---
title: "9.0.x to 9.0.4 Upgrade Prerequisites and Affected Features"
canonical: "https://docs.infoblox.com/space/niosupgrade/1320419911/9.0.x%20to%209.0.4%20Upgrade%20Prerequisites%20and%20Affected%20Features"
format: markdown
---
This section details general and specific upgrade prerequisites that you **must** follow before upgrading NIOS versions. It also details features that are impacted by a NIOS upgrade and guidelines that you **must **follow before the upgrade.

> Macro (toc)

> ℹ️ **Caution: **Powering off or resetting the appliance during an upgrade may cause the upgrade to fail and leave the system in an unusable state. Wait until the upgrade process is complete and till all associated scripts have been fully executed before initiating any power actions.

# NIOS 9.0.x to NIOS 9.0.4 Upgrade Prerequisites 

|  |  |
| --- | --- |
| **Target Version** | **9.0.4** |
| **Current Version** | **9.0.1 or 9.0.2 or 9.0.3** |

|  |  |
| --- | --- |
| Upgrade Critical | For NIOS 9.0.4, the CPUID hypervisor bit (CPUID(1)ECX:31 must be enabled for VM guests. It is the default for all VM hypervisors, but can be disabled in some hosting configurations. Do not disable it. Otherwise, the appliance may fail. |
| Certificates and Licenses | - If you try to upgrade to NIOS 9.0.x, the distribution fails if CA certificates with the `md5WithRSAEncryption` or `sha1WithRSAEncryption` ciphers are present. Infoblox recommends that you delete the certificates before upgrading.
- When you upgrade to NIOS 9.0.*x* and you upgrade or replace your X5 series appliance with an X6 series appliance and you have valid X5 series license, then you can use the X5 series on an X6 series appliance till the license expires. However, you need to contact Infoblox Support to generate a new X5 series license so that it will work with the X6 series appliance. The new license is generated with an X6 series appliance hardware ID and will have the X5 series license validity.
- Upgrading to NIOS 9.0.x is restricted, subject to the following checks:
  - CA certificates violating RFC: Subject Key Identifier MUST exist if CA=TRUE
  - Certificate validity dates
  - Restrict MD5 and SHA1 for HTTPS certificates and CA certificates
  - OpenVPN certificates. Contact Infoblox Support before proceeding with the distribution.
- If the Dual Engine DNS license is present in your Grid in the deleted or expired state (can be validated by running the show license CLI command on the node), contact Infoblox Support to have it removed. The NIOS upgrade fails if the license is not deleted. |
| Algorithm and Keys | - If you have used the ZSK or KSK algorithm key size 640 (which is invalid in BIND 9.16), the upgrade may fail.
- If the length of the DH key is lower than 1024, upgrade will fail. Before upgrading to 9.0.6 read the  KB #<u>[000009588](https://support.infoblox.com/s/article/How-to-recover-NIOS-from-old-certificate-related-issues)</u> and** ensure that the hotfix mentioned in the KB is applied before the upgrade**.
- Using an unsupported algorithm RSAMD5(1), DSA (3), DSA-NSEC3-SHA1(6) may cause the upgrade to fail.
- Using invalid key size for RSASHA1(5), RSA-NSEC3-SHA1(7), RSASHA256(8) (should be within range [1024 to 4096]) may cause the upgrade to fail.
- Manually creating (through the import keyset) a DNSSEC record with an unsupported algorithm or digest type SHA-1 may cause the upgrade to fail. |
| Threat Insight | - If you set up your Grid to use Infoblox Threat Insight (known as Threat Analytics in versions earlier than 9.0.5) but have not enabled automatic updates for Threat Insight (known as Threat Analytics in versions earlier than 9.0.5). module sets, you must manually upload the latest module set to your Grid or enable automatic updates before upgrading. Otherwise, your upgrade will fail.
- If the Threat Insight service is enabled before upgrading to NIOS 9.0.5 and later, read the KB article [000010304](https://support.infoblox.com/s/article/Threat-Insight-new-moduleset-release) to understand how to manage the feature functioning correctly post upgrade. You must have installed the minimum moduleset version (20210620) before upgrading to NIOS 9.*x*.
- There will be an impact on the CPU and DNS performance when Threat Insight is enabled.
- You can only run Threat Insight when a minimum disk size of 250 GB is set on the Grid member; the size includes upgrading with Threat Insight enabled on the member. Failing to do so may result in functionality issues. |
| Splunk | - Splunk does not support TLS version 1.3 and therefore NIOS reporting will not work if you disable all other TLS versions and enable only TLS version 1.3. A warning to this effect is displayed if you enable only TLS version 1.3. |
| Amazon Route 53 | - Before upgrading to NIOS 9.0.4 or later, Amazon Route 53 requires the AmazonRoute53ReadOnlyAccess permission for synchronization of data. Otherwise, add the following actions explicitly to the permission:
  - route53:GetHostedZone
  - route53:ListHostedZones
  - route53:ListResourceRecordSets
  - route53:ListTagsForResources
  - route53:ListQueryLoggingConfigs
  - route53:GetHealthCheck
- After an upgrade to NIOS 9.0.4 or later, for the Route 53 synchronization to function properly, ensure that your network firewall settings permit access to the global STS endpoint ([sts.amazonaws.com](http://sts.amazonaws.com)) and the regional STS endpoints specific to your region listed on the AWS STS Regions and endpoints page. This is crucial for establishing a connectivity between the NIOS appliance and your configured AWS accounts.
- After a scheduled upgrade to NIOS 8.6.3 and later is complete, you must run the command on the Grid Master to get the Cloud Sync (Cloud DNS Sync in 9.0.x versions prior to 9.0.4) service to be update_rabbitmq_password functional. Until that time, Route 53 synchronization does not start because the service has not been started. |
| Sort List | - From NIOS 9.0.0 onwards, when you define a sort list using the **Grid DNS Properties** > **Sort List **tab, ensure that you select or add a correct network and make sure that you set the correct prefix or netmask. Otherwise, the DNS service fails to start because of invalid configuration. An example of an invalid configuration is 11.14.73.0/16. An example of the syslog error is: /infoblox/var/named_conf/named.conf:60: '11.14.73.0/16': address/prefix length mismatch ‘16’ |
| RADIUS authentication | - The shared secret that you enter when adding a RADIUS authentication server in the *Add RADIUS Authentication Service* wizard >** RADIUS Servers** > **Shared Secret** field must be between 4 and 64 characters (inclusive) in length. Otherwise, the upgrade will fail. |

# NIOS 9.0.x to NIOS 9.0.4 Upgrade Affected Features

|  |  |
| --- | --- |
| **Target Version** | **9.0.4** |
| **Current Version** | **9.0.1 or 9.0.2 or 9.0.3** |

| **Affected Feature** | **Descriptions** |
| --- | --- |
| Certificates | - If you are using an Ubuntu client and a CA certificate of key length 1024 and some unsupported ciphers, after a NIOS upgrade, services that depend on the unsupported ciphers cease to work.
- Before you upgrade to NIOS 9.0.x, check the validity of the CA certificates uploaded. If the certificate is invalid, install a new certificate that is in compliance with RFCs (for example RFC 5280). Failure to do so may result in the Grid Manager UI/WAPI not being accessible after the upgrade. However, NIOS will continue to be functional. To check the validity of the certificate, contact Infoblox Support. |
| SSL security levels | During a normal upgrade, until the entire Grid is upgraded, Infoblox does not recommend that you toggle between the SSL security levels. If you have offline members prior to the upgrade migration, Infoblox recommends that you upgrade the members manually to the current version and then join. |
| Accelerated Networking | - Accelerated networking can be enabled for NIOS members in Microsoft Azure from version 9.0.5 onwards. This resolves an issue where accelerated networks had to be disabled on NIOS members in Microsoft Azure before upgrading to NIOS 9.0.0, 9.0.1, 9.0.2, 9.0.3, or 9.0.4.
- If you have enabled Accelerated networking or enabled SRIOV on NIOS members in Microsoft Azure, Infoblox requires you to upgrade to NIOS 9.0.5 or later. |
| Cloud Sync Service | - After an upgrade to NIOS 9.0.4 or later, the Cloud Sync service starts automatically on members that have AWS and GCP vDiscovery jobs configured.
- After an upgrade to NIOS 9.0.4 or later, the Cloud Sync service will not start automatically on members that have VMWare, Azure, and Openstack vDiscovery jobs configured. |
| Threat Protection | - If there are Threat Protection members in your Grid, for features such as Grid Master Candidate test promotion, forwarding recursive queries to Infoblox Threat Defense Cloud, and CAA records to function properly, ensure that you upload the latest Threat Protection ruleset. |
| Bandwidth | Make sure that the bandwidth between the nodes in a Grid is at least 100 Mbps or higher to ensure timely completion of distribution. In slower environments, distribution may take longer and may result in delays. |
| Images and Files | - Infoblox recommends that you use a minimum size of 150 GB when using discovery resizable images. This applies even when upgrading a resizable discovery image whose size is lower than 150 GB.
- Infoblox recommends using a minimum size of 150 GB for any of the files that has resizable as part of the file name, and you can resize them depending on your requirement and deployment. |
| SSO (Single Sign-On) | - If you are logging on to NIOS using SSO, in **IDP Configuration** you must enter the following URL in the **SP Entity ID **field: <grid_virtual IP address>:8765/metadata. If you are using Okta, the **SP Entity ID** field is also called the **Audience URI** field. |
| Cisco ISE Endpoint | - From NIOS 9.0.0 onwards, the Cisco ISE endpoint (Cisco pxGrid 1.0) has been deprecated. |