IBM Guardium

 View Only
  • 1.  upgrade GI 11.5 to 12

    Posted Mon July 22, 2024 02:38 PM

    Hi

    I want to prepare to upgrade GDP from 11.5 to 12 p10

    If I choose to create a parallel environment with 12 p10 and gradually retire 11 by changing GIM_URL of GIM on 11 to 12 MU

    The question is : can I move 11.x GIM and STAP to new build 12 p10 appliance?

    I ask this because I had a previous experience/ IBM ticket  when an appliance was upgraded from 11.5 to 11.0p530 WITHOUT GIM or STAP client connected and IBM code logic assumed that new STAP will all be SHA256 and when I wanted to move GIM clients from another 11.0p530 MU  (which was upgraded with connected GIM clients) the change  GIM_URL  did not succeeded because GIM clients used SHA 128 communication on first MU (upgraded with connected clients) and when tried to connect to new MU (upgraded without connected clients) did not succeed to connect due to SHA 256 certificate on new MU

    Thanks

    Sorin



    ------------------------------
    Sorin Tapalaga
    ------------------------------


  • 2.  RE: upgrade GI 11.5 to 12

    IBM Champion
    Posted Tue July 23, 2024 08:36 AM

    Hi @Sorin Tapalaga,

    You do have to consider the GIM SHA256 situation, but it sounds like maybe all of your GIMs are using SHA256 now, in which case you should be fine with your planned migration strategy. If you have GIMs still running SHA1, you should upgrade them using the transitional bundle first.



    ------------------------------
    Wendy Zemba
    Sr. Consultant, Data Protection
    wendy.zemba@convergetp.com
    Converge Technology Solutions

    Need help with your Guardium deployment? Contact me directly to discuss engagement opportunities. Currently serving North America.
    ------------------------------



  • 3.  RE: upgrade GI 11.5 to 12

    Posted Fri July 26, 2024 08:39 AM

    Hi Wendy,

    I already have a situation when despite I upgraded all GIM agents using transitional package, the communication algorithm remained SHA 1 (the only benefit of transitional package was the ability to install new bundles signed 256)

    Thanks

    Sorin



    ------------------------------
    Sorin Tapalaga
    ------------------------------



  • 4.  RE: upgrade GI 11.5 to 12

    IBM Champion
    Posted Mon July 29, 2024 09:01 AM

    @Sorin Tapalaga,

    It's all about the order in which the GIM bundles and appliance version upgrades are performed. If your GIMs are still using SHA1, even after transitional bundle of a GIM using a GIM version with default SHA256 (Unix v11.5_r115368 or Windows v11.5.258 or later) on appliance with P530 or later, you should open a case with support. They can help determine why and provide recommendations to fix your environment. Unfortunately it's not something that can be easily determined through this channel.  



    ------------------------------
    Wendy Zemba
    Sr. Consultant, Data Protection
    Converge Technology Solutions
    wendy.zemba@convergetp.com

    Need help with your Guardium deployment? Contact me directly to discuss engagement opportunities. Currently serving North America.
    ------------------------------



  • 5.  RE: upgrade GI 11.5 to 12

    Posted Wed August 28, 2024 04:12 AM

    Hy Wendy,

    Thank you!

    Sorin



    ------------------------------
    Sorin Tapalaga
    ------------------------------



  • 6.  RE: upgrade GI 11.5 to 12

    Posted Wed August 28, 2024 09:03 AM

    Hi Sorin,
    Please consider to move to p20, there is some important bugs removed from code between 10 and 20



    ------------------------------
    Zbigniew (Zibi) Szmigiero
    IBM
    Międzyrzecz
    ------------------------------



  • 7.  RE: upgrade GI 11.5 to 12

    Posted Wed August 28, 2024 10:25 AM

    Thanks for info!

     


    Clasificare: Uz Intern

    From: Zbigniew (Zibi) Szmigiero via IBM TechXchange Community <Mail@ConnectedCommunity.org>
    Sent: 28/08/2024 4:05 PM
    To: Sorin Tapalaga <Sorin.Tapalaga@btrl.ro>
    Subject: RE: Guardium : upgrade GI 11.5 to 12

     

    Atentionare BT: Acest mesaj provine din exteriorul Grupului BT. Fiti atenti la deschiderea fisierelor atasate, accesarea de linkuri sau furnizarea de informatii solicitate in mesaj.

    Hi Sorin, Please consider to move to p20, there is some important bugs removed from code between 10 and 20 ------------------------------... -posted to the "IBM Security Guardium" group






  • 8.  RE: upgrade GI 11.5 to 12

    IBM Champion
    Posted Wed August 28, 2024 11:57 AM

    @Sorin Tapalaga,

    The 11.x agents are backward compatible and can be moved to the 12.x appliances. What you ran into previously was due to certificate algorithm changes within the agent that needed to be compatible with the appliance. This needs to be considered still, but if your GIMs are now using SHA256 then there should be no issues pointing them to your new 12 environment. If they are still using SHA128, you will have the same issues you described.



    ------------------------------
    Wendy Zemba
    Sr. Consultant, Data Protection
    Converge Technology Solutions
    wendy.zemba@convergetp.com

    Need help with your Guardium deployment? Contact me directly to discuss engagement opportunities. Currently serving North America.
    ------------------------------