IBM Verify

IBM Verify

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only

Migrating MFA from a unsupported ISAM Platform

  • 1.  Migrating MFA from a unsupported ISAM Platform

    Posted Tue January 16, 2024 10:10 AM

    Hello team,

    Currently, we're facing a problem migrating from ISAM 9.0.5 to the newest 10 version, after the process finish some of the ACL are not supported by the new systems, and some pages are not working as they should.

    This ISAM serves only as an MFA endpoint where some systems send an HTTP request to challenge users for a second-factor authentication.

    To avoid the problems experienced during the upgrade process from 9.0.x to 10.x, I propose the following steps to move the services from one platform to a new one:

    • Create a new set of Verify VA (Virtual Appliances) with the exact configuration as the previous version (9.0.x).
    • Import the user repository from the previous version into the new set of Verify VA.
    • Create a new pair of reverse proxies (mobile and default, as in the MFA Cookbook) from scratch using the MMFA Wizard from version 10.
    • Point the new Verify VA AAC HVDB configuration to the previous HVDB to avoid losing current user registrations and tokens.

    Does this process make sense?

    I appreciate any help regarding this

    Hernan



    ------------------------------
    Hernan Dario Arredondo Rivera
    ------------------------------