This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Domain name migration questions

Hello Sophos !

In the framework of domain migration, we need to move both Sophos Management server and Sophos database installed on two separate virtual machines.

For now, there is a trust relationship between the two domains.

We "just" want to change domain name, server name and IP address will remain the same for both server.

And, we want to use the same separate virtual servers -> so doesn't want to move from an OLD server to a NEW server.

We found following article regarding "Changing Domain Name"

https://sophos.com/kb/119532

Sophos support also send this but this is not relevant as we do not want to do a server to server migration

http://www.sophos.com/en-us/medialibrary/PDFs/documentation/sec_52_mgeng.pdf?la=en

1/ We will follow steps describe in article ID 119532 by saving CertAuthStor registry key, removing all Sophos components existing on Management Server (including Sophos AV / AutoUpdate / RMS / Update Manager / Sophos Console / Management server) and delete Sophos registry key  (HKLM\Software\[Wow6432Node]\Sophos\)

2/ Regarding Database server (using SQL Server 2005 for info), do we need to follow some specific instructions?

Do we need to remove Sophos Database component and re-install after the change of domain name?

3/ Still regarding the db server, the existing account used by management server to connect to the remote database will need to be changed as well.

In OLDDOMAIN, it is called OPEUSOPHOSADMIN (OLDDOMAIN\OPEUSOPHOSADMIN)

IN NEWDOMAIN, the same account is already created NEWDOMAIN\OPEUSOPHOSADMIN.

Do we need to include the NEWDOMAIN account in some specific group? or/and do we need to do some specifics SQL stuff?

4/ After domain name change applied on both server, we plan to import saved registry key and then to reinstall Sophos Management/Console normally, but using the NEWDOMAIN\OPEUSOPHOSADMIN account for database connection.

Excepted questions raised above, what do you think of this high-level plan?

Thank you for your support!

Regards,

Fabrice.

:53989


This thread was automatically locked due to age.
Parents
  • Hello Fabrice,

    thanks for the clarification. Just curious - did the endpoints (when joined to the new domain) simply change their domain info in SEC or appear as new computers?

    Anyway, it's clear you want to keep the database, naturally  you'd have to amend the updating policies. Personally I'd consider a complete reinstall of the two servers, after exporting the database and certificates and taking a snapshot  just in case - depends on the amount of customization on the servers besides the SEC stuff - followed by an import of the database. Might also be a good occasion to upgrade SEC.

    Christian 

    :53999
Reply
  • Hello Fabrice,

    thanks for the clarification. Just curious - did the endpoints (when joined to the new domain) simply change their domain info in SEC or appear as new computers?

    Anyway, it's clear you want to keep the database, naturally  you'd have to amend the updating policies. Personally I'd consider a complete reinstall of the two servers, after exporting the database and certificates and taking a snapshot  just in case - depends on the amount of customization on the servers besides the SEC stuff - followed by an import of the database. Might also be a good occasion to upgrade SEC.

    Christian 

    :53999
Children
No Data