If you have multiple vRealize Automation 6.2.x tenants and IaaS administrators, use the Identity Stores Migration Tool to migrate your tenant administrators to your newly synchronized vsphere.local tenant. Alternatively, you can add them manually to the respective tenants.

About this task

In a Linux environment, run the Identity Stores Migration Tool as administrator.

In a Windows environment, you must have administrative rights on the machine where you run the Identity Stores Migration Tool.

Prerequisites

Log in to the management console of the master vRealize Automation appliance that you upgraded.

Procedure

  1. Go to the management console for your virtual appliance by using its fully qualified domain name, https://va-hostname.domain.name:5480.
  2. Log in with the user name root and the password you specified when the appliance was deployed.
  3. Select vRA Settings > SSO.
  4. Perform the following steps according to your operating system.

    Linux

    1. Right-click Identity Stores Migration Tool and select Copy Link Address.

    2. Open a secure shell connection as root user to your vRealize Automation 6.2.x SSO virtual appliance.

    3. At the command prompt, run the following command to download the vra-sso-migration.zip file using the link you copied in step 4a.

      wget --no-check-certificate URL_link_address

      For example, wget --no-check-certificate https://va_hostname.vcac.local:5480/service/cafe/download/vra-sso-migration.zip.

    4. Run the following command to unzip the migration file.

      unzip vra-sso-migration.zip

    5. In the directory where you extracted vra-sso-migration.zip, change directories to bin.

      cd bin

    6. Edit the migration.properties file in the bin directory to change the value of property vra.system.admin.username from administrator to administrator@vsphere.local.

    7. Run the following command to migrate your tenants and IaaS administrators to your newly synchronized vsphere.local tenant.

      ./reassign-tenant-administrators

      Because you are logged in as root user, do not use sudo to run this script.

      Even if you see your tenant users assigned in your tenant before running this command, you must run this command to register your users in Horizon to obtain full tenant administrator privileges.

    WIndows

    1. Double-click Identity Stores Migration Tool to download the tool to your Downloads directory.

    2. Log in to the Windows machine where SSO is running.

    3. Copy the vra-sso-migration.zip file from your Downloads directory to a local directory of your choice.

    4. Right-click vra-sso-migration.zip and select Extract all.

    5. Open the extracted vra-sso-migration folder and open the bin folder.

    6. Edit the migration.properties file in the bin directory to change the value of property vra.system.admin.username from administrator to administrator@vsphere.local with the full address including the tenant extension.

    7. Right-click reassign-tenant-administrators.bat and select Run as administrator.

      Even if you see your tenant users assigned in your tenant before running this command, you must run this command to register your users in Horizon to obtain full tenant administrator privileges.

  5. Log in to the vRealize Automation appliance default tenant as tenant administrator. For each tenant, verify that under the Administrators tab you can see the list of migrated tenant administrators.

What to do next

Upgrade the secondary appliances. See Install the Update on Additional vRealize Automation 6.2.4 or 6.2.5 Appliances.