Troubleshooting security updates
Troubleshoot issues that might occur after you upgrade IBM® Storage Protect.
Symptom | Resolution |
---|---|
An administrator account cannot log in to a system that is using software earlier than V8.1.2. | After an administrator successfully authenticates with the server by using IBM Storage Protect V8.1.2 or later software, the administrator can
no longer authenticate with that server that uses client or server versions earlier than V8.1.2.
This restriction also applies to the destination server when you use functions such as command
routing, server-to-server export that authenticates with the destination IBM Storage Protect server as an administrator from another server,
administrator connections that use the Operations Center, and connections from the administrative
command-line client. To resolve authentication issues for administrators, complete the following steps:
Tip: If necessary, create a separate administrator account to use only with clients
and servers that are using V8.1.1 or earlier software.
|
Certificate distribution failed for a node, administrator, or server. | A node, administrator, or server that is using V8.1.2 or later software has a
SESSIONSECURITY value of STRICT, but you has to reset the value to TRANSITIONAL
to retry certificate distribution. When using the new protocol, the automatic transfer of a server’s public certificate is performed only on the first connection to a server with enhanced security. After the first connection, the SESSIONSECURITY parameter value of a node changes from TRANSITIONAL to STRICT. You can temporarily update a node, administrator, or server to TRANSITIONAL to allow another automatic transfer of the certificate. While in TRANSITIONAL, the next connection automatically transfers the certificate if needed and resets the SESSIONSECURITY parameter to STRICT. Update the value of the
SESSIONSECURITY parameter to TRANSITIONAL by issuing one of the following commands:
Alternatively, you can manually transfer and import the public certificate by using the
dsmcert utility to issue the following
commands:
If you are using CA-signed certificates, you must install the CA-root and any CA-intermediate certificates on each key database for the client, server, and storage agent that initiates SSL communication. |
Certificate exchange between IBM Storage Protect servers was not successful. | When using the new protocol, the automatic transfer of a server’s public certificate is performed only on the first connection to a server with enhanced security. After the first connection, the SESSIONSECURITY parameter value of a server changes from TRANSITIONAL to STRICT. Retry certificate exchange between two IBM Storage Protect servers. For information, see Retrying certificate exchange between servers. |
Certificate exchange between an IBM Storage Protect server and a client node was not successful. | When using the new protocol, the automatic transfer of a server’s public certificate is
performed only on the first connection to a server with enhanced security. After the first
connection, the SESSIONSECURITY parameter value of a node changes from
TRANSITIONAL to STRICT. To retry certificate exchange between clients and servers at versions
earlier than V8.1.2, complete these steps:
For clients and servers at V8.1.2 and later, the certificates are automatically distributed.
If communication between clients or servers fails, complete these steps to retry certificate acquisition:
|
You want to manually distribute certificates to client systems. | The IBM Storage Protect server administrator can
automatically deploy a backup-archive client to update workstations where the backup-archive client
is already installed. For information, see Automatic backup-archive client deployment. To manually add certificates to clients, see Configuring IBM Storage Protect client/server communication with Secure Sockets Layer. |
You want to reset certificates for client-to-client sessions. | The dsmcert utility that is installed with the IBM Storage Protect backup-archive client is used to create a certificate store for server certificates. Use the dsmcert utility to delete the files and re-import the certificates. |
As a root user, you want to allow non-root users to manage your files. | The trusted communications agent (TCA), previously used by non-root users in V8.1.0 and
V7.1.6 and earlier IBM Storage Protect clients, is no longer
available. Root users can use the following methods to allow non-root users to manage their files:
If neither of these methods are satisfactory, you must use the earlier clients that included the TCA. |
You want to resolve GSKit compatibility issues. | When multiple applications that use GSKit are installed on the same system, incompatibility
issues might occur. To resolve these issues, see the following information:
|