Backreving or downgrading Access Manager versions does not downgrade version reported

  • 7005391
  • 25-Feb-2010
  • 26-Apr-2012

Environment

Novell Access Manager 3 Linux Novell Identity Server
Novell Access Manager 3 Linux Access Gateway
Novell Access Manager 3 Access Administration
Novell Access Manager 3.1 Linux Access Gateway
Novell Access Manager 3.1 Access Administration
Novell Access Manager 3.1 Linux Novell Identity Server

Situation

AFter upgrading from Access Manager 3.0.4 (version 3.0.4-38) to 3.0.4 IR3 (version 3.0.4-70), an issue was uncovered that required the Administrator to backrev to the previous 3.0.4 IR3 version. To do this, the following steps were run:

1. Backup current config
2. Reinstall Admin console, Identity Server
3. Restore config.
4. Install the Linux Access Gateways from the ISO with same IP address ... it will inherit the info read from the config store.

After the downgrade, users could access the system and work just fine.

However, after all components were roll back to SP4 and the config was restored, all versions reported for the Access Gateways were 3.0.4-70. The Admin Console Access Gateway health check shows the server is not reporting.

Resolution

If you upgrade to a newer release and then decide to revert to your older release:
1. Back up your current configuration.
2. Reinstall the Administration Console to the earlier version.
Use the same DNS name and IP address.
3. Restore the configuration.
4. Reinstall the Identity Servers to the earlier versions.
Use the same DNS names and IP addresses.
5. Reinstall the Linux Access Gateway Appliances, using the ISO of the earlier version.
Use the same DNS names and IP addresses.
6. One at a time, remove an Access Gateway from the cluster, then add it back to the cluster.
The back up contains the wrong version for the Access Gateway. The version
is reset to the correct value when you remove the server from the cluster
then add it to the cluster.
7. Back up your current configuration.

Additional Information

The restore of device info includes the version of the device .. hence the invalid version strings after restore. It is clearly documented that a restore of the Access Manager configuration must be done on the same code base. SOme basic testing has been done (also with 3.1) and shows that it works with the workaround above.