Question 5.1 Patch 4 ACS
OK, maybe a stupid question... when I download the patch on the Cisco site, it indicates that it is a. GPG file, however, once the download complete it appears as one. TAR. TAR file... am I supposed to rename it? Or am I wanted to unzip somehow, unpack everything utility I try says that the file contains no archives or is incomplete or corrupted!
If there is a document that details how to install patches please someone could post the link.
Hi Paul,.
It is a browser problem. You must rename the file with the extension .gpg (the original name of the patch file) for a successful installation of patch later. In other words, the installation will fail if you leave the patch name with the. tar.tar extension.
As for your question on how to install the patch, it's in the Readme of the patch that you would see a link to "Readme for ACS download the patch file itself. "Here is the link to the Readme for 5.1.0.44.4 update rollup. Click this link to open the readme file before you click on the "Go ahead with Download" button to download the patch file.
Here is the Readme for patch 5.1 ACS 4.
http://www.Cisco.com/Web/software/282766937/28141/ACS-5-1-0-44-4-Readme...
Kind regards
Cam.
Tags: Cisco Security
Similar Questions
-
Apply the patches to ACS 5.1
Hi all
I hope someone can help with this problem.
I have an ACS 5.1 with the next load of S/W
Deploying applications engine Cisco OS version: 1.2
ADE-OS Build Version: 1.2.0.146
ADE-OS System Architecture: i386Cisco ACS VERSION INFORMATION
-----------------------------
Version: 5.1.0.44
The identifier for the internal version: B.2347I downloaded 5-1-0-44 - 3.tar.gpg, 5-1-0-44 - 4.tar.gpg and 5-1-0-44 - 5.tar.gpg to a local directory on GBA, but every time I try to run the upgrade patch GBA fix install 5-1-0-44 - 5.tar.gpg repository_name repository get following error output...
chmod: cannot access at the "* .sh ': no such file or directory".
Patch not valid 5-1-0-44-5.tar.gpg'-missing install.sh
% Error: failed to open / validate the patchI have moved the 5-1-0-44 - 5.tar.gpg to a linux machine and tried to dencrypt the file using gpg d 5-1-0-44 - 5.tar.gpg but it invites then pass phrase, I tried a few guesses, but I couldn't decipher.
So what part of the upgrade process I am missing, or do I have to install some kind of password so that the ACS can properly decrypt files to fix.
I tried this with the patch 3, 4 and 5. I need to start pathch 1?
Thank you
Cefyn Arch
Helloz,
Form where you downloaded the patch. I suggest you download from cisco.comif you download before.
http://Tools.Cisco.com/Squish/1D47B
No, you can directly apply the patch 5.
Correct the command that you run to apply the patch.
I wish allows you to check a few things1 are you using TFTP? If so, then switch to FTP and try again.
2. prior to apply the hotfix, make sure that you can see the file in the repository.Show repository
If you can see patch 5 under the repository then you're good to go.
HTH
Jousset
~ Make useful messages rate
-
Patch level ACS migration: 4.1.4 Bundle 13 - >; 5.1
I'm migrating ACS 1111 devices running ACS version 4.1.4 build 13-1121 ACS ACS version 5.1 devices.
In the migration process, it is stated that:
"The machine of migration must be a Windows platform that is running the same version of ACS (including the fix) as the source machine.
and with regard to the supported versions:
"You must install the latest patch for versions of migration supported listed here. In addition, if you have another version of ACS 4.x installed, you must upgrade to one of the supported versions and install the latest patch for this version before you can migrate to ACS 5.1. »
If I check the web associated with ACS version 4.1.4.13 download page, there are many opportunities for software to download from 4.1.4.14.1 and goes up to 4.1.4.13.20.
How do I now which is the patch installed in my system if the ACS Web Interface only provides the information "4.1.4 build 13?
Thank you
If you have installed the patch, ACS web interface also displays the patch level. See the attached screenshot
-
I was wondering if someone can help me to update my ACS camera with patch 4.1.1.23.4 - SW. It's simple to apply it in a normal server, 2000. The ACS unit according to me is different because we can access through normal terminal, keyboard and mouse.
Some I had to read it is necessary a tomcat server?
Help, please
ADI
Hello
ACS v4.1.1.23 patch 5 is available then go for this new patch.
You should have a pc that can access the ACS through the web interface. Keep the file of fix on the PC.
Follow the steps below on the PC:
[1] extract zipped file
[2] get? Autorun.exe? file and double-click it
[3] it will start a server tomcat on your desk and you? 'll see a web page asking ACS
IP SE:
Provide the IP ACS SE and the press? Install?
[4] he will ask for ACS admin username and password as shown below:
Specify the user name and the password and connect.
[5] then he raise ACS GUI, then go to
System configuration > device upgrade status > download,.
Then we? 'll get a screen where it will ask for the ip address of the server to install:
Provide the ip address of the system where we apply this patch, in our case our
ip address of office, and then click on connect.
[6] he will show us after screen:
Click on? Download now?
Then he? show us this screen:
Press? Refresh? Until we see the following screen:
[7] now, press on? Apply the update? Then he? He wants confirmation:
Press? Update?, then we? 'll get information about the patch.
Click on? Yes?.
It? LL take a few minutes to apply this hotfix on the device.
Then he? show us a confirmation message:
Press? Fact?, then the system will restart.
To confirm that the patch has been applied successfully, goto
System configuration > status upgrade unit
After all right, stop the tomcat server by clicking on? stop server distribution? or
If you want to apply this hotfix on a device more click on? Install following?
I hope this helps.
~ Rohit
-
Question about PSU patch when IM and DB are different version
Hello world
I have some doubts when it comes to the application of patches to the PSU, when the House of GI and DB House are different versions.
I have 2 node RAC on RHEL 5 cluster.
My home grid Infrastructure is running version 11.2.0.3 while my 11.2.0.2 RDBMS RAC is.
I know that the PSU of grid Infrastructure also includes the power supply of the database and that it should be applied in two homes the same version.
When patching my RDBMS RAC at home (11.2.0.2); should I install the PSU IM for 11.2.0.2 or only the part of the RAC database?
For example:
installation 11.2.0.2.6 PSU which consists of 13696242 (game of Grid infrastructure update fixes) and 13696224 (database updated Patch to update).
Should I ignore the 13696242 and just install 13696224? Or do I have to install both.
Thank you.
Published by: AJ on 20.jul.2012 05:26Hello
ignore the part of IM and use the - oh flag on DB home only.
(Section in the readme file, which talks about the application of software patches DB only).Concerning
Sebastian
-
I need to patch our ACS server at 4.2.0.124.6 4.2.0.124.17. My question is, do I need to apply the patch even to our remote agents? Cisco documentation indicates only that both the ACS and the Remote Agents must be 4.2.0.
I just want to confirm.
Thank you!
Hello
Well Yes, the ACS and RA, version including the patch must be same.
I hope this helps.
Kind regards
Anisha
P.S.: Please mark this thread as answered if you feel that your query is resolved. Note the useful messages.
-
AAA GANYMEDE + accounting - CLI question by user not appear in the report of the ACS.
Can I know why CLI cancelled by the user does not show on GANYMEDE ACS accounting report. The length of time is displayed, but I also wanted to connect what is the commands issued by the user.
WHA is missing here?
enable AAA authentication login VTY P1_ACS local group
Group default AAA authorization exec local P1_ACS authenticated by FIS
AAA authorization exec CONSOLE none
AAA exec by default start-stop accounting P1_ACS group
AAA commands 5 default start-stop accounting P1_ACS group
AAA commands 15 arrhythmic default accounting P1_ACS group
Accounting logs command is stroed in the newspapers of the administration of Ganymede.
There is also a known issue on ver 4.1.1 and we must
apply the ACS 4.1.1.23.5 patch to fix the problem.
Patch for the unit is available on
http://www.Cisco.com/cgi-bin/tablebuild.pl/ACS-Soleng-3DES
The patch name: ACS SE 4.1.1.23.5 rollup
Acs hotfix for windows is available on
http://www.Cisco.com/cgi-bin/tablebuild.pl/ACS-win-3DES
The patch name: ACS 4.1.1.23.5 rollup
CCIE Security
-
No report of Directors GANYMEDE + after upgrading to 4.1 ACS
Hello
I was running ACS 4.0 demo version. Everything worked very well.
After the upgrade, and keep the old configuration, I can't see logs in the reports of the directors of GANYMEDE. I kept the configurations of the router and get the same thing, so I think that the problem lies in the ACS software.
I tested a few debug, and it seems that the router sends the command that is typed to the ACS.
Here is the config I have? m using:
AAA new-model
GANYMEDE-Server 192.168.X.X XXXXXXXXXXX host key
AAA authentication telnet connection group Ganymede + activate
enable console AAA authentication login
the AAA authentication enable default group Ganymede + activate
AAA accounting send stop-record an authentication failure
AAA accounting exec default start-stop Ganymede group.
orders accounting AAA 1 by default start-stop Ganymede group.
orders accounting AAA 15 by default start-stop Ganymede group.
AAA accounting arrhythmic telnet connection group Ganymede +.
Line con 0
exec authorization no.-AUTH
console login authentication
line vty 0 4
exec authorization AUTH
authentication telnet connection
AUTH AAA authorization exec group Ganymede + none
AAA authorization config-commands
No.-AUTH AAA authorization exec no
AAA authorization commands 0 default group Ganymede + none
1 default AAA authorization commands group Ganymede + none
default 15 AAA authorization commands group Ganymede + none
Hello
It is a known issue, you must apply the hotfix ACS 4.1.1.23.5 to solve the problem.
Patch for the unit is available on
http://www.Cisco.com/cgi-bin/tablebuild.pl/ACS-Soleng-3DES
The patch name: ACS SE 4.1.1.23.5 rollup
Patch for windows acs is available on
http://www.Cisco.com/cgi-bin/tablebuild.pl/ACS-win-3DES
The patch name: ACS 4.1.1.23.5 rollup
That should solve the problem
Kind regards
Jagdeep
Note: If this answers your question, then please mark this thread as solved, so that others can benefit from.
-
Upgrade ACS 5.1 to 5.3
Hi all
I need to upgrade our ACS 5.1 to 5.3 after I see this cisco Dockment this Doc is more complex
I don't understand any help please think of me answering my question
1. we have 2 primary and secondary, with which we have to start to upgrade?
-at the top, Doc started with
Upgrade a deployment ACS 5.1 to 5.3
2 - sholud I start using this method ACS upgrade deployments or sholud I use only a 5.1 to 5.3 ACS server is upgraded ?
3 - frist I must save my server how to back up the two page server web ACS server or should I use ony command line?
-This command
Step 1 Save the ACS since the ACS 5.2 Server data.
Step 2 Enter the following backup EXEC mode to perform a backup and place the backup in a repository.
backup backup-name-name of the repository repository
4. What is the name of a repository and how do I find
5. also
ACS, install patch patch - repository name.tar.gpg repository-name
-Idon't know whatever that means
Note
Before upgrading a secondary server, you must cancel the registration of the primary server.
6. what it means, what strike?
7. I can take this update of the page Web directors of ACS
8. If I need to upgrade our CMD ACS must install FTP server? How to install the FTP server in ACs or how to talk about this ACS server FTP
Thank you all for the help
AHA
Tarik, great answer + 5
Hello Abdullah Hashim
You start by secondary. If he's a collector of newspaper and then move it to primary school for a while, once the upgrade has completed, bring it back to secondary, and upgrade of the main box.
He recommended latest patch on the current version (to avoid known problems) before you upgraded to 5.3 or 5.4 GBA
You are already using the latest patch of ACS 5.1 (IE patch 6) so you do not need to install another patch. ACS patches are cumulative, so no need to install the previous patches. The last being should have correct all defects.
Let me know if you still have any questions.
~ BR
Jatin kone* Does the rate of useful messages *.
-
DISCONNECTED in Cisco Secure ACS AD
We have ACS
5-3-0-40-8
As disconnected Active Directory showing connectivity
We faced the same problem when he was 5.x, we went to
5-3-0-40-8
After 2.5 months now, we have faced this problem. Permanent any solution for this.
Restarting the service got suspended and where we rebooted the server to fix.
Please help on this as soon as possible.
Thank you best regards &,.
Sakthivel M
You questions'are running one of the code and patch of ACS more stable if we are talking about ACS - AD. I don't know that it should not be a problem with the ACS. Something is not configured correctly. Most likely a problem of DNS or NTP.
In order to deepen and to know what might be the causes, you will need to provide some information and newspapers when it happens again.
1.] we have ACS currently running on the machine or Vmware?
2.] when you say that it is in the disconnected state, you see do both authentication failed or it shows just disconnected status. In case of failure, what is the error, we get in the section logging ACS? In addition, you can see test connection arrive at positive results?
3.] what is the status of the customer-ad on the CLI service, can be verified with "view the status of the acs application" when you say its disconnected?
4.] in addition, when you try to join again while it is disconnected, you see an error? can you share?
5.] more importantly, debug level logs would tell us the real story. Before you reproduce the problem, we must look at the newspapers to the debug level. (If this can not be reproduced then wait the issue reproduce)
Go to the ACS CLI:
ACS / admin # acs - config
Escape character is CNTL/D.
Username: acsadmin
Password: XXXXXXXX
ACS/admin(config-ACS) #.
Set newspapers ACS desired debugging level.
ACS/admin(config-ACS) # debug level to debug-log duration
ACS/admin(config-ACS) # enable debug-adclient
NOTE: once you have finished, put newspapers.
Generate the support beam and download it here. Talk about the timestamp when the questions has been reproduced, it will help me track down the newspapers concerned.
Jatin kone
-Does the rate of useful messages- -
UAC Patcher with limited user account
I am referring to a section of documentation:
'Control (UAC) correction (Windows) user accounts' located at
http://msdn.Microsoft.com/en-us/library/Windows/desktop/aa372388%28V=vs.85%29.aspx
I am interested especially in the part:
"If the application was installed on Windows XP, the application must also have been installed from removable media, like a CD-ROM disc or DVD. This restriction does not apply if the application has been installed on Windows Vista. »
I heard a rumor that this restriction has been removed in Windows Installer 4.0. The source of this rumor:
Is this true? I couldn't find any changelog Windows Installer. I have found that it's a ( http://msdn.microsoft.com/en-us/library/windows/desktop/aa372796%28v=vs.85%29.aspx ), but there is no direct comparison between 3.1 and 4.0. There is only the comparison associated 5.0 it.
If this rumor is true and restriction of installation from removable media in Windows XP has been removed, then I would like to know, what should I do now. I already install applications to client machines only with Windows Installer 3.1. Is it necessary to uninstall my applications to client machines, then install Windows Installer 4.0 (or 4.5) and then again install my apps? Or is it enough to install only Windows Installer 4.0 and apply the patch created by Windows Installer 4.0?
Hi Benedik,
Thanks for posting your query in the Microsoft Community Forums.
The question you posted would be better suited in the TechNet Forums. I would recommend posting your query in the TechNet Forums.
http://social.technet.Microsoft.com/forums/en-us/category/windowsxpitpro
It will be useful.
Let us know if you encounter problems under windows in the future. We will be happy to help you.
-
Accounting distribution ACS server
Hello
I wanted to install a patch for ACS solution engine. I would like to know how we can configure the distribution server. I refer to the foll.document:
I have an XP machine. I extracted the patch in one of the Windows folder. Now when I try to install the patch to the web interface of ACS. I get an error "failed to contact server.
I would be grateful if someone help me to solve this problem.
Thank you.
Rgds.,.
Sachin
Sachin,
Find enclosed the doc that explains the whole process.
Kind regards
~ JG
Note the useful messages
-
Hello
I just installed Cisco ACS 5.5.0.46. We managed to get Juniper devices to authenticate using RADIUS.
The problem is that the authentication logs are empty.
I intend to patch the ACS of Update Rollup 4 for tonight, hoping that it can fix the problem.
Can someone advise?
Concerning
Vijay
Good to hear your issue was resolved. Also, thank you for taking the time to come back and post the solution to the problem! (+ 5 from me). Now, if your issue is resolved, please check the thread as "answered" :)
-
ACS 5.1 - users turning off intermittently
Hello
I am currently having problems with intermittently disabling user accounts. The expiration in global settings is 30 days and the system was and running for less than a week now.
Any ideas?
Have tried a few things but nothing seems to work in other than allowing the new user/s and work correctly for a while.
Is there a log I can look for tell me why?
Thank you.
Andrew
All internal user accounts are disabled, if so you can be hitting the following problem:
CSCtf06311: all internal users automatically disabled after you be connected to a single user
f if, this is expected to be included in the third cumulative patch for ACS 5.1, 5.1.0.44.3, which should be available in a few weeks.
-
Problem of GANYMEDE ACS 4.2 NDG and shell permission sets
Hi all
I am trying to solve this problem without success so far. I have fresh GBA 4.2.15 patch 5 ACS installation and I am tryng to deploy to our environment. So I configured a 2960 S to be my test client and everything works well. Problem is when I try to create strategies to fine grains using groups of network devices and shell permission sets.
I created called ReadOnly and FullAccess authorization of shell games. I also created NDG called FloorSwitches and added my 2960. I have 2 groups of users called FloorSwitchesReadOnly and FloorSwithcesFullAccess. Now, if I have set up a FloorSwitchesFullAccess group and assign the set of permission controls Shell by NDG and then log in to the switch, all my orders are rejected as unauthorized.
One thing I noticed, is that if I give the command shell permission set it to any device (in the settings of user group) works fine. Or if I create binding with DEFAULT NDG to the Group of users that works too. My conclusion is therefore that the ACS for some reason any does not associate my passage to correct group but is instead the DEFAULT group for some reason any.
Someone at - it had the similar problem, or is there something I'm doing wrong? Is there another way to achieve such a thing without use of NDG?
Thank you all...
Please upgrade to patch 6, there is a bug in the patch 5 and you can see the release notes or the Readme for more information.
Which is the user setting on while you test command authorization, do you have it set on the group setting?
Thank you
Tarik Admani
Maybe you are looking for
-
How to remove corruption Encarta Premium 2009
I have a corrupted Encarta Premium 2009 version and want to uninstall it, but the software uninstall program cannot find the file .iso of origin. How can I remove Encarta 2009? [Moved from comments]
-
Camcorder LEGRIA HF - G30 with WD-H58W lens compatibility.
Hi all, I own a camcorder Legria HF - G10 with a converter WD-H58W wide-angle lens. Now, I want to change my cam with the Legria HF - new G30. Will I can continue using the WD-H58W camcorder HF - G30 or I have to buy the lens of WA - H58 as suggested
-
My HP Photosmart C5180 gives me - error Oxc19a0021 ink system failure
How can I fix this or do I have to get a new printer?
-
Users of Windows Audio Pro need a "core level" Thunderbolt pilot of Microsoft. Universal Audio, one of the leading manufacturers in Pro Audio Hardware and Software,. said the lack of a lightning conductor that Microsoft is the reason why their newest
-
Showing games blackBerry Smartphones Blackberry Tour
Hi all, I'm new to the forum, but I support BB in recent years as part of my job in it. Just upgraded to BB tour and I have a question about the game screens I have a game solitaire Spider that the menu screen fills only a quarter of the top left of