Info Security Memo
  • Blog
  • Sitemap
    • Categories
  • Contact
  • About
  • Resources
  • Tools
  • 51sec.org

Build Confidence

Focusing on Information Security 

Info Security Notes

Thycotic Secret Server Upgrade Process Document Example

11/8/2021

0 Comments

 
Thycotic Secret Server Upgrade Process Document Example

This process document has been developed based on Thycotic SS Upgrade process post:

  • https://blog.51sec.org/2021/09/thycotic-secret-server-upgrade-methods.html
It might give you an idea what the TSS upgrading looks like. But based on your environment, current version, new version, servers, DR, and down time requirement, the whole process will be completely different.





Backup


  1. Backup application folder manually through TSS Web Gui. Application backup folder :D:\backup\secretserver


On main site TSS server and DR site TSS server

Completed

  1. Take DBs Database Backup

 

On both main site and DR site DBs


  1. Take Snapshot of all servers

 

On all servers listing in the scope


  1. Application folder backup to ’s VDI machine


On all TSS servers

Completed



.Net Framework 4.5 Upgrade to 4.8



  1. Download .Net and save it to local folder on SS’s temp folder c:\temp\upgrade


On all servers except DB servers

Completed

  1. Install .Net Framework 4.8 and related security patches

/ 

On all servers except DB servers


  1. Restart Servers

/ 

On all servers except DB servers




Version and Configuration Verification



  1. TSS Version verification


All three servers verified. Version is “10.8.000000 - Platinum Edition”

Completed

  1. DE Version verification


All DE server verified. Version is: 10.8.000000

Completed

  1. Database version verification


On both sites’ DB: 14.0.3281.6 

Completed

  1. Check Collation value: SQL_Latin1_General_CP1_CL_AS 


On both sites’ DB servers

Completed

  1. For Secret Server folder permission, add “Everyone” and provide full control for the folder. Modify permission from full control to just modified after upgrade activity.


On all TSS servers 

Optional until issue happened

  1. ASP.net?.NET trust level should be full in both levels (Server and Secret Server)



On all TSS servers

Optional until issue happened

  1. IIS?Request Filtering (Server and SecretServer), check the first three options at both levels (Server and SecretServer)


On all TSS servers

Optional until issue happened

  1. Minimum requirement check: https://docs.thycotic.com/ss/11.0.0/secret-server-setup/system-requirements/index.md


On All TSS servers

Completed

  1. No Microsoft Monitor Agent


On All TSS related servers.

Completed



Others



  1. Thycotic Support Availability


Brian from Thycotic will support us on Sep 15 from 7pm

Completed

  1. CAB 



  1. Copy your own admin password from Thycotic Secret Server which will be used later during upgrading.

, , , , 


  1. Turn off alerts from monitoring system





Main Site Manual Upgrade Process Steps - Primary Thycotic Secret Server


  1. Confirm all pre-requisites completed



  1. Download latest 11.0.000007 version Application files (Not Installation EXE File) 


Completed

  1. Stop SS Application Pool in IIS



  1. DBA run Upgrade script which was provided by Thycotic. Please see DB upgrade process steps.



  1. Extract downloaded zip application file to a temporary location C:\temp



  1. Extract the ss_update.zip file



  1. Create a zip file of existing SS application folder and send it to the desktop. (Another backup)



  1. Ctrl+a select all files in step 6. Copy and paste the contents contained in the newly extracted ss_update folder to SS’s application folder over the top of the existing application files. Replace all files with the same name.



  1. Once completed, start the SS application pool



  1. Open an administrative command prompt and perform an “iisreset” command






Main Site DB Upgrade Process



  1. Open SQL Management Studio and connect to the SQL Server database engine that hosts the Secret Server database



  1. Expand Databases on the right



  1. Right-click on the Secret Server database and select New Query. Paste the script.



  1. Confirm there is no error on the query. If so, uncomment “COMMIT TRAN”.



  1. Click the Execute button, Ctrl+E, or hit F5



  1. Close SSMS





Secondary Thycotic Secret Server



  1. Confirm Primary SS Server upgraded and works. 



  1. Download latest 11.0.000007 version Application files (Not Installation EXE File) 


Completed

  1. Stop SS Application Pool in IIS



  1. Extract downloaded zip application file to a temporary location C:\temp



  1. Extract the ss_update.zip file



  1. Create a zip file of existing SS application folder and send it to the desktop. (Another backup)



  1. Ctrl+a select all files in step 6. Copy and paste the contents contained in the newly extracted ss_update folder to SS’s application folder over the top of the existing application files. Replace all files with the same name.



  1. Once completed, start the SS application pool



  1. Open an administrative command prompt and perform an iisreset command





DR Site Manual Upgrade Process Steps - DR Thycotic Secret Server


  1. Confirm all pre-requisites completed



  1. Download latest 11.0.000007 version Application files (Not Installation EXE File) 


Completed

  1. Stop SS Application Pool in IIS



  1. DBA run Upgrade script which was provided by Thycotic. Please see DB upgrade process steps.

 

(Optional, decided by )

  1. Extract downloaded zip application file to a temporary location C:\temp



  1. Extract the ss_update.zip file



  1. Create a zip file of existing SS application folder and send it to the desktop. (Another backup)



  1. Ctrl+a select all files in step 6. Copy and paste the contents contained in the newly extracted ss_update folder to SS’s application folder over the top of the existing application files. Replace all files with the same name.



  1. Once completed, start the SS application pool



  1. Open an administrative command prompt and perform an iisreset command





DR DB Upgrade Process (Optional)


If DR DB will be synchronized automatically from Main site since all of them are in AlwaysOn group, this step can be omitted. 

  1. Confirm main SS upgrade works



  1. Stop DR SS application pool in IIS



  1. Copy Web application folder from primary SS in main site to DR SS server, without database.config and encryption.config. Replace the content of the existing web application folder with the new. 



  1. Confirm there is no error on the query. If so, uncomment “COMMIT TRAN”.



  1. Once completed, start the SS application pool



  1. Do verification






Test and verification


For each upgrade, please do following testing and verification. 

  1. Log into Secret Server. Check the version of Secret Server in the application files by visiting https://<server host name>/SecreteServer



  1. Check the database 



  1. Check system and DE health



  1. Test RDP/SSH from SS web browser protocol handler

/  /  / 


  1. Testing customized launcher



  1. Test Connection Manager

/  /  / 


  1. Check system logs



  1. Check DR Server



  1. Check DE version



  1. Check Recording 

/ 


  1. Privilege Manager Authentication Testing

/ 






Post Upgrade


There are e pending tasks which will need to be resolved later after upgrade, not same day as upgrading day. 

  1. Web Password handler upgrade. Current configuration disabled auto-upgrade.

TBD


  1. Remove VM Snapshots



  1. DE Upgrade


  1. Protocol handler upgrade

























via Blogger http://blog.51sec.org/2021/11/thycotic-secret-server-upgrade-process.html
November 08, 2021 at 04:29PM Thycotic
0 Comments



Leave a Reply.

    Categories

    All
    Architecture
    Blog
    Checkpoint
    Cisco
    Cloud
    CyberArk
    F5
    Fortigate
    Guardium
    Juniper
    Linux
    Network
    Others
    Palo Alto
    Qualys
    Raspberry Pi
    Security
    SIEM
    Software
    Vmware
    VPN
    Wireless

    Archives

    March 2024
    February 2024
    January 2024
    December 2023
    November 2023
    October 2023
    September 2023
    August 2023
    July 2023
    June 2023
    May 2023
    April 2023
    March 2023
    February 2023
    January 2023
    December 2022
    November 2022
    October 2022
    September 2022
    August 2022
    July 2022
    June 2022
    May 2022
    April 2022
    March 2022
    February 2022
    January 2022
    December 2021
    November 2021
    October 2021
    September 2021
    August 2021
    July 2021
    June 2021
    May 2021
    April 2021
    March 2021
    February 2021
    January 2021
    December 2020
    November 2020
    October 2020
    September 2020
    August 2020
    July 2020
    October 2019
    September 2019
    June 2019
    July 2018
    May 2018
    December 2017
    August 2017
    April 2017
    March 2017
    January 2017
    December 2016
    November 2016
    October 2016
    September 2016
    August 2016
    July 2016
    June 2016
    May 2016
    April 2016
    March 2016
    February 2016
    January 2016
    December 2015
    November 2015
    October 2015
    September 2015
    August 2015
    July 2015
    June 2015
    May 2015
    April 2015
    March 2015

    Print Page:

    RSS Feed

    Email Subscribe
Powered by Create your own unique website with customizable templates.
  • Blog
  • Sitemap
    • Categories
  • Contact
  • About
  • Resources
  • Tools
  • 51sec.org