This article addresses issues where security.cfg fails to propagate to Secure or Tunnel hubs in a tiered DX UIM environment. This often occurs when workaround settings are applied to prevent security file corruption.
Deploying probes on remote hubs triggered unnecessary version increments in security.cfg. If a remote hub's version surpassed the primary hub, configurations were overwritten (causing corruption). To mitigate this, customers were advised to disable security_config_propagation and restrict callbacks. This permanent fix addresses the root cause of the version bumps in Hub version 23.4.9.
Upgrade all hubs (Primary, Tunnel, DMZ, and Secure) to Hub version 23.4.9. Once upgraded, follow these steps to restore standard propagation:
hubsec_setup_put callback via the pu utility to change secure_callbacks_from_primary_hub_only to no.security.* files on the secure hub and restart the service to force a fresh configuration pull.security_config_propagation = yes in the hub.cfg of all secondary hubs.Notes:
Related KB: