Symantec IGA

 View Only
  • 1.  Transfer PROV Roles data IM Upgrade.

    Posted Nov 05, 2019 09:56 AM

    ​Hello There,

    We are in the process of upgrading our CA infrastructure from IM 14.0 to IM 14.3 (parallel upgrade) and its using CA SSO R12.8 SP2. We are almost finished with this upgrade with our Corporate Store Users ( CA DIR 14.0) and the PROV DIR working (CA DIR 14.0 as well).

    How can we make sure the PROV ROLES, including the default birth right role that creates the user identity in the PROV DIR ( PROV MANAGER) be given to the users profile? Is there any other way then BULKLOAD process with CSV that we are missing here in our upgrade that can automatically populate the data from OLD CA DIR 12.6 to new environment in case of PROV DIR ( PROV MANAGER). The question here is important because we have our custom ESB connector that will initiate all these transactions if we use Bulk Load method and its hard to gather all the information for all the users in CSV and BULK LOAD all these users with required PROV ROLES that will initiate the User Provisioning method towards the connector and the Endpoints.

    Please advise how some of you guys have upgraded Identity Minder in past and brought over your PROV DIR data with PROV ROLES for users etc.

    In past we have upgraded IM from R 12.6 to R 14.0 and the data came over of its own that we could see in PROV MANAGER but not sure why R14.0 to R14.3 upgrade is not doing the same, the documentation from past we have is also not providing much details that which step could have brought over (populated the data) into the PROV DIR "without" Bulk Load method in past.


    Thank you so much for your help and suggestions in advance.

    Rakesh



  • 2.  RE: Transfer PROV Roles data IM Upgrade.
    Best Answer

    Broadcom Employee
    Posted Nov 05, 2019 11:28 AM
    The recommended procedure would be to install 14.0 on the new server, ensure the data is in place there using dxdumpdb/dxloaddb, then upgrade the new system to 14.3.  You should not be multi-write replicating between the old and new servers during this process.  Is this the process that was followed or did you install 14.3 only onto the new system?  You should not load the 14.0 data directly into the 14.3 system, it needs to be in place prior to upgrading from 14.0 to 14.3.  For reference, see the below which is the procedure that should have been followed:

    https://techdocs.broadcom.com/content/broadcom/techdocs/us/en/ca-enterprise-software/layer7-identity-and-access-management/identity-manager/14-3/upgrading/upgrade-provisioning-components/migrate-the-provisioning-directory.html

    ------------------------------
    ------------------------------
    And, as always Perhaps there are others in the communities who have experience in doing this and we invite them to comment here also.

    Another option may be to reach out to our partner HCL Technologies to see in what way they can assist further. The Enterprise Studio team of HCL can be reached at enterprisestudio@hcl.com. https://www.hcltech.com/enterprise-studio
    ------------------------------



  • 3.  RE: Transfer PROV Roles data IM Upgrade.

    Broadcom Employee
    Posted Nov 05, 2019 11:30 AM
    You said you are upgrading 14.0 to 14.3.  You seem to suggest 14.0 on old system and 14.3 on new system.  We don't install 14.3 and move data over from 14.0.  You must go through the upgrade.  

    1.  Install 14.0 on new server
    2.  Confirm data.  Move directory over on new set of servers
    3.  Upgrade to 14.3.

    Did you do a fresh install of 14.3?  If the data was there in 14.0 the data would still be there in 14.3 (if an upgrade from 14.0).  If this was an upgrade was there data to begin with?

    You are not multi-write replicating between old servers and new servers.

    https://www.google.com/search?q=Migrate+provisioning+directory+IDM&rlz=1C1GCEU_enUS845US846&oq=Migrate+provisioning+directory+IDM&aqs=chrome..69i57j33l4.8959j0j8&sourceid=chrome&ie=UTF-8

    See step 3 on the doc link above.

    3.  On the new server, install the same version of the provisioning components that you had installed on the existing system, in the following order:

    Order is important where you go from 14.0 to 14.0 (installed) and once confirmed 14.0 on new server, upgrade to 14.3.

    Thank you.



    ------------------------------
    Best regards,

    Scott Owens
    Sr Support Engineer

    ------------------------------
    And, as always Perhaps there are others in the communities who have experience in doing this and we invite them to comment here also.

    Another option may be to reach out to our partner HCL Technologies to see in what way they can assist further. The Enterprise Studio team of HCL can be reached at enterprisestudio@hcl.com. https://www.hcltech.com/enterprise-studio
    ------------------------------
    ------------------------------



  • 4.  RE: Transfer PROV Roles data IM Upgrade.

    Posted Feb 14, 2020 11:57 AM

    Hello All,

    In one of our environment ​like QA we were able to stop the DIR instances on OLD environment and then export the four "IMPD" directories and then import the same into the new "IMPD" directory server and the users were able to get back their Provisioning Roles back.

    Thanks

    Rakesh