SunScreen EFS Release 3.0 Installation Guide

Upgrading a Remotely Administered SunScreen EFS

The following procedures explain how to upgrade to a remotely administered SunScreen EFS 3.0 from either SunScreen EFS 1.1 or 2.0. The upgrade software automatically backs up your system in case the upgrade fails. If there are any other system backups you want to make, do so now before performing the upgrade.


Note -

The upgrade procedure for remote administration requires that you install the upgrade software on the Screen first and then on the Administration Station.


To Upgrade a Remotely Administered Screen
  1. Open a terminal window on the Screen and become root.


    Caution - Caution -

    Ensure that the OpenWindows File Manager is not running because it interferes with the operation of the volcheck command used for installation.


  2. Insert the SunScreen EFS 3.0 CD-ROM into the CD-ROM drive.

  3. Mount the CD-ROM by typing:


    # volcheck
    

  4. Start the upgrade software by typing:


    # /cdrom/cdrom0/upgrade
    

  5. Next, the program automatically does a back up of your existing SunScreen EFS configurations, software packages, and certificates.

    The file system names appear as output on your monitor. Wait until this completes.

  6. Next, the software automatically removes the existing SunScreen SKIP and SunScreen EFS 1.1 or 2.0 software packages. Wait until this completes.

    The packages are removed automatically one-by-one. No confirmations are needed or accepted. The file and package names will appear as output on your monitor.

  7. Next, the SunScreen EFS 3.0 software is automatically installed for you. Wait until this completes.

    The file and package names will appear as output on your monitor.

  8. Next your existing SunScreen EFS 1.1 or 2.0 configurations are automatically converted to SunScreen EFS 3.0 policies. Wait until this completes.

    If there are any conversion errors, they are itemized as output on your monitor.

  9. Remove the SunScreen EFS, Release 1.1 or 2.0 PATH and MANPATH from your shell initialization file.

  10. Set the SunScreen EFS 3.0 PATH and MANPATH by editing your shell initialization file (such as .profile or .login file).

    1. Set the PATH for the Bourne shell by typing:

      PATH=/opt/SUNWicg/SunScreen/bin:$PATH

      PATH=/usr/dt/bin:$PATH

      export PATH

    2. Set the MANPATH for the Bourne shell by typing:

      MANPATH=$MANPATH:/opt/SUNWicg/SunScreen/man

      export MANPATH

  11. Eject the CD from the CD-ROM drive by typing:


    # eject cdrom0
    

  12. Install any SKIP upgrades (Export Controlled [1024-bit] or U.S. and Canada Use Only [2048-bit] keys) as instructed in the documentation that is included with the upgrade SKIP CD-ROM.


    Caution - Caution -

    Do not run the installation wizard as it is for an initial installation only and can corrupt your existing configurations.


  13. Reboot by typing:


    # sync; init 6
    

  14. Open a terminal window and become root, if not already.

  15. List the policies that have been converted by typing:


    # ssadm policy -l
    


    Note -

    NAT mappings have changed considerably in SunScreen EFS 3.0. If you are using NAT, you must modify it before activating the configuration. If you are converting from SunScreen EFS 1.1, be aware that ordered rules is a new feature. See the SunScreen EFS 3.0 Reference Manual for more detail.


  16. Choose the one policy that you want to activate by typing:


    # ssadm activate configuration_name
    

    You next move to the remote Administration Station.

To Upgrade a Remote Administration Station
  1. Open a terminal window on the Administration Station and become root.


    Caution - Caution -

    Ensure that the OpenWindows File Manager is not running because it interferes with the operation of the volcheck command used for installation.


  2. Remove each SunScreen EFS, Release 1.1 or 2.0, package individually by typing:


    For SunScreen EFS 1.1:
    # pkgrm SUNWicgSA 
    
    For SunScreen EFS 2.0:
    # pkgrm SUNWicgSA SUNWicgSD SUNWicgSM SUNWHJicg
    

  3. Follow the program prompts and answer all the questions with y.

    The pkgrm program ends with the statement: Removal of name_of_package was successful.


    Note -

    If you did not originally install any of these packages, omit them from the string or else remove the packages one at a time.


  4. Remove the SKIP software packages by typing:


    # pkgrm SICGcrc2 SICGcrc4 SICGes SICGkeymg SICGkisup SICGbdcdr
    

  5. If needed, remove any SKIP crypto upgrades by typing:


    # pkgrm SICGcdes SICGc3des SICGcsafe SICGkdsup
    SICGkusup
    

  6. Insert the SunScreen EFS 3.0 CD-ROM into the Administration Station's CD-ROM drive.

  7. Mount the CD-ROM by typing:


    # volcheck
    


  8. For SPARC systems:
    # pkgadd  -d /cdrom/cdrom0/sparc
    
    For x86 systems:
    # pkgadd  -d /cdrom/cdrom0/i386
    
    Add the SunScreen EFS 3.0 packages by typing:

For SPARC systems, you are prompted with a menu of packages to install:


The following packages are available:
1  SUNWbdc       SKIP Bulk Data Crypt  1.5 Software
                   (sparc) 1.5
  2  SUNWbdcx      SKIP Bulk Data Crypt (64-bit) 1.5 Software
                   (sparc) 1.5
  3  SUNWdthj      HotJava Browser for Solaris
                   (sparc) 1.1.5,REV=1998.12.03
  4  SUNWes        SKIP End System  1.5 Software
                   (sparc) 1.5
  5  SUNWesx       SKIP End System (64-bit) 1.5 Software
                   (sparc) 1.5
  6  SUNWfwcnv     SunScreen Firewall conversion
                   (sparc) 3.0
  7  SUNWhttp      Sun WebServer daemon and supporting binaries
                   (sparc) 2.0
  8  SUNWicgSA     SunScreen Administration Software
                   (sparc) 3.0
  9  SUNWicgSD     SunScreen online documentation
                   (sparc) 3.0
 10  SUNWicgSM     SunScreen man pages
                   (sparc) 3.0

... 7 more menu choices to follow;
<RETURN> for more choices, <CTRL-D> to stop display:


 11  SUNWicgSS     SunScreen Firewall
                   (sparc) 3.0
 12  SUNWkeymg     SKIP Key Manager Tools 1.5 Software
                   (sparc) 1.5
 13  SUNWkisup     SKIP I-Support module 1.5 Software
                   (sparc) 1.5
 14  SUNWrc2       SKIP RC2 Crypto Module
                   (sparc) 1.5
 15  SUNWrc4       SKIP RC4 Crypto Module  1.5 Software
                   (sparc) 1.5
 16  SUNWrc4x      SKIP RC4 Crypto Module (64-bit) 1.5 Software
                   (sparc) 1.5
 17  SUNWsman      SKIP Man Pages 1.5 Software
                   (sparc) 1.5

Select package(s) you wish to process (or 'all' to process
all packages). (default: all) [?,??,q]: 

For x86 systems, you are prompted with a menu of packages to install:


The following packages are available:
1  SUNWbdc       SKIP Bulk Data Crypt  1.5 Software
                   (i386) 1.5
  2  SUNWdthj      HotJava Browser for Solaris
                   (i386) 1.1.5,REV=1998.12.03
  3  SUNWes        SKIP End System  1.5 Software
                   (i386) 1.5
  4  SUNWfwcnv     SunScreen Firewall conversion
                   (i386) 3.0
  5  SUNWhttp      Sun WebServer daemon and supporting binaries
                   (i386) 2.0
  6  SUNWicgSA     SunScreen Administration Software
                   (i386) 3.0
  7  SUNWicgSD     SunScreen online documentation
                   (i386) 3.0
  8  SUNWicgSM     SunScreen man pages
                   (i386) 3.0
  9  SUNWicgSS     SunScreen Firewall
                   (i386) 3.0
 10  SUNWkeymg     SKIP Key Manager Tools 1.5 Software
                   (i386) 1.5

... 4 more menu choices to follow;
<RETURN> for more choices, <CTRL-D> to stop display:


 11  SUNWkisup     SKIP I-Support module 1.5 Software
                   (i386) 1.5
 12  SUNWrc2       SKIP RC2 Crypto Module
                   (i386) 1.5
 13  SUNWrc4       SKIP RC4 Crypto Module  1.5 Software
                   (i386) 1.5
 14  SUNWsman      SKIP Man Pages 1.5 Software
                   (i386) 1.5

Select package(s) you wish to process (or 'all' to process
all packages). (default: all) [?,??,q]:

  1. For SPARC systems, enter: 1-5, 8, 10, 12-17 For x86 systems, enter: 1-3, 6, 8, 10-14

  2. Follow the program prompts, answering all the questions with y.

    When completed, you return to the same menu of packages.

  3. Type q to quit pkgadd.

  4. Move the SKIP keys by typing:


    # cp -rp /etc/opt/SUNWicg/skip/* /etc/skip/.
    

  5. Eject the CD-ROM from the CD-ROM drive by typing:


    # eject cdrom0
    

  6. Install any SKIP upgrades (Export Controlled [1024-bit] or U.S. and Canada Use Only [2048-bit] keys) as instructed in the documentation that is included with the upgrade CD-ROM.

  7. Reboot to complete the upgrade by typing:


    # sync; init 6
    

  8. Open a terminal window and become root, if necessary.

  9. To configure and manage your SunScreen from your Administration Station, run a Java-enabled Web browser compliant with JDK 1.1.3 or later, and launch the Administration GUI by typing the following URL:


     http://localhost:3852
    

To configure and manage SunScreen EFS, see the SunScreen EFS 3.0 Administration Guide.