Thank you for your feedback.
Form temporarily unavailable. Please try again or contact to submit your comments.

Schedule an Edge Encryption proxy server upgrade

Log in to subscribe to topics and get notified when content changes.

Schedule an Edge Encryption proxy server upgrade

Create an upgrade schedule to enable the instance to upgrade an out-of-date proxy server.

Before you begin

To schedule an upgrade, you must be logged in to your instance through the proxy server.

If using AES 256-bit encryption with Java 8 update 141 (8u141) or lower, you must install the Java Cryptography Extension (JCE) jurisdiction policy files by copying them into the system Java home directory of each Edge Encryption proxy server host. Add these files to the <Java-home-directory>/jre/lib/security folder before performing a scheduled or manual upgrade. To install the AES 256-bit encryption policy files, see Enable AES 256-bit encryption for Java 8 update 141 (8u141) or lower.

Role required: security_admin

About this task

Once the upgrade is scheduled, the proxy server automatically upgrades at the scheduled time. During the upgrade, the proxy server is offline for only a short time.

Note: Because the proxy server restarts during the upgrade, it is offline for a short time. The amount of time is determined by your environment and how long it takes to stop and restart the proxy service.
During the scheduled upgrade, a new proxy directory is created and your configuration files are copied to the new directory. New properties are written to your existing properties file. The following files or directories in your old proxy directory are copied to the new proxy directory.
  • /conf directory
  • /keys directory
  • /keystore directory
  • java/jre/lib/security/cacerts file

As a result, your keys, keystores, settings, and certificates are preserved.

Note: Only the above files are copied to the new proxy directory. Any other customized files in the proxy server directory will not be preserved during a scheduled upgrade. The upgrade log file can be found in the original proxy directory in the following folder: <original-proxy-directory>/tmp/upgrade-wrapper/bin.

If multiple proxy servers are out-of-date, you must schedule an upgrade for each proxy server individually.

Note: Avoid hosting multiple proxy servers on the same machine. However, if your environment includes this configuration, do not schedule upgrades to multiple proxies on the same machine at the same time.


  1. Navigate to Edge Encryption Configuration > Proxies > Upgrade Schedules.
  2. Click New.
  3. Complete the form.
    Table 1. Edge Encryption Proxy Upgrade Schedule form
    Field Description
    Proxy server Proxy server being upgraded.
    Target version Version to which you are upgrading your proxy server. This value is read-only and set to the most up-to-date proxy version available for your instance.
    Scheduled Start Time Date and time on which to start the upgrade.
    Active Whether the scheduled upgrade is active. If this field is not selected, the upgrade will not perform on the scheduled date and time.
    Status The status of the upgrade. This value is read-only. Possible statuses include:
    • Pending
    • Running
    • Complete
    • Failed
  4. Click Submit.

What to do next

After an upgrade is executed, you can review the upgrade details to learn more about it. If your upgrade failed, review the Failure Reason to determine next steps.
Table 2. Upgrade details
Field Description
From Version The version that the server was upgraded from.
To Version The version that the server was upgraded to.
Actual Start Time Time that the upgrade began.
End Time Time that the upgrade ended.
Failure Reason Reason that the upgrade failed.