|
For migration of an AquaLogic Service Bus 2.1 domain to an AquaLogic Service Bus 2.5 domain, no wizard is provided. All steps are manual. To upgrade an AquaLogic Service Bus 2.1 domain to 2.5 using the migration upgrade method, complete the steps described in this section.
Use the AquaLogic Service Bus Console to export the AquaLogic Service Bus 2.1 configuration that you want to upgrade. To do so, select Export Resources from the System Administration panel in the console. For information about exporting AquaLogic Service Bus configurations, see "Exporting Configuration Data" in System Administration in Using the AquaLogic Service Bus Console.
| Note: | In most cases, you cannot export WebLogic Server resources, such as JMS resources and Work Manager definitions. You must re-create these objects in the new AquaLogic Service Bus 2.5 domain, as described in Step 6: Recreate Other WebLogic Server Objects. |
Use the WebLogic Server Administration Console to export security data from the domain: Inthe WebLogic Server Administration Console, select Domain Structure
Security Realms, then choose the security realm. Select Migration
Export to export the data.
The following table summarizes the security data and the types of security providers in which it is stored.
If you created service accounts and added user names and passwords to the service accounts, then your domain includes a username/password credential mapping provider. If your domain includes this provider or a PKI credential mapping provider, you must configure the export process to export credential mapping passwords in clear text (unencrypted). Your new domain will not be able to use passwords that were encrypted by a different domain.
WebLogic Server allows you to either export all of the security data in a single export operation or to export data from each security provider individually. Do not export all of the data in a single export operation. The single export operation does not allow you to export passwords in clear text.
passwords=cleartextFor more information, see Migrating Security Data in Securing WebLogic Server.
Install the AquaLogic Service Bus 2.5 software as described in the AquaLogic Service Bus Installation Guide.
Create a new AquaLogic Service Bus 2.5 domain using the Domain Configuration Wizard or using the offline configuration tools, as described in:
In the new domain, configure the WebLogic security framework with SSL and the security providers that you need to support your proxy and business services. See Configuring the WebLogic Security Framework: Main Steps in the AquaLogic Service Bus Security Guide.
__SERVICE_BUS_INBOUND_WEB_SERVICE_SECURITY_MBEAN__ or __SERVICE_BUS_OUTBOUND_WEB_SERVICE_SECURITY_MBEAN__, make the same modifications in the 2.5 domain. UseX509ForIdentity property to the __SERVICE_BUS_INBOUND_WEB_SERVICE_SECURITY_MBEAN__ configuration (which is required to support inbound authentication with an X.509 token), add the property in the 2.5 domain. See
Use X.509 certificates to establish identity in The WebLogic Server Administration Console Online Help.
In the new AquaLogic Service Bus 2.5 domain, recreate WebLogic Server objects that could not be exported in Step 1 (Step 1: Export the AquaLogic Service Bus 2.1 Configuration), including:
For more information about configuring WebLogic Server domain resources, see Overview of WebLogic Server System Administration in Introduction to BEA WebLogic Server and BEA WebLogic Express.
Use the WebLogic Server Administration Console to import the 2.1 security data that you exported in Step 2: Export the Security Configurations into the new AquaLogic Service Bus 2.5 domain. See Import data into a security provider in The WebLogic Server Administration Console.
DefaultAtz from the Import Format list.DefaultRoles in the Import Format list.
Import into the new 2.5 domain the 2.1 configuration data that you exported in Step 1: Export the AquaLogic Service Bus 2.1 Configuration. For information about how to import the configuration data, see System Administration in Using the AquaLogic Service Bus Console.
For each 2.1 service account, the import process attempts to re-bind service accounts to the user names and passwords that are in the username/password credential mapping provider. For example, if your 2.1 domain included a service account with the user name of "pat" and password of "patspassword", the import process looks in the username/password credential mapping provider in the 2.5 domain for "pat" and "patspassword." If the import process does not find the credentials for a service account in the username/password credential mapping provider, you must add credentials to the service account before you can activate the session. You cannot import empty service accounts into AquaLogic Service Bus 2.5.
For each 2.1 proxy service provider, the import process does the following:
In AquaLogic Service Bus 2.5 you cannot create a proxy service provider that supplies an X.509 credential only for WSS authentication. You can create a proxy service provider that supplies X.509 credentials for digital signatures, digital encryption, or SSL client authentication. The proxy service provider uses the X.509 digital-signature credential for those web services that require the certificate for both WSS authentication and digital signature.
If a 2.1 proxy service provider contained a digital-signature credential and an X.509 authentication credential, and if both credentials refer to the same key-pair, the import process does not import the X.509 token authentication credential. You do not need to remove the credential. To confirm that the X.509 token authentication credential will not be imported into the 2.5 domain, the import process outputs the following message: Service Provider has been upgraded. The Web Service Security X.509 Token key has been removed. This credential has been deprecated in AquaLogic Service Bus 2.5. The Digital Signature key will be used instead.
See Security Updates Expand Configuration Options in "What's New in AquaLogic Service Bus" in BEA AquaLogic Service Bus Release Notes.
Some AquaLogic Service Bus domain configuration changes are not automated and must be implemented manually. See Upgrade Considerations.
This completes the upgrade of your domain to AquaLogic Service Bus 2.5.
For additional resources, see the BEA AquaLogic Service Bus 2.5 documentation.
|