Video Screencast Help
Search Video Help Close Back
to help
Not able to make it to Vision this year? Get a sampling in the Best of Vision on Demand group.

keystorepass password changed after SEPM DB restore

Updated: 21 May 2010 | 1 comment
Scott_Lockington's picture
0 0 Votes
Login to vote
This issue has been solved. See solution.

Hello,

 I recently uninstalled/reinstalled and restored the DB on my SEPM server in order to move the remote SQL DB to a different server running SQL 2008, from SQL 2005.  Following the instructions at the below link.
 
Moving an existing Symantec Endpoint Protection Manager 11 RU5 database to SQL Server 2008
http://service1.symantec.com/support/ent-security.nsf/docid/2009092823041448  
  (this article's link appear's to be no longer working for some reason, but I've seen it referenced by other's in the forums)

Anyway the process has completed successfully for me, with clients getting green dot. I'm now verifying I have the correct info in the Disaster recovery backup .txt file Symantec suggests to create here.

http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2007082112135948

In doing so I noticed that the keystorepass has changed (although the DomainID in sylink.xml did not), even though I successfully restored the SEPM server cert as per instructions pasting the now "old" keystorepass into the input wizard during restore. I have even checked both locations Symantec references for the server.xml file.
 
 C:\Program Files\Symantec\Symantec Endpoint Protection Manager\Server Private Key Backup\server_<timestamp>.xml
 C:\Program Files\Symantec\Symantec Endpoint Protection Manager\tomcat\conf\server.xml
 
Both have the same "new" keystorepass password.  So I have updated my Disaster recovery text file with new one as well as keeping the old one, anyone know if this is expected behavior when restoring a SEPM?  Is that just a natural part of regening the keys? Should I just use the new password in event of a disaster?

Thanks

Comments

Vikram Kumar-SAV to SEP's picture
02
Dec
2009
0 Votes 0
Login to vote

 I am not sure if it is

 I am not sure if it is expected behaviour but i have many times seen two keys getting generated.
For future Disaster recovery you will have to use the latest/New Keystorepass.