Post-Upgrade Steps

The recommended best practice after you finish running the Keyfactor Command configuration wizard is to reboot the Keyfactor Command server to assure that the services have a clean start. If this is not possible:

There is no particular order in which the tasks on the following pages must be accomplished.

Important:  On upgrade from an implementation prior to the introduction of enrollmentClosed Certificate enrollment refers to the process by which a user requests a digital certificate. The user must submit the request to a certificate authority (CA). patterns, enrollment patterns generated for any templates from CAs managed using a Keyfactor Universal OrchestratorClosed The Keyfactor Universal Orchestrator, one of Keyfactor's suite of orchestrators, is used to interact with servers and devices for certificate management, run SSL discovery and management tasks, and manage synchronization of certificate authorities in remote forests. With the addition of custom extensions, it can provide certificate management capabilities on a variety of platforms and devices (e.g. Amazon Web Services (AWS) resources, Citrix\NetScaler devices, F5 devices, IIS stores, JKS keystores, PEM stores, and PKCS#12 stores) and execute tasks outside the standard list of certificate management functions. It runs on either Windows or Linux servers or Linux containers. will result in an error similar to the following when the CAClosed A certificate authority (CA) is an entity that issues digital certificates. Within Keyfactor Command, a CA may be a Microsoft CA or a Keyfactor gateway to a cloud-based or remote CA./templateClosed A certificate template defines the policies and rules that a CA uses when a request for a certificate is received. cache attempts to build:
Unable to retrieve templates from CA 'CorpIssuingCA1.keyexample.com\CorpIssuingCA1': The RPC server is unavailable. (0x800706BA)

An enrollment pattern is automatically generated on upgrade for any certificate template for which at least one of the following is true:

The Keyfactor Universal OrchestratorClosed Keyfactor orchestrators perform a variety of functions, including managing certificate stores and SSH key stores. does not support certificate enrollment, so no enrollment patterns are required for templates from CAs managed with the orchestrator. To workaround this error, remove any enrollment patterns generated for these templates after upgrade.

Tip:  If, following the upgrade, you open a page in the Keyfactor Command Management Portal and find it unexpectedly blank or otherwise displaying incorrectly, try refreshing the page with a CTRL-F5. If this doesn't resolve the problem, try clearing the browser cache and then reloading the page. It may be helpful to advise all end users to do this following an upgrade.