---
title: Upgrade from DS 7.4.0
description: Steps to upgrade from PingDS 7.4.0 when using default data encryption, working around an incompatibility introduced in that release.
component: pingds
version: 8
page_id: pingds:upgrade-guide:from-740
canonical_url: https://docs.pingidentity.com/pingds/8.1/upgrade-guide/from-740.html
llms_txt: https://docs.pingidentity.com/pingds/llms.txt
docs_for_agents: https://developer.pingidentity.com/build-with-ai/docs-for-agents.md
revdate: 2025-05-21T10:02:12Z
keywords: ["LDAP", "Upgrade"]
superseded_by: https://docs.pingidentity.com/pingds/8.1/upgrade-guide/from-740.html
section_ids:
  the_problem: The problem
  the_solution: The solution
  next_steps: Next steps
---

# Upgrade from DS 7.4.0

If the deployment includes a DS 7.4.0 server with [data encryption](../security-guide/data.html) using default settings, follow the procedures on this page.

If the deployment has no DS 7.4.0 servers or does not use data encryption, skip this page.

## The problem

Due to an issue (OPENDJ-10211) in the way DS 7.4.0 encrypts data on disk when using the default `cipher-transformation: AES/GCM/NoPadding` setting, the backend or changelog data on disk and encrypted with 7.4.0 is incompatible with all other DS versions.

If the deployment is configured with non-default `cipher-transformation` settings that do not use the AES algorithm and GCM mode, the problem doesn't affect the deployment. In this case, skip this page.

Otherwise, the directory data on disk uses incompatible encryption. Any binary backups of the backend data are also affected. You can't use the `upgrade` command to upgrade a DS server to 7.4.0 from earlier versions or from 7.4.0 to later versions.

## The solution

You *can* upgrade by adding new DS servers; follow these steps:

1. Upgrade by [adding new servers](add-new-servers.html), leaving existing 7.4.0 servers in operation during the upgrade.

   When initializing new servers, *do not use backup files*, as they use incompatible encryption. Instead, either [initialize data over the network](../config-guide/repl-init.html#init-repl-online) or [initialize all replicas from plaintext LDIF](../config-guide/repl-init.html#init-repl-ldif).

2. Change the [bootstrap replication servers](../config-guide/repl-bootstrap.html) for each server to stop using the DS 7.4.0 servers.

3. If you use backup files, create them from the new servers with compatible encryption.

4. Stop directing client application traffic to the DS 7.4.0 servers.

5. Wait until the replication purge delay has elapsed (default: 3 days) and retire the DS 7.4.0 servers.

## Next steps

* [icon: check-square-o, set=fa]Perform [these steps](before-you-upgrade.html) before you add servers

* [icon: check-square-o, set=fa]Add new servers:

  * [icon: check-square-o, set=fa]Follow [these instructions](add-new-servers.html) unless upgrading from DS 7.4.0

  * [icon: check-square-o, set=fa]Follow [these instructions](from-740.html) when upgrading from DS 7.4.0

* [icon: square-o, set=fa]*Perform [these steps](after-you-upgrade.html) after you finish adding servers*
