security.cfg propagation fails to DX UIM Secure Hubs and Tunnel hubs
search cancel

security.cfg propagation fails to DX UIM Secure Hubs and Tunnel hubs

book

Article ID: 454452

calendar_today

Updated On:

Products

DX Unified Infrastructure Management (Nimsoft / UIM)

Issue/Introduction

This article addresses issues where security.cfg fails to propagate to Secure or Tunnel hubs in a tiered DX UIM environment. This often occurs when workaround settings are applied to prevent security file corruption.

Environment

  • DX UIM 23.4 CU8 and earlier
  • Environments utilizing Secure Hubs or Tunnel Hubs

Cause

Deploying probes on remote hubs triggered unnecessary version increments in security.cfg. If a remote hub's version surpassed the primary hub, configurations were overwritten (causing corruption). To mitigate this, customers were advised to disable security_config_propagation and restrict callbacks. This permanent fix addresses the root cause of the version bumps in Hub version 23.4.9.

Resolution

 Upgrade all hubs (Primary, Tunnel, DMZ, and Secure) to Hub version 23.4.9. Once upgraded, follow these steps to restore standard propagation:

  1. Modify Callback Settings: On the primary hub, use the hubsec_setup_put callback via the pu utility to change secure_callbacks_from_primary_hub_only to no.
  2. Reset Secure Hub: Delete all security.* files on the secure hub and restart the service to force a fresh configuration pull.
  3. Re-enable Propagation: Set security_config_propagation = yes in the hub.cfg of all secondary hubs.

Additional Information

Notes:

  • The HUB Version 23.4.9 is no longer available (ETA: September-October 2026)
  • HUB version 23.4.9 can run on a DX UIM Server that is on a lower version
    (Eg. DX UIM server on 23.4CU6+primary hub and secondary hub runnig hub 23.4.9 is a supported configuration)

 

Related KB: