Security

 View Only
  • 1.  CPPM migration to 6.11 - licensing

    Posted Feb 17, 2025 05:51 AM

    Hi team

    Existing Cluster of CPPM 6.10 and we will migrate them to 6.11

    Already have 2 new VM's with 6.11.10 and all the configuration , Certificates and licenses restored from the "production CPPM"

    at the end of the week we are going to stop the current CPPM and change the new CPPM IP's to match the old ones

    we have all prepared , and a tac openned with licensing team.

    My only dought here is, can we activate the licenses on the new ones ( offline with tac, since CPPM does not have internet access) before the migration ? 

    Without affecting the production ones?

    Regards



  • 2.  RE: CPPM migration to 6.11 - licensing

    Posted Feb 17, 2025 06:01 AM
    Edited by shpat Feb 17, 2025 06:02 AM

    Why don't you activate firstly some Trial Licenses, test the platform for a few days and then initiate a License Migration with TAC using Offline activation?

    So you will have the old system having your licenses, the new system having trial licenses and being tested.

    If all goes well, you transfer license from old system to new one and then shut down the old platform.

    With this, nothing will be affected. 



    ------------------------------
    Shpat | ACEP | ACMP | ACCP | ACDP
    Just an Aruba enthusiast and contributor by cases
    If you find my comment helpful, KUDOS are appreciated.
    ------------------------------



  • 3.  RE: CPPM migration to 6.11 - licensing

    Posted Feb 17, 2025 06:19 AM

    Hi

    Activating the license for 6.11 will not affect the 6.10 servers in any aspect.

    Keep in mind that changing the IP addresses of ClearPass servers will make the database certificate invalid. From 6.11 the server will generate a new database certificate with the new IP address, if the database certificate is a self signed certificate. If it's signed by a CA it must be replaced manually. The generation of a new database certificate can take some time before it has taken effect.

    Also changing IP address may cause the cluster replication to stop, and you may need to join the subscriber again to the cluster.



    ------------------------------
    Best Regards
    Jonas Hammarbäck
    MVP Guru, ACEX, ACDX #1600, ACCX #1335, ACX-Network Security, Aruba SME, ACMP, ACSA
    Aranya AB
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------



  • 4.  RE: CPPM migration to 6.11 - licensing

    Posted Feb 17, 2025 06:45 AM

    Hi Thanks 

    are you talking HTTPS certificates or database ones?




  • 5.  RE: CPPM migration to 6.11 - licensing

    Posted Feb 17, 2025 06:48 AM
    This case it would be Database.

    ---------------------------------
    Shpat | ACEP | ACMP | ACCP | ACDP
    Just an Aruba enthusiast and contributor by cases
    If you find my comment helpful, KUDOS are appreciated.
    ---------------------------------





  • 6.  RE: CPPM migration to 6.11 - licensing

    Posted Feb 18, 2025 10:39 AM
    Edited by MFollmer Feb 18, 2025 10:45 AM

    As was mentioned, activating the licenses on the 6.11 systems will not effect the 6.10 cluster, and since so many upgrades are taking place lately, they have made is so that TAC is not required to reactivate. 

    Before taking the final TIPS backup from your 6.10 publisher to be restored to the 6.11 publisher, be sure to disable Standby publisher if configured in 6.10.  Also, any self-signed certificates on the 6.11 nodes will need to be updated since their IP address is included as a SAN name, and the HTTPS(ECC) cert should likely be disabled.  As others have stated, changing the IP would require that you reform the cluster, so for that reason you wouldn't want to join the 6.11 subscriber until after the IPs have been updated.

    Once the 6.11 cluster is formed, server specific settings on the publisher and subscriber will need to be configured to match those in 6.10, including any non-default service parameters, and re-enabling the VIP if present. 

    Another consideration is, if you had purchased a custom skin from Aruba, that is tied to your HPe/Passport account, so you would want to be sure to generate a token in Software Updates with the associated account, and install the custom skin before restoring the TIPs configuration and forming the 6.11 cluster.  Failure to do so will change any guest pages using the custom skin to one of the built-in skins.




  • 7.  RE: CPPM migration to 6.11 - licensing

    Posted 30 days ago

    Hi all

    Migration completed on both appliances

    used same IP's , only one small issue joining domain , we needed to use a admin account , and where using a domain user account only.

    After that promote the node 2 to subscriber , created the VIP and all is ok

    Thanks for support