BCAAA 5.5.x Service Requirements BCAAA Versions: 5.5.x Image Location: https://bto.bluecoat.com/download/product/14447 SGOS Compatibility: SGOS 5.4, 5.5, 6.1, 6.2, 6.3, 6.4 and 6.5 Platform Compatibility: Windows Server 2000, 2003, 2008, 2012 Revision: July, 2013 This document describes the BCAAA compatibility and upgrade/downgrade requirements for SGOS versions that use BCAAA 5.5x. This version of BCAAA, which is compatible with Windows Server 2003, will continue to be supported through the end of Microsoft s extended support for Windows Server 2003. The information in this document supersedes all BCAAA information found elsewhere. Important: Blue Coat has since updated its authentication agent to version BCAAA 6.1. This update includes support for additional Blue Coat products, such as PacketShaper, as well as some performance and reliability enhancements. These latter enhancements rely on the newer APIs provided in Windows Server 2008 and later; these are the only Windows Server versions compatible with BCAAA 6.1. Blue Coat recommends that customers using Windows Server 2008 or later upgrade to BCAAA 6.x to take advantage of ongoing software enhancements and support. BCAAA 6.1 is compatible with SGOS 5.4, 5.5 and all currently available 6.x releases For information about installing BCAAA 6.1, refer to the BCAAA 6.1 Service Requirements. About this Guide This guide does not include BCAAA installation instructions. Refer to the BCAAA information in the Administration Guide corresponding to your SGOS release for those instructions. All documentation is available at https://bto.bluecoat.com/documentation For information on SGOS releases, please refer to the Release Note that corresponds to the SGOS version to which you are upgrading. Topics in this document: "BCAAA 5.5.x Operating System Requirements" on page 2 1
"BCAAA Disk Space Requirements" on page 3 "About the BCAAA Upgrade/Downgrade Process" on page 4 "Using Multiple Versions of the BCAAA Service" on page 4 "Fix Matrix" on page 5 BCAAA 5.5.x Operating System Requirements The following list describes the platforms that BCAAA can run on to support the specified authentication method. For a list of supported operating systems for your directory services, see "Compatible Directory Service Operating Systems" on page 3. Table 1 1 Supported Authentication Methods Platforms 2012 (64-bit) 2008 (64-bit) 2008 (32-bit) 2008 R2 (64-bit) Windows 2008 Domain Controller Windows 2008 Read-Only Domain Controller 2003 (64-bit) 2003 (32-bit) Windows 2000 Server (32-bit) Solaris 5.8 or 5.9 Supported Authentication Methods Integrated Windows Authentica tion Oracle COREid version 6.5 and 7.0 CA etrust SiteMinder version 5.5 and 6.0 Windows SSO Novell SSO 2
Important: BCAAA can run on any hardware as long as the preceding operating system requirements are met. For virtual machine deployments on Windows, please see the appropriate documentation for your Windows platform and the virtual machine software to ensure compatibility. The BCAAA service cannot be installed on Windows NT, Windows Vista, or Windows 7. Compatible Directory Service Operating Systems The only compatible directory service operating systems for the authentication methods listed in Table 1 1: "Supported Authentication Methods" on page 2 are: Windows Server 2000 Windows Server 2003 Windows Server 2003 R2 Windows Server 2008 Windows Server 2008 R2 Windows Server 2008 Read-Only Domain Controller Windows Server 2012 Solaris 5.8 and 5.9 (SiteMinder and COREid only) Note: BCAAA can be run directly on a server that is also acting as a domain controller. The domain controller can be in full Read-Write or Read Only operation. BCAAA Disk Space Requirements To install BCAAA, make sure that you have at least 45 MB of disk space on your Windows server. Although some versions of BCAAA might require less than 45 MB of disk space, allocating 45 MB of disk space will address the needs to complete the BCAAA installation process. Additional space might be required, depending on the features that have been enabled. If using Windows SSO with Domain Controller Query Add 256 bytes for each concurrent login. For example, if 1000 users will be concurrently logged in to the Windows domain during peak hours, then this feature requires 256k (256 bytes record * 1000 concurrently logged in users). If using Novell SSO Add 256 to 512 bytes for each user concurrently logged in to Novell edirectory. You only need to count users that are in containers that are monitored by a Novell SSO realm. 3
For Novell SSO, the record length is dependant on the length of each user s distinguished name in edirectory. Users with long distinguished names require extra storage. Because distinguished names have a maximum length of 256 bytes in edirectory, an individual Novell SSO record will not be larger than 512 bytes. About the BCAAA Upgrade/Downgrade Process Before upgrading to, or downgrading from your current SGOS version, you must first install the BCAAA version required for the release you are migrating to. This procedure is described in the Upgrade Guide, refer to the appropriate document for your SGOS version: SGOS Version SGOS 5.4.x SGOS 5.5.x SGOS 6.1.x SGOS 6.2.x SGOS 6.3.x SGOS 6.4.x Upgrade Guide Link on BTO https://bto.bluecoat.com/doc/12117 https://bto.bluecoat.com/doc/12580 https://bto.bluecoat.com/doc/14786 https://bto.bluecoat.com/doc/16295 https://bto.bluecoat.com/doc/17153 https://bto.bluecoat.com/doc/17370 WARNING! If you do not install the compatible BCAAA version before upgrading or downgrading, authentication fails and you will not be able to reach the BCAAA server to download a compatible version without bypassing the ProxySG. Using Multiple Versions of the BCAAA Service Accessing ProxySG appliances running different versions of SGOS requires multiple version of the BCAAA service to be installed on your computer. Before installing the SGOS version, always ensure you are running the compatible BCAAA version for that release. You must install the compatible BCAAA service before upgrading or downgrading the SGOS version on your ProxySG appliances. Install the lowest version of the BCAAA service first and the highest version of BCAAA last, allowing each version to uninstall the previous version. This process leaves behind the bcaaa.ini and bcaaa-nn.exe files for the lower version. Only one listening port is used, no matter how many versions you have installed. The BCAAA service hands off the connection to the appropriate BCAAA version. Installation instructions for BCAAA are located in the BCAAA chapter of the Blue Coat SGOS Administration Guide for your SGOS version. This document is accessible through your BlueTouch Online account at https://bto.bluecoat.com/documentation/pubs/proxysg 4
Fix Matrix This section lists BCAAA issues that have been resolved. SGOS 5.5.10.1 Fixed an issue in which Windows SSO sometimes stopped the domain controller query when a DC could not be found through the DNS service. (B#177099, SR-2-465952782) 2013 Blue Coat Systems, Inc. All rights reserved. BLUE COAT, PROXYSG, PACKETSHAPER, CACHEFLOW, INTELLIGENCECENTER, CACHEOS, CACHEPULSE, CROSSBEAM, K9, DRTR, MACH5, PACKETWISE, POLICYCENTER, PROXYAV, PROXYCLIENT, SGOS, WEBPULSE, SOLERA NETWORKS, DEEPSEE, DS APPLIANCE, SEE EVERYTHING. KNOW EVERYTHING., SECURITY EMPOWERS BUSINESS, BLUETOUCH, the Blue Coat shield, K9, and Solera Networks logos and other Blue Coat logos are registered trademarks or trademarks of Blue Coat Systems, Inc. or its affiliates in the U.S. and certain other countries. This list may not be complete, and the absence of a trademark from this list does not mean it is not a trademark of Blue Coat or that Blue Coat has stopped using the trademark. All other trademarks mentioned in this document owned by third parties are the property of their respective owners. This document is for informational purposes only. BLUE COAT MAKES NO WARRANTIES, EXPRESS, IMPLIED, OR STATUTORY, AS TO THE INFORMATION IN THIS DOCUMENT. BLUE COAT PRODUCTS, TECHNICAL SERVICES, AND ANY OTHER TECHNICAL DATA REFERENCED IN THIS DOCUMENT ARE SUBJECT TO U.S. EXPORT CONTROL AND SANCTIONS LAWS, REGULATIONS AND REQUIREMENTS, AND MAY BE SUBJECT TO EXPORT OR IMPORT REGULATIONS IN OTHER COUNTRIES. YOU AGREE TO COMPLY STRICTLY WITH THESE LAWS, REGULATIONS AND REQUIREMENTS, AND ACKNOWLEDGE THAT YOU HAVE THE RESPONSIBILITY TO OBTAIN ANY LICENSES, PERMITS OR OTHER APPROVALS THAT MAY BE REQUIRED IN ORDER TO EXPORT, RE-EXPORT, TRANSFER IN COUNTRY OR IMPORT AFTER DELIVERY TO YOU. 5
Americas: Rest of the World: Blue Coat Systems, Inc. Blue Coat Systems International SARL 420 N. Mary Ave. 3a Route des Arsenaux Sunnyvale, CA 94085 1700 Fribourg, Switzerland 6