This article provides the steps to upgrade CA PAM from an unsupported version, such as 4.1.7 to CA PAM latest version (4.3.1 with security patches as of the writing ot this article)
PAM 4.1.x (unsupported versions)
Upgrade of a CA PAM appliance/cluster from any version below 4.3.0 to any 4.3.x version is not possible. It is necessary first of all to upgrade to version 4.3.0 after which any subsequent upgrade will proceed by means of the upgrade utility introduced in this version.
Therefore, to move from an unsupported version to 4.3.1 the first step is to migrate it to version 4.2.1, which can be upgraded to version 4.3.0 and proceed from there.
As an example, see below the process for upgrading CA PAM 4.1.7 to version 4.3.1 plus security fix 4.3.1
For an upgrade to 4.3.1 it would be :
(cluster off) PAM_PRE_4.2.X_KERNEL_CLEANUP -> 4.2.1 upgrade patch -> 4.3.0 upgrade patch -> turn cluster on -> apply 4.3.1 upgrade patch to the cluster (using upgrade utility) -> apply 4.3.1.01 to the cluster (using upgrade utility)
Once on 4.3.0, the upgrade utility will be used to apply patches. This requires knowledge of the config user password on the node where the utility is launched.
Note that there are two 4.3.0 upgrade patches, one for upgrades from 4.2.0 and one for upgrades from 4.2.1-4.2.4. Make sure the correct version (upgrade from 4.2.1+) is downloaded from the PAM Solutions & Patches page.
If you are using Windows Proxy agents, they should be upgraded to the 4.3.1 version, not the 4.2.1 version. The 4.3.1 Windows Proxy is compatible with PAM 4.3.0 servers and includes recent vulnerability fixes.