IBM Support

SmartCloud Provisioning 2.1 Fix Pack 5 (SCP - 2.1.0.5)

Fix Readme


Abstract

IBM SmartCloud Provisioning 2.1 Fix Pack 5 (2.1.0.5) is available. This is the README file for the release.

Content

Copyright International Business Machines Corporation 2014. All rights reserved.


Component: IBM SmartCloud Provisioning, Version 2.1.0

Component ID: 5725-C88

Fix: Fix Pack 5 (2.1.0.5)

Date: July 2014


Contents:

1.0 General description
2.0 Problems fixed
3.0 Architecture and prerequisites
4.0 Image directory contents
5.0 Installation instructions
6.0 Additional installation information
7.0 Known problems and workarounds
8.0 Additional product information
9.0 Notices


1.0 General description
=======================

This Fix Pack has been issued to address security vulnerabilities related to the SmartCloud Provisioning product:

- The JVMs of the product components have been upgraded to Java 6 SR16

This Fix Pack also includes the fixes delivered in the previous SmartCloud Provisioning 2.1.0.X fix packs as listed in sections 2.4 and 2.5.


2.0 Problems fixed
==================

The following problems are addressed by this fix:

2.1 APARs & Defects
-------------------

None.


2.2 Security Vulnerabilities
----------------------------
- CVE-2014-0453 --- An Exception thrown by the Security component reveals information that an attacker could use to break RSA keys via a Bleichenbacher attack.

- CVE-2014-0460 --- The JNDI DNS service provider has several implementation flaws that make spoofing DNS responses much easier

- CVE-2014-0878 --- A flaw exists in the seeding mechanism for the IBMSecureRandom implementation of the IBMJCE and IBMSecureRandom cryptographic providers.

- CVE-2014-1876 --- If the unpack tool is configured to use a log file, and the specified file name cannot be opened, the fallback is a hard-coded name in the /tmp directory.

- CVE-2014-0339 --- Webmin view.cgi cross-site scripting


More details on the security vulnerabilities addressed are available in the security bulletins published here:

Multiple vulnerabilities in current IBM SDK for Java for WebSphere Application Server April 2014 CPU
http://www-01.ibm.com/support/docview.wss?uid=swg21673013

Multiple vulnerabilities in current releases of the IBM SDK, Java Technology Edition
http://www-01.ibm.com/support/docview.wss?uid=swg21672043


2.3 Enhancements
----------------

None.


2.4 Superseded fix packs
------------------------

Fix Pack 1 (2.1.0.1-TIV-ISCP)
Fix Pack 2 (2.1.0.2-TIV-ISCP)
Fix Pack 3 (2.1.0.3-TIV-ISCP)
Fix Pack 4 (2.1.0.4-TIV-ISCP)




2.5 APARs and defect fixes included from superseded fix packs
--------------------------------------------------------------

APAR IV25825 ADD A STATEMENT ABOUT PORTS 80 AND 443 IN PREREQ SECTION
APAR IV27022 ICCT 1.2 SILENT INSTALL DOES NOT PROCESS UNENCRYPTED PASSWORD
APAR IV27035 FAILURE WHEN CUSTOMER TRIES TO EXPORT THE IMAGE TO AN OVA FOR IWD
APAR ZZ00008 SCP UI DOES NOT DISPLAY THE CHANGED VM PARAMETERS
APAR ZZ00009 VIL STATUS BAR DOES NOT ACCURATELY REPRESENT THE PROGRESS MADE TOWARD COPYING AN IMAGE INTO THE REFERENCE LIBRARY.
APAR ZZ00011 INFORCENTER REFER TO SCPQURY NEED TO BE UPDATED
APAR ZZ00013 FIREFOX BROWSER'S LANGUAGE SET TO CHINESE DOESN'T WORK
APAR ZZ00014 Deployment fails on IE8 if the instance has 2 nics
APAR ZZ00016 DOC APAR FOR MESSAGE CTGHL0325W
APAR ZZ00021 THE IMAGE LIST IN IL IS NOT UPDATING AUTOMATICALLY
APAR ZZ00022 KVM VIRTIO DEVICE AND WINDOWS2003 COMPATIBILITY PROBLEM.
APAR ZZ00023 COMPUTE NODE INSTALLATION FAILED TO FORCE PARTITION
APAR ZZ00024 SCP 2.1 SAN RACE CONDITION ISSUE ON FP1
APAR ZZ00025 SCP 2.1 HARD DISK CHECK & LOOP DEVICE CREATION PARTS NEED TO BE REFINED
APAR ZZ00027 MISSING FILE WINIMAGEPREPARATION_V#.#.ZIP
APAR ZZ00028 INTERNET EXPLORER LOGIN BUTTON ISSUE
APAR ZZ00029 HYPERVISOR SHOULD BE IN MAINTENANCE MODE TO ADD IP GROUPS HYPERVISOR ITSELF
APAR ZZ00030 INFORMATION ABOUT RESTARTING A PERSISTANT INSTANCE OF A VM
APAR ZZ00031 UNABLE TO CREATE THE LOCAL GROUP ONCE THE "ENABLE LDAP AUTHENTICATION" IS CHECKED IN.
APAR ZZ00032 LACK OF SYNCH BETWEEN VIL AND SCP
APAR ZZ00033 CHINESE BROWSER WILL SHOW UP " UNTRANSLATED MESSAGE RM 26288" WHILE THE IWD FINDING THE NETWORK OF THE CLOUD GROUP
APAR ZZ00034 CHINESE PANEL IS CHANGED TO ENGLISH
APAR ZZ00035 IWD FP1 WINDOWS SCRIPT PACKAGE VARIABLE NOT WORKING WELL
APAR ZZ00036 THE DOCUMENT NEED TO BE CORRECTED TO ILLUSTRATE THE RIGHT USE OF THE VIEW ACTION OF A VIRTUAL MACHINE PANEL FIELD.
APAR ZZ00037 USE THE IWD CLI QUERYING GROUPS PROPERTY FOR THIS USER THROWS IOERROR
APAR ZZ00038 THE CLOUD GROUP AND THE VCENTER HYPERVISOR SHOW DIFFERENT STATUS AFTER THE NETWORK BETWEEN THE ESXI AND IWD RESTORED
APAR ZZ00039 THE MEMORY AND CPU INFORMATION DISPLAY ABNORMAL, SOMETIME BLANK
APAR ZZ00040 VIL STATUS BAR DOES NOT ACCURATELY REPRESENT THE PROGRESS MADE DURING THE IMAGE IMPORT ACTION
APAR ZZ00041 THE SNAPSHOTS ON THE VCENTER IS NOT SYNCHRONIZED WITH THE IWD CONSOLE
APAR ZZ00042 THE OPERATION REPOSITORY CAN'T BE DELETED FROM THE VIL AFTER THE CLOUD GROUP IS DELETED FROM THE IWD CONSOLE
APAR ZZ00043 IWD IS NOT COMPATIBLE WITH CHINESE VERSION OF VCENTER.
APAR ZZ00044 THE HOSTNAME OF THE LINUX VM ARE THE SAME IF THERE IS NO DNSWORK.
APAR ZZ00045 CHECKED OUT IMAGE CAN'T BE USED TO LAUNCH VM
APAR ZZ00046 AFTER UPGRADE TO SCP 2.1.0.1, YOU CANNOT CREATE INSTANCESANYMORE
APAR ZZ00047 ERROR CONFIGURING Z/VM LINUX MASTER SYSTEM USER ID
APAR ZZ00048 VIL DOC: HIGHLIGH THAT THE SUGGESTED RPM PACKAGES MUST BE INSTALLED ONLY AFTER THE VIL INSTALLATION
APAR ZZ00049 PROBLEMS RUNNING SCRIPT PACKAGES ON LINUX AND WINDOWS
APAR ZZ00050 SCP CONNECTION VCENTER
APAR ZZ00051 HYPERVISOR IMAGES NOT TRANSFERRING TO CLOUD GROUP.
APAR ZZ00052 SCP 2.1 FP1 INSTALLATION HUNGS IN STEP "UPGRADING USING GUI ORCLI"
APAR ZZ00053 VIL INSTALLATION PROCEDURE CHECKS THE AVAILABLE SPACE IN /HOME INSTEAD OF /HOME/LIBRARY
APAR ZZ00054 MISSING PARAM (IWD PATH) VALIDATION IN UPGRADE SCRIPT
APAR ZZ00056 THE IP ADDRESS OF THE VLAN BR IS HARDCODE , NEED TO BE CONFIGURABLE
APAR ZZ00057 THE ICON DOCUMENT MISSED THE PART TO SET UP WITH KVM
APAR ZZ00058 TMP DIRECTORY HAS TO BE CREATED RUNNING RBAGENT RESTART TOO (NOT ONLY RUNNING IL.SH RESTART)
APAR ZZ00059 IBM WORKLOAD DEPLOYER DISPLAYS AN ERROR "THE HYPERVISOR CANNOT BE REACHED" WHEN TRYING TO DISCOVER THE POWERVM HYPERVISOR
APAR ZZ00060 MODIFY VIL PORT NUMBER IN THE OUTPUT MESSAGE AFTER A MIN INSTALLATION
APAR ZZ00061 AFTER UPGRADING IWD, VIL AND IWD FAIL TO SYNCH
APAR ZZ00062 ONLY ONE NIC IS USED
APAR ZZ00063 THE DOCUMENT NEVER ILLUSTRATE THAT THE CPU AND MEMORY UTILIZATION FUNCTION DOES NOT WORK ON HSLT INFRASTRUCT
APAR ZZ00064 CHECK OUT A MUTLIDISK OVF FAILED FROM THE VIL
APAR ZZ00065 Error connecting to the IWD UI using Firefox 20
APAR ZZ00066 PROVISION MULTIPLE USING THE ENVIRONMENT PROFILE FAILS
APAR ZZ00067 LDAP USER PASSWORD IS SENT VIA EMAIL
APAR ZZ00068 CANNOT ADD USERS OR GROUPS INTO "ACCESS GRANTED TO" FOR DEFAULTHSLT CLOUD GROUP IN IWD
APAR ZZ00069 PASSWORD MISMATCH DOESN'T PREVENT DEPLOYMENT OF IMAGE
APAR ZZ00070 RBAGENT SCRIPT FAILS TO INITIALIZE THE RBAGENT DIR
APAR ZZ00071 DIFFERENCE BETWEEN THE IWD AND HSLT GROUPS
APAR ZZ00073 NEED TO REMOVE DELETEVM SCRIPT FROM SCP TROUBLESHOOTING GUIDE. (OR ADD WARNING)
APAR ZZ00074 IWD DOC: IMPROVE SETTING AND TROUBLESHOOTING RELATED TO IP ADDRESSES RESOLUTION
APAR ZZ00075 VIL - IMAGE INDEXING FAILED WHEN THE VCENTER IS SET IN LOCAL LANGUAGE.
APAR ZZ00076 THE STATIC IP FUNCTION DOES NOT WORK AS EXPECTED.
APAR ZZ00077 VIL - IMAGE IMPORT ERROR DUE TO '<' CHARACTER
APAR ZZ00078 DOC CLARIFICATION (SSH WORKS FOR LINUX ONLY)
APAR ZZ00079 DEPLOYMENT OF THE 5TH IMAGE OF LINUX FOR SYSTEM Z ALWAYS FAILED IN A MULTIPLE IMAGE DEPLOYMENT.
APAR ZZ00081 SCP-VIL DOES NOT SUPPORT OVF IMPORT
APAR ZZ00082 THE CLOUD GROUP WILL SHOW "CAN NOT CONNECT TO VIRTUAL CENTER" ONCE THE USER REMOVE SECURITY CERTIFICATE.
APAR ZZ00085 THE PROTOCOLS USED ARE ALWAYS HTTP AND HTTPS.
APAR ZZ00086 IMPORTING ZVM IMAGE WHICH WAS EXTENDED BY ICCT DOES NOT WORK.
APAR ZZ00088 SCRIPT PACKAGE VARIABLE ARE NOT BEING DEFINED CORRECTLY
APAR ZZ00089 ZVM DEPLOYMENT FAILURE DUE TO LOCKED MASTER
APAR ZZ00092 IP GROUP CONFIGURATION DOES NOT GET READ PROPERLY, INSTANCE DEPLOYMENT USES WRONG NETWORK.
APAR ZZ00093 THE ISCP 2.1 UPGRADE CODE WILL REFRESH SOME OF THE CUSTOMER'S CUSTOMIZATION FILE.
APAR ZZ00094 CUSTOMIZING THE SIZE OF A VIRTUAL MACHINE DOEN'T WORK
APAR ZZ00095 THERE IS SYNTAX ERROR IN VARIABLES SPECIFICATION
APAR ZZ00098 SCP CLI ERROR TRYING TO DISPLAY ENDPOINTTYPE FOR ZVM HYPERVISOR
APAR ZZ00099 SCP 2.1.0.2 INSTALLATION SCRIPT ERROR
APAR ZZ00101 PROBLEM WITH CLONE OPTION ON A VIRTUAL INSTANCE
APAR ZZ00102 REMOTE_STD_ERR.LOG IS NOT CREATED
APAR ZZ00104 PROFILE ENVIRONMENT LIMITS ARE NOT BEING ADHERED FOR STORAGE. CPU AND MEMORY ARE WORKING FINE.
APAR ZZ00109 ENVIRONMENT PROFILE > IN USE COLUMNS ARE NOT BEING UPDATED PROPERLY.
APAR ZZ00111 PROBLEM WITH EDITING VALUES FROM VMS
APAR ZZ00112 COPIML817E HTTP VERSION NOT SUPPORTED
APAR ZZ00113 FP2 OF SCP-IWD IS NOT UPGRADING THE GROUPS TABLE CORRECTLY
APAR ZZ00126 SLES 11 SP2 64BIT SCRIPT PACKAGES DO NOT DEPLOY
APAR ZZ00131 IMPROVE UNSUPPORTED OS TEMPLATES HANDLING


Product quality and image management improvements:

85585: VIL - performance indexing issue: Using vmware-mount cmd instead of the VDDK mount cmd
72942: UI - SCP 2.1 FP1: forbid choosing cloud groups when deploying virtual machines and vSyses


Enhancements:

Support of Firefox 17 for the web console UI.


3.0 Architecture and prerequisites
==================================

This fix is supported on all operating systems listed in the IBM SmartCloud Provisioning documentation at:
http://pic.dhe.ibm.com/infocenter/tivihelp/v48r1/topic/com.ibm.scp.doc_2.1.0/planning/c_os.html

The following link is for the Tivoli operating system and application support matrix. Refer to this matrix for the latest certification information:
http://www.ibm.com/software/sysmgmt/products/support/Tivoli_Supported_Platforms.html

The following components are upgraded to version 2.1.0.5:

Workload Deployer
isaac-common
isaac-hyper-bots
isaac-hyper-bots-xen
isaac-storage-bots
isaac-webconsole
isaac-webservices
isaac-cli
isaac-rest-server
Virtual Image Library


3.1 Prerequisites for this fix
------------------------------

None.

If IBM SmartCloud Provisioning Version 2.1.0 is already installed, because this Fix Pack is cumulative, it can be installed on any fix level for this product version, release, and modification level later than the GA level.


4.0 Image directory contents
============================

This fix image contains the following files:

- 2.1.0.5-TIV-ISCP.README - This README file
- CI91KML.tar - IBM SmartCloud Provisioning Version 2.1.0.5 for RHEL6/RHEL 6.1 Multilingual
- CI91LML.tar - IBM SmartCloud Provisioning Version 2.1.0.5 for IBM Provided Software Virtual Appliance for RHE Linux Multilingual
- CI91MML.tar - Image Construction and Composition Tool Version 1.2 for RHE Linux Multilingual


5.0 Installation instructions
=============================

This Fix Pack can be installed on top of an existing installation or as a fresh installation. Proceed with the specific scenario as suggested in the infocenter at:
http://pic.dhe.ibm.com/infocenter/tivihelp/v48r1/topic/com.ibm.scp.doc_2.1.0/welcome.html

5.1 Before installing the fix
-----------------------------

- The prerequisites listed under section 3.1, "Prerequisites for this fix", must be installed before this fix can be installed.

- Because there is no uninstall utility for this Fix Pack, perform a backup of your environment before installing this Fix Pack as described in product infocenter.

5.2 Fresh Install
-----------------

To proceed with IBM SmartCloud Provisioning install, please refer to information available in the infocenter at:

http://pic.dhe.ibm.com/infocenter/tivihelp/v48r1/topic/com.ibm.scp.doc_2.1.0/installing/c_installing.html


5.3 Upgrade
-----------

To proceed with IBM SmartCloud Provisioning upgrade, please refer to information available in the infocenter at:

http://pic.dhe.ibm.com/infocenter/tivihelp/v48r1/topic/com.ibm.scp.doc_2.1.0/installing/c_upgrading.html

It is strongly suggested to proceed with product backup before starting the upgrade procedure.
Follow the information available in infocenter to proceed with components backup.
When the upgrade is finished, clear out browser cache before starting to use the product web user interfaces.

5.4 Virtual Image Library update
--------------------------------

This procedure is optional. Run the procedure only if you have Virtual Image Library deployed in your environment.
It is recommended that you back up your Virtual Image Library environment when you apply a fix pack, so that you can restore the existing environment, if needed.
To back up your existing Virtual Image Library environment and restore it if needed, follow the information available in the infocenter at the following link:

http://pic.dhe.ibm.com/infocenter/tivihelp/v48r1/topic/com.ibm.scp.doc_2.1.0/VIL/topics/backupandrestore.html

To automatically upgrade Virtual Image Library from level 2.1 to 2.1.0.5, select the installation package from the Fix Pack package, unpack it and launch the following
command from the directory where the package has been unpacked

./install_vil.sh -u <username> -p <password>

NOTICE
This fix pack is designed to automatically patch Virtual Image Library with interim fix IFPI19109.
However, if the installation to be upgraded contains interim fix IFPI08995, the upgrade might fail.
If this is the case, you must manually uninstall interim fix IFPI08995 before running the upgrade.
To manually uninstall interim fix IFPI08995, see step 4 in section 5.4.1 below.


5.4.1 Installing interim fix IFPI19109
--------------------------------------

Perform the following steps:

1) Stop and back up Virtual Image Library by following the steps from 1 to 8 that are described at
http://www-01.ibm.com/support/knowledgecenter/SSZH3R_2.1.0/com.ibm.scp.doc_2.1.0/VIL/topics/backupandrestore.html?lang=en

2) Download the 8.0.0.0-WS-WASJavaSDK-LinuxX32-IFPI19109.zip file from the IBM Support Fix Central site, and store the file
in the Virtual Image Library machine, for example in the /home/WAS directory.

3) Install the interim fix IFPI19109, by running the following commands, for example:

[root@image-library ~]# cd /opt/IBM/InstallationManager/eclipse/tools/
[root@image-library tools]# ./imcl install 8.0.0.0-WS-WASJavaSDK-LinuxX32-IFPI19109 -installationDirectory /opt/IBM/WebSphere/AppServer/
-repositories /home/WAS/8.0.0.0-WS-WASJavaSDK-LinuxX32-IFPI19109.zip

4) If the installation completes successfully, the following message is displayed:
"Installed 8.0.0.0-WS-WASJavaSDK-LinuxX32-IFPI19109_8.0.0.20140602_1627 to the /opt/IBM/WebSphere/AppServer directory."

If the following error message is displayed:

ERROR: An interim fix for the Java SDK is installed already. Uninstall interim fix 8.0.0.0-WS-WASJavaSDK-LinuxX32-IFPI08995 before installing a different Java SDK interim fix.

the interim fix must be uninstalled by running the following command, for example:

[root@image-library tools]# ./imcl uninstall 8.0.0.0-WS-WASJavaSDK-LinuxX32-IFPI08995 -installationDirectory /opt/IBM/WebSphere/AppServer/

When the unistall procedure completes, the following message is displayed:

"Uninstalled 8.0.0.0-WS-WASJavaSDK-LinuxX32-IFPI08995_8.0.0.20140115_1540 from the /opt/IBM/WebSphere/AppServer directory."

You can now reinstall the interim fix as described in step 3.

5) Restart Virtual Image Library by running the following command:

[root@image-library tools]# /home/library/il.sh start wasadmin passw0rd



5.5 Image Construction and Composition Tool update
--------------------------------------------------

This procedure is optional. Run the procedure only if you have Image Construction and Composition Tool deployed in your environment.
The following different scenarios are supported:

- Performing a fresh Fix Pack installation
Select the installation package from the Fix Pack package and follow the same procedure to install the GA level of the tool described at:
http://pic.dhe.ibm.com/infocenter/tivihelp/v48r1/topic/com.ibm.scp.doc_2.1.0/ICON/topics/scp_cicn_installationsteps.html

- Upgrading from the GA level
Perform an update of the current version of the tool using the Installation Manager:
a) To start the Installation Manager, run the command:
/opt/IBM/InstallationManager/eclipse/launcher
b) From the File menu, select "Preferences -> Add Repository..." and select the ICCT_IM_repository_1.2.0.2-33.zip file.
c) Select "Update" from the Installation Manager.

6.0 Additional installation information
=======================================

None.


7.0 Known problems and workarounds
==================================

None.


8.0 Additional product information
==================================

None.


9.0 Notices
===========

For trademark attribution, visit the IBM Terms of Use web site (http://www.ibm.com/legal/us/).

[{"Product":{"code":"SSZH3R","label":"IBM Service Agility Accelerator for Cloud"},"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Component":"Installation","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"2.1","Edition":"","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
17 June 2018

UID

swg21679713