Important:  

  • You must upgrade the Cryptographic Security Platform Compliance Manager before you upgrade Cryptographic Security Platform Vault.

  • The CSP Vault Management Appliance and all CSP Vaults must be connected to the CSP Compliance Manager and must have a valid unexpired license, as well as usage within the limits for each category, before you start the upgrade.

    Note:  

    • If your vaults are not connected to the CSP Compliance Manager, you can connect them after you have upgraded CSP Compliance Manager to 10.5.1. For versions 10.4.5 and above, follow the directions in Connecting CSP Vault and CSP Compliance Manager. For CSP Vault version 10.4.3, you will need to download the JSON file and then copy the Compliance Manager ID and the App Link Token from the JSON file. To do this: 

      1. Download the JSON file from the CSP Compliance Manager webGUI.

      2. Open the JSON file with a text editor. The beginning will look similar to the following text:

        "appLinkToken": "NkFGNDM0MUMzRDI4NEExNzQ5NDYzMDlENjE4QjZGREQ0Q0Y5NjlEQzg5MDgxRUJDRDBBQzY1RTFBQjU2OTZGREEwNzc0NjhERjVCRDQwOEZBRDc0ODM4QTlBRjFCRkY5NTVGMjNDMkUwNDA4QkQ3NTc1MzQ3MDk3QjVBMTU1MDZCQkQ4QUFCNTA4QzJBQkMxMTlBQ0U2MTQyRTRCQUIwRkZDOTc4ODY0QjRCRDM1NDgyRjcwMUM4MDcyQjg5Q0IwREMyMDk5NkM4NjZFQjRGQkYzN0M1MUFCOEUwRjMxMzBGRkQ2MUNGRDQ0QTY2NkRBMjhENzA4RDQzQjMwMTJBNkMyQjA5QkZCRTIzRkJERUE5QjUxMjcyRUU1QThBMUVB",
          "kcmId": "10.1.232.31",
          "sslVerify": true,
          "applicationId": "cbe4d5a1-a25c-4721-a95f-5981522b7ef5",
          "rootCertificate": "-----BEGIN CERTIFICATE-----\nMIIGATCCA+mgAwIBAgIEaYuG/jANBgkqhkiG9w0BAQsFADBbMQswCQYDVQQGEwJV\n
      3. Copy the text for the appLinkToken and paste it in the Token field in the KeyControl webGUI.

      4. Copy the applicationId and paste it in the KeyControl Compliance Manager ID field in the KeyControl webGUI.

      5. Click Connect.

    • If you are using BYOK or TDE, you may encounter an error message during the upgrade process similar to: The upgrade can not be started: ["Cloud Keys Vault 'BYOK_Dev_Vault' Cloud Key(s) license entitlement above limit (count: 479, limit: 0)."]. The message text will vary, but the count will be non-zero and the limit zero.

      If this happens, open your Cryptographic Security Platform Compliance Manager to the collection that contains the Vault where you received the error messages. Navigate to the Licenses page and remove all but one license file (CSP Compliance Manager will not let you remove all licenses). Add those licenses back in, then remove and add back the last license file.

      After you complete that step, restart the upgrade.

  • If you have a multi-node cluster with passphrase-based startup authentication, you cannot upgrade directly to 10.5.1. You must either disable the startup authentication or reduce the cluster to a standalone node before you upgrade.
  • If you have just upgraded from a previous version, and want to upgrade to a newer version, you may see a message that reads: Ongoing Encrypt on Cryptographic Security Platform Vault system device - Try again later. In this case, the internal processing will take about 30 minutes to complete before you can continue.

After you upgrade your Cryptographic Security Platform Vault nodes, we strongly recommend that you also upgrade the Policy Agents running on all VMs registered with Cryptographic Security Platform Vault. For details, see Policy Agent Upgrade Requirements.