The openam.deserialisation.classes.whitelist can be updated independently of the serverdefaults.properties file so it would be worthwhile providing upgrade support for the openam.deserialisation.classes.whitelist property so that any new values added to the serverdefaults.properties over time are taken into account along with any custom entries added locally during the upgrade of OpenAM.
See comments in http://sources.forgerock.org/cru/CR-7839