I just did this upgrade yesterday. Yes, you upgrade each secondary first (making sure COOP is active before moving to next one) and then finally hit primary. Since we like to have the primary be at our primary DC, we rebooted the now primary so that a reelection would occur.
GETVPN IOS Upgrade Procedure
This Cisco IOS upgrade procedure should be followed when a Cisco IOS code upgrade needs to be performed in a GETVPN environment:
- Upgrade a secondary KS first and wait until COOP KS election is completed.
- Repeat Step1 for all secondary KSs.
- Upgrade the primary KS.
- Upgrade GMs.
From <http://www.cisco.com/c/en/us/support/docs/security/group-encrypted-transport-vpn/118125-technote-getvpn-00.html>