HP-UX AAA Server A.08.01 administrator's guide (T1428-90072, May 2010)

Table Of Contents
2 Upgrading to Version A.08.01
This chapter explains how to upgrade to the HP-UX AAA Server A.08.01 from previous
versions.
The HP-UX AAA Server Upgrade Process
The following process describes the HP-UX AAA Server A.08.01 product installation
on a system where a previous version of the HP-UX AAA server is currently installed:
1. The contents of the existing configuration in /etc/opt/aaa/ are copied to /etc/
opt/aaa.old/. If any files with the same names exist in /etc/opt/aaa.old/,
they will be overwritten.
2. The old product binaries are removed and new product binaries are installed.
3. Old unmodified configuration files are replaced with the new default configuration
files in /etc/opt/aaa/.
4. Backup of the default A.08.01 files are installed in /opt/aaa/newconfig/etc/
opt/aaa/ for your reference.
5. Generally, no additional migration is necessary, except as specified in the following
sections:
Upgrading from Versions A.07.00, A.06.02, A.06.01, or A.07.01 to Version
A.08.01.”
“Upgrading from Version A.06.00.x to Version A.08.01” (page 51)
“Upgrading from Version A.05.x to Version A.08.01” (page 53)
NOTE: Contact your HP Support representative if you are upgrading from version
A.05.x and require assistance.
Upgrading from Versions A.07.00, A.06.02, A.06.01, or A.07.01 to
Version A.08.01
Starting with HP-UX AAA Server A.08.00 release, EAP-LEAP AATV is obsolete. The
EAP-LEAP authentication method is replaced by the EAP-PEAP authentication method.
HP recommends that you use EAP-PEAP in place of EAP-LEAP for improved security.
Unlike EAP-LEAP, EAP-PEAP supports mutual authentication and uses an encrypted
tunnel to transmit the user's credentials.
If you have configured a realm for EAP-LEAP authentication, remove the realm entry
from the /etc/opt/aaa/authfile and /etc/opt/aaa/EAP.authfile and
re-configure the realm. For information on EAP-PEAP, see Chapter 13 “Securing LAN
Access With EAP”.
Starting with HP-UX AAA Server A.08.00 release, the Oracle authentication module
is obsolete. The Oracle authentication module is supported using SQL Access. HP
The HP-UX AAA Server Upgrade Process 49