Trust 2024年07月05日
Required ZPA App Connector Manager and Private Service Edge Manager Upgrade - private.zscaler.com, zpatwo.net
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

Zscaler指出早于23.374.1版本的App Connector Manager或Private Service Edge Manager可能在2025年5月面临证书过期问题,影响ZPA升级,建议升级到23.374.1或更高版本,文中还介绍了多种升级方法及相关信息。

🎯Zscaler发现低于23.374.1版本的管理器可能存在证书过期问题,影响ZPA为所有部署了App Connectors或Private Service Edges的客户进行升级,此问题需引起重视。

📄Zscaler建议将所有App Connectors和Private Service Edges的Manager版本升级到23.374.1或更高,以使用最新的G2中间和根CA证书,符合Digicert政策。

💻文中详细介绍了针对不同操作系统和平台的App Connector Manager及Private Service Edge Manager的升级方法,如CentOS、Redhat、AWS、Microsoft Azure、VMware等。

❓对于一些特殊情况,如计划升级到RHEL9图像,若已安排则无需手动升级,新RHEL9图像包含新证书。同时还提到了如何检查管理器软件版本及有疑问时的解决途径。

Zscaler has determined that any App Connector Manager or Private Service Edge Manager version that is earlier than 23.374.1 would potentially face certificate expiration issue by May 2025. The certificate expiration affects ZPA’s ability to upgrade the App Connector or the Private Service Edges for any and all customers that have App Connectors or Private Service Edges deployed. 

 

More details on the new G2 certificate policy by Digicert is available at the below link https://knowledge.digicert.com/general-information/digicert-root-and-intermediate-ca-certificate-updates-2023 

 

 

Zscaler recommends that the Manager version of all App Connectors and Private Service Edges should be on version 23.374.1 or later in order to use the latest G2 intermediate and root CA certificates as aligned with the above Digicert Policy. The certificate expiration affects ZPA’s ability to upgrade the deployed App Connectors or the Private Service Edge.

 

To upgrade App Connector Manager for CentOS, and Redhat, use the yum update command. For example:

[admin@zpa-connector ~]$ sudo yum update zpa-connector
[admin@zpa-connector ~]$ sudo systemctl restart zpa-connector

To learn more, see App Connector Deployment Guide for CentOS, Oracle, and Redhat and Managing Deployed App Connectors. To upgrade for Amazon Web Services (AWS), Microsoft Azure, VMware, and other supported platforms, see App Connector Deployment Guides for Supported Platforms.

To upgrade Private Service Edge Manager for CentOS, Oracle, and Redhat, use the yum update command. For example:

[admin@zpa-service-edge ~]$ sudo yum update zpa-service-edge
[admin@zpa-service-edge ~]$ sudo systemctl restart zpa-service-edge

To learn more, see Service Edge Deployment Guide for CentOS, Oracle, and Redhat and Managing Deployed ZPA Private Service Edges. To upgrade for Amazon Web Services (AWS), Microsoft Azure, VMware, and other supported platforms, see Private Service Edge Deployment Guides for Supported Platforms.

 

Do I need to perform this upgrade if I plan to upgrade to RHEL9 images?

If you have already scheduled upgrading App-Connector and PSE to RHEL9 images then the manual upgrade noted above is not needed as the new RHEL9 images contain new certificates.

 

How does this affect me?

ZPA relies on App Connector Manager and Private Service Edge Manager to configure and manage App Connector and Private Service Edge software and services. ZPA will not be able to upgrade App Connector and Private Services Edges if App Connector Manager and Private Service Edge Manager are outdated.You will not be able to apply bug fixes and new enhancements unless you upgrade.

 

How to check the Manager Software version?

App Connector: Configuration & Control > Private Infrastructure  > App Connector Management > App Connector : the second column shows the manager version of each App Connectors

Private Service Edge: Configuration & Control > Private Infrastructure > Private Service Edge Management >   Private Service Edge : the second column shows the manager version of each Private Service Edges

 

What if I have more questions? 

If you have additional questions, contact Zscaler Support via the Support link in the Admin Portal or contact us at +1-408-701-0534. Within the U.S., you can use 1-800-953-3897.

 

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

Zscaler 证书过期 软件升级 管理器版本
相关文章