Upgrade on Windows - SSO
These are the upgrade instructions to the latest release: SSO 9.1. If you are upgrading from a SSO 8.x.x version, ensure the upgrade steps to SSO 9.0 (Java11) have been considered.
Note: we have removed all upgrade steps for SSO 8.x.x to SSO 9.0.0 - please ensure you follow the required upgrade instructions to move from SSO 8.x.x to SSO 9.0.0 then follow these upgrade steps to SSO 9.1.0
IMPORTANT: Sign in using an Administrator account - the same account used during initial product installation.
Stop the services that are running,
ubisecureaccountingis a new service since 8.4.net stop ubiloginserver net stop ubilogindirectory net stop ubisecureaccountingRemove SSO and Accounting Service Windows service configurations
cd "C:\Program Files\Ubisecure\ubilogin-sso\ubilogin" config\tomcat\remove.cmdMove the existing installation to ubilogin-sso-old directory.
cd "C:\Program Files\Ubisecure\" move ubilogin-sso ubilogin-sso-oldExtract the archive
ubilogin-sso-8.x.x.xxxxx.zipto a temporary location.Move the complete unzipped ubilogin-sso directory from the distribution package to
C:\Program Files\Ubisecure.Copy
win32.configandconfig.indexfile from the older version. Overwriteconfig.index.copy "C:\Program Files\Ubisecure\ubilogin-sso-old\ubilogin\win32.config" "C:\Program Files\Ubisecure\ubilogin-sso\ubilogin\win32.config" copy "C:\Program Files\Ubisecure\ubilogin-sso-old\ubilogin\config.index" "C:\Program Files\Ubisecure\ubilogin-sso\ubilogin\config.index"Verify the following Accounting Service related settings in
C:\Program Files\Ubisecure\ubilogin-sso\ubilogin\win32.configare according to your requirements, check these guidelines.# Accounting configuration accounting.url = https://localhost:8442 accounting.proxy.local.url = @accounting.url@ accounting.instancename = UbisecureAccounting accounting.username = @tomcat.username@ accounting.datasource.url = jdbc:postgresql://localhost:5432/accountingdb accounting.datasource.username = accounting.datasource.password = accounting.secret-key-location-uri = file:///${user.dir}/config/accounting-service.secret accounting.actuator.username = accounting_admin accounting.actuator.password = accounting.jms.broker.port = 36161 accounting.jms.broker.socket-timeout-ms = 10Depending of the location of your Accounting Service secret key you may need to copy the file from the older version. NOTE: The secret key must be the same during the entire reporting period which is a month, see Accounting Service security. Example (use the path you have set in the configuration):
mkdir "C:\Program Files\Ubisecure\ubilogin-sso\accounting\config" copy "C:\Program Files\Ubisecure\ubilogin-sso-old\accounting\config\accounting-service.secret" "C:\Program Files\Ubisecure\ubilogin-sso\accounting\config"Copy the following files and directories (recursively) from the previous installation to the matching
ubilogin-ssodirectory. Note that Tomcat, Ubisecure SSO, and Accounting Service logs are retained.xcopy "C:\Program Files\Ubisecure\ubilogin-sso-old\ubilogin\custom" "C:\Program Files\Ubisecure\ubilogin-sso\ubilogin\custom" /e /y xcopy "C:\Program Files\Ubisecure\ubilogin-sso-old\ubilogin\methods" "C:\Program Files\Ubisecure\ubilogin-sso\ubilogin\methods" /e /y xcopy "C:\Program Files\Ubisecure\ubilogin-sso-old\ubilogin\logs" "C:\Program Files\Ubisecure\ubilogin-sso\ubilogin\logs" /e /y xcopy "C:\Program Files\Ubisecure\ubilogin-sso-old\tomcat\logs" "C:\Program Files\Ubisecure\ubilogin-sso\tomcat\logs" /e /y xcopy "C:\Program Files\Ubisecure\ubilogin-sso-old\accounting\logs" "C:\Program Files\Ubisecure\ubilogin-sso\accounting\logs" /e /y copy "C:\Program Files\Ubisecure\ubilogin-sso-old\ubilogin\webapps\cdc\WEB-INF\config.properties" "C:\Program Files\Ubisecure\ubilogin-sso\ubilogin\webapps\cdc\WEB-INF\config.properties" copy "C:\Program Files\Ubisecure\ubilogin-sso-old\ubilogin\webapps\ROOT\robots.txt" "C:\Program Files\Ubisecure\ubilogin-sso\ubilogin\webapps\ROOT\robots.txt"Check the Common Domain Cookie Discovery.
Run the setup script
cd "C:\Program Files\Ubisecure\ubilogin-sso\ubilogin" setup.cmdAfter the setup script, you may still need to check some files from the backup folder if you have customized them. Compare the files under
C:\Program Files\Ubisecure\ubilogin-sso-oldwith the ones underC:\Program Files\Ubisecure\ubilogin-ssoand copy the necessary changes from:C:\Program Files\Ubisecure\ubilogin-sso-old\ubilogin\webapps\uas\WEB-INF\uas.properties C:\Program Files\Ubisecure\ubilogin-sso-old\ubilogin\webapps\totp\WEB-INF\application.yamlEnsure that a supported version of PostgreSQL is installed and running - for supported versions, see System Recommendations), additional links in our documentation: PostgreSQL preparation on Windows, Upgrade and migrate to new version of PostgreSQL
Start the UbiloginDirectory service
net start ubilogindirectoryUpgrading Ubisecure Directory
To update your ADAM or AD LDS installation, the schema and directory settings of the instance must be updated. Before starting, make sure that you are logged in with the same user account that was used to install ADAM or AD LDS.
To update the schema and directory settings, execute the command adaminstall.cmd shown below.This command updates the LDAP schema and does not delete existing user or configuration data.
cd "C:\Program Files\Ubisecure\ubilogin-sso\ubilogin\ldap" adam\adaminstall.cmdAdd new entries and update LDAP secrets:
adam\import-changes.cmdCheck Password application.
Skip this step if the Password application is not enabled.
Copy the following files to the matching ubilogin-sso directory:
C:\Program Files\Ubisecure\ubilogin-sso-old\ubilogin\webapps\password\WEB-INF\password.properties C:\Program Files\Ubisecure\ubilogin-sso-old\ubilogin\webapps\password\WEB-INF\saml2Edit
server.xml fileand uncomment:<Context path="/password" docBase="${catalina.base}/webapps/password"/>notepad C:\Program Files\Ubisecure\ubilogin-sso\ubilogin\config\tomcat\conf\server.xmlAlso check web.xml for mail.smtp.host and mail.smtp.from configuration and copy those to new web.xml (C:\Program Files\Ubisecure\ubilogin-sso\ubilogin\webapps\password\WEB-INF\web.xml)
notepad C:\Program Files\Ubisecure\ubilogin-sso-old\ubilogin\webapps\password\WEB-INF\web.xmlVerify your Accounting Service customisation in
C:\Program Files\Ubisecure\ubilogin-sso\ubilogin\custom\accounting\config\application.yamlappears as you require, check Accounting Service additional configuration about the properties to set. Remember secret key in the location referred byaccounting.secret-key-locationinwin32.configmust exist. See Accounting Service security about the usage of the key for pseudonymisation.Update Tomcat and Accounting Service configuration and restart the services. Since version 8.4 remove should be done before installation directory is replaced. About Accounting Service start see also Windows single node installation.
cd "C:\Program Files\Ubisecure\ubilogin-sso\ubilogin" config\tomcat\install.cmdEnsure that you have imported initial signing and decryption key via
initial-key.ldif. This should have been completed during earlier upgrades.The system upgrade is complete, see also Single node installation finalization
Either securely remove the backed up ubilogin-sso-old directory, or rename it and store it in a secure location. All configuration files in the old installation directory (win32.config and unix.config) should either be removed from the system or otherwise protected from unauthorized users.
Clear your web browser’s cache before accessing the user interface.
This web page (including any attachments) may contain confidential, proprietary, or privileged information – not for disclosure without authorization from Ubisecure Inc. Copyright © 2026. All Rights Reserved.