow - In the
/var/lib/pki/instance_name/ca/profiles/ca/caDualCert.cfgfile, set:policyset.signingCertSet.2.default.params.startTime=0
policyset.signingCertSet.2.default.params.startTime=0Copy to Clipboard Copied! Toggle word wrap Toggle overflow - In the
/var/lib/pki/instance_name/ca/profiles/ca/caJarSigningCert.cfgfile, set:policyset.caJarSigningSet.2.default.params.startTime=0
policyset.caJarSigningSet.2.default.params.startTime=0Copy to Clipboard Copied! Toggle word wrap Toggle overflow - In the
/var/lib/pki/instance_name/ca/profiles/ca/caSignedLogCert.cfgfile, set:policyset.caLogSigningSet.2.default.params.startTime=0
policyset.caLogSigningSet.2.default.params.startTime=0Copy to Clipboard Copied! Toggle word wrap Toggle overflow
- Add the
issuerNameattribute to certificate records:pki-server db-upgrade
# pki-server db-upgradeCopy to Clipboard Copied! Toggle word wrap Toggle overflow - Update the attribute syntax to allow underscores in instance names:
Copy to Clipboard Copied! Toggle word wrap Toggle overflow
21.1.3. Upgrading the KRA database Copier lienLien copié sur presse-papiers!
Copier lienLien copié sur presse-papiers!
To update the key recovery authority (KRA) database:
- Upgrade the database indexes:
Copy to Clipboard Copied! Toggle word wrap Toggle overflow - Add the
realmattribute:Copy to Clipboard Copied! Toggle word wrap Toggle overflow - Update and re-index the virtual list views (VLV):
- Delete the existing indexes:
pki-server kra-db-vlv-del -i CS_instance_name -D DS_bind_DN \ -w DS_bind_password# pki-server kra-db-vlv-del -i CS_instance_name -D DS_bind_DN \ -w DS_bind_passwordCopy to Clipboard Copied! Toggle word wrap Toggle overflow - Add the new indexes:
pki-server kra-db-vlv-add -i CS_instance_name -D DS_bind_DN \ -w DS_bind_password# pki-server kra-db-vlv-add -i CS_instance_name -D DS_bind_DN \ -w DS_bind_passwordCopy to Clipboard Copied! Toggle word wrap Toggle overflow - Restart the Directory Server instance:
systemctl restart dirsrv@DS_instance_name
# systemctl restart dirsrv@DS_instance_nameCopy to Clipboard Copied! Toggle word wrap Toggle overflow - Re-index the database:
pki-server kra-db-vlv-reindex -i CS_instance_name -D DS_bind_DN \ -w DS_bind_password# pki-server kra-db-vlv-reindex -i CS_instance_name -D DS_bind_DN \ -w DS_bind_passwordCopy to Clipboard Copied! Toggle word wrap Toggle overflow
21.1.4. Upgrading the TPS database Copier lienLien copié sur presse-papiers!
Copier lienLien copié sur presse-papiers!
The token processing system (TPS) was a technology preview in Certificate System 9.0. Therefore, upgrading the TPS from this version is not supported.