IBM Verify

IBM Verify

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  The road from ISVIG (ISIM) 10.0x to 11

    Posted 10 days ago

    Ideally just a very short answer is requested here...

    Planning to upgrade ISIM from version 10 to 11

    Current env: a single virtual appliance + a data/TDI machine.

    Desired target env: a single virtual appliance + a data/TDI machine.

    Is it possible to do an 'in place upgrade' (answer: 'yes') or it is necessary to go through building/migrating to a parallel environment?

    (service interruptions are, of course, tolerated)

    Thank you in advance for your time!

    Ciao



    ------------------------------
    Andrea Gatto
    ------------------------------


  • 2.  RE: The road from ISVIG (ISIM) 10.0x to 11

    Posted 9 days ago
    Edited by Ali Malik Gürbüz 9 days ago

    Short answer : No.  

    IVIG 11 is based on ISIM and your documentation is here -> https://www.ibm.com/docs/en/sig-and-i/11.0.1?topic=upgrading-from-isvg-im-va-ivig-va 

    With the FP1 IVIG 11 has Virtual Appliance and so has an upgrade path. But its not an in place , upload pkg and forget type upgrade. But it's also not too complex, just set up new ISO's and set same variables.

    Long Answer: If you are ok with troubleshooting and rather closed box nature of VA you can follow the upgrade path. There are also lots of new features and infrastructure upgrades may be needed, like db2, ldap , better check them too, like documentation says.  For example Security Directory Suite is out of support, LDAP 6.4 likewise, its better to move on Verify directory 10.x etc etc. So the amount of work will depend on your infrastructure versions. If all are already compatible you just install new VA's and migrate configuration and key files. 

    Hope it helps. 



    ------------------------------
    Ali Malik Gürbüz
    Bilgibirikim A.S - Turkey/EMEA
    IBM Business Partner
    13+ Years with ISIM/ISVG etc.
    5.2.5 Certified Exam Developer *I* - 2019
    IBM Champion 2025
    ------------------------------



  • 3.  RE: The road from ISVIG (ISIM) 10.0x to 11

    Posted 9 days ago

    Fine!

    That's the type of answer I was looking for.

    Thank you Ali



    ------------------------------
    Andrea Gatto
    ------------------------------



  • 4.  RE: The road from ISVIG (ISIM) 10.0x to 11

    Posted 9 days ago

    I strongly recommend to move to our container platform instead of VA as this also makes it possible to have the data layer (database and ldap) covered. The VA was not really a good idea for a process based thing like ISIM/ISVG - the closed form factor makes it difficult to debug in case of problems. 



    ------------------------------
    Franz Wolfhagen
    WW IAM Solution Architect - Certified Consulting IT Specialist
    IBM Expert Labs
    ------------------------------



  • 5.  RE: The road from ISVIG (ISIM) 10.0x to 11

    Posted 8 days ago

    I agree about the limitations of VAs and the need to make troubleshooting easier (although, after a few years of practice, I've more or less learned to live with them).
    Speaking of personal preferences (for whatever they're worth) and from a troubleshooting perspective, I'd lean towards a full software stack installation, where all components are directly accessible without the intermediate container layer.

    That said, the container option is under evaluation; right now I don't know it well enough, and I'd really like to get to a point where I can compare all the pros and cons of the different approaches.

    As always, thanks for your time and your help.



    ------------------------------
    Andrea Gatto
    ------------------------------



  • 6.  RE: The road from ISVIG (ISIM) 10.0x to 11

    Posted 8 days ago

    It will be easier for you to migrate to the SW version than to the CNT version as you do not need to change your data layer ("only" upgrade the ldap and DB to the latest supported versions) - moving to CNT will involve moving the DB to postgresql with export/import.

    And yest - the SW will make debugging very simple - it is not that bad on the CNT but it is - different.... - but once a CNT is up an running there is a lot of things that the kubernetes performs that makes things much simpler - e.g. fixpacking the environment is very simple and fast compared to SW and VA - but there is no free lunch there either :-)  



    ------------------------------
    Franz Wolfhagen
    WW IAM Solution Architect - Certified Consulting IT Specialist
    IBM Expert Labs
    ------------------------------