It might give you an idea what the TSS upgrading looks like. But based on your environment, current version, new version, servers, DR, and down time requirement, the whole process will be completely different.
For Secret Server folder permission, add “Everyone” and provide full control for the folder. Modify permission from full control to just modified after upgrade activity.
On all TSS servers
Optional until issue happened
ASP.net🡪.NET trust level should be full in both levels (Server and Secret Server)
On all TSS servers
Optional until issue happened
IIS🡪Request Filtering (Server and SecretServer), check the first three options at both levels (Server and SecretServer)
Brian from Thycotic will support us on Sep 15 from 7pm
Completed
CAB
Copy your own admin password from Thycotic Secret Server which will be used later during upgrading.
, , , ,
Turn off alerts from monitoring system
Main Site Manual Upgrade Process Steps – Primary Thycotic Secret Server
Confirm all pre-requisites completed
Download latest 11.0.000007 version Application files (Not Installation EXE File)
Completed
Stop SS Application Pool in IIS
DBA run Upgrade script which was provided by Thycotic. Please see DB upgrade process steps.
Extract downloaded zip application file to a temporary location C:\temp
Extract the ss_update.zip file
Create a zip file of existing SS application folder and send it to the desktop. (Another backup)
Ctrl+a select all files in step 6. Copy and paste the contents contained in the newly extracted ss_update folder to SS’s application folder over the top of the existing application files. Replace all files with the same name.
Once completed, start the SS application pool
Open an administrative command prompt and perform an “iisreset” command
Main Site DB Upgrade Process
Open SQL Management Studio and connect to the SQL Server database engine that hosts the Secret Server database
Expand Databases on the right
Right-click on the Secret Server database and select New Query. Paste the script.
Confirm there is no error on the query. If so, uncomment “COMMIT TRAN”.
Click the Execute button, Ctrl+E, or hit F5
Close SSMS
Secondary Thycotic Secret Server
Confirm Primary SS Server upgraded and works.
Download latest 11.0.000007 version Application files (Not Installation EXE File)
Completed
Stop SS Application Pool in IIS
Extract downloaded zip application file to a temporary location C:\temp
Extract the ss_update.zip file
Create a zip file of existing SS application folder and send it to the desktop. (Another backup)
Ctrl+a select all files in step 6. Copy and paste the contents contained in the newly extracted ss_update folder to SS’s application folder over the top of the existing application files. Replace all files with the same name.
Once completed, start the SS application pool
Open an administrative command prompt and perform an iisreset command
DR Site Manual Upgrade Process Steps – DR Thycotic Secret Server
Confirm all pre-requisites completed
Download latest 11.0.000007 version Application files (Not Installation EXE File)
Completed
Stop SS Application Pool in IIS
DBA run Upgrade script which was provided by Thycotic. Please see DB upgrade process steps.
(Optional, decided by )
Extract downloaded zip application file to a temporary location C:\temp
Extract the ss_update.zip file
Create a zip file of existing SS application folder and send it to the desktop. (Another backup)
Ctrl+a select all files in step 6. Copy and paste the contents contained in the newly extracted ss_update folder to SS’s application folder over the top of the existing application files. Replace all files with the same name.
Once completed, start the SS application pool
Open an administrative command prompt and perform an iisreset command
DR DB Upgrade Process (Optional)
If DR DB will be synchronized automatically from Main site since all of them are in AlwaysOn group, this step can be omitted.
Confirm main SS upgrade works
Stop DR SS application pool in IIS
Copy Web application folder from primary SS in main site to DR SS server, without database.config and encryption.config. Replace the content of the existing web application folder with the new.
Confirm there is no error on the query. If so, uncomment “COMMIT TRAN”.
Once completed, start the SS application pool
Do verification
Test and verification
For each upgrade, please do following testing and verification.
Log into Secret Server. Check the version of Secret Server in the application files by visiting https://<server host name>/SecreteServer
Check the database
Check system and DE health
Test RDP/SSH from SS web browser protocol handler
/ / /
Testing customized launcher
Test Connection Manager
/ / /
Check system logs
Check DR Server
Check DE version
Check Recording
/
Privilege Manager Authentication Testing
/
Post Upgrade
There are e pending tasks which will need to be resolved later after upgrade, not same day as upgrading day.
Web Password handler upgrade. Current configuration disabled auto-upgrade.