Upgrade requirements and considertations

Software license file

  • Have your software license file ready:
  • The system verifies the software license file before you can continue. Already added hardware devices and other devices that require licenses will enter a grace period. If you have not enabled automatic license activation (see Enable automatic license activation), remember to activate your licenses manually before the grace period expires.

    If you do not have your software license file, contact your XProtect reseller.

    New product version

    Have your new product version software ready. You can download it from the download page on the Milestone website.

    System backup

    Make sure that you have backed up the system configuration (see Backing up and restoring your system configuration )

    The management server stores the system configuration in a SQL Server database. The SQL Server database can be located in a SQL Server instance on the management server machine itself or in a SQL Server instance on the network.

    If you use a SQL Server database in a SQL Server instance on your network, the management server must have administrator permissions on the SQL Server instance whenever you want to create, move or upgrade the SQL Server database. For regular use and maintenance of the SQL Server database, the management server only needs to be a database owner.

    Milestone XProtect cannot be installed or upgraded using an MS-SQL database enrolled in a database mirroring session or an availability group because some operations cannot run on this kind of database. Remove the database from the availability group or mirroring session during the installation or upgrade. After the installation or upgrade is complete, the database can be enrolled in a mirroring session or an availability group again.

  • Encryption
  • If you plan to enable encryption during installation, you need to have the proper certificates installed and trusted on relevant computers.
  •  
  • Device packs
  • Device drivers are split into two device packs: the regular device pack with newer drivers and a legacy device pack with older drivers. The regular device pack is always automatically installed with an update or upgrade. If you have older cameras that use device drivers from the legacy device pack, and you do not have a legacy device pack installed already, the system does not automatically install the legacy device pack.

    If your system has older cameras, check if the cameras use drivers from the legacy device pack on this page (https://www.milestonesys.com/support/software/device-packs/). To check if you have the legacy pack installed already, look in the XProtect system folders. If you need to download the legacy device pack, go to download page (https://www.milestonesys.com/download/).

    Upgrade XProtect VMS to run in FIPS 140-2 compliant mode

    From version 2020 R3, XProtect VMS is configured to run so that it uses only the FIPS 140-2-certified algorithm instances.

    For detailed information on how to configure your XProtect VMS to run in FIPS 140-2 compliant mode, see the FIPS 140-2 compliance section in the hardening guide.

    For FIPS 140-2 compliant systems, with exports and archived media databases from XProtect VMS versions prior to 2017 R1 that are encrypted with non FIPS-compliant cyphers, it is required to archive the data in a location where it can still be accessed after enabling FIPS.

    The following process describes what is necessary to configure XProtect VMS to run in FIPS 140-2 compliant mode:

    1. Disable the Windows FIPS security policy on all of the computers that are part of the VMS, including the computer that hosts SQL Server.

      When you upgrade, you cannot install XProtect VMS when FIPS is enabled on the Windows operating system.

    2. Ensure standalone third-party integrations can run on a FIPS enabled Windows operating system.

      If a standalone integration is not FIPS 140-2 compliant, it cannot be run after you set Windows operating system to operate in FIPS mode.

      To prevent this:

      • Make an inventory of all your standalone integrations to XProtect VMS
      • Contact the providers of these integrations and ask if the integrations are FIPS 140-2 compliant
      • Deploy the FIPS 140-2 compliant standalone integrations
    3. Ensure that the drivers, and hence the communication to the devices, adhere to FIPS 140-2 compliance.

      XProtect VMS is guaranteed and can enforce FIPS 140-2 compliant mode of operation if the following criteria are met:

      • Devices use only compliant drivers to connect to XProtect VMS

        See the FIPS 140-2 compliance section in the hardening guide for more information about drivers that can assure and enforce compliance.

      • Devices use device pack version 11.1 or higher

        Drivers from the legacy driver device packs cannot guarantee a FIPS 140-2 compliant connection.

      • Devices are connected over HTTPS and on either Secure Real-Time Transport Protocol (SRTP) or Real Time Streaming Protocol (RTSP) over HTTPS for the video stream

        Driver modules cannot guarantee FIPS 140-2 compliance of a connection over HTTP. The connection may be compliant, but there is no guarantee that it is in fact compliant.

      • The computer that is running the recording server runs Windows OS with FIPS mode enabled
    4. Ensure that data in the media database is encrypted with FIPS 140-2 compliant ciphers.

      This is done by running the media database upgrade tool. For detailed information on how to configure your XProtect VMS to run in FIPS 140-2 compliant mode, see the FIPS 140-2 compliance section in the hardening guide.

    5. Before you enable FIPS on the Windows operating system, and after you have configured your XProtect VMS system and ensured that all components and devices can run on a FIPS enabled environment, update your existing hardware passwords in the XProtect Management Client.

      To do this, in the Management Client, from the selected recording server in the Recording Servers node, right-click and select Add Hardware. Progress through the Add hardware wizard. This will update all the current credentials and encrypt them to be FIPS-compliant.

    You can enable FIPS only after you have upgraded the entire VMS, including all clients.