05-14-2014 07:03 AM - edited 03-10-2019 09:43 PM
Hello.
I'm using ACS on virtual machines with a primary and secondary instances.
The primary server also functions as a log collector in my deployment. I don't use AD. LDAP is configured.
Now I need to upgrade to 5.5.
Reading installation guide I find this note..
Upgrading to ACS 5.5 may fail if any LDAP identity store is configured without groups or attributes and
an AD identity store is not configured. To avoid this issue, before upgrading to ACS 5.5, either add
groups or attributes to the LDAP identity store or configure an AD identity store.
How can I verify this?
Thanks.
Regards.
Andrea
Solved! Go to Solution.
05-30-2014 07:28 AM
Give it some time, GUI should come up.
you cannot delete configuration from the CLI.
if the GUI does not come up, you need to get the DB fixed from TAC.
Regards
Ed
10-20-2014 05:12 AM
Hello Andrea,
You're probably facing the BUG CSCun85949
https://tools.cisco.com/bugsearch/bug/CSCun85949/
This issue has been resolved in ACS 5.5 patch 3 but You need to delete and recreate some AV pair to run runtime process correctly.
My suggestion is to delete the AV pair from authorization profile BEFORE upgrade 5.5.
Have a nice day
Regards
Gabriele
05-19-2014 11:52 PM
Hey Andrea,
Go to External Identity stores-->LDAP
Go to directory attributes, directory groups and check, it should not be empty, at least one of them should be populated.
Rate if Useful :)
Sharing knowledge makes you Immortal.
Regards,
Ed
05-21-2014 05:27 AM
Hello Edward and many thanks for your help.
Groups and attributes are empty. So I need to populate for the upgrade only and remove settings when upgrade is done!
And AD? What's about it?
Regards.
Andrea
05-22-2014 12:36 AM
Andrea,
Yes populate them before upgrade and remove later.
No issues with AD, leave it in what ever condition it is.
Rate if Useful :)
Sharing knowledge makes you Immortal.
Regards,
Ed
05-22-2014 01:11 PM
Many thanks Edward.
So with my deployment, where the primary server also functions as a log collector and only one secondary is present, I need to deactivated the secondary and delete it from instances table.
With two primary, and standalone server, I can upgrade it independently. When upgrade is done I can register to primary again.
Regards.
Andrea
05-22-2014 09:38 PM
After the upgrade, runtime process is not monitored and application doesn't respond.
Any ideas?
Thanks.
acsdue/admin# application upgrade ACS_5.5.0.46.tar.gz patch
Do you want to save the current configuration ? (yes/no) [yes] ?
Generating configuration...
Saved the running configuration to startup successfully
% CARS Install application required post install reboot...
Broadcast message from root (pts/0) (Fri May 23 00:04:11 2014):
The system is going down for reboot NOW!
Application upgrade successful
acsdue/admin#
Connection was reset.
Copyright(c) 2013 Cisco Systems, Inc. All rights Reserved
Last login: Thu May 22 23:13:39 2014 from 10.164.0.1
Copyright(c) 2013 Cisco Systems, Inc. All rights Reserved
acsdue/admin#
acsdue/admin# sh app status acs
ACS role: PRIMARY
Process 'database' running
Process 'management' running
Process 'runtime' not monitored
Process 'ntpd' running
Process 'view-database' running
Process 'view-jobmanager' running
Process 'view-alertmanager' running
Process 'view-collector' running
Process 'view-logprocessor' running
acsdue/admin#
05-22-2014 10:51 PM
Andrea,
The procedure you followed was correct.
Did you try starting the service manually?
"acs start runtime"
Rate if Useful :)
Sharing knowledge makes you Immortal.
Regards,
Ed
05-23-2014 01:54 AM
Yes Edward.
I try starting it manually also.
Reimage maybe the solution....
Thanks.
Andrea
05-23-2014 05:53 AM
Re-image might be an option, you might have a backup from the older version.
If you wish to share the logs, I can have a look at it.
Regards
Edward
05-26-2014 07:15 AM
Edward,
I'm trying to reimage. After a successfully restore, application is initializing... forever....
acsuno/admin# sh app sta acs
Application initializing...
Status is not yet available.
Please check again in a minute.
acsuno/admin#
Any ideas?
Regards.
05-26-2014 07:22 AM
Which version is the backup from?
What version are you at now?
Regards
Ed
05-26-2014 08:01 AM
Backup comes from 5.3, patch 9 and Pointed-PreUpgrade.
Restore to 5.5, fresh installation without any patches.
acsuno/admin# sh ver
Cisco Application Deployment Engine OS Release: 2.1
ADE-OS Build Version: 2.1.1.129
ADE-OS System Architecture: i386
Copyright (c) 2005-2013 by Cisco Systems, Inc.
All rights reserved.
Hostname: acsuno
Version information of installed applications
---------------------------------------------
Cisco ACS VERSION INFORMATION
-----------------------------
Version : 5.5.0.46
Internal Build ID : B.723
acsuno/admin#
05-27-2014 12:01 AM
After applying restore, there is another encryption patch that you need to get from TAC.
Rate if Useful :)
Sharing knowledge makes you Immortal.
Regards,
Ed
05-27-2014 06:49 AM
Sorry Edward, is it related to bug ID CSCum67932? If so, this bug is resolved with cumulative patch 2.
Anyway I apply patch 3 and then restore with success.
When virtual machine reboots, service runtime is not monitored again: this is the same issue I have got with application bundle.
Ideas?
Thanks.
Regards.
Andrea
05-28-2014 12:07 AM
Ok good, yes that was the defect, Could you share the debugs:
>acs-config
login with GUI username
>debug-log runtime level debug
Collect the support file from the ACS and attach it.
http://www.cisco.com/c/en/us/td/docs/net_mgmt/cisco_secure_access_control_system/5-5/user/guide/acsuserguide/viewer_troubleshooting.html#pgfId-1057672
Rate if Useful :)
Sharing knowledge makes you Immortal.
Regards,
Ed
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide