Data Center Security Server (DCS) Upgrade Plan: Know before you upgrade
search cancel

Data Center Security Server (DCS) Upgrade Plan: Know before you upgrade

book

Article ID: 213959

calendar_today

Updated On:

Products

Data Center Security Server Data Center Security Server Advanced Data Center Security Monitoring Edition

Issue/Introduction

If you plan to upgrade your DCS Manager you should follow this article to ensure a seamless upgrade

Environment

Symantec Data Center Security (DCS) 

  • All Versions

Resolution

DCS Version

Note: You must first upgrade to DCS 6.9.2 for all prior versions, before upgrading to DCS 6.9.3
You can upgrade DCS 6.9.3 to DCS 6.10.3 or DCS 6.11.0 (or higher)

Please contact Technical Support if you require assistance

Backups

  • Make a backup of the database
  • Snapshot or backup of the DCS manager

  • Backup the following files

    • For DCS 6.10.x and DCS 6.11.x
      • all the .ssl files and certs in the DCS Server directories and subdirectories (install directory\Server)
      • cacerts file location (install directory\Server\jre\lib\security\cacerts)
      • application.properties (install directory\Server\Management and install directory\Server\Communication)

    • For DCS 6.9.x the following additional files
      • server.xml <InstallDirectory>\Server\tomcat\conf\
      • sss.ssl <InstallDirectory>\Server\
      • umcserver.ssl <InstallDirectory>\Server\
      • agent-cert.ssl <InstallDirectory>\Server\
      • server-cert.ssl <InstallDirectory>\Server\
      • rootkey.cer <InstallDirectory>\Server\umc\ssl\umcCA\certs\
      • cacerts <InstallDirectory>\Server\jre\lib\security\

Drive Space

SQL Users and Settings 

  • Stop all maintenance tasks on the DB (nothing should be running, Splunk connectors, etc)
  • Disable and log out any SIEM type of users so nothing is pulling data from the database
  • Verify your database users (sa, scsp_ops, scspdba) are present/enabled in the database and have the correct permissions and you have the passwords that you installed with. For DCS 6.9.x there will be a umcadmin user for the dcsc_umc database.
  • It's common for DBAs to disable accounts like SA and the umcadmin account and these are needed during the upgrade.
  • Ensure scsp_ops and umcadmin passwords are 17 or more characters in length, the upgrade will fail on the UMC database if the password is under 17 characters
  • Use the actual "sa" account when upgrading, it will only be used during the upgrade as we make changes in SQL that require the "sa" account
  • DCS 6.10.x or DCS 6.11.x - The UMC database is migrated and no longer used, you can backup and remove the database, however you can't rename the database to its prior name as the upgrade looks for that database to migrate it


DCS Manager Action Items

Service Name Details

For DCS 6.9.x and lower

    • Symantec Data Center Security Service (SISManager)
    • UMC Telemetry Service
    • UMC Credential Service

For DCS 6.10.x and DCS 6.11.x and newer

    • Symantec Data Center Security Management Server (DCSManagementServer)
    • Symantec Data Center Security Communication Server (DCSCommunicationServer)
  1. Stop DCS services on ALL managers
    • DCS 6.9.x and lower 
      • Disable the SISManager service on all but the primary manager (You will re-enable those when you start the upgrade on those managers)
    • DCS 6.10.x and DCS 6.11.x
      • Ensure you have stopped and disabled all DCS Management and Communication Server Services

  2. Stop any AntiVirus software and disable UAC and SmartScreen
    • For Symantec Endpoint Protection, also disable tamper protection

  3. Move all Agent Bulk logs from the <install directory>\Server\Logfiles to another location (outside of the DCS Manager Path)
    • Important Note: Do not move the directory, only the files within it

  4. Ensure no GPO is set to re-enable the services

  5. If there's a DCS Agent installed on the server, set the prevention policy to null

  6. For DCS 6.9.x, ensure the 'TomcatOnlyInstall' registry key on the primary server is either absent or set to FALSE.
  7. Upgrade primary
    1. DCS 6.9.x - run server.exe (from an Administrative Command Prompt)
      • After the primary has been upgraded, login to UMC and ensure you can see your Assets page
    2. DCS 6.10.x - run sdcs-management-server-6.10.x-xxxx.msi (from an Administrative Command Prompt)
    3. DCS 6.11.x - run sdcs-management-server-6.11.x-xxxx.msi (from an Administrative Command Prompt)

Upgrading Secondary Management Servers (aka Tomcat Only)

  • DCS 6.9.x

    • Enable the SISManager Service (disabled in prior steps)
    • Run server.exe from an Administrative Command Prompt

  • DCS 6.10.x

    • Ensure all Management and Communication Server Services are stopped and disabled on all Servers 
    • DCS Management Servers
      • run sdcs-management-server-6.10.x-xxxx.msi (from an Administrative Command Prompt)
      • After the upgrade has completed, stop and disable the management service on that machine
    • DCS Communication Servers
      • run sdcs-communication-server-6.10.x-xxxx.msi (from an Administrative Command Prompt)
      • After the upgrade has completed, stop and disable the management service on that machine
    • After all Secondary Servers are updated, you can reenable and start all services 

  • DCS 6.11.x

    • DCS Management Servers
      • run sdcs-management-server-6.11.x-xxxx.msi (from an Administrative Command Prompt)
    • DCS Communication Servers
      • run sdcs-communication-server-6.11.x-xxxx.msi (from an Administrative Command Prompt)
    • After all Secondary Servers are updated, you can reenable any services still disabled and then start all services 

Additional Information

Upgrading from DCS 6.6 – 6.9
  • Windows Agents (< 6.7.3.1474): After completing the upgrade, apply the LiveUpdate fix (contact Technical Support to obtain it).
  • Manager Upgrades to 6.9.3: If your Manager is currently running 6.7.x, 6.8.x, 6.9.0, or 6.9.1, you must first upgrade it to 6.9.2 before advancing to 6.9.3.
Upgrading from DCS 6.9.3 or 6.10.x
  • Targeting DCS 6.10.x: Your Manager must be running DCS 6.9.3 prior to the upgrade.
  • Targeting DCS 6.11.x: Your Manager must be running either DCS 6.9.3 or DCS 6.10.x prior to the upgrade.