This forum is closed to new posts and responses. Individual names altered for privacy purposes. The information contained in this website is provided for informational purposes only and should not be construed as a forum for customer support requests. Any customer support requests should be directed to the official HCL customer support channels below:

HCL Software Customer Support Portal for U.S. Federal Government clients
HCL Software Customer Support Portal


Jun 3, 2013, 12:45 PM
3 Posts

Upgrade and move server, cert.id is lost

  • Category: Administration
  • Platform: Linux
  • Release: 9.0
  • Role: Administrator
  • Tags:
  • Replies: 1

I am doing a server move and upgrade. The server is currently running 8.5.3 on Windows and will be moved to 9.0 on Linux. 

- cert.id is lost, but CA is set up and running.

- The old server will be shut down.

- Small installation with ~20 users(3 notes clients, the rest is web-access only).

 

In this scenario I see 2 alternatives, but don't know if one of them are possible:

1) create new server certificate with CA, and move everything including CA. (is it possible to move CA without cert.id?)

2) install new server in new domain and set up new CA.

 

Alternative 2 seems a little more work, but then I would be on solid ground all the way.

 

Johnny

Feb 10, 2014, 9:22 PM
4 Posts
upgrade and move server,cert id is lost
"In this scenario I see 2 alternatives, but don't know if one of them are possible:

1) create new server certificate with CA, and move everything including CA. (is it possible to move CA without cert.id?)

2) install new server in new domain and set up new CA."

1.) I don't think you can move CA to another server without the cert.id. When you migrate certifier to CA, you would be asked to which server should CA run, if you create a new server, this new server won't have the CA process running on it

2.)  If you will do a totally new (different) server, then you would have to register or certify your existing users to this new server (with a new domain).

 I can give you a third alternative:
There is a way to recover a cert.id when you have CA setup.
(You must be a CAA in order to do this)
Steps to recover Cert.id from ICL database:
1.) Open ICL database
2.)Open the document called "IDStorage"
3.) An id file should be stored in that document, usually will have a name of  ~tmp.id
4.)Save it to your computer(password on this id would be different, do the next steps to get the password)
5.) Go back to the document, right click then access document properties
6.)On the fields tab(second tab from left), look for the password field. that would be the password for the certifier.

Then after you recover the cert.id you can proceed with creating a new server.id, install and setup the new server, move your users to this new server, then migrate the certifier (cert.id) to the ca process to be run on this newly setup server.


Hope this helps


This forum is closed to new posts and responses. Individual names altered for privacy purposes. The information contained in this website is provided for informational purposes only and should not be construed as a forum for customer support requests. Any customer support requests should be directed to the official HCL customer support channels below:

HCL Software Customer Support Portal for U.S. Federal Government clients
HCL Software Customer Support Portal