This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Domain name migration questions

Hello Sophos !

In the framework of domain migration, we need to move both Sophos Management server and Sophos database installed on two separate virtual machines.

For now, there is a trust relationship between the two domains.

We "just" want to change domain name, server name and IP address will remain the same for both server.

And, we want to use the same separate virtual servers -> so doesn't want to move from an OLD server to a NEW server.

We found following article regarding "Changing Domain Name"

https://sophos.com/kb/119532

Sophos support also send this but this is not relevant as we do not want to do a server to server migration

http://www.sophos.com/en-us/medialibrary/PDFs/documentation/sec_52_mgeng.pdf?la=en

1/ We will follow steps describe in article ID 119532 by saving CertAuthStor registry key, removing all Sophos components existing on Management Server (including Sophos AV / AutoUpdate / RMS / Update Manager / Sophos Console / Management server) and delete Sophos registry key  (HKLM\Software\[Wow6432Node]\Sophos\)

2/ Regarding Database server (using SQL Server 2005 for info), do we need to follow some specific instructions?

Do we need to remove Sophos Database component and re-install after the change of domain name?

3/ Still regarding the db server, the existing account used by management server to connect to the remote database will need to be changed as well.

In OLDDOMAIN, it is called OPEUSOPHOSADMIN (OLDDOMAIN\OPEUSOPHOSADMIN)

IN NEWDOMAIN, the same account is already created NEWDOMAIN\OPEUSOPHOSADMIN.

Do we need to include the NEWDOMAIN account in some specific group? or/and do we need to do some specifics SQL stuff?

4/ After domain name change applied on both server, we plan to import saved registry key and then to reinstall Sophos Management/Console normally, but using the NEWDOMAIN\OPEUSOPHOSADMIN account for database connection.

Excepted questions raised above, what do you think of this high-level plan?

Thank you for your support!

Regards,

Fabrice.

:53989


This thread was automatically locked due to age.
Parents
  • Hello Fabrice,

    endpoints simply change their domain

    fine - SEC does its best to keep track of known endpoints but given the complexity of the task the algorithm is not infallible, so I thought I'd ask.

    OR a full operating system re-installation?

    Well, at our shop setting up a (virtual) Windows server isn't considered extraordinary work (although removing the half-dozen components is definitely less). Depending on the procedures available YMMV. It's an opportunity to upgrade the OS and other components (please see also Supported Platforms for Sophos products) and get rid of potential debris.

    the NEW service account [...] do additional SQL stuff?

    The installer should take care of the group membership (see http://www.sophos.com/en-us/support/knowledgebase/113954.aspx). Whatever procedure you choose you'll likely have to deal with SQL and the changed SIDs (you might need the ResetUserMappings.sql mentioned here). I've started with a new database when we had to rename our domain and anyway this was a long time ago, so no experience.

    SEC 5.2

    Thinking about it - migration and upgrade more or less in one step isn't a documented scenario (and probably also not supported). But then it's also not guaranteed not to work :smileywink:.BTW, are you using Patch - dunno if it's necessary to migrate the patch database or if it simply gets repopulated over time?

    So ... I'd backup the database(s) and export the Certificate Store (the rest would have to be changed anyway or can easily be recreated). Install 5.2.x (yes!) components on the database and management server respectively. Next step would be to restore the SOPHOS50 database ("completely manually" if the path to the database files is different from the previous installation). As the management server connects to the new SOPHOS521 database the old SOPHOS50 would have to be upgraded (i.e. its contents appropriately replicated to the new one) manually. When the management service is eventually started it should see a server-to-server same-version migration and make the necessary amendments. I've done it once during beta-tests ...

    Oh, as you keep the server's name, IP and certificates your endpoints will assail your new/redomained server with their messages as soon as its services are running and they can connect to it - so make sure the server is out of reach for them until you are done with a database migration.   

    Christian

    :54029
Reply
  • Hello Fabrice,

    endpoints simply change their domain

    fine - SEC does its best to keep track of known endpoints but given the complexity of the task the algorithm is not infallible, so I thought I'd ask.

    OR a full operating system re-installation?

    Well, at our shop setting up a (virtual) Windows server isn't considered extraordinary work (although removing the half-dozen components is definitely less). Depending on the procedures available YMMV. It's an opportunity to upgrade the OS and other components (please see also Supported Platforms for Sophos products) and get rid of potential debris.

    the NEW service account [...] do additional SQL stuff?

    The installer should take care of the group membership (see http://www.sophos.com/en-us/support/knowledgebase/113954.aspx). Whatever procedure you choose you'll likely have to deal with SQL and the changed SIDs (you might need the ResetUserMappings.sql mentioned here). I've started with a new database when we had to rename our domain and anyway this was a long time ago, so no experience.

    SEC 5.2

    Thinking about it - migration and upgrade more or less in one step isn't a documented scenario (and probably also not supported). But then it's also not guaranteed not to work :smileywink:.BTW, are you using Patch - dunno if it's necessary to migrate the patch database or if it simply gets repopulated over time?

    So ... I'd backup the database(s) and export the Certificate Store (the rest would have to be changed anyway or can easily be recreated). Install 5.2.x (yes!) components on the database and management server respectively. Next step would be to restore the SOPHOS50 database ("completely manually" if the path to the database files is different from the previous installation). As the management server connects to the new SOPHOS521 database the old SOPHOS50 would have to be upgraded (i.e. its contents appropriately replicated to the new one) manually. When the management service is eventually started it should see a server-to-server same-version migration and make the necessary amendments. I've done it once during beta-tests ...

    Oh, as you keep the server's name, IP and certificates your endpoints will assail your new/redomained server with their messages as soon as its services are running and they can connect to it - so make sure the server is out of reach for them until you are done with a database migration.   

    Christian

    :54029
Children
No Data