security.cfg changes are reverted back because of unexpected security version increments
search cancel

security.cfg changes are reverted back because of unexpected security version increments

book

Article ID: 454456

calendar_today

Updated On:

Products

DX Unified Infrastructure Management (Nimsoft / UIM)

Issue/Introduction

Symptoms 

  • Users may observe that ACL changes or user updates made on the Primary hub are unexpectedly overwritten or reverted. This often coincides with rapid, unexplained increments in the security.cfg version number.
  • Even though changes are not done on any hub, the increments of security.cfg version is constant and the cause is unknown.

 

What is causing this version increments? 

Environment

  • DX UIM 23.4.x (versions prior to 23.4.9)
  • Secondary Hubs, Tunnel Hubs, or Secure Hubs

Cause

The issue is caused by a design behavior where deploying or redeploying certain probes (such as logmon) on a remote hub automatically increases the local security.cfg version by 1. In large environments with frequent deployments, a remote hub's version can surpass the Primary hub's version. When synchronization occurs, the higher version number "wins," propagating back to the Primary and overwriting genuine security changes.

Resolution

A permanent fix is available in Hub version 23.4.9 (released with DX UIM 23.4CU9)

The hub 23.4.9 eliminates unnecessary version increments during probe deployment.

Upgrade all hubs: Upgrade all hubs in the environment (Primary, Tunnel, and Secure hubs) to version 23.4.9.

 

Notes:

  • The HUB Version 23.4.9 is not yet available (ETA: September-October 2026)
  • HUB version 23.4.9 can run on a DX UIM Server that is on a lower version
    (Eg. DX UIM server on 23.4CU6+primary hub and secondary hub runnig hub 23.4.9 is a supported configuration)

Additional Information

Workaround (Big Environments):

If an immediate upgrade is not possible, the following procedure prevents secondary hubs from overwriting the Primary: Prevent Secondary hubs from propagating changes to the hub security.cfg

 

Related KBs: