Hello,
we will need to redeploy to all our endpoints ? will that require remote registry service being enabled?
If you don't want to redeploy - this is possible. But first a question: do you want to migrate any/all settings or will you start from scratch?
Caution: this is a summary and not a step-by-step guide
In all cases export the HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\Certification Manager keys from the "old" server and import them on the new one before installing SEC (whether SEC3.1 or SEC4).
Please see also Re: Backup, Restore and Migrate Server Help
1) If starting from scratch:
Install SEC4 on the new server and make all necessary configurations. In your old CID(s) edit mrinit.conf to point to the new server ("MRParentAddress" and "ParentRouterAddress") and place it in the \RMS subdirectory, then use ConfigCID.exe. Article 14635 contains details (but of course we do want to modify "MRParentAddress"). The clients will then report to the new server and appear in the Unassigned group. After they've been assigned to their group they will get the new policies and upgrade to SESC 9.
[Edit:] Dunno why I didn't think of the simpler approach - rather than editing just copy the mrinit.conf from the new server as it should contain the required settings [/Edit]
2) If migrating on the new server
Install SEC3.1 on the new server. Export/import the database and EM Library settings (requires editing) to the new server. You will of course have to edit the updating policies. Do with mrinit.conf as above. After the clients have "switched" to the new server migrate to SEC4.
3) if migrating on the old server
Migrate to SEC4 on the old server. Migrate all clients and remove EM Library. Install SEC4 on the new server and export/import the database. Haven't done this (i.e. restored a SOPHOS4 database on a different server) so I don't know what changes will have to be made in the Update Managers section. If an article already exists I haven't found it. Do with mrinit.conf as above.
Christian