cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1255
Views
5
Helpful
8
Replies

Upgrade FMCv 7.2 to 7.2.1 - signature validation fails?

I've got a FMCv in the lab and am attempting to upgrade from 7.2.0.1-12 to 7.2.1-40, however it is failing the upload from the workstation to the server.  Product Updates, Upload Update, choose file and click upload.  It goes through the motions and then an error pops up saying:fmc-error-1.jpg

The syslog message above indicates the same thing.  I have verified the SHA-512 hash on the workstation I'm uploading it from and its correct.  I've also downloaded it again via a different browser and get the same error when uploading it.

I have checked the disk space requirements and there is 159GB in /Volume and 2GB in /, both of which are more than enough (22GB & 20MB according to the release notes).

The only thing that looks odd is the timestamp on the two syslog messages as they appear to be an hour in front?

Any ideas?

8 Replies 8

Chakshu Piplani
Cisco Employee
Cisco Employee

A defect has been filed: https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwd20551

Regards,

Chakshu

Do rate helpful posts!

Thanks for the BugID @Chakshu Piplani . Multiple people were reporting the same issue in the Firepower Foundry WebEx space. I also confirmed it on one of my deployments.

How much testing actually happens....

Just tried upgrading a locally managed failover pair of FTDvs from and to the same version (7.2 -> 7.2.1) and this failed with a certificate error (uploaded the image to the standby unit and clicked upgrade and it failed around 50% with this certificate error).  There aren't any certificates installed other than what are built-in or self created as part of the initial build.

I'll refer to my last email - How much testing actually happens....

Most likely you are seeing the same root cause manifesting itself differently when using FDM. The upgrade package is digitally signed using a code-signing certificate. The FDM error is actually a bit more illuminating in that respect in that it points us to a certificate being the problem vs. the more generic "validation" error in FMC.

Marvin Rhoads
Hall of Fame
Hall of Fame

There is a new download available - same file name but updated hash. Apparently something in the original image was corrupted.

I have used it to upgrade two FMCs successfully.

Chakshu Piplani
Cisco Employee
Cisco Employee

That's right @Marvin Rhoads the new image is live.

Is the FTD upgrade replacement to follow?

This is error message when upgrading the on-board managed FTD if it helps.

ftdv-upgrade-fail.jpg

Review Cisco Networking for a $25 gift card