top of page

Stronger Identity,
Happier Customers.

Ready to modernize your identity infrastructure?

Let's secure your growth together.

How our Accelerators can enable you to upgrade your End of Life ForgeRock, economically!

  • Writer: Ajit  Gupta
    Ajit Gupta
  • May 20, 2020
  • 3 min read

Updated: Sep 19, 2025

Migrating data from OLD servers to secure NEW cloud storage

Access Management release and EOSL dates

Directory Services release and EOS dates

If this is daunting for you, or you are worried about budget/expertise, then Midships can support your upgrade using our low-cost accelerators for ForgeRock Access Manager (openAM) and Directory Services (openDJ) to reduce the complexity and therefore the overall risk, time and cost of the upgrade process.

It's also worth noting that by upgrading to the latest version, you will be able to take advantage of some great new features including authentication trees as well as move to containerised services.

The remainder of this blog shows you how our upgrade accelerator works...

The ForgeRock upgrade tool is a combination of automated infrastructure tools and an intuitive UI that will upgrade your ForgeRock stack typically in less than one hour (and often less than 30 minutes), requiring minimal configuration such as hostnames, paths and keys.

The UI is divided into two tabs, one for upgrading the existing Directory Services servers and another one to upgrade the Access Manager instances.

For our blog, we are going to use the following FR deployment:


OpenAM and OpenDJ cluster architecture diagram

ForgeRock architecture is composed by two highly available openAM instances and two highly available openDJ directories with self-replication enabled that will serve as Configuration, Token, and Identity store.

Note that the upgrade tool is fully scalable and is not restricted to a certain number of replicas for OpenAM or OpenDJ instances. Also note that the upgrade is also suitable for customers with dedicated DJ instances for token/config and identity stores.

We can verify that the OpenDJ instances are running the specified version (3.5.3) and that they are self-replicating data:


OpenLDAP server status:  'cn=Directory Manager', started, 26 open connections

Green text on black background; illegible

We can also verify the cluster configuration and OpenAM version on the deployed OpenAM instances:


Servers configuration interface showing two servers with add server button

The Upgrade...

We start by running our self contained upgrade accelerator and updating our tab for openDJ:


OpenDJ 3.x to latest Directory Server/Services (6.x) upgrade settings

Once we configure the required parameters and select "Deploy to Pipeline" this will trigger the execution of a job in our pipeline that will manage the upgrade of the targeted servers.

When the pipeline job is finished, we can verify on the OpenDJ servers that they have been successfully upgraded to the latest DS version (6.5.3):


ForgeRock Directory Services 6.5.3 server details: status, ports, and connection handlers

and IT'S DONE...

For OpenAM, it is much the same, simply update our tab for OpenAM:


OpenAM 13.x to Access Manager 6.5.x upgrade settings

Once we configure the required parameters and select "Deploy to Pipeline" this will trigger the execution of a job in our pipeline that will manage the upgrade of the targeted servers.

When the pipeline job is finished, we can verify on the OpenAM servers that they have been successfully upgraded to the latest version (6.5.2):


ForgeRock Servers configuration: Add a Server

and IT'S DONE...

With regard to any bespoke plugins, we can migrate those as part of the upgrade by just placing the relevant AM plugins (Jar files) into the /plugins folder in the AM upgrade accelerator source control. This will ensure that no bespoke feature is lost during the upgrade process.

Note that where the plugins use Java Code that has been deprecated, these will need to be updated before you switch across.

As many ForgeRock customers will be aware, ForgeRock 13.x will reach end of life at the end of this year, with 5.5 following in April 2021 :-(

To learn more about our upgrade accelerator or see a demo, please contact us at sales@midshios.io


Writer’s Overview

Ajit Gupta – Co-Founder & CEO, Midships

Ajit leads Midships Group’s transition from a specialist identity consultancy to a portfolio of autonomous, AI-native business units. He focuses on long-term business relevance through platform thinking, customer outcomes, and scalable operating models.

Short bio: Ajit is a strategic founder with deep expertise in IAM, platform delivery, and AI services, driving Midships’ expansion across Asia, the Middle East, and beyond.

Comments


bottom of page