24.2.1 Prerequisites for Migrating Identity Server

  • Ensure that the system meets the requirements for Identity Server.

    For information about the requirements, see NetIQ Access Manager System Requirements.

  • Determine if you want to reuse an existing IP address or use a new IP address for the migration process.

  • The time of Identity Server is synchronized with the time of Administration Console.

  • Ensure that Administration Console is running. See Installing Administration Console.

  • If you installed Administration Console on a separate machine, ensure that the DNS names resolve between Identity Server and Administration Console.

  • Ensure that the following ports are open on both Administration Console and Identity Server:

    • 8444
    • 1443
    • 1289
    • 1290
    • 524
    • 636

    For information about ports, see Configuring the Administration Console Firewall.

  • You must establish a static IP address for your Identity Server to reliably connect with other Access Manager components. If the IP address changes, Identity Server can no longer communicate with Administration Console.

  • Ensure that the following RHEL RPMs are installed on the machine:

    • ncurses-libs.i686

    • createrepo

    • yum-utils

    • ntp

    • glibc.i686

    • nss-softokn-freebl.i686

    • libgcc.i686

    • libstdc++.i686

    • rsyslog.x86_64

    • rsyslog-gnutls.x86_64

    • unzip

    • bind-utils

    • net-tools

    • zip

    • net-snmp

    • expat

    For installing RHEL packages manually, see Installing Packages and Dependent RPMs on RHEL for Access Manager.

    NOTE:You can select to install these RPMs automatically along with Access Manager installation. While installing Access Manager, specify N when you get the following prompt:

    Enter the local mount directory if you have the OS ISO mounted locally. This will be used as the local catalog for the additional rpms.
    Do you have a locally mounted ISO (y/n)?

    The Access Manager installer checks the online catalog and then installs the required RPMs automatically.

  • gettext

  • python (interpreter)

  • (Conditional) If the Identity Server cluster has been assigned to delegated administrators, remove them before migration and re-add them after the migration is complete.

    If you do not perform this action, the delegated administrators will not be able to log in and configure devices assigned to them. You must manually re-create these administrators and assign the respective devices.

    For more information about delegated users, Managing Delegated Administrators in the NetIQ Access Manager 5.0 Administration Guide.

  • Physical access to the server or server console (in case of VMWare setups) as a root user and you are familiar with iptables.

  • Back up the customized files.